I. Legal basic
-
Law on Personal Data Protection 2025
-
Decree No. 356/2025/NĐ-CP guiding the implementation of the Law on Personal Data Protection.
-
Decision No. 778/QĐ-BCA-A05 dated 2026, announcing the List of new and abolished administrative procedures in the field of personal data protection within the scope of state management of the Ministry of Public Security.
II. Core concepts – Legal foundations for Personal Data Protection
1. What is Personal Data?
The concept of personal data is stipulated under Article 2 of the Law on Personal Data Protection 2025 as follows: “Personal data refers to data in digital form or other forms that identifies or helps identify a specific individual, including basic personal data and sensitive personal data. Personal data, once de-identified, shall no longer be considered personal data.” Basic personal data and sensitive personal data are defined as follows:
-
Basic Personal Data: refers to personal data reflecting identity factors and common backgrounds frequently used in transactions and social relationships, falling within the list issued by the Government in the aforementioned Decree.
-
Sensitive Personal Data: refers to personal data inherently linked to an individual’s privacy which, if infringed upon, will directly affect the legitimate rights and interests of agencies, organizations, or individuals, falling within the list issued by the Government in the aforementioned Decree.
The specific lists of basic and sensitive personal data are enumerated in Article 3 and Article 4 of Decree No. 356/2025/NĐ-CP. Enterprises must pay close attention to these two categories when conducting the Personal Data Processing Impact Assessment (DPIA) and the Cross-border Personal Data Transfer Impact Assessment.
2. What is Personal Data Protection?
According to the Law on Personal Data Protection 2025, personal data protection is understood as the application of technical, operational, and administrative measures by agencies, organizations, and individuals to prevent, detect, stop, and handle acts of personal data infringement.
This concept reflects an urgent requirement in a context where enterprises are increasingly dependent on the digital environment, network systems, and online platforms, where the personal data of employees, customers, and partners is frequently collected, stored, and processed.
Personal data protection includes activities such as:
- Ensuring the confidentiality, integrity, and availability of personal data;
- Applying technical measures (encryption, authorization, access control, etc.);
- Establishing internal governance procedures, recording, and responding to data incidents;
- Complying with legal obligations regarding transparency, consent, data processing impact assessments, and cross-border data transfers.
In other words, personal data protection is not merely a cyber-security measure but a mandatory legal requirement aimed at safeguarding the privacy and data protection rights of every individual, while simultaneously mitigating legal risks for the enterprise.
3. What is Personal Data Processing & What is DPIA?
3.1. Personal Data Processing
The Law on Personal Data Protection 2025 defines: “Personal data processing refers to activities impacting personal data, including one or more activities such as: collection, analysis, aggregation, encryption, decryption, amendment, deletion, destruction, de-identification, provision, disclosure, transfer of personal data, and other activities impacting personal data.”
In other words, any enterprise that stores personnel records, operates CRM/ERP systems, manages customers, utilizes SaaS platforms, runs advertisements, analyzes user behavior, or synchronizes data between systems, is considered to be processing personal data under the provisions of the law.
Example 1: If Enterprise A enters into a service agreement with Enterprise B to use software for calculating payroll, social insurance, and personal income tax (PIT) for employees, Enterprise B is identified as a personal data processor.
3.2. Data Processing Impact Assessment (DPIA)
The Law on Personal Data Protection 2025 introduces the concept of Data Protection Impact Assessment (DPIA) as a process of analyzing, identifying, and evaluating risks that may arise during personal data processing activities. Based on this assessment, necessary measures are proposed to ensure data security and safeguard the legitimate rights and interests of data subjects.
A Data Protection Impact Assessment (DPIA) assists enterprises in:
- Identifying risks throughout the entire data processing lifecycle;
- Evaluating the level of impact on the legitimate rights and interests of data subjects;
- Selecting appropriate technical and administrative mitigation measures;
- Ensuring compliance with personal data protection laws, particularly in the context of large-scale processing or the processing of sensitive data.
In other words, a DPIA is not only a mandatory legal requirement but also a strategic tool that helps enterprises limit violations, prevent data breaches, and mitigate legal liabilities in the event of an incident.
