DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

AesirX ComplianceOne | Vietnam PDPL Compliance

Overview Image

Why the Vietnam PDPL Matters

The Vietnam Personal Data Protection Law (Law 91/2025/QH15) is Vietnam's comprehensive personal data protection framework. Administered by the Ministry of Public Security (MPS), it establishes obligations for organizations that collect, store, process, or transfer personal data within Vietnam or involving Vietnamese data subjects. Effective from 1 January 2026, it is supported by implementing and procedural instruments that define how those obligations operate in practice.

Implementation Decree 356/2025/NĐ-CP provides the active operational requirements, Decision 778/QĐ-BCA-A05 establishes Ministry of Public Security administrative procedures, and Government Resolution NQ22/2026 temporarily adjusts selected procedures until 1 March 2027. A separate draft enforcement instrument covering both personal data protection and cybersecurity remains under development.

Organizations must coordinate DPIAs, cross-border transfer assessments, data subject rights, breach notifications, consent records, and authority interactions across legal, IT, HR, marketing, procurement, and other business functions. These activities require more than standalone policies, they require evidence that the work was completed, reviewed, and approved.

ComplianceOne keeps the full stack connected while preserving each instrument's legal status. Current obligations, temporary procedures, draft enforcement preparation, and submission activities are managed within their own legal context.

What the Vietnam PDPL Covers

Dimension

Coverage

Core obligations

Lawful processing, consent, rights, impact assessment, cross-border transfer governance, incidents, responsible personnel, and processing records.

Active implementation

Decree 356/2025/NĐ-CP and Decision 778/QĐ-BCA-A05.

Temporary procedure

NQ22/2026, effective 29 April 2026 through 1 March 2027.

Draft enforcement

Shared cybersecurity and personal data protection sanctions draft; not yet in force.

Evidence requirements

Assessment dossiers, official forms, supporting records, approvals, submission proof, authority responses, and audit history.

Practical email guidance

An optional, unofficial evidence-pack route that requires legal review and customer-controlled sender configuration.

The PDPL Instrument Stack

The PDPL compliance landscape spans current requirements, superseded instruments still relevant as context, and upcoming enforcement changes. Understanding the full picture matters.

Decree 356/2025/NĐ-CP

Active Implementing Decree

Decree 356 provides the detailed implementing rules and official forms for impact assessment, cross-border transfer, dossier updates, incidents, and service-provider procedures.

Decision 778/QĐ-BCA-A05

Active Administrative Procedures

Decision 778 operationalizes Ministry of Public Security handling for relevant personal data protection procedures. It complements the forms and obligations rather than replacing them.

Government Resolution NQ22/2026

Temporary Procedural Overlay

NQ22 temporarily simplifies or adjusts selected administrative procedures. It is procedural only, expires on 1 March 2027, and is not a sanctions instrument.

Shared Cybersecurity and PDPL Enforcement Draft

Draft

The draft enforcement overlay covers sanctions chapters across both laws. Its draft fine language is not presented as final, and it remains separate from NQ22.

Vietnam PDPL (Decree 13/2023 era)

Legacy

Legacy compliance records, evidence retention obligations, and transition gap analysis for the regulatory period that preceded Vietnam's comprehensive PDPL.

Decree 13 – PDPL Operational Baseline

Legacy

Legacy compliance program architecture that organizations built under Decree 13 and what carried forward into the PDPL era.

Overview Image

How ComplianceOne Supports the Vietnam PDPL

ComplianceOne operationalizes the Vietnam Personal Data Protection Law through governed workflows for Data Processing Impact Assessments (DPIAs), Cross-Border Transfer Impact Assessments (TIAs), data subject rights, consent, incidents, and authority interactions. Teams can assign contributors, collect processing and transfer evidence, prepare the official forms under Implementation Decree 356/2025/NĐ-CP, review responsible-personnel records, route submissions through approval workflows, and retain a complete history of decisions and approvals.

Evidence packs connect completed forms with their supporting documentation, audit records, and submission context. Teams can review completeness, approve the package, and preserve evidence of what was prepared, submitted, and acknowledged throughout the filing lifecycle.

Where Government Resolution NQ22/2026 permits practical authority-facing email guidance, ComplianceOne supports package assembly, review, optional Forseti AI drafting assistance, customer-controlled email configuration, response tracking, and required hard-copy follow-up. Email is not presented as an official submission channel, AesirX is not the default sender, and every submission remains subject to human review and approval.

