Ngày đi
Ngày về
Thank you for trusting and using Vietjet’s services through the website www.vietjetair.com, mobile application, Vietjet Skyjoy membership program, customer support center, or ticket agents. We are committed to respecting and protecting your personal data, ensuring that all personal data collected is processed securely and transparently in accordance with legal regulations. This Personal Data Protection Policy explains how We collect, use, store, share, and protect your personal data, and also clarifies your rights related to your personal data, including updates related to personal data integrated into the VNeID and Galaxy Pay (GPay) systems (hereinafter referred to as the “Policy”).
This Policy applies to all personal data that you consent to provide and share with Us during your use of Vietjet’s services. We recommend that you carefully read this Policy to clearly understand how We process your personal data.
This Policy is made available in both Vietnamese and English. In the event of any inconsistency or discrepancy between the two language versions, the Vietnamese version shall prevail and be the binding version for all purposes.
Capitalized terms in this Policy shall have the meanings as set out below:
1.1. “We” or “Vietjet”: refers to Vietjet Aviation Joint Stock Company, headquartered at 302/3 Kim Ma Street, Ngoc Ha Ward, Hanoi City;
1.2. “Services”: means passenger transportation services, customer support services, and other services provided by Vietjet via websites, mobile applications, the Vietjet Skyjoy membership program, customer support centers, and/or in cooperation with Partners to provide services to you;
1.3. “Personal Data”: means data in digital or other forms that identifies or helps identify a specific individual, including basic personal data and sensitive personal data;
1.4. “Basic Personal Data”: means personal data reflecting identity and general background factors commonly used in transactions and social relationships, as prescribed by the Government;
1.5. “Sensitive Personal Data”: means personal data associated with an individual’s privacy, which when infringed upon may directly affect the lawful rights and interests of organizations and individuals, as prescribed by the Government;
1.6. “Partner”: means any organization, enterprise, or third party that provides services to Vietjet or has cooperation/affiliation with Vietjet to support service provision to you, including but not limited to service providers, contractors, agents, and affiliated parties;
1.7. “Contract of Carriage”: means agreements between Vietjet and you, whereby We transport you and your baggage to a destination and you are required to pay transportation service fees. The contract of carriage is evidenced by a ticket or other equivalent form;
1.8. “Personal Data Protection Personnel” or “DPO (Data Protection Officer)”: means an individual or department appointed/designated by Vietjet to organize and supervise compliance with personal data protection laws and internal policies; to advise and assess risks in personal data processing activities; and to act as the focal point for receiving and handling requests, complaints, and issues related to your personal data;
1.9. “Customer”: means an individual who directly or indirectly uses, registers to use, or is related to the use of Vietjet’s products and services, including but not limited to passengers, ticket bookers, contact persons, or individuals providing personal data to Vietjet; and is also the data subject under applicable personal data protection laws, within the scope of data processed by Vietjet;
1.10. “Account”: means a set of identification and access information created and managed by you within Vietjet’s system, allowing you to log in, authenticate identity, use Services, and conduct transactions with Vietjet;
1.11. “Mobile Application”: means software applications owned, managed, or operated by Vietjet, installed on mobile devices (including but not limited to smartphones and tablets), enabling you to access information, register, use products/services, or conduct transactions with Vietjet;
1.12. “Website”: means Vietjet’s official electronic information pages, including but not limited to domains, subdomains, and related web pages/applications owned, managed, or operated by Vietjet, allowing you to access information, register, use products/services, or conduct transactions with Vietjet.