3.3. Cross-border Personal Data Transfer
Following the issuance of Decree No. 356/2025/NĐ-CP, which replaces Decree No. 13/2023/NĐ-CP, the cross-border transfer of personal data is now uniformly regulated under the Law on Personal Data Protection 2025. Pursuant to Article 20 of the Law on Personal Data Protection 2025, “cross-border personal data transfer” is not specifically defined but is instead identified through a list of circumstances deemed to constitute such a transfer.
The legislative objective is to control and ensure the security of personal data when it is transferred abroad or processed by systems, organizations, or individuals in foreign countries. In summary, the cross-border transfer of personal data is understood as any activity that causes the personal data of Vietnamese citizens to be moved, stored, processed, or accessed from outside the territory of Vietnam, whether directly or via technology platforms, cloud computing services, SaaS systems, APIs, or servers located overseas.
3.4. Cross-border Data Transfer Impact Assessment (CBTIA)
Decree No. 356/2025/NĐ-CP and the Law on Personal Data Protection 2025 do not provide a direct definition of a Cross-border Personal Data Transfer Impact Assessment. However, based on the mandatory legal requirements for transferring personal data abroad, it can be determined that a CTIA is the process by which an enterprise analyzes and evaluates risks and establishes protective measures for personal data before such data is transferred outside the territory of Vietnam.
The objectives of the Cross-border Personal Data Transfer Impact Assessment (CTIA) include:
-
Assessing risks that may arise during the process of data transfer and data processing abroad;
-
Identifying the potential for personal data to be subject to unauthorized access, leakage, alteration, or misuse;
-
Evaluating the level of compliance of the data recipient in the foreign country;
-
Proposing and implementing protective measures to ensure that the personal data of Vietnamese citizens is protected at a level equivalent to, or no lower than, the standards prescribed by Vietnamese law.
The CTIA has become a crucial tool for enterprises to demonstrate legal compliance when utilizing systems, platforms, or service providers with servers located abroad—a prevalent trend in contemporary operations, marketing, and data governance.
III. Which Businesses Must Conduct DPIA and CBTIA?
1. Data Processing Impact Assessment Obligations
Decree No. 356/2025/NĐ-CP and the Law on Personal Data Protection 2025 both provide clear and consistent regulations stipulating that the Personal Data Controller, the Personal Data Processor, and the Personal Data Controller-cum-Processor are responsible for formulating and maintaining a Personal Data Processing Impact Assessment (DPIA) Dossier. This signifies a mandatory and continuous legal obligation throughout Vietnam’s personal data protection framework.
Accordingly, the definitions of the aforementioned subjects are detailed under Clauses 7, 8, and 9 of Article 2 of the Law on Personal Data Protection 2025:
-
Personal Data Controller: refers to an agency, organization, or individual that determines the purposes and means of personal data processing.
-
Personal Data Processor: refers to an agency, organization, or individual that performs personal data processing on behalf of the Personal Data Controller or the Personal Data Controller-cum-Processor via a contract.
-
Personal Data Controller-cum-Processor: refers to an agency, organization, or individual that determines the purposes and means of processing and directly performs the personal data processing.
-
Third Party: refers to an organization or individual other than the data subject, the Personal Data Controller, the Personal Data Controller-cum-Processor, or the Personal Data Processor who is involved in personal data processing in accordance with the law.
Example 2: Continuing from Example 1 in Section 3.1 to identify roles based on the above definitions:
-
Enterprise A is the Personal Data Controller and Enterprise B is the Personal Data Processor because Enterprise A decides the purpose and method of collecting employee data, while Enterprise B processes such data based on Enterprise A’s requirements via a contract.
-
In the event that Enterprise A directly collects, stores, and evaluates data, and notifies candidates of results during the recruitment process, Enterprise A acts as the Personal Data Controller-cum-Processor as they determine the purposes and means while simultaneously undertaking the processing activities.
-
If Enterprise A shares customer data with Enterprise C (an e-commerce entity) for Enterprise C to conduct its own analysis and independent advertising campaigns, Enterprise C is considered a Third Party because they have their own independent purposes and means.
It is evident that enterprises in Vietnam are currently processing personal data at various levels: storing personnel records on HRM systems; managing customers via CRM/ERP; and utilizing accounting, marketing, or customer service software that collects personal information. This implies that every enterprise or organization involved in the collection, use, or storage of personal data belonging to employees, customers, or partners is legally mandated to formulate and maintain a DPIA Dossier.
