Short answer: Vietnam's Personal Data Protection Law (91/2025/QH15) took effect on 1 January 2026, and the 2026 penalty decree raised fines sharply for illegal trading or mishandling of personal data. If your business uses web forms, chatbots, Zalo, or a CRM to collect customer phone numbers and details, review it now — not to panic, but to collect only what is needed, store it correctly, and be able to delete it on request.
This article is for owners and operators putting AI into customer care. It focuses on operations and engineering, not legal advice. For specific legal questions, consult a lawyer or compliance advisor.
What the law changes for AI-driven businesses
The core point: customer personal data — name, phone, email, purchase history, even chat logs — may only be collected and processed on a valid basis, usually the customer's clear consent. Chatbots and AI agents make collection automatic and large-scale, so careless setups carry more risk.
Seven things to review before AI touches customer data
- List every collection point: web forms, chatbot, Zalo OA, landing pages, spreadsheets, CRM.
- For each, record what is collected, who holds it, where, and for how long.
- Show clear consent before collecting, and let customers withdraw it.
- Limit access: which people and systems can read customer data.
- Audit third parties: where the chatbot/AI sends data, and whether a data-processing agreement exists.
- Provide a real deletion path on request, not just hiding records.
- Keep logs of who accessed, edited, or deleted which data and when.
Design principle: collect what you need, not for the sake of it
A well-built AI flow does not ask for everything. It asks for what the next step needs. Booking needs a name, phone, and time slot — not a home address. Less data means less risk and more trust.
What chatbots usually collect, and how to handle it
| Data | Basis | Where to store | How to delete |
|---|---|---|---|
| Name, phone | Consent when leaving contact | Access-controlled CRM or sheet | Delete record on request, with a log |
| Chat content | Consent + care purpose | Conversation store with retention | Auto-expire or manual delete |
| Purchase/booking history | Performing the requested service | Internal operations system | Anonymize when no longer needed |
| Sensitive data (health…) | Explicit consent, stricter | Separate store, least-privilege access | Deletable, with access logs |
AI is not what makes you non-compliant — careless use is
You do not need to drop chatbots. The problem is uncontrolled use: over-collection, scattered storage, no accountable owner. A properly designed AI flow can make compliance easier because every collection, storage, and deletion point sits in one logged system instead of on staff phones.
How Golden Sea approaches this
Golden Sea builds AI customer-care flows that collect only what is needed, store it correctly, delete it on request, and keep a human reviewing sensitive cases. Data compliance is designed in from the start, not patched on later.
FAQ
Is using a chatbot to collect phone numbers illegal?
No, if you have a valid basis — usually clear consent — and you collect for a stated purpose, store safely, and can delete on request. Violations come from covert collection, misuse, or selling data.
Do small businesses have to comply?
Yes. The law applies to the act of processing personal data, with no exemption by size.
Read more: AI Automation services, AI Inbox & Lead Assistant.
Sources and limitations
Based on Personal Data Protection Law 91/2025/QH15 and its 2026 implementing/penalty decrees. This is general operational information, not legal advice; verify specific fines and clauses against the original texts.