We are committed to complying with the following principles when processing your Personal Data:
2.1. Your Personal Data is processed lawfully, fairly, transparently, and in compliance with applicable legal regulations;
2.2. Your Personal Data is collected with your voluntary consent for specific, clear, and lawful purposes and will not be processed beyond the purposes stated in this Policy, relevant service policies, and legal regulations;
2.3. Your Personal Data is stored selectively and only to the extent necessary for processing purposes in accordance with the law;
2.4. Your Personal Data is accurate, updated, and any inaccurate data related to processing purposes will be promptly deleted or corrected in accordance with applicable laws;
2.5. Your Personal Data is protected by appropriate security measures during processing, including protection against violations of personal data protection regulations and prevention of loss, destruction, or damage through technical measures;
2.6. We commit to implementing appropriate internal processes to raise awareness among all employees and ensure compliance with these principles within Our organization;
2.7. We ensure that individuals and organizations with whom We share Personal Data also comply with equivalent levels of data protection under contracts with Us;
2.8. In addition, We commit to complying with other principles prescribed by Vietnamese law and the laws of countries where We process Personal Data.
During your use of the Services, We may process the following basic Personal Data:
Identification information: Full name, date of birth, gender, nationality, passport number, ID card/citizen identification number.
Contact information: Email address, phone number, residential address.
Booking and itinerary information (PNR/API): Flight details, ticket price, booking date, itinerary, reservation information, additional services (baggage, standard meals).
Loyalty program information: Vietjet Skyjoy membership number, membership tier, reward points balance, reward transaction history.
Payment information (basic level): Cardholder name, payment method.
Communication information: Content of emails, messages, calls, complaints, surveys (excluding sensitive content).
Information from social media and third-party platforms: Name, email, and other information shared according to your privacy settings.
Photo library access: Profile images (standard image format).
Interaction and technical data:
IP address, browser type, browser version.
Pages visited, access time, time spent on each page.
Login ID, search history, cookies (session and persistent).
Device identifiers, diagnostic data.
Application access permissions: Access to photo library, camera, or other permissions granted by you through your device.
We may process sensitive Personal Data within the necessary scope and in compliance with legal regulations:
Biometric data: Portrait images (used for identification), selfie videos, facial recognition data, fingerprints, electronic identification data from VNeID, and eKYC data.
Identity documents: Images of identification documents (ID card/passport).
Detailed payment information: Card number, expiration date, CVV, and other payment-related transaction data.
Health data: Information about health conditions or special assistance needs (wheelchair, oxygen, allergies, etc.).
Information that may reveal beliefs or religion: For example, special meal requests related to religion.
Precise location data (if any): Real-time geolocation data from the Application (to determine the nearest airport).
We process your Personal Data to provide the best services, ensure safety, comply with legal requirements, and enhance customer experience. The specific purposes include:
We process your Personal Data for the purpose of performing the Contract of Carriage and providing Services to you, including:
a) Ticket issuance and transportation: We use your identification information (including full name, date of birth, passport number or citizen identification number) and contact information to complete the booking, ticket issuance, check-in process, identity verification, perform automated airport procedures (auto-gate), as well as to notify you of flight schedule changes and provide services related to your itinerary.
b) Identity verification and fraud prevention: We may integrate and use Personal Data from identity and payment platforms (such as VNeID, Galaxy Pay) to perform electronic Know Your Customer (eKYC) securely. For features such as online check-in, biometric data (e.g., portrait images, facial recognition data) may be used, subject to your consent, to verify identity, shorten processing time, and enhance accuracy.
c) Provision of special services: We may process certain sensitive Personal Data (e.g., information related to health conditions or special meal requests) based on your explicit consent in order to provide services tailored to your individual needs.
d) Enhancement and optimization of user experience: We analyze usage data to improve the interface, content, and performance of the Website and Mobile Application, as well as to enhance Service quality.
e) Marketing and promotional communications: Where you provide consent, We may use your Personal Data to send information about promotions, advertisements, or marketing content that is relevant to your needs and usage behavior.
f) Compliance with legal obligations: We may process and provide your Personal Data to competent State authorities upon lawful request, in accordance with applicable laws and regulations.
g) Automated Decision-Making: In certain cases, We may use automated processing systems (e.g., auto-gate systems or restricted passenger list screening) to make decisions that may affect you. In such cases, you have the right to (i) request human intervention instead of decisions based solely on automated processing; (ii) object to and request an explanation of the decision made; and (iii) lodge a complaint through Vietjet’s customer support channels in accordance with applicable regulations.
