{"id":2550,"date":"2026-09-23T23:55:32","date_gmt":"2026-09-23T16:55:32","guid":{"rendered":"https:\/\/kmunion.vn\/en\/?p=2550"},"modified":"2026-09-23T23:55:32","modified_gmt":"2026-09-23T16:55:32","slug":"vietnam-personal-data-impact-assessment-dossier","status":"publish","type":"post","link":"https:\/\/kmunion.vn\/en\/vietnam-personal-data-impact-assessment-dossier.html","title":{"rendered":"Vietnam Personal Data Processing Impact Assessment Requirements"},"content":{"rendered":"<p class=\"km-updated\">Updated: 23 September 2026<\/p>\n<p>A personal data processing impact assessment dossier describes processing activities, assesses their effects and sets out safeguards. It is not a certificate confirming that a business has met every data obligation. The main provisions are Articles 21\u201322 of the Personal Data Protection Law and Articles 19\u201320 of Decree No. 356\/2025\/ND-CP.<\/p>\n<h2>Who prepares and submits the dossier<\/h2>\n<p>Under Article 21, controllers and controllers-cum-processors must prepare, retain and submit dossiers as required; processors prepare and retain them as agreed with controllers. Article 19(1), (2) and (4) of Decree No. 356 also addresses preparation, contents and submission for all three categories. Processors must follow the detailed rules rather than assume that working under contract exempts them from filing. Check Article 38 of the Law and Article 41 of the Decree for special arrangements.<\/p>\n<p>A retailer operating a loyalty programme, for example, must describe its decisions on data collection and use. The platform provider supplies information about infrastructure, processing flows, subcontractors and safeguards within its scope. The parties should not use the same generic description where their roles and activities differ.<\/p>\n<h2>The dossier must reflect actual operations<\/h2>\n<p>Article 19 of Decree No. 356 prescribes the assessment report in Form No. 10. It covers the parties, data protection contacts, purposes, data categories, processing processes and flows, notices and consent, retention periods, safeguards, impact assessment and mitigation measures.<\/p>\n<p>Processing contracts or agreements, internal rules and related documents must be checked against that article. The application uses Form No. 02a or 02b as applicable. Take the precise checklist from the current annex rather than reuse the forms under Decree No. 13\/2023\/ND-CP unchanged.<\/p>\n<p>A useful assessment identifies specific risks. Customer data might be downloaded in bulk by employees, accessed beyond scope by subcontractors or retained in backups beyond its purpose. Corresponding controls may include restricted permissions, access logs, data export approvals and deletion procedures. These are examples of controls, not the only legally acceptable measures.<\/p>\n<h2>Where and when to file<\/h2>\n<p>One original dossier must be sent to the Ministry of Public Security&#x27;s specialised personal data protection authority within 60 days of the first day of personal data processing, as prescribed. Article 19 permits online, in-person or postal submission. Check the procedure published on the public service portal and the Ministry&#x27;s correct receiving unit when filing.<\/p>\n<p>The Decree provides a 15-day assessment period and, where completion is requested, a 30-day period to complete the dossier. These periods should not be presented as guaranteed approval deadlines: quality, completeness and supplementary requests may affect processing.<\/p>\n<h2>When updates are required<\/h2>\n<p>Article 22 requires updates every six months where contents have changed, and immediate updates in specified cases such as restructuring, cessation or other listed changes. It should not be described as requiring resubmission of the entire dossier every six months when nothing has changed.<\/p>\n<p>Internal governance should trigger reassessment when a processing purpose is added, a provider changes, sensitive data is introduced or the storage model changes. Then apply Article 22 and Article 20 of Decree No. 356 to determine the update type, documents and timing.<\/p>\n<h2>One dossier per organisation or per software system<\/h2>\n<p>The Personal Data Protection Law Handbook describes two organisation-level dossiers: a processing impact assessment covering processing activities, and a cross-border transfer impact assessment covering transfers. This does not mean each CRM, website or provider needs a separate dossier. The essential requirement is complete coverage of the relevant activities, parties and flows under Articles 18\u201319 of Decree No. 356.<\/p>\n<p>Consolidation does not mean a corporate group may use one legal entity&#x27;s name to replace every subsidiary&#x27;s obligations. Identify the responsible organisation, its role and each activity&#x27;s scope before consolidating documents.<\/p>\n<h2>How data dossiers relate to security level dossiers and contracts<\/h2>\n<p>System diagrams, data inventories and access permissions can inform both impact assessments and cybersecurity plans. However, the purposes and competent authorities differ: impact assessments examine data processing and its effects on individuals, while security level dossiers establish system protection requirements under the Cybersecurity Law and Decree No. 331.<\/p>\n<p>If a contract states that the provider retains no copies but the design includes overseas backups, resolve the inconsistency before completing the dossier. This is why the transfer and security level articles are useful alongside a report template.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>Must a dossier prepared before 1 January 2026 be completely replaced? Article 39 provides transitional arrangements for dossiers already received. Check the existing dossier and make updates under current rules when required.<\/strong><\/p>\n<p><strong>Does a DPIA replace an overseas transfer dossier? Not automatically. Transfers are governed by Article 20 of the Law and Article 18 of Decree No. 356; obligations and exemptions must be identified separately.<\/strong><\/p>\n<h2>Legal sources<\/h2>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=214590&amp;pageid=27160\">Personal Data Protection Law No. 91\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216387&amp;pageid=27160\">Decree No. 356\/2025\/ND-CP implementing personal data protection requirements<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216499&amp;pageid=27160\">Cybersecurity Law No. 116\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-331-2026-nd-cp-470334.htm\">Decree No. 331\/2026\/ND-CP on cybersecurity assurance by security level<\/a><\/p>\n<p><em>Sources checked through 23 September 2026.<\/em><\/p>\n<h2>Related articles<\/h2>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-business-responsibilities.html\">Article 02  Vietnam Personal Data Protection Law and Business Responsibilities in 2026<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-overseas-cloud-crm-data-transfer.html\">Article 05  Overseas Cloud and CRM Services and Vietnam Data Transfer Filings<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-system-security-level-dossier-approval.html\">Article 12  Vietnam Information System Security Level Dossiers and Approval Authorities<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-templates.html\">Article 21  Vietnam Personal Data Protection Templates and How to Use Them<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understand Vietnam&#8217;s personal data impact assessment requirements, responsible parties, dossier contents, 60-day filing deadline and update rules.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[78],"tags":[],"_links":{"self":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2550"}],"collection":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/comments?post=2550"}],"version-history":[{"count":1,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2550\/revisions"}],"predecessor-version":[{"id":2583,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2550\/revisions\/2583"}],"wp:attachment":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/media?parent=2550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/categories?post=2550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/tags?post=2550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}