{"id":2548,"date":"2026-09-23T23:55:30","date_gmt":"2026-09-23T16:55:30","guid":{"rendered":"https:\/\/kmunion.vn\/en\/?p=2548"},"modified":"2026-09-23T23:55:30","modified_gmt":"2026-09-23T16:55:30","slug":"vietnam-personal-data-protection-business-responsibilities","status":"publish","type":"post","link":"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-business-responsibilities.html","title":{"rendered":"Vietnam Personal Data Protection Law and Business Responsibilities in 2026"},"content":{"rendered":"<p class=\"km-updated\">Updated: 23 September 2026<\/p>\n<p>A customer asks for their data to be deleted, but it is held in a CRM, sales spreadsheets and a provider&#x27;s system. Which team should act? The Personal Data Protection Law assigns responsibilities by role and activity, while implementation requires coordination across departments. Compliance therefore starts by identifying who makes decisions, who processes the data and who must cooperate when a request arrives.<\/p>\n<h2>Identify roles before assigning tasks<\/h2>\n<p>Article 2 of the Personal Data Protection Law distinguishes controllers, processors, and controllers-cum-processors. Controllers determine the purposes and means of processing. Processors act on a controller&#x27;s behalf under a contract. A controller-cum-processor performs both roles.<\/p>\n<p>For example, a company decides to use customer data to manage warranties, while a software provider operates the system to its instructions. Roles must reflect actual decision-making powers and activities. If the provider uses the data for its own purpose, calling it a processor in the contract is insufficient to determine its role across all those activities.<\/p>\n<h2>Tasks that need an accountable owner<\/h2>\n<p>Article 3 sets processing principles; Article 4 defines data subjects&#x27; rights; and Article 37 allocates responsibilities. Operationally, businesses need to know where data comes from, why it is used, who receives it, how long it is kept and how individuals&#x27; requests are handled. This information feeds into policies, contracts and impact assessment dossiers.<\/p>\n<p>HR commonly holds applicant and employee data; sales manages customer lists; and IT controls access and logs. Data protection personnel need to coordinate these teams. The appointment of personnel or a department must be documented under Article 13 of Decree No. 356, which also sets competency requirements. A title on an organisation chart does not replace performance of the assigned duties.<\/p>\n<h2>Are small businesses exempt<\/h2>\n<p>Article 38 allows small enterprises and start-ups to choose not to perform certain obligations for five years, and exempts household businesses and microenterprises from certain obligations. This is not an exemption from the entire Personal Data Protection Law.<\/p>\n<p>Exceptions apply to businesses providing personal data processing services, directly processing sensitive personal data or processing personal data at scale. Article 41 of Decree No. 356 defines the large-scale threshold as data concerning at least 100,000 data subjects, counted cumulatively. Businesses must check their category, activities and data rather than claim an exemption based only on headcount.<\/p>\n<p>The choice or exemption above concerns Articles 21 and 22 and Article 33(2), not Article 20 on cross-border data transfers. The five-year period for small enterprises and start-ups runs from the Law&#x27;s effective date, not from when a business starts planning compliance. A small business using an overseas CRM must still assess transfer obligations and any corresponding exception separately.<\/p>\n<h2>What provider contracts should clarify<\/h2>\n<p>Contracts should address purposes, scope, data categories, access rights, individual requests, incident notification, subcontractors and data return or deletion. Specific terms must reflect Article 37 and specialised requirements, such as Article 12 of Decree No. 356 for cloud computing.<\/p>\n<p>When outsourcing HR software, the business must still decide what data is genuinely needed and who may view it. The provider must meet its obligations within the processing scope and contract. If both parties wait for the other to handle a deletion request or incident, the allocation does not meet operational needs.<\/p>\n<h2>From legal rules to evidence of implementation<\/h2>\n<p>Businesses should assign owners to each process and retain appointment decisions, notice versions and request-handling results. Impact assessment dossiers should match access rights, data flows and actual activities; complete paperwork alone does not demonstrate compliant operations.<\/p>\n<h2>Individual rights must reach every system<\/h2>\n<p>Article 5 of Decree No. 356 requires processes, procedures and forms for exercising rights. For example, a properly submitted deletion request must receive a response within two working days; implementation is due within 20 days, or 30 days where processors or third parties must act under paragraph 4. Extensions are permitted only within that article&#x27;s conditions and limits. Acknowledging receipt and completing the request are separate milestones.<\/p>\n<p>Deletion requests must also be assessed against Article 14 of the Law and sector-specific retention duties. For data lawfully retained, the business must identify the basis, scope and permitted continuing purposes. Coordinating with providers, checking copies and recording outcomes turns a paper policy into a workable process.<\/p>\n<p>If you are unsure which template to start with, map the data flows first. The impact assessment and reference template articles explain how to convert this operational information into suitable documentation.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>Does appointing an external data protection specialist remove responsibility? No. Resources may be organised as permitted, but legal responsibility is determined by the law and actual activities.<\/strong><\/p>\n<p><strong>Must all consent obtained under Decree No. 13 be collected again? Article 39 contains transitional provisions for previously valid consent. Check its scope, purposes and validity: renewed consent is not automatically required, and existing consent does not automatically cover new purposes.<\/strong><\/p>\n<h2>Legal sources<\/h2>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=214590&amp;pageid=27160\">Personal Data Protection Law No. 91\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216387&amp;pageid=27160\">Decree No. 356\/2025\/ND-CP implementing personal data protection requirements<\/a><\/p>\n<p><em>Sources checked through 23 September 2026.<\/em><\/p>\n<h2>Related articles<\/h2>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-consent-marketing.html\">Article 03  Personal Data Consent and Marketing Compliance in Vietnam<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-impact-assessment-dossier.html\">Article 04  Vietnam Personal Data Processing Impact Assessment Requirements<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-overseas-cloud-crm-data-transfer.html\">Article 05  Overseas Cloud and CRM Services and Vietnam Data Transfer Filings<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-processing-service-certificate.html\">Article 09  Certification for Personal Data Processing Services in Vietnam<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-templates.html\">Article 21  Vietnam Personal Data Protection Templates and How to Use Them<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understand business responsibilities under Vietnam&#8217;s personal data law, controller and processor roles, small business exemptions and compliance ownership.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[78],"tags":[],"_links":{"self":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2548"}],"collection":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/comments?post=2548"}],"version-history":[{"count":1,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2548\/revisions"}],"predecessor-version":[{"id":2581,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2548\/revisions\/2581"}],"wp:attachment":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/media?parent=2548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/categories?post=2548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/tags?post=2548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}