We process the Personal Data of members of the Vietjet SkyJoy membership program for the purpose of managing, operating, and enhancing the quality of the program, including:
a) Updating member information: Sending notifications related to the program such as new policies, offers, promotions, or changes to applicable terms and conditions.
b) Booking and service management: Using membership account information to support the booking process, ticket issuance, reward point accumulation, redemption, and the provision of related services within the program.
c) Data analysis: Evaluating flight history, behavior, and preferences of members in order to personalize the experience, as well as to provide suitable products, services, or offers.
d) Customer support: Receiving and handling requests, inquiries, or complaints from members to improve service quality and user experience.
We process Personal Data related to payment activities to ensure transaction security and compliance with legal regulations, including the following purposes:
a) Transaction authentication: Using your Personal Data (including full name, card information, and related identification data) to verify the identity of the account holder, thereby ensuring that transactions are conducted lawfully and securely.
b) Fraud prevention: Storing data in accordance with electronic Know Your Customer (eKYC) processes to detect and prevent impersonation, fraud, or unauthorized use of payment information.
c) Legal compliance: Providing payment information and related data to competent State authorities, including the State Bank of Vietnam or other relevant authorities, upon lawful request for inspection, supervision, or auditing purposes.
Vietjet, as an international airline, has a legal obligation to collect and share passenger data, including Passenger Name Record (PNR) data and Advance Passenger Information (API), with competent State authorities in the countries where We operate routes. These authorities may include border and immigration authorities, customs authorities, security and counter-terrorism agencies, and other law enforcement authorities in accordance with relevant international treaties or bilateral and multilateral cooperation agreements.
The sharing of PNR/API data is carried out in accordance with international regulations and standards, including the Guidelines on Passenger Name Record (PNR) Data (Doc 9944) of the International Civil Aviation Organization (ICAO), Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime, applicable to flights to, from, or transiting through the European Union, as well as international agreements to which Vietnam is a party or has entered into with relevant countries.
You have the right to request information regarding the scope and the countries that have received your PNR/API data by contacting Vietjet’s DPO using the contact details provided in this Policy.
We process your Personal Data to ensure aviation security and safety and to comply with relevant legal regulations, including the following purposes:
a) Passenger screening: Verifying your identity prior to boarding to ensure flight safety and compliance with aviation security requirements.
b) Management of restricted passenger lists: Establishing and maintaining a list of passengers who are denied carriage in accordance with regulations in order to protect the safety of the public, passengers, and flight operations.
c) Sharing information with competent authorities: Providing your Personal Data, booking information, or itinerary details to competent State authorities (including border, customs, immigration, or security authorities) upon lawful request to support state management and the prevention and handling of legal violations.
We process your Personal Data to support financial and accounting activities and to ensure compliance with related legal obligations, including:
a) Record retention: Collecting and storing your transaction information for accounting purposes, financial reporting, and auditing in accordance with applicable regulations.
b) Legal compliance: Fulfilling related legal obligations, including meeting tax requirements, financial inspections, or providing information upon lawful request from competent State authorities.
We process your Personal Data to enhance Service quality and customer experience, including the following purposes:
a) Handling inquiries and complaints: Using your contact information to receive and respond to questions, handle complaints, and support requests arising during your use of the Services.
b) Service improvement: Analyzing your Personal Data and feedback to upgrade the Website, Mobile Application, operational processes, and to design suitable products, services, or promotional programs.
c) Customer surveys: Conducting surveys to collect feedback, assess satisfaction levels, and understand your needs, thereby improving Service quality.
d) Personalized customer support: Using identification information and transaction history to provide support tailored to each customer, helping to shorten processing time and improve support efficiency.
