Personal Data Protection

Data Processing Impact Assessment Vietnam: 2026 Compliance Guide

A practical 2026 Vietnam data-processing impact assessment guide covering controller and processor roles, processing purposes, data mapping, legal basis, consent, children, sensitive data, vendors, security, retention, data-subject rights, cross-border transfers and evidence-based updates after system, purpose or vendor changes.

JURION & PARTNERS 9 min read

Data processing impact assessment Vietnam work documents how an organization collects, uses, shares, stores, protects and deletes personal data, why each activity is necessary and which risks require control. The assessment should reflect real systems and decisions. A generic policy copied into a form cannot explain a recruitment platform, customer-profiling tool, CCTV network or cross-border cloud environment.

For an intended August 2026 publication, the current core framework is the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, both effective from 1 January 2026. Decree No. 13/2023/ND-CP belongs to the earlier framework and should not be presented as current authority. Existing files created under that decree should be reviewed and transitioned against the new law, decree and official procedure.

Jurion & Partners' Personal Data Protection practice can coordinate legal, security, procurement and operational inputs. This article gives general information, not legal advice or confirmation that a particular assessment satisfies filing, update or inspection requirements.

Official legal references used for this guide

  • Law on Personal Data Protection No. 91/2025/QH15, effective 1 January 2026.
  • Decree No. 356/2025/ND-CP, effective 1 January 2026, detailing and guiding the current framework.
  • Cybersecurity, electronic-transactions, consumer, employment, healthcare, banking and sector rules where they apply to the processing.
  • Current official forms, submission channels and competent-authority guidance at the assessment or update date.
  • Decree No. 13/2023/ND-CP only as historical evidence for pre-2026 files, not as current August 2026 authority.

Scope a data processing impact assessment Vietnam correctly

Begin with the processing operation and decision required. An enterprise-wide inventory, a new mobile application, employee monitoring, biometric access, marketing analytics, an artificial-intelligence tool and a vendor migration may need different assessment boundaries. Define entities, systems, locations, people, products, launch date and whether an existing process is changing.

Data processing impact assessment Vietnam work should state which legal deliverable is being prepared and whether a cross-border transfer assessment or another sector filing is separate. The engagement should identify the legal cut-off date, assumptions, evidence sample and responsible approvers. One file should not be labeled as satisfying every data obligation unless it genuinely contains each required analysis.

Set a change-control rule at the start. A new purpose, data type, algorithm, vendor, destination, user group, security architecture or retention period can make the assessment inaccurate. The product owner should notify privacy and security reviewers before deployment, not after the changed processing is discovered in an incident.

Identify controller, processor and other roles

Role allocation follows actual decisions and processing, not the heading of a vendor contract. Determine who decides purposes and means, who acts on instructions, who receives data and whether parties make independent or joint decisions. Map each legal entity separately; a group privacy notice does not erase corporate roles.

A service provider may process data for a customer while acting independently for security, billing or legal compliance. Those activities should be separated. Contracts, architecture, support access and deletion behavior must tell a consistent story. Incorrect role allocation can distort notices, rights handling, security, incident response and assessment responsibilities.

Two advisers assess data-flow charts and risk metrics in a security operations room for a Vietnam data processing impact assessment
Two advisers assess data-flow charts and risk metrics in a security operations room, illustrating a practical workstream in a Vietnam data processing impact assessment.

Build the data inventory and end-to-end flow

Inventory personal-data elements rather than using labels such as “customer data.” Identify identity, contact, financial, location, device, behavior, communication, employment, health, biometric and inferred data as applicable. Mark sensitive categories under the current law and decree. Explain whether information is collected directly, observed, generated or obtained from another source.

The flow should show collection interface, device, application, API, database, analytics, backup, support access, vendor, country, archive and deletion. Include manual exports and messaging channels; many incidents occur outside the primary system. Reconcile diagrams with contracts, configuration, access lists and logs.

For data processing impact assessment Vietnam quality, record volumes, frequency, affected groups and special vulnerability. Processing data about children, employees, patients or people unable to freely refuse may require enhanced analysis. A small dataset can still create serious harm if it contains identity credentials, health information or precise location.

Evidence map for a processing assessment
Assessment areaEvidenceControl question
PurposeProduct requirement, policy, notice and management approvalIs each use specific, lawful and necessary?
Data flowArchitecture, API, database, export and backup recordsWhere does each data type actually travel?
RolesDecisions, instructions, contracts and accessWho controls, processes or independently uses data?
RightsRequest channel, identity checks, workflow and logsCan requests be completed across all systems?
SecurityAccess, encryption, logging, testing and incident recordsDoes control design match the stated risk?
DeletionRetention schedule, system rules, backups and vendor proofCan the organization stop use and delete lawfully?

State purpose, legal basis and necessity

Each processing purpose should be understandable and operational. “Business improvement” may cover unrelated analytics, marketing and product development and is too broad for good governance. Break it into decisions and outputs. Identify the current legal basis or permitted ground for each activity and the evidence supporting it.

Where consent is used, examine whether it is informed, specific, freely expressed and recorded under current requirements. Bundling necessary service processing with optional marketing can undermine choice. A withdrawal mechanism must connect to systems and vendors. Consent should not be used to conceal a processing activity that is unnecessary or misleading.

Data processing impact assessment Vietnam analysis should compare the purpose with less intrusive alternatives. Ask whether the same result can be achieved with fewer fields, shorter retention, local processing, aggregation, lower precision or voluntary participation. Document why the selected approach is proportionate.

