EYC
Early Years Circle - EYC
Operations, HR & Finance8 min read · Published · Updated

Protecting Children's Data in Preschools Under Current Vietnamese Law

E
Prepared by Early Years Circle Editorial Team
3 references
Protecting Children's Data in Preschools Under Current Vietnamese Law
Share this guide
Since 1 January 2026, Vietnam's Personal Data Protection Law No. 91/2025/QH15 and Decree 356/2025/ND-CP have been the central instruments schools should check when processing personal data. For young children, responsible practice begins with clear decisions about purpose, scope, access, retention, and how the school responds when a guardian changes their choice—not with a technology feature.
01.

1. Map the data before requesting it

List each category of data the school collects and connect it to a specific operational purpose. Habitual collection and indefinite retention increase risk without necessarily helping children or families.

  • Enrollment records: identity details, guardian contacts, and authorized pickup persons.
  • Care and health information: allergies, medication, relevant conditions, and emergency contacts.
  • Photos, video, and learning work: distinguish internal use, private family sharing, and public promotion.
  • Cameras or biometrics: assess necessity and less intrusive alternatives before deployment.
02.

2. Make consent understandable and manageable

A single blanket form can obscure what a family is agreeing to. Separate choices by purpose, use plain language, and retain a record of the date, scope, and any later change.

  • Explain what data is used, for what purpose, who may receive it, and how long it is kept.
  • Do not bundle essential care administration with permission for promotional media.
  • Provide a clear contact for questions, corrections, and changed choices.
  • When a choice changes, update access and relevant sharing channels.
03.

3. Limit access to the work each role performs

Teachers, health staff, finance teams, admissions staff, and leaders do not automatically need the same access. Permissions should follow responsibilities.

  • Review accounts when staff move classrooms, change roles, or leave.
  • Limit downloads to personal devices and avoid channels the school cannot administer.
  • Keep records of significant actions such as viewing, editing, exporting, or sharing a child record.
  • Define how staff report and respond to misdirected messages, lost devices, or unusual access.
04.

4. Set retention and deletion schedules

Different records may have different retention duties. Compare sector recordkeeping rules, contracts, and data-protection requirements before setting a schedule for each category.

  • Assign an owner and review date to each data store.
  • Delete or anonymize copies that no longer have a valid purpose.
  • Include exports, old devices, shared folders, and service providers in the review.
⚠️ This checklist is not a legal conclusion for every situation. Health data, public media, biometrics, and third-party transfers require context-specific assessment.

★Executive Summary

A trustworthy data program can answer five questions: what the school collects, why it is needed, who can see it, how long it remains, and what happens when a family requests a change. Technology supports those decisions after they are clear.

Before you apply this guidance

This article provides general information, not legal advice, medical diagnosis, or emergency instructions. Check the rules currently in force and consult the relevant authority or qualified professional for your specific situation.

Updated
Early Years Circle

Turn guidance into a workable school process

Early Years Circle organizes admissions, tuition, classrooms, food service, and family communication in one connected workflow.

Share this guide

Want clearer workflows for your school?

Talk with Early Years Circle about the day-to-day operational needs of your campus.

Request Demo