{"id":2555,"date":"2026-09-23T23:55:37","date_gmt":"2026-09-23T16:55:37","guid":{"rendered":"https:\/\/kmunion.vn\/en\/?p=2555"},"modified":"2026-09-23T23:55:37","modified_gmt":"2026-09-23T16:55:37","slug":"vietnam-personal-data-processing-service-certificate","status":"publish","type":"post","link":"https:\/\/kmunion.vn\/en\/vietnam-personal-data-processing-service-certificate.html","title":{"rendered":"Certification for Personal Data Processing Services in Vietnam"},"content":{"rendered":"<p class=\"km-updated\">Updated: 23 September 2026<\/p>\n<p>The certificate of eligibility to provide personal data processing services is a separate mechanism under Decree No. 356\/2025\/ND-CP. It should not be confused with an impact assessment dossier or the amended data analysis and aggregation procedures under Decree No. 169. Assess each layer of a business model separately.<\/p>\n<h2>Which services fall within scope<\/h2>\n<p>Article 21 of Decree No. 356 lists personal data processing services. Categories include automated processing systems for controllers, credit scoring, online data collection, certain healthcare and education services, personal data analysis or use, encryption, automated processing using advanced technology and location-related platforms.<\/p>\n<p>A software name does not determine the entire scope. A product marketed as analytics may actually receive, organise and use customers&#x27; personal data. Conversely, processing employee data for a business&#x27;s own administration does not automatically mean it provides processing services to the market. Compare Article 21&#x27;s descriptions with the actual service and contract.<\/p>\n<h2>Key organisational and staffing conditions<\/h2>\n<p>Article 22 sets conditions for organisations established under Vietnamese law, the professional lead, management structure and personnel. These include at least three staff meeting the competency requirements referenced in Article 13(2). The professional lead must meet the nationality, residence and other conditions in that article.<\/p>\n<p>The organisation must also have suitable infrastructure, equipment, facilities and technology, and satisfactory results for its personal data processing impact assessment dossier and cross-border transfer dossier where transfers occur. Certification preparation is therefore linked to operational design, not merely collecting copies of qualifications.<\/p>\n<h2>What the application dossier contains<\/h2>\n<p>Article 25 requires an application using Form No. 04, the enterprise registration certificate, a document appointing a data protection department or a service contract, a project proposal and evidence of staff competence. The registration document need not be submitted where the authority can retrieve the information from a database under the prescribed conditions.<\/p>\n<p>The proposal must describe objectives, requested service areas, the business plan, processing scale, risk management framework, compliance assessment plan, relevant standards and technical regulations, identification and authentication, responsibilities and personnel. It should accurately reflect intended data flows, customers and technology.<\/p>\n<h2>Where to apply and how processing works<\/h2>\n<p>Under Article 24, the Ministry of Public Security has authority, exercised through the specialised personal data protection authority assigned by the Minister. Article 25 provides for one dossier to be submitted to that authority online, in person or by post.<\/p>\n<p>The process includes 10 days for dossier assessment, 15 days for the organisation to complete it when requested, and 30 days from receipt of a complete valid dossier for a decision as prescribed. Do not add or compress these periods into a promised result date for every case. Check the current forms and procedure published by the competent authority when filing.<\/p>\n<h2>Responsibilities after certification<\/h2>\n<p>Article 23 requires compliance with data protection law, risk management and service obligations. Changes to the model, scope or certificate contents require review of replacement, reissuance and related rules. The certificate does not authorise every use of customers&#x27; data.<\/p>\n<h2>When a provider offers several services<\/h2>\n<p>One company may provide a cloud platform, analyse personal data and add cybersecurity monitoring. These raise three different questions: telecommunications service notification, personal data processing conditions under Decree No. 356, and cybersecurity business scope under Decree No. 332. Only actual activities within the relevant scope trigger the corresponding duties.<\/p>\n<p>Data roles can also differ by task within one contract. Storing data on customer instructions differs from using it independently to improve a product. Reassess purposes, roles and grounds for independent use; describing a provider as a processor does not override the facts.<\/p>\n<p>Before asking how many licences are needed, list services, inputs, outputs and each party&#x27;s decision-making powers. The data services, cloud and cybersecurity licensing articles help assess each part of this inventory.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>Does Decree No. 347&#x27;s repeal of analytics procedures also abolish this certificate? That cannot be inferred. This mechanism arises under Decree No. 356 and must be checked independently of amendments to Decree No. 169.<\/strong><\/p>\n<p><strong>Does sufficient staffing guarantee certification? No. Staffing is only one set of conditions; the authority assesses all conditions and the complete dossier.<\/strong><\/p>\n<h2>Legal sources<\/h2>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=214590&amp;pageid=27160\">Personal Data Protection Law No. 91\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216387&amp;pageid=27160\">Decree No. 356\/2025\/ND-CP implementing personal data protection requirements<\/a><\/p>\n<p><a href=\"https:\/\/chinhphu.vn\/?docid=219411&amp;pageid=27160\">Decree No. 347\/2026\/ND-CP amending Decree No. 169<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-332-2026-nd-cp-470329.htm\">Decree No. 332\/2026\/ND-CP on cybersecurity products and services businesses<\/a><\/p>\n<p><a href=\"https:\/\/xaydungchinhsach.chinhphu.vn\/toan-van-luat-vien-thong-119240405141649213.htm\">Telecommunications Law No. 24\/2023\/QH15<\/a><\/p>\n<p><em>Sources checked through 23 September 2026.<\/em><\/p>\n<h2>Related articles<\/h2>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-impact-assessment-dossier.html\">Article 04  Vietnam Personal Data Processing Impact Assessment Requirements<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-data-analytics-licensing-2026.html\">Article 08  Vietnam Data Analytics Licensing Changes from 15 September 2026<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-cybersecurity-licence-atttm-2026.html\">Article 13  Vietnam Cybersecurity Licences and the 2026 Transition from ATTTM<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-cloud-service-notification-responsibilities.html\">Article 19  Vietnam Cloud Service Notification and Data Protection Responsibilities<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-templates.html\">Article 21  Vietnam Personal Data Protection Templates and How to Use Them<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Explore Vietnam&#8217;s personal data processing service certification, staffing conditions, Form 04 dossier and issuing authority under Decree 356\/2025.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[78],"tags":[],"_links":{"self":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2555"}],"collection":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/comments?post=2555"}],"version-history":[{"count":1,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2555\/revisions"}],"predecessor-version":[{"id":2588,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2555\/revisions\/2588"}],"wp:attachment":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/media?parent=2555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/categories?post=2555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/tags?post=2555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}