DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

Draft Enforcement Decree 2026 (PDPL)

Overview Image

Draft Enforcement Decree 2026: Scope and Current Status

This draft enforcement instrument contains sanctions chapters relevant to both Vietnam’s Cybersecurity Law and Personal Data Protection Law. It is not a PDPL-only decree and is not yet promulgated.

The draft can inform readiness work, but its provisions, structure, and fine language may change. ComplianceOne therefore presents it as a draft enforcement overlay with explicit status warnings.

No draft fine amount is represented as a final penalty. Current obligations continue to come from the applicable enacted laws, decrees, and procedures.

Overview Image

How the Draft Relates to Its Parent Frameworks

The Vietnam Personal Data Protection Law (Law 91/2025/QH15) is the parent statutory framework establishing the compliance obligations. Decree 356/2025/ND-CP specifies the administrative procedures and form requirements. For current obligations under both instruments, see the Vietnam PDPL (Law 91/2025/QH15) compliance page and the Decree 356 PDPL Implementation page.

The Draft Enforcement Decree 2026, when enacted, will complete the PDPL regulatory instrument hierarchy by adding the enforcement layer. Organizations that have already built compliant operations under Law 91 and Decree 356 will have the strongest defensive position under the enforcement regime. Organizations that are still building toward compliance when the enforcement decree takes effect will face a shorter window between enactment and enforcement action.

For the Enterprise DPO, the Breach Response Lead, and the Internal Audit Lead, the enforcement decree is relevant both as a compliance risk (what are the specific consequences of non-compliance) and as a compliance program driver (what evidence will be required to demonstrate compliance in an enforcement proceeding). Enforcement decrees typically establish record-keeping requirements that are more specific than the underlying compliance decree, because they need to define what evidence satisfies a compliance defense.

For personal data protection, the draft sits alongside the active PDPL, Decree 356, and Decision 778 operating stack. For cybersecurity, it sits alongside Law 116/2025/QH15 and the transition from the earlier cybersecurity framework.

The enforcement draft does not replace either parent law and does not merge their operational evidence. It provides a shared readiness lens for potential enforcement exposure across the two areas.

The draft is separate from Government Resolution NQ22/2026. NQ22 is a temporary personal data protection procedural overlay; it is not a sanctions instrument.

  • Vietnam Personal Data Protection Law
  • Vietnam Cybersecurity Law 2025

Draft Enforcement Areas

Draft AreaReadiness FocusStatus Guardrail
Personal data protection sanctionsEvidence for assessments, transfers, rights, consent, incidents, and accountable processingDraft only; no final fine claims
Cybersecurity sanctionsEvidence for incidents, authority cooperation, controls, and remediationDraft only; no final fine claims
Aggravating or mitigating contextRecord cooperation, remediation, repeat findings, and management decisionsTreat as draft criteria until promulgated
Inspection and evidence responseMaintain complete, reviewable records for authority requestsCurrent evidence readiness, not a prediction of final procedure
RemediationAssign owners, actions, due dates, and closure evidenceValuable regardless of final draft changes

Preparing for the Draft Enforcement Decree 2026

Organizations can improve readiness without relying on unsettled penalty text. The practical focus is the quality of current compliance evidence: complete assessment records, approved forms, incident history, control evidence, authority interactions, and closed remediation.

A draft readiness review should identify missing evidence and accountable owners across both cybersecurity and personal data protection. Findings should link to current enacted obligations rather than to speculative final penalties.

When the instrument is promulgated, teams should review the final title, scope, effective date, sanction structure, procedures, and authority guidance before converting draft readiness items into active controls.

Overview Image

How ComplianceOne Supports Enforcement Readiness Preparation

ComplianceOne keeps the draft overlay distinct from current law. Teams can assess evidence coverage, record findings, assign remediation, and preserve the assumptions used for each readiness decision.

