Vietnam Personal Data Protection Law and Business Responsibilities in 2026

Updated: 23 September 2026

A customer asks for their data to be deleted, but it is held in a CRM, sales spreadsheets and a provider's system. Which team should act? The Personal Data Protection Law assigns responsibilities by role and activity, while implementation requires coordination across departments. Compliance therefore starts by identifying who makes decisions, who processes the data and who must cooperate when a request arrives.

Identify roles before assigning tasks

Article 2 of the Personal Data Protection Law distinguishes controllers, processors, and controllers-cum-processors. Controllers determine the purposes and means of processing. Processors act on a controller's behalf under a contract. A controller-cum-processor performs both roles.

For example, a company decides to use customer data to manage warranties, while a software provider operates the system to its instructions. Roles must reflect actual decision-making powers and activities. If the provider uses the data for its own purpose, calling it a processor in the contract is insufficient to determine its role across all those activities.

Tasks that need an accountable owner

Article 3 sets processing principles; Article 4 defines data subjects' rights; and Article 37 allocates responsibilities. Operationally, businesses need to know where data comes from, why it is used, who receives it, how long it is kept and how individuals' requests are handled. This information feeds into policies, contracts and impact assessment dossiers.

HR commonly holds applicant and employee data; sales manages customer lists; and IT controls access and logs. Data protection personnel need to coordinate these teams. The appointment of personnel or a department must be documented under Article 13 of Decree No. 356, which also sets competency requirements. A title on an organisation chart does not replace performance of the assigned duties.

Are small businesses exempt

Article 38 allows small enterprises and start-ups to choose not to perform certain obligations for five years, and exempts household businesses and microenterprises from certain obligations. This is not an exemption from the entire Personal Data Protection Law.

Exceptions apply to businesses providing personal data processing services, directly processing sensitive personal data or processing personal data at scale. Article 41 of Decree No. 356 defines the large-scale threshold as data concerning at least 100,000 data subjects, counted cumulatively. Businesses must check their category, activities and data rather than claim an exemption based only on headcount.

The choice or exemption above concerns Articles 21 and 22 and Article 33(2), not Article 20 on cross-border data transfers. The five-year period for small enterprises and start-ups runs from the Law's effective date, not from when a business starts planning compliance. A small business using an overseas CRM must still assess transfer obligations and any corresponding exception separately.

What provider contracts should clarify

Contracts should address purposes, scope, data categories, access rights, individual requests, incident notification, subcontractors and data return or deletion. Specific terms must reflect Article 37 and specialised requirements, such as Article 12 of Decree No. 356 for cloud computing.

When outsourcing HR software, the business must still decide what data is genuinely needed and who may view it. The provider must meet its obligations within the processing scope and contract. If both parties wait for the other to handle a deletion request or incident, the allocation does not meet operational needs.

From legal rules to evidence of implementation

Businesses should assign owners to each process and retain appointment decisions, notice versions and request-handling results. Impact assessment dossiers should match access rights, data flows and actual activities; complete paperwork alone does not demonstrate compliant operations.

Individual rights must reach every system

Article 5 of Decree No. 356 requires processes, procedures and forms for exercising rights. For example, a properly submitted deletion request must receive a response within two working days; implementation is due within 20 days, or 30 days where processors or third parties must act under paragraph 4. Extensions are permitted only within that article's conditions and limits. Acknowledging receipt and completing the request are separate milestones.

Deletion requests must also be assessed against Article 14 of the Law and sector-specific retention duties. For data lawfully retained, the business must identify the basis, scope and permitted continuing purposes. Coordinating with providers, checking copies and recording outcomes turns a paper policy into a workable process.

If you are unsure which template to start with, map the data flows first. The impact assessment and reference template articles explain how to convert this operational information into suitable documentation.

Frequently asked questions

Does appointing an external data protection specialist remove responsibility? No. Resources may be organised as permitted, but legal responsibility is determined by the law and actual activities.

Must all consent obtained under Decree No. 13 be collected again? Article 39 contains transitional provisions for previously valid consent. Check its scope, purposes and validity: renewed consent is not automatically required, and existing consent does not automatically cover new purposes.

Legal sources

Personal Data Protection Law No. 91/2025/QH15

Decree No. 356/2025/ND-CP implementing personal data protection requirements

Sources checked through 23 September 2026.

Related articles

Article 03 Personal Data Consent and Marketing Compliance in Vietnam

Article 04 Vietnam Personal Data Processing Impact Assessment Requirements

Article 05 Overseas Cloud and CRM Services and Vietnam Data Transfer Filings

Article 09 Certification for Personal Data Processing Services in Vietnam

Article 21 Vietnam Personal Data Protection Templates and How to Use Them

Similar Blog Posts

Vietnam Personal Data Protection Templates and How to Use Them

Request reference templates for Vietnam personal data protection and understand their scope and the review…

Vietnam and EU Data Protection and AI Laws Compared by Obligation

Compare Vietnam and EU data protection and AI duties, including DPIAs, 72-hour breach rules, territorial…

Vietnam Cloud Service Notification and Data Protection Responsibilities

Explore Vietnam cloud notification rules for domestic and overseas providers and the data protection responsibilities…

Vietnam Data Centre Services Registration and Licensing

Distinguish Vietnam data centre registration from telecommunications licensing, with provincial authority and processing changes under…
Designed by W.O.A.