We process your Personal Data for marketing and communication purposes based on your consent, including:
a) Sending promotional information: Providing information about promotional programs, special fares, additional services, or related products via email, messages, or other communication channels.
b) Personalizing marketing content: Analyzing your preferences, behavior, and service usage history to provide advertisements and offers tailored to your individual needs.
c) Managing and implementing marketing campaigns: Contacting you to inform you about promotions, marketing activities, or surveys to improve Service quality and customer experience.
You have the right to opt out of receiving marketing communications at any time by using the unsubscribe function provided in such communications or by contacting Us directly using the contact information provided in this Policy.
We may collect your Personal Data through the following methods:
We will request that you provide your Personal Data when you access the Website, install and use the Mobile Application, contact us to book flights, check in, create an online account, register for programs, submit requests, communicate directly with us, or via email, phone, chatbot, etc.
If you provide Personal Data of another individual, we will also process such Personal Data. In this case, you are responsible for ensuring that you are authorized to provide that individual’s Personal Data; and that such individual or their legal guardian fully understands this Policy and voluntarily consents to providing their Personal Data to us.
We receive your Personal Data from third parties such as agents, ticket offices, travel agencies, online booking platforms, service providers, social media platforms, Partners, and competent State authorities for the purpose of providing Services to you.
When you use our Website and Mobile Application, we collect your information through cookies and similar technologies.
Cookies are text identifiers that are downloaded and stored on your computer’s hard drive when you access our Websites. Each time you revisit the Website, our system may recognize your device, store information about visits and visitors, and automatically log you in when necessary. We use cookies to make it easier for you to access the Website.
For more detailed information, please refer to our Cookie Policy available on the Website or Mobile Application.
Our Services are provided globally. In order to serve you and deliver a consistent experience across all our destinations, we need to share your Personal Data with third parties both domestically and internationally. The sharing of your Personal Data with these third parties is carried out on the basis of contracts or agreements to ensure that your Personal Data is protected at a level consistent with this Policy and applicable laws.
Vietjet’s officers and employees process your Personal Data to fulfill the purposes set out in Article 4 of this Policy.
Vietjet has subsidiaries and affiliated companies in Vietnam and in several other countries worldwide. Vietjet shares your Personal Data with these entities to carry out the purposes set out in Article 4 of this Policy.
Vietjet may also share your Personal Data with legal advisors, tax consultants, accountants, and auditors to carry out activities related to internal business operations and dispute resolution.
We share your Personal Data with other airlines that have cooperative arrangements with us to provide transportation services to you; ground handling service providers for passengers and baggage; delivery and logistics service providers; infrastructure developers; technical infrastructure developers; information technology system developers; logistics and terminal service providers; cloud service providers; data analytics service providers; partners in travel, hospitality, tourism, finance, insurance, and banking card issuers; catering contractors; customer care service providers; and other third parties that provide goods and services for the purpose of enhancing your Service experience. The sharing of your Personal Data with these contractors shall be carried out on a contractual basis to ensure that the information is protected at a level consistent with this Policy and applicable laws.
We may be required to provide your Personal Data to competent State authorities such as customs, immigration, police, and other relevant authorities when they request such data in order to complete mandatory entry procedures or for the purposes of preventing and combating terrorism and other serious criminal activities.
We may transfer your Personal Data to individuals or organizations in other countries in order to fulfill the purposes set out in Article 4 of this Policy, such as Vietjet’s subsidiaries, affiliated companies, offices, branches; third-party providers of goods and services; and competent authorities in other countries. In such cases, we will implement appropriate measures to ensure that your Personal Data is processed securely and in compliance with applicable data protection laws in those countries.
For customers who are citizens of the European Union/European Economic Area (EU/EEA):
Data is processed in accordance with Article 49(1)(b) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation (GDPR)) and/or through Standard Contractual Clauses (SCC) under Implementing Decision (EU) 2021/914 of the European Commission executed with data processing partners.
For PNR/API data shared with foreign competent authorities:
The transfer is carried out in accordance with binding international treaties and the legal regulations of each country. We do not have control over how foreign competent authorities process this data, but we ensure that only the minimum required information is shared in accordance with legal requirements.
