DPO Radio

AesirX ComplianceOne | Vietnam PDPL Compliance

Overview Image

Why the Vietnam PDPL Matters

Vietnam’s Personal Data Protection Law (Law 91/2025/QH15) is the parent framework for personal data governance, rights, impact assessments, cross-border transfers, breach handling, and accountable processing. It has been active since 1 January 2026 and is supported by several instruments with different legal and operational roles.

Decree 356 provides the active implementing layer. Decision 778 defines related Ministry of Public Security administrative procedures. Government Resolution NQ22/2026 temporarily adjusts selected procedural handling until 1 March 2027. Decree 330/2026/NĐ-CP, in force since 19 August 2026, supplies the shared enforcement layer: statutory penalty schedules across both personal data protection and cybersecurity.

For organizations, the practical challenge is proving that the work happened: impact assessments were complete, responsible personnel were identified, transfer risks were reviewed, official forms were supported by evidence, and authority interactions passed the correct human approvals.

ComplianceOne keeps the full stack connected while preserving each instrument’s status. Current obligations, temporary procedural changes, enforcement exposure under the promulgated penalty decree, and practical submission guidance are not collapsed into one generic checklist.

What the Vietnam PDPL Covers

Dimension

Coverage

Core obligations

Lawful processing, consent, rights, impact assessment, cross-border transfer governance, incidents, responsible personnel, and processing records.

Scope

Organizations that process personal data in Vietnam as a data controller, processor, or controller-cum-processor, together with the data subjects whose personal data is protected.

Active implementation

Decree 356/2025/NĐ-CP and Decision 778/QĐ-BCA-A05.

Temporary procedure

NQ22/2026, effective 29 April 2026 through 1 March 2027.

Enforcement penalties

Decree 330/2026/NĐ-CP – shared cybersecurity and personal data protection penalty schedules, in force since 19 August 2026.

Evidence requirements

Assessment dossiers, official forms, supporting records, approvals, submission proof, authority responses, and audit history.

Practical email guidance

An optional, unofficial evidence-pack route that requires legal review and customer-controlled sender configuration.

The PDPL Instrument Stack

The PDPL compliance landscape spans current requirements, superseded instruments still relevant as context, and upcoming enforcement changes. Understanding the full picture matters.

Decree 356/2025/NĐ-CP

Active Implementing Decree

Decree 356 provides the detailed implementing rules and official forms for impact assessment, cross-border transfer, dossier updates, incidents, and service-provider procedures.

Decision 778/QĐ-BCA-A05

Active Administrative Procedures

Decision 778 operationalizes Ministry of Public Security handling for relevant personal data protection procedures. It complements the forms and obligations rather than replacing them.

Government Resolution NQ22/2026

Temporary Procedural Overlay

NQ22 temporarily simplifies or adjusts selected administrative procedures. It is procedural only, expires on 1 March 2027, and is not a sanctions instrument.

Decree 330/2026/NĐ-CP

Enforcement Penalties, Active

Decree 330/2026/NĐ-CP carries the statutory penalty schedules across both personal data protection and cybersecurity, in force since 19 August 2026. Cybersecurity amounts are stated per individual with organizations at twice the level; personal-data amounts are stated per organization with individuals at half, reaching 3 billion VND, 5% of preceding-year revenue for cross-border violations, or ten times the illicit gain for unlawful data trading. It remains separate from NQ22. The earlier shared draft overlay is retained as a legacy record.

Decree 13/2023/NĐ-CP

Legacy, Superseded

Decree 13/2023/NĐ-CP was the personal data protection baseline before the PDPL. It is superseded and is not a source of current obligations. It remains represented because records created under it stay relevant for retention, audit periods covering the Decree 13 era, and transition gap analysis.

Overview Image

How ComplianceOne Supports the Vietnam PDPL

ComplianceOne supports personal data processing impact assessments and cross-border transfer impact assessments as governed dossiers. Teams can assign contributors, collect processing and transfer evidence, review responsible-personnel records, prepare official forms, and retain approval history.

Evidence packs connect the completed forms to their supporting documents, audit records, and submission context. Teams can review completeness, approve the package, and retain proof of what was prepared and sent.

Where practical authority-facing email guidance is used, the workflow supports package assembly, review, optional Forseti AI assistance, email drafting, customer-controlled provider configuration, sending, response recording, and hard-copy follow-up. Email is not presented as an official NQ22 submission channel. AesirX is not the default sender, and AI cannot approve a submission; every package must pass a human approval gate.

