Children's Data Under Decree 330/2026: Has the Old Dual-Consent Rule Come Back?

Must a business obtain both the child's consent and the consent of the child's legal representative, a parent or guardian (dual consent), whenever it processes the personal data of a child aged 7 or over? Under the Personal Data Protection Law (PDPL), the answer is no. Dual consent is required only for processing that would disclose the child's private life or personal secrets. For other processing, the legal representative consents on the child's behalf, and the child's own consent is not required (Article 24.2 of the PDPL). However, Decree 330/2026 of the Government on administrative penalties for violations in the fields of cybersecurity and personal data protection (Decree 330/2026) seems to apply dual consent to a broader set of circumstances. Article 60.1(c) of Decree 330/2026 fines processing of the data of a child aged 7 or over without dual consent. That rule was taken from Decree 13/2023, which ceased to have effect on 1 January 2026.

1. The PDPL rule and the Decree 330/2026 rule

Decree 13/2023, the former personal data decree, required dual consent for processing a child's data from age 7 generally, not only for disclosure (Article 20.2 of Decree 13/2023). The PDPL, in force from 1 January 2026, kept dual consent only for disclosure of private life and personal secrets. Decree 13/2023 ceased to have effect on the same day (Article 42.2 of Decree 356/2025). Decree 356/2025 guiding the PDPL contains no rule specific to children, such as an age threshold or a parental-consent rule. Its only reference that touches children is indirect. It lists the processing of personal data through educational software with monitoring features, such as attendance, video recording or emotion recognition, among the personal data processing services it regulates (Article 21.5 of Decree 356/2025).

Under the PDPL, the legal representative's consent is the baseline. The legal representative of a child is the parents, the guardian or a person appointed by a court (Article 136 of the Civil Code 2015). Consent is one of the data subject's rights, and for a child those rights are exercised by the legal representative (Articles 4.1(b) and 24.2 of the PDPL). The child's own consent is added in one case only. Under the PDPL, where consent is the basis for processing, the position is:

Age

Ordinary processing

Processing to disclose private life or personal secrets

Under 7

Legal representative

Legal representative

7 to 15

Legal representative

Legal representative and child

16 and 17

The minor (người chưa thành niên) alone (not a "child")

The minor alone

The table applies to all organisations and individuals that process a child's data. No consent is needed at all, not even the legal representative's, where one of the PDPL's no-consent cases applies (Article 19.1 of the PDPL). Examples are performing an agreement with the data subject and urgent protection of life or health. This post assumes that "child" has the meaning given in the Law on Children 2016, which defines a child as a person under 16 (Article 1). Under the Civil Code 2015, a minor is a person under 18 (Article 21.1).

The laws do not define "private life or personal secrets". Decree 56/2017 detailing the Law on Children lists a child's name, age, image, school, results and friendships, among other things, as private information (Article 33 of Decree 56/2017). So the dividing line appears to be the purpose of the processing rather than the type of data. Using a child's data to provide a service, such as registering the child for an offline class, is likely to be ordinary processing. Making it visible to others, such as on a public profile, a leaderboard or a school website, could be disclosure. So could showing it to a limited group, such as classmates.

Article 60.1(c) of Decree 330/2026 now sanctions the old rule, at VND 30 to 50 million for an organisation. The fines are modest, but the remedies are not. For violations of Article 60, Decree 330/2026 orders deletion of all personal data processed unlawfully (Article 60.5(b)). How much data must be deleted depends on which data was processed unlawfully. For an education, games or family-app business whose consent flow was built on the PDPL alone, the exposure could be significant.

2. Two readings

On a literal reading of Article 60.1(c) of Decree 330/2026, dual consent is required for any processing of the data of a child aged 7 or over, unless one of the PDPL's no-consent cases applies. Those cases include performing an agreement with the data subject and urgent protection of life or health. Article 60.2(a) of Decree 330/2026 separately fines processing that discloses a child's private life without dual consent, at a higher level of VND 50 to 100 million for an organisation. If Article 60.1(c) also covered only disclosure, the two would overlap, which points to Article 60.1(c) being wider.

The alternative reading confines Article 60.1(c) to what the PDPL requires. The rules on drafting sanctions decrees require each offence to involve a breach of an obligation, responsibility or prohibition under the law (Article 4.1 of Decree 118/2021, as amended). An inspector would answer that Article 24.2 of the PDPL does not say its disclosure rule is the only case requiring the child's consent. But Article 24.2 makes a deliberate allocation. The legal representative acts for the child, and the child's own consent is added only for disclosure. That is also the position of the Law on Children 2016 and its implementing decree (Article 6.11 of the Law on Children 2016; Article 36.1 of Decree 56/2017). The PDPL replaced Decree 13/2023's broader rule, and a decree should not reinstate what a law has narrowed.

In our view, the second reading is the more reasonable one: Article 60.1(c) of Decree 330/2026 should be read as confined to what the PDPL requires, because it would otherwise impose a duty that the PDPL chose not to impose. But the first reading is the enforcement risk. Until an authority confirms the narrower reading, businesses that process children's data should plan for the wider one.

This blog is written by Ha Thanh Phuc.