Records, supporting evidence, approvals, submissions, authority responses, and audit history remain connected across the operational lifecycle, preserving the operational proof behind every compliance decision.

Related Modules

DPIA and Assessments

Coordinates processing and transfer assessments, evidence, review, and approval.

Explore DPIA and Assessments

Data Mapping

Maintains processing, system, data-flow, and transfer context.

Explore Data Mapping

Rights Requests

Manages intake, verification, fulfillment, response, and closure evidence.

Consent Governance

Records consent, legal basis, changes, and withdrawal history.

Incident Response

Supports incident assessment, notification records, remediation, and authority interaction.

Explore Incidents

Compliance Forms

Supports official Mẫu số forms with linked evidence and approvals.

Explore Compliance Forms

Audit Trail

Preserves contributor, review, approval, sending, and response history.

Explore Audit Trail

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconAssessment dossiers are assembled from disconnected department files.
IconAssessment and transfer dossiers retain owners, evidence, review, and approval.
IconOfficial forms lose their supporting evidence and approval context.
IconForms, supporting records, and submission packages stay connected.
IconTemporary procedures are mistaken for permanent or substantive legal changes.
IconNQ22 is tracked as a temporary procedural overlay with an expiry review.
IconDraft sanctions are confused with enacted penalties.
IconDraft enforcement readiness remains separate from current obligations.
IconSubmission proof and authority responses remain in individual inboxes.
IconSending proof, responses, and hard-copy follow-up form one audit-ready record.

Built for PDPL Compliance Operations

Build For Image

ComplianceOne supports the complete operating stack without presenting temporary procedures, unofficial guidance, or draft enforcement language as final law.

Build For Image

Human approval gates keep accountability with the customer, including where Forseti AI assists with review or drafting.

Build For Image

Evidence remains connected from the underlying processing activity through dossier preparation, submission proof, authority response, and follow-up.

Background Image

Book a Demo

Ready to see how ComplianceOne's command center, guided setup, platform administration, and AI advisor work together in practice? Request a personalized demo with your compliance scenarios.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

Yes. The platform includes interactive Form Wizard templates for all Mau so administrative procedure forms and all Phu luc statutory annexes defined by Decree 356/2025/ND-CP. Forms are pre-labeled with official template IDs and structured to match the format required by MPS administrative procedures.

The DPIA workflow routes specific dossier sections to responsible departments (legal, IT security, HR, marketing, procurement), tracks each department's contribution progress against shared deadlines, and consolidates completed sections into a submission-ready package. Contributor lineage is preserved in the audit trail, showing who completed which section and when.

The Incident Response module tracks the breach notification timeline from discovery, generates Mau so 08 (breach notification form) for MPS filing, manages supplement request loops if MPS requires additional information, and tracks remediation actions through to case closure. SLA enforcement is configurable to match your organization's internal escalation procedures.

Each rights request creates a case with identity verification, rights-type classification, department routing for fulfillment, SLA tracking against configured deadlines, and automated generation of acknowledgment, completion, or rejection documentation. Evidence packs are generated at case closure for audit readiness.

Decree 356 is the active implementing decree beneath the PDPL. Decision 778 adds the administrative-procedure layer for relevant Ministry of Public Security interactions. ComplianceOne links the layers while preserving their separate roles.

No. NQ22 is a temporary procedural overlay. It adjusts selected administrative handling from 29 April 2026 through 1 March 2027 and does not create the draft cybersecurity and personal data protection sanctions framework.

 

No. NQ22 identifies the National Public Service Portal, direct submission, and postal submission as official channels. Any email evidence-pack route is presented as practical, unofficial guidance that requires legal review.

 

No. Forseti AI may assist with review or drafting, but it cannot approve a package. A human approval gate is required, and any direct email uses a provider configured and controlled by the customer.

 

 ComplianceOne can retain sending proof, record authority responses, and track hard-copy follow-up when requested. Those records remain linked to the package and its audit history.

 

Yes. ComplianceOne supports all Vietnam regulatory frameworks within a shared workflow engine. Organizations subject to multiple frameworks, such as PDPL, the Data Law, and the Cybersecurity Law, manage all obligations from a single platform with consistent audit trail coverage and evidence production across frameworks.

 

Next Steps

Icon Image

Start a Compliance Pilot

Test PDPL compliance workflows with your team – DPIA filing, rights requests, breach notification, and evidence generation.

Icon Image

Discuss Your Compliance Needs

Talk to our team about PDPL compliance operations, multi-framework coverage, and deployment options for your organization.