Rights, incidents, consent, data mapping, and deletion work can be linked to the same regulatory record. Sent proof, authority responses, and required hard-copy follow-up remain part of the evidence and audit history rather than disappearing into personal mailboxes.

Related Modules

DPIA and AssessmentsDPIA and Assessments

Coordinates processing and transfer assessments, evidence, review, and approval.

Explore DPIA and Assessments

Data MappingData Mapping

Maintains processing, system, data-flow, and transfer context.

Explore Data Mapping

Rights RequestsRights Requests

Manages intake, verification, fulfillment, response, and closure evidence.

Consent Governance

Records consent, legal basis, changes, and withdrawal history.

Incident ResponseIncident Response

Supports incident assessment, notification records, remediation, and authority interaction.

Explore Incidents

Compliance FormsCompliance Forms

Supports official Mẫu số forms with linked evidence and approvals.

Explore Compliance Forms

Audit TrailAudit Trail

Preserves contributor, review, approval, sending, and response history.

Explore Audit Trail

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconAssessment dossiers are assembled from disconnected department files.
IconAssessment and transfer dossiers retain owners, evidence, review, and approval.
IconOfficial forms lose their supporting evidence and approval context.
IconForms, supporting records, and submission packages stay connected.
IconTemporary procedures are mistaken for permanent or substantive legal changes.
IconNQ22 is tracked as a temporary procedural overlay with an expiry review.
IconDraft sanctions are confused with enacted penalties.
IconEnforcement exposure under Decree 330 stays traceable to the statutory articles it comes from.
IconSubmission proof and authority responses remain in individual inboxes.
IconSending proof, responses, and hard-copy follow-up form one audit-ready record.

Built for PDPL Compliance Operations

Build For Image

ComplianceOne supports the complete operating stack without presenting temporary procedures, unofficial guidance, or draft enforcement language as final law.

Build For Image

Human approval gates keep accountability with the customer, including where Forseti AI assists with review or drafting.

Build For Image

Evidence remains connected from the underlying processing activity through dossier preparation, submission proof, authority response, and follow-up.

Background Image

Book a Demo

Ready to see how ComplianceOne's command center, guided setup, platform administration, and AI advisor work together in practice? Request a personalized demo with your compliance scenarios.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

Decree 356 is the active implementing decree beneath the PDPL. Decision 778 adds the administrative-procedure layer for relevant Ministry of Public Security interactions. ComplianceOne links the layers while preserving their separate roles.

No. NQ22 is a temporary procedural overlay. It adjusts selected administrative handling from 29 April 2026 through 1 March 2027 and does not create the draft cybersecurity and personal data protection sanctions framework.

No. NQ22 identifies the National Public Service Portal, direct submission, and postal submission as official channels. Any email evidence-pack route is presented as practical, unofficial guidance that requires legal review.

No. Forseti AI may assist with review or drafting, but it cannot approve a package. A human approval gate is required, and any direct email uses a provider configured and controlled by the customer.

ComplianceOne can retain sending proof, record authority responses, and track hard-copy follow-up when requested. Those records remain linked to the package and its audit history.

The DPIA workflow routes specific dossier sections to responsible departments (legal, IT security, HR, marketing, procurement), tracks each department's contribution progress against shared deadlines, and consolidates completed sections into a submission-ready package. Contributor lineage is preserved in the audit trail, showing who completed which section and when.

Each rights request creates a case with identity verification, rights-type classification, department routing for fulfillment, SLA tracking against configured deadlines, and automated generation of acknowledgment, completion, or rejection documentation. Evidence packs are generated at case closure for audit readiness.

Yes. ComplianceOne supports all Vietnam regulatory frameworks within a shared workflow engine. Organizations subject to multiple frameworks, such as PDPL, the Data Law, and the Cybersecurity Law, manage all obligations from a single platform with consistent audit trail coverage and evidence production across frameworks.

Next Steps

Icon Image

Start a Compliance Pilot

Test PDPL compliance workflows with your team – DPIA filing, rights requests, breach notification, and evidence generation.

Icon Image

Discuss Your Compliance Needs

Talk to our team about PDPL compliance operations, multi-framework coverage, and deployment options for your organization.