2. Cross-border Personal Data Transfer Impact Assessment
Decree No. 356/2025/NĐ-CP stipulates that any party transferring personal data cross-border must formulate and maintain a Cross-border Personal Data Transfer Impact Assessment (CTIA) Dossier, making it available for inspection and evaluation by the specialized personal data protection agency under the Ministry of Public Security upon request.
This regulation is further codified in Article 20 of the Law on Personal Data Protection 2025, whereby all agencies, organizations, and individuals conducting cross-border transfers of personal data must formulate a CTIA Dossier and submit it to the specialized data protection agency, except for cases exempted under Clause 6 of this Article.
Consequently, any enterprise engaged in transferring the personal data of Vietnamese citizens abroad—whether directly or through technology platforms with overseas servers—is required to prepare a CTIA Dossier. This dossier must be prepared prior to the transfer, although the timeline for notifying or submitting the dossier to the state authority is stipulated as within 60 days from the date the cross-border transfer of personal data commences (unless exempted by law).
3. Implementation roadmap and exemptions
The processing of personal data has become an indispensable part of all business administration and operations. The Law on Personal Data Protection 2025 and Decree No. 356/2025/NĐ-CP have flexibly established a suitable roadmap for enterprises, including exemptions from mandatory personal data impact assessments in certain cases, specifically:
-
Micro-enterprises and household businesses are entitled to waive the requirement to conduct personal data processing impact assessments, update DPIA and CTIA dossiers, and are not required to appoint a Data Protection Officer (DPO) or a dedicated data protection unit. This exemption does not apply if they provide personal data processing services, directly process sensitive personal data, or engage in processing activities involving a scale of 100,000 data subjects or more, based on the cumulative total volume of personal data processed.
-
Small enterprises and startups have the option to implement or waive regulations regarding personal data processing impact assessments, update DPIA and CTIA dossiers, and are not required to appoint a DPO or data protection unit for a period of 05 years from January 1, 2026. This exclusion is revoked if they provide personal data processing services, directly process sensitive personal data, or reach a processing scale of 100,000 data subjects or more based on the cumulative total volume of processed data.
Consequently, Vietnamese law provides highly appropriate roadmap regulations to facilitate compliance for household businesses, micro-enterprises, small enterprises, and startups.
IV. Are there Penalties for Failing to Conduct a Cross-border Personal Data Transfer Impact Assessment?
While a specific Decree on administrative sanctions for personal data violations may not yet be fully implemented, the Law on Personal Data Protection 2025 stipulates that enterprises or organizations violating regulations on cross-border personal data transfer shall be subject to a maximum fine of 5% of the organization’s total revenue from the immediately preceding fiscal year.
In cases where there is no revenue from the preceding year, or where the calculated 5% is lower than the statutory ceiling, a maximum fine of 3 billion VND shall be applied. For individuals committing the same violation, the maximum fine shall be equal to one-half (1/2) of the fine imposed on organizations.
Failure to comply with regulations on DPIA and CTIA is not only a legal violation but also poses significant risks to the reputation, finances, and operations of an enterprise, especially as the new Law on Personal Data Protection comes into effect with substantially high penalty thresholds.
V. Personal Data Compliance Services Provided by Vo & Associates
- Formulating Personal Data Processing Impact Assessment (DPIA) Dossiers
- Formulating Cross-border Personal Data Transfer Impact Assessment (CTIA) Dossiers
- Drafting and reviewing Data Processing Agreements (DPA), data protection policies, and compliance forms
- Reviewing compliance levels, assessing risks, and proposing remedial solutions
- Providing internal training and guidance on establishing personal data protection procedures
If your enterprise processes personnel or customer data, or utilizes CRM/ERP/SaaS platforms with servers located abroad, please contact Vo & Associates for comprehensive legal compliance solutions.
Contact Information
📞 Hotline: +84 909 865 891 (Zalo, WhatsApp)
📧 Email: hello@vo-associates.vn
🌐 Website: https://vo-associates.vn
🏢 Room 105, 1st floor, Cityview Building, 12 Mac Dinh Chi Street, Sai Gon Ward, Ho Chi Minh City.
Best regards./.
Tiếng Việt