For global data processing partners (GDS systems, international payment gateways):
We enter into Data Processing Agreements (DPA) with all international data processing partners to ensure security standards equivalent to those required under Vietnam’s current personal data protection laws and the European GDPR.
Data transfer impact assessment:
We are committed to fully complying with current Vietnamese laws regarding impact assessments for cross-border transfers of Personal Data. Accordingly, prior to transferring Personal Data internationally, we conduct impact assessments to identify potential risks, ensure the lawful rights and interests of data subjects, and implement appropriate protection measures. Assessment records are prepared, maintained, and periodically updated in accordance with legal regulations, and we are prepared to provide them to competent State authorities upon lawful request.
We apply the principle of data minimization in terms of retention period. Accordingly, Personal Data is only stored for the period necessary to fulfill the identified purposes of collection, unless otherwise required by law. The specific retention periods are set out in the table below:
|
Data Type |
Retention Period |
Legal Basis |
|
Booking / itinerary information |
05 years from the flight date |
Decree No. 174/2016/ND-CP detailing certain provisions of the Law on Accounting |
|
SkyJoy membership account |
During account activity + 2 years after termination |
Service contract / SkyJoy membership program terms of use |
|
Payment data, invoices |
05 years |
Decree No. 174/2016/ND-CP detailing certain provisions of the Law on Accounting |
|
Biometric data (check-in) |
Maximum 30 days after the last flight date |
Data minimization principle |
|
Health data / medical requests |
Maximum 90 days after the flight date |
Consent of the data subject; aviation safety |
|
Session cookies |
Until the browser is closed |
Technical requirement |
|
Persistent cookies |
Maximum 13 months |
Consent of the data subject |
|
Complaint / support request data |
03 years from resolution date |
Civil procedure law |
|
Marketing data (with consent) |
Until consent is withdrawn + 30 days |
Consent of the data subject |
|
Restricted passenger list |
As required by competent authorities |
Legal obligations for security |
|
PNR/API data |
As required by each country (typically 05 years) |
International treaties; laws of each country |
|
Personal data processing impact assessment records; cross-border data transfer impact assessment records |
For the entire duration of business operations while such data processing activities are conducted |
Law on Personal Data Protection No. 91/2025/QH15 |
a) To be informed about Vietjet’s Personal Data processing activities;
b) To give or refuse consent, and to withdraw consent for the processing of Personal Data;
c) To view, edit, or request correction of Personal Data;
d) To request the provision, deletion, or restriction of processing of Personal Data; and to object to the processing of Personal Data;
e) To lodge complaints, make denunciations, initiate legal proceedings, and request compensation for damages in accordance with the law;
f) To request competent authorities or relevant organizations and individuals involved in Personal Data processing to implement measures and solutions to protect your Personal Data in accordance with legal regulations.
We will receive and process your requests related to data subject rights within a reasonable timeframe, in accordance with applicable legal regulations. Specifically, we will provide an initial response within 02 (two) working days from the time a valid request is received, and complete the processing within the timeframes corresponding to each type of request as set out in the table below.
In cases where the request is complex or involves third parties, the processing time may be extended. In such cases, we will notify you of the extension (if any), the reason for the extension, and the expected completion time.
We may refuse or be unable to process certain requests in accordance with legal regulations, including but not limited to cases where we cannot verify your identity or where the request affects the lawful rights and interests of third parties. In such cases, Vietjet will clearly inform you of the reason.
