DPO Radio

The Vietnam Personal Data Protection Law (Law 91/2025/QH15) is Vietnam's comprehensive personal data protection framework. Administered by the Ministry of Public Security (MPS), it establishes obligations for organizations that collect, store, process, or transfer personal data within Vietnam or involving Vietnamese data subjects. Effective from 1 January 2026, it is supported by implementing and procedural instruments that define how those obligations operate in practice.
Implementation Decree 356/2025/NĐ-CP provides the active operational requirements, Decision 778/QĐ-BCA-A05 establishes Ministry of Public Security administrative procedures, and Government Resolution NQ22/2026 temporarily adjusts selected procedures until 1 March 2027. A separate draft enforcement instrument covering both personal data protection and cybersecurity remains under development.
Organizations must coordinate DPIAs, cross-border transfer assessments, data subject rights, breach notifications, consent records, and authority interactions across legal, IT, HR, marketing, procurement, and other business functions. These activities require more than standalone policies, they require evidence that the work was completed, reviewed, and approved.
ComplianceOne keeps the full stack connected while preserving each instrument's legal status. Current obligations, temporary procedures, draft enforcement preparation, and submission activities are managed within their own legal context.
Lawful processing, consent, rights, impact assessment, cross-border transfer governance, incidents, responsible personnel, and processing records.
Decree 356/2025/NĐ-CP and Decision 778/QĐ-BCA-A05.
NQ22/2026, effective 29 April 2026 through 1 March 2027.
Shared cybersecurity and personal data protection sanctions draft; not yet in force.
Assessment dossiers, official forms, supporting records, approvals, submission proof, authority responses, and audit history.
An optional, unofficial evidence-pack route that requires legal review and customer-controlled sender configuration.
The PDPL compliance landscape spans current requirements, superseded instruments still relevant as context, and upcoming enforcement changes. Understanding the full picture matters.
Decree 356 provides the detailed implementing rules and official forms for impact assessment, cross-border transfer, dossier updates, incidents, and service-provider procedures.
Decision 778 operationalizes Ministry of Public Security handling for relevant personal data protection procedures. It complements the forms and obligations rather than replacing them.
NQ22 temporarily simplifies or adjusts selected administrative procedures. It is procedural only, expires on 1 March 2027, and is not a sanctions instrument.
The draft enforcement overlay covers sanctions chapters across both laws. Its draft fine language is not presented as final, and it remains separate from NQ22.
Legacy compliance records, evidence retention obligations, and transition gap analysis for the regulatory period that preceded Vietnam's comprehensive PDPL.
Legacy compliance program architecture that organizations built under Decree 13 and what carried forward into the PDPL era.

ComplianceOne operationalizes the Vietnam Personal Data Protection Law through governed workflows for Data Processing Impact Assessments (DPIAs), Cross-Border Transfer Impact Assessments (TIAs), data subject rights, consent, incidents, and authority interactions. Teams can assign contributors, collect processing and transfer evidence, prepare the official forms under Implementation Decree 356/2025/NĐ-CP, review responsible-personnel records, route submissions through approval workflows, and retain a complete history of decisions and approvals.
Evidence packs connect completed forms with their supporting documentation, audit records, and submission context. Teams can review completeness, approve the package, and preserve evidence of what was prepared, submitted, and acknowledged throughout the filing lifecycle.
Where Government Resolution NQ22/2026 permits practical authority-facing email guidance, ComplianceOne supports package assembly, review, optional Forseti AI drafting assistance, customer-controlled email configuration, response tracking, and required hard-copy follow-up. Email is not presented as an official submission channel, AesirX is not the default sender, and every submission remains subject to human review and approval.
Records, supporting evidence, approvals, submissions, authority responses, and audit history remain connected across the operational lifecycle, preserving the operational proof behind every compliance decision.
Coordinates processing and transfer assessments, evidence, review, and approval.
Explore DPIA and AssessmentsManages intake, verification, fulfillment, response, and closure evidence.
Records consent, legal basis, changes, and withdrawal history.
Supports incident assessment, notification records, remediation, and authority interaction.
Explore IncidentsSupports official Mẫu số forms with linked evidence and approvals.
Explore Compliance FormsPreserves contributor, review, approval, sending, and response history.
Explore Audit Trail


ComplianceOne supports the complete operating stack without presenting temporary procedures, unofficial guidance, or draft enforcement language as final law.

Human approval gates keep accountability with the customer, including where Forseti AI assists with review or drafting.

Evidence remains connected from the underlying processing activity through dossier preparation, submission proof, authority response, and follow-up.
Ready to see how ComplianceOne's command center, guided setup, platform administration, and AI advisor work together in practice? Request a personalized demo with your compliance scenarios.

Yes. The platform includes interactive Form Wizard templates for all Mau so administrative procedure forms and all Phu luc statutory annexes defined by Decree 356/2025/ND-CP. Forms are pre-labeled with official template IDs and structured to match the format required by MPS administrative procedures.
The DPIA workflow routes specific dossier sections to responsible departments (legal, IT security, HR, marketing, procurement), tracks each department's contribution progress against shared deadlines, and consolidates completed sections into a submission-ready package. Contributor lineage is preserved in the audit trail, showing who completed which section and when.
The Incident Response module tracks the breach notification timeline from discovery, generates Mau so 08 (breach notification form) for MPS filing, manages supplement request loops if MPS requires additional information, and tracks remediation actions through to case closure. SLA enforcement is configurable to match your organization's internal escalation procedures.
Each rights request creates a case with identity verification, rights-type classification, department routing for fulfillment, SLA tracking against configured deadlines, and automated generation of acknowledgment, completion, or rejection documentation. Evidence packs are generated at case closure for audit readiness.
Decree 356 is the active implementing decree beneath the PDPL. Decision 778 adds the administrative-procedure layer for relevant Ministry of Public Security interactions. ComplianceOne links the layers while preserving their separate roles.
No. NQ22 is a temporary procedural overlay. It adjusts selected administrative handling from 29 April 2026 through 1 March 2027 and does not create the draft cybersecurity and personal data protection sanctions framework.
No. NQ22 identifies the National Public Service Portal, direct submission, and postal submission as official channels. Any email evidence-pack route is presented as practical, unofficial guidance that requires legal review.
No. Forseti AI may assist with review or drafting, but it cannot approve a package. A human approval gate is required, and any direct email uses a provider configured and controlled by the customer.
ComplianceOne can retain sending proof, record authority responses, and track hard-copy follow-up when requested. Those records remain linked to the package and its audit history.
Yes. ComplianceOne supports all Vietnam regulatory frameworks within a shared workflow engine. Organizations subject to multiple frameworks, such as PDPL, the Data Law, and the Cybersecurity Law, manage all obligations from a single platform with consistent audit trail coverage and evidence production across frameworks.

Test PDPL compliance workflows with your team – DPIA filing, rights requests, breach notification, and evidence generation.

Talk to our team about PDPL compliance operations, multi-framework coverage, and deployment options for your organization.