Evidence from personal data protection and cybersecurity records can be linked into a shared readiness review without being duplicated or stripped of source context. Human reviewers can assess completeness and approve remediation priorities.

Regulatory-change tracking supports a later comparison between the draft and promulgated instrument. This helps teams update the operating model based on final text rather than silently carrying draft assumptions forward.

Related Modules

Program Governance

Coordinates regulatory-change review, ownership, findings, and remediation.

Explore Program Governance

Audit Trail

Preserves decisions, reviews, approvals, and closure history.

Explore Audit Trail

Risk Assessments

Records draft risk areas without presenting them as final penalties.

Explore Risk and Assessment

Incident Response

Maintains incident, notification, response, and remediation evidence.

Explore Data Mapping

Compliance Forms

Connects current official forms to their supporting evidence and approval.

Explore Compliance Forms

Enforcement Readiness Preparation Checklist

Organizations preparing for the anticipated enforcement decree should confirm:

The draft is labeled as not yet in force.

Both cybersecurity and personal data protection scope are represented.

NQ22 remains separate as a temporary procedural overlay.

No draft fine amount is presented as a final penalty.

Readiness findings link to current enacted obligations and evidence.

Remediation work has accountable owners and closure proof.

Final promulgation will trigger a fresh legal and operational review.

Background Image

See Enforcement Readiness in Action

See how ComplianceOne assesses evidence gaps and remediation without converting draft sanctions into final-law claims. Request a demo.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

No. It remains a draft and may change before promulgation. ComplianceOne presents it as a readiness overlay, not an active source of final penalties.

The obligations being enforced under the draft decree – DPIA filing, breach notification, consent management, cross-border transfer documentation – are already in force under Law 91/2025/QH15 and Decree 356/2025/ND-CP. The enforcement decree will not create new obligations; it will specify penalties for non-compliance with existing obligations. An organization that is not yet compliant today is accumulating enforcement risk that the decree's enactment will convert into quantified penalty exposure. Preparation is more effective before the decree takes effect, when there is still time to remediate gaps without enforcement scrutiny.

 

No. The draft includes sanctions chapters relevant to both cybersecurity and personal data protection, which is why the same page is linked from both parent frameworks.

 

Based on the structure of Law 91 and Decree 356, and the pattern of enforcement priorities in comparable Vietnamese administrative frameworks, the most likely primary enforcement areas are: DPIA filing completeness for high-risk processing activities; breach notification compliance (72-hour window and Mau so 08 form requirements); cross-border transfer documentation; and consent record quality. These are the areas where Law 91 and Decree 356 are most prescriptive and where evidence requirements are most clearly defined. ComplianceOne's enforcement readiness assessment focuses on these areas.

 

Yes. The enforcement decree's specific requirements – penalty tiers, record-keeping requirements, procedural obligations – will be reflected in updated compliance rules in the Program Governance module when the decree is enacted. This may include updates to compliance scoring, new evidence categories, and updated alert thresholds. ComplianceOne's compliance rules are configurable without platform updates, allowing rapid alignment to enacted instrument requirements.

 

Yes. Draft provisions are inherently subject to change. The preparation approach recommended here focuses on actions that strengthen compliance under Law 91 and Decree 356 regardless of how the enforcement decree's specific provisions are finalized – completing DPIA filings, ensuring breach notification workflows are functional, verifying evidence pack quality. These actions reduce compliance risk and improve enforcement defensibility under any likely version of the enforcement decree.

 

Organizations can review evidence completeness, incident records, official forms, authority interactions, controls, and remediation. Those improvements remain useful even if the draft changes.

 

Next Steps

Icon Image

Start a Compliance Pilot

Test enforcement readiness workflows with your team – evidence pack generation, DPIA filing completeness assessment, and compliance documentation review.

Icon Image

Discuss Your Compliance Needs

Talk to our team about enforcement readiness preparation, compliance posture assessment, and how to structure your PDPL compliance program for defensibility under the anticipated enforcement regime.