|
Type of Request |
Initial Response |
Completion (no third party) |
Completion (with third party) |
Maximum Extension |
|
● Withdrawal of consent for personal data processing; ● Restriction of personal data processing; ● Objection to personal data processing |
02 working days |
15 days |
20 days |
+15 days |
|
● Access to personal data; ● Correction or request for correction of personal data; ● Provision of personal data |
02 working days |
10 days |
15 days |
+10 days |
|
Deletion of personal data |
02 working days |
20 days |
30 days |
+20 days |
|
Implementation of measures and solutions for personal data protection |
02 working days |
15 days |
|
+15 days |
For customers who are citizens of the European Union/European Economic Area (EU/EEA), pursuant to Article 12 of the GDPR, we commit to responding to and processing requests to exercise data subject rights without undue delay and in any event no later than one (01) month from the date of receipt of a valid request. In cases where the request is complex or there is a large number of requests, this period may be extended by up to an additional two (02) months (with a total period not exceeding three (03) months). Where an extension is necessary, the Company will inform the data subject of the reasons for the delay within one (01) month from the date of receipt of the initial request. If we do not take action on the request, we will inform you of the reasons within one (01) month from the date of receipt of the request and provide guidance on your right to lodge a complaint with a supervisory authority or to initiate legal proceedings in accordance with applicable law.
You may submit requests to exercise your rights through the following channels:
Email: dpo@vietjetair.com (subject line: “Personal Data Protection Rights Request – [Full Name]”)
Postal mail: Send a written request to the DPO address specified in Article 11 of this Policy.
We may require you to verify your identity before processing such requests to ensure information security and to protect your lawful rights and interests. Please note that, in certain cases, Personal Data may continue to be retained if we have a legal obligation or a valid legal basis to do so.
For children who are Vietnamese nationals, in cases where we need to process children’s Personal Data for the purpose of publishing or disclosing information relating to their private life or personal secrets for children aged 07 years or older, consent must be obtained from both the child and their legal representative. Parents or guardians of children aged 07 years or older undertake that they have obtained the child’s consent before providing the child’s information to us.
For children who are Korean nationals, we collect, share, and use personal information of children under the age of 14 only upon obtaining consent from their parents, legal representatives, and/or guardians.
For children in member states of the European Union who are below the minimum age required to provide consent under the applicable laws of each country (ranging from 13 to 16 years depending on the country), we collect information only after obtaining consent or authorization from the child’s parent or guardian.
For children of other nationalities, we collect information only after obtaining consent or authorization from parents or guardians in accordance with applicable personal data protection laws.
Our top priority is to ensure the confidentiality and security of Personal Data. Therefore, we implement all appropriate administrative and technical measures in accordance with applicable laws, taking into account the nature of the Personal Data we receive from you and the risks associated with processing such data. Measures to protect your Personal Data are applied from the outset and throughout the entire data processing lifecycle to prevent any accidental or unlawful destruction, loss, alteration, disclosure, intrusion, or unauthorized access to such data.
a) Administrative measures:
At Vietjet, we implement various administrative measures to enhance awareness and accountability among our officers and employees. Applicable legal regulations on personal data protection are regularly updated and communicated to employees. Internal personal data protection procedures are established and strictly followed by departments involved in personal data processing.
b) Technical measures:
We implement technical measures based on the nature of each type of Personal Data and the risks associated with its processing, including:
Data encryption and security: Personal Data, particularly sensitive data, is encrypted and stored on systems protected by strict authentication and access control mechanisms; access rights are granted only to authorized individuals in accordance with their roles and responsibilities.
Security and intrusion prevention systems: We deploy technical security measures such as firewalls, anti-malware software, and intrusion detection and prevention systems to protect information systems and Personal Data from cybersecurity risks.
Regular security testing and assessment: We conduct penetration testing and vulnerability assessments on our systems at least once per year or following any significant system changes, to promptly identify and remediate information security risks.
Role-Based Access Control (RBAC): Access to Personal Data is assigned based on roles and job functions, ensuring that each individual can only access data within the scope necessary, in accordance with the principle of least privilege.
Although we have implemented appropriate administrative and technical measures to protect Personal Data, no method of transmission or storage can guarantee absolute security. In all cases, we are committed to proactively monitoring, promptly detecting, responding to, and mitigating information security incidents (if any), while fulfilling notification obligations and cooperating with competent authorities in accordance with applicable laws.
