DPO Radio

This draft enforcement instrument contains sanctions chapters relevant to both Vietnam’s Cybersecurity Law and Personal Data Protection Law. It is not a PDPL-only decree and is not yet promulgated.
The draft can inform readiness work, but its provisions, structure, and fine language may change. ComplianceOne therefore presents it as a draft enforcement overlay with explicit status warnings.
No draft fine amount is represented as a final penalty. Current obligations continue to come from the applicable enacted laws, decrees, and procedures.

The Vietnam Personal Data Protection Law (Law 91/2025/QH15) is the parent statutory framework establishing the compliance obligations. Decree 356/2025/ND-CP specifies the administrative procedures and form requirements. For current obligations under both instruments, see the Vietnam PDPL (Law 91/2025/QH15) compliance page and the Decree 356 PDPL Implementation page.
The Draft Enforcement Decree 2026, when enacted, will complete the PDPL regulatory instrument hierarchy by adding the enforcement layer. Organizations that have already built compliant operations under Law 91 and Decree 356 will have the strongest defensive position under the enforcement regime. Organizations that are still building toward compliance when the enforcement decree takes effect will face a shorter window between enactment and enforcement action.
For the Enterprise DPO, the Breach Response Lead, and the Internal Audit Lead, the enforcement decree is relevant both as a compliance risk (what are the specific consequences of non-compliance) and as a compliance program driver (what evidence will be required to demonstrate compliance in an enforcement proceeding). Enforcement decrees typically establish record-keeping requirements that are more specific than the underlying compliance decree, because they need to define what evidence satisfies a compliance defense.
For personal data protection, the draft sits alongside the active PDPL, Decree 356, and Decision 778 operating stack. For cybersecurity, it sits alongside Law 116/2025/QH15 and the transition from the earlier cybersecurity framework.
The enforcement draft does not replace either parent law and does not merge their operational evidence. It provides a shared readiness lens for potential enforcement exposure across the two areas.
The draft is separate from Government Resolution NQ22/2026. NQ22 is a temporary personal data protection procedural overlay; it is not a sanctions instrument.
| Draft Area | Readiness Focus | Status Guardrail |
|---|---|---|
| Personal data protection sanctions | Evidence for assessments, transfers, rights, consent, incidents, and accountable processing | Draft only; no final fine claims |
| Cybersecurity sanctions | Evidence for incidents, authority cooperation, controls, and remediation | Draft only; no final fine claims |
| Aggravating or mitigating context | Record cooperation, remediation, repeat findings, and management decisions | Treat as draft criteria until promulgated |
| Inspection and evidence response | Maintain complete, reviewable records for authority requests | Current evidence readiness, not a prediction of final procedure |
| Remediation | Assign owners, actions, due dates, and closure evidence | Valuable regardless of final draft changes |
Organizations can improve readiness without relying on unsettled penalty text. The practical focus is the quality of current compliance evidence: complete assessment records, approved forms, incident history, control evidence, authority interactions, and closed remediation.
A draft readiness review should identify missing evidence and accountable owners across both cybersecurity and personal data protection. Findings should link to current enacted obligations rather than to speculative final penalties.
When the instrument is promulgated, teams should review the final title, scope, effective date, sanction structure, procedures, and authority guidance before converting draft readiness items into active controls.

ComplianceOne keeps the draft overlay distinct from current law. Teams can assess evidence coverage, record findings, assign remediation, and preserve the assumptions used for each readiness decision.
Evidence from personal data protection and cybersecurity records can be linked into a shared readiness review without being duplicated or stripped of source context. Human reviewers can assess completeness and approve remediation priorities.
Regulatory-change tracking supports a later comparison between the draft and promulgated instrument. This helps teams update the operating model based on final text rather than silently carrying draft assumptions forward.
Coordinates regulatory-change review, ownership, findings, and remediation.
Explore Program GovernanceRecords draft risk areas without presenting them as final penalties.
Explore Risk and AssessmentMaintains incident, notification, response, and remediation evidence.
Explore Data MappingConnects current official forms to their supporting evidence and approval.
Explore Compliance FormsOrganizations preparing for the anticipated enforcement decree should confirm:
See how ComplianceOne assesses evidence gaps and remediation without converting draft sanctions into final-law claims. Request a demo.

No. It remains a draft and may change before promulgation. ComplianceOne presents it as a readiness overlay, not an active source of final penalties.
The obligations being enforced under the draft decree – DPIA filing, breach notification, consent management, cross-border transfer documentation – are already in force under Law 91/2025/QH15 and Decree 356/2025/ND-CP. The enforcement decree will not create new obligations; it will specify penalties for non-compliance with existing obligations. An organization that is not yet compliant today is accumulating enforcement risk that the decree's enactment will convert into quantified penalty exposure. Preparation is more effective before the decree takes effect, when there is still time to remediate gaps without enforcement scrutiny.
No. The draft includes sanctions chapters relevant to both cybersecurity and personal data protection, which is why the same page is linked from both parent frameworks.
Based on the structure of Law 91 and Decree 356, and the pattern of enforcement priorities in comparable Vietnamese administrative frameworks, the most likely primary enforcement areas are: DPIA filing completeness for high-risk processing activities; breach notification compliance (72-hour window and Mau so 08 form requirements); cross-border transfer documentation; and consent record quality. These are the areas where Law 91 and Decree 356 are most prescriptive and where evidence requirements are most clearly defined. ComplianceOne's enforcement readiness assessment focuses on these areas.
Yes. The enforcement decree's specific requirements – penalty tiers, record-keeping requirements, procedural obligations – will be reflected in updated compliance rules in the Program Governance module when the decree is enacted. This may include updates to compliance scoring, new evidence categories, and updated alert thresholds. ComplianceOne's compliance rules are configurable without platform updates, allowing rapid alignment to enacted instrument requirements.
Yes. Draft provisions are inherently subject to change. The preparation approach recommended here focuses on actions that strengthen compliance under Law 91 and Decree 356 regardless of how the enforcement decree's specific provisions are finalized – completing DPIA filings, ensuring breach notification workflows are functional, verifying evidence pack quality. These actions reduce compliance risk and improve enforcement defensibility under any likely version of the enforcement decree.
Organizations can review evidence completeness, incident records, official forms, authority interactions, controls, and remediation. Those improvements remain useful even if the draft changes.

Test enforcement readiness workflows with your team – evidence pack generation, DPIA filing completeness assessment, and compliance documentation review.

Talk to our team about enforcement readiness preparation, compliance posture assessment, and how to structure your PDPL compliance program for defensibility under the anticipated enforcement regime.