Skip to content

GPS Tracking of Sales Reps Under Vietnam Data Protection Law: What the New Rules Require

What GPS tracking of sales reps under Vietnam's data protection law actually requires inside a field app: the consent prompt, the lead-source trail, and the rep-versus-customer data split.

5 min read

A four-step diagram showing what GPS tracking of sales reps under Vietnam data protection law changes inside a field sales app's consent, logging and data-handling screens.

Most English-language coverage of GPS tracking of sales reps under Vietnam data protection law stops at the statute. Law-firm explainers and market-entry advisories get the legal summary right — consent has to be explicit, the rules changed — but none of them go on to say which screen in a field sales app actually needs to change because of it.

Some of what's circulating is also just outdated. This piece skips the legal summary and goes straight to the engineering: three concrete places the new law touches a field app, and where the old rules still get cited by mistake.

Four steps showing how GPS tracking of sales reps under Vietnam data protection law changes a field app's consent prompt, lead-source logging, data-subject split and consent record.
None of this is abstract policy — each item maps to one specific screen or field inside a field sales app.

Law-firm explainers cover the statute; none of them cover your app's location prompt

Most English-language coverage of this topic stops at the statute. Law-firm explainers and market-entry advisories get the legal summary right — consent has to be explicit, the rules changed — but none of them go on to say which screen in a field sales app actually needs to change because of it.

Some of what's circulating is also just outdated. Decree 13/2023 governed personal data protection before it was superseded; from January 1, 2026 the operative framework is Law No. 91/2025/QH15 — the Personal Data Protection Law, passed and officially announced in June 2025 — together with its implementing Decree 356/2025/NĐ-CP. Enough English content still cites Decree 13 as current that it's worth checking any compliance document you've been handed against that date before trusting it.

Location consent needs its own explicit prompt, not a line inside general terms

The new law requires consent that's explicit, verifiable and traceable — not implied, and not satisfied by an opt-out. For a field app, that means the first time it requests a rep's location, it needs a standalone prompt explaining why: route verification, visit proof, safety — not a clause folded into a general terms-of-service screen tapped through once at onboarding.

"Explicit and verifiable" also means the app has to record that consent happened — who, when, and which version of the prompt they saw — not just proceed once a checkbox is ticked. If a rep or a regulator ever asks whether consent was actually given, the answer needs to come from a log, not from memory.

  • A standalone prompt the first time location is requested, not a clause inside general terms
  • A record of who consented, when, and to which version of the prompt
  • No default-on tracking and no opt-out-only design — implied consent isn't sufficient under the new standard

Every lead needs a traceable source, not just a name and a phone number

The list a field team works from is personal data with its own provenance requirement. Each entry needs a traceable source — which visit, which referral, which public listing it came from, and when it entered the system. A list that's just names with no origin field is the kind of gap that's easy to ignore until someone specifically asks where a contact came from.

This matters more the moment a list gets merged from multiple sources or brought in from a third party. Whatever field app sits behind the list needs to carry that source field forward through the merge, not drop it the moment a record gets imported — the traceability requirement doesn't go away just because the record changed hands.

Rep data and customer data are two different data subjects, not one bucket

A field sales app collects two categories of personal data at once: the rep's own location and activity, and the customer's contact and visit details. They have different legal bases for collection, different retention logic, and often a different set of people who should be allowed to see them — but most field apps store both in the same visit record and apply one blanket policy across it.

Splitting them means separate consent flows: one for the rep as an employee tracked for work purposes, one for the customer as an outside contact engaged for a business relationship, and being able to answer, for each independently, what was collected, why, and how long it's kept.

None of this is legal advice, and it isn't meant to be. It's the engineering translation of what the statute requires — the actual consent wording and retention schedule still need sign-off from local counsel before any of it ships.

FAQ

What law governs GPS tracking of sales reps in Vietnam now?
From January 1, 2026, the operative framework is Law No. 91/2025/QH15 (the Personal Data Protection Law, passed in June 2025) together with its implementing Decree 356/2025/NĐ-CP. Decree 13/2023, which a lot of older articles still cite, was superseded.
Do we need to re-collect consent for reps already in the system?
Data already processed under the old Decree 13 framework doesn't need retroactive consent. Anything collected from January 1, 2026 onward — new hires, new prompts, re-consent flows — has to meet the new law's standard: explicit, verifiable, and not opt-out.
Can a general terms-of-service checkbox cover location tracking consent?
Not under the explicit-consent standard. A field app needs its own standalone prompt the first time it requests location, plus a record of who agreed, when, and to which version — not a clause folded into a broader onboarding screen.
Should rep location data and customer contact data be handled the same way?
No. Treat them as two different data subjects with separate consent, separate retention logic and separate access rules, even if they currently sit inside the same visit record.
Is this legal advice?
No. This is engineering guidance for what to build into the app. Have local counsel confirm the actual consent wording and retention schedule for your business before you ship it.

Related reading

Want to see a system actually running?

Tell us the stage that hurts most, and we'll bring the working system to the conversation.

Book a demo