You can take steps to protect your own Personal Data in the following situations:
a) When you make a booking, you will be provided with information related to that booking. This information must always be kept confidential. Disclosing it to others may allow them to access your Personal Data through Vietjet’s system or through third parties involved in organizing your trip (for example, travel agencies or online search and booking platforms). If you are booking tickets with other passengers and do not wish to share your personal information with them, we recommend that you make separate bookings.
b) During your use of Vietjet’s services, we also recommend that you do not disclose your account passwords used to access Vietjet’s services to any third party. You should unlink your account within our system from other accounts (especially in cases where accounts are linked) and close your browser window at the end of each session, particularly if you are accessing the Internet from a shared computer, in order to prevent others from accessing your Personal Data. To avoid information theft, we recommend using different passwords for all online services you use. Vietjet shall not be responsible in cases where your login information is compromised on platforms not managed by our Services.
c) In addition, you should not communicate to third parties or post on social media any documents or information provided by us that contain your Personal Data (such as booking information, flight tickets, etc.) or any other information related to your trip. In such cases, you are responsible for reading and understanding the terms and conditions of use, information security measures, and privacy policies applicable to those social media platforms managed by third parties, and we shall not be liable for such matters.
In the event of a breach involving Personal Data, we will proactively implement necessary measures to handle and mitigate risks, while fulfilling our notification obligations in accordance with applicable laws. Specifically, we will notify competent State authorities and affected customers as soon as possible, in compliance with current personal data protection regulations, with a maximum notification timeframe not exceeding 72 hours from the time the breach is detected. In cases involving a high risk to the rights and interests of data subjects, we will notify you without undue delay and no later than 72 hours.
The content of the breach notification (if applicable) will include: (i) a description of the nature of the breach, including the scope and number of affected data subjects; (ii) contact information of the DPO; (iii) potential consequences that may arise; and (iv) measures we are implementing to remedy and mitigate the damage.
In certain cases as prescribed by law, we may not provide direct notification to data subjects, including but not limited to situations where the data has been encrypted or protected by equivalent measures, where the breach is unlikely to result in a high risk, or where notification is not feasible. In such cases, we will consider providing notification through appropriate public communication channels.
We are committed to closely cooperating with competent State authorities and implementing necessary technical and organizational measures to control, remediate the incident, and prevent recurrence.
If you have any questions, concerns, or requests related to this Policy or the protection of Personal Data within the scope of Vietjet’s Services, please contact Vietjet or our DPO using the details below:
Vietjet Aviation Joint Stock Company
Office: Vietjet Plaza, 60A Truong Son Street, Tan Son Hoa Ward, Ho Chi Minh City
Hotline: 1900 1886
Email: info@vietjetair.com
Personal Data Protection Officer (DPO):
Dedicated email: dpo@vietjetair.com
Address: Vietjet Plaza, 60A Truong Son Street, Tan Son Hoa Ward, Ho Chi Minh City
Data Protection Supervisory Authorities:
● In Vietnam: Department of Cybersecurity and High-Tech Crime Prevention (A05), Ministry of Public Security.
● In the EU: Data Protection Authority of the EU Member State where you reside.
● In the United Kingdom: Information Commissioner's Office (ICO) – www.ico.org.uk
If you are located in the EEA and have questions about your personal data or would like to request to access, update, or delete it, you may contact our representative at:
Bird & Bird GDPR Representative Services SRL
Avenue Louise 235
1050 Bruxelles
Belgium
EUrepresentative.vietjetair@twobirds.com
This Personal Data Protection Policy takes effect from April 18, 2026 and replaces our previous versions of the Personal Data Protection Policy.
We may amend and update this Policy from time to time to ensure compliance with applicable laws and our operational practices. Any changes will be published on our Website and will take effect from the time of posting, unless otherwise specified. You are advised to regularly visit the Website to stay updated with the latest version of the Policy. For passengers from the European Union (EU), in cases where changes relate to the legal basis for processing Personal Data, we will obtain your consent again in accordance with applicable laws.