Assess notices and data-subject rights

Notices should describe the actual controller, purposes, data, recipients, risks, time, rights and contact route required by current law. Layered notices can help comprehension, but the short layer must not contradict the full document. Product teams should verify that notice appears at the appropriate collection or decision point.

Test rights with realistic scenarios. Can the organization locate a person's data across active systems, vendors, archives and backups? Can it verify identity without collecting excessive new data? Who determines a lawful restriction, and how is the response recorded? A policy without a working ticket and ownership process is not an effective control.

Evaluate security and incident readiness

Security review should connect threat, vulnerability, likelihood, impact and control. Relevant measures may include access control, multifactor authentication, encryption, segregation, secure development, patching, monitoring, backup, testing, vendor oversight and staff training. Do not list a certification as though it proves every system is covered.

Risk scenarios should be specific: credential theft exposing payroll; an API returning another customer's profile; an employee export sent to a personal account; a vendor support session copying production data; or a backup retained after deletion. Rate inherent and residual risk using defined criteria and record who accepts any residual risk.

Test the incident path, not only the prevention control

Run a tabletop exercise showing detection, triage, containment, evidence, legal assessment, authority and individual notification, remediation and lessons learned. Confirm contact details and time zones for vendors. The incident log should allow counsel to determine facts and deadlines without waiting for a perfect root-cause report.

A privacy team reviews global transfer routes and processing risks on wall displays for a Vietnam data processing impact assessment
A privacy team reviews global transfer routes and processing risks on wall displays, illustrating a practical workstream in a Vietnam data processing impact assessment.

Handle sensitive data, children and employee monitoring

Sensitive personal data requires identification and controls matching the current statutory category and risk. Limit access, separate duties, restrict exports, enhance logging and scrutinize retention. Avoid placing highly sensitive fields in free-text notes or test environments where governance is weak.

For children, verify age-related processes, parental or guardian involvement where required, notices and the child's best interests under applicable law. Do not use manipulative interface design to obtain agreement. Reassess profiling, advertising, location and public-sharing features with particular caution.

Employee monitoring occurs in a relationship where consent may not be freely refused. Define necessity, transparency, access, review, retention and prohibited uses. Continuous surveillance should not be adopted merely because technology makes it possible. Consult employment rules and internal governance alongside data-protection law.

Control processors and downstream vendors

Vendor diligence should examine service scope, data location, subprocessors, security, incident history, rights support, deletion, audit evidence, government requests and exit. Contract terms should match actual product capabilities. A vendor promise to delete “customer content” may exclude logs, models, support tickets or backups unless defined.

Data processing impact assessment Vietnam files should include a vendor decision, approved configuration and residual-risk owner. Procurement approval alone does not close privacy risk. After signing, monitor material changes, security reports, subprocessors and incidents and reassess before expanding use.

Assess cross-border transfers as a distinct workstream

Identify each foreign destination, recipient, remote-access country, cloud region, support location and onward transfer. The fact that a server is in Vietnam does not eliminate foreign access; the fact that a vendor is Vietnamese does not prove local storage. Verify configuration and contractual flow.

The Law 91/2025 and Decree 356/2025 framework should be used to determine the applicable cross-border assessment, documentation, filing or update duties at the transfer date. Do not reuse an old Decree 13 template as though it were current. Preserve official submission evidence and connect it to the exact system version assessed.

A credible impact assessment does not claim that risk has disappeared. It shows which data and people may be affected, why processing remains necessary, which controls reduce harm, who accepted residual risk and which change will trigger a new review.

Jurion & Partners Professional Perspective

Set retention, deletion and exit controls

Retention should be defined by record category, purpose, legal requirement and trigger, not “as long as needed.” Map deletion across production, cache, archive, backup, analytics and vendors. Where immediate backup deletion is not technically feasible, restrict restoration and ensure deleted data is not returned to active use.

For system or vendor exit, plan export format, identity, integrity, deletion confirmation, access revocation and business continuity. A data-processing assessment should test whether the organization can end processing, not only how it begins.

Approve, submit and maintain the assessment

The final file should identify version, scope, system owner, controller and processor roles, evidence, legal analysis, risk register, controls, residual-risk approvals, required official action and review triggers. Approval should come from people with authority over product, security, legal obligations and resources.

For data processing impact assessment Vietnam procedure, verify the official filing or submission channel, required content, timing and update duties under Law 91/2025, Decree 356/2025 and current guidance. Keep receipt and correspondence. Do not state an inherited deadline from the 2023 decree without confirming that the current instrument preserves it.

A data processing impact assessment Vietnam review register should record planned and event-driven reassessments. Product owners should report a new purpose, sensitive field, automated decision, vendor, destination, user population or security incident. Privacy counsel can then decide whether the existing file needs an amendment, replacement or additional official action. This keeps data processing impact assessment Vietnam evidence connected to the deployed system instead of a historic approval snapshot.

A presenter explains a cross-border data map to legal, security and business stakeholders for a Vietnam data processing impact assessment
A presenter explains a cross-border data map to legal, security and business stakeholders, illustrating a practical workstream in a Vietnam data processing impact assessment.

Related privacy guidance is available through Legal Insights. Organizations launching or changing a high-risk process can Book a Consultation and provide the data map, architecture, vendor list, current assessment and launch date through a secure channel.

Conclusion on data processing impact assessment Vietnam

An assessment is useful when it makes processing visible and decisions accountable. It should connect purposes, roles, data flows, rights, security, vendors, transfers, retention and incident response to verified systems and evidence. The move to Law 91/2025 and Decree 356/2025 requires organizations to check pre-2026 files rather than relabel them.

Data processing impact assessment Vietnam work is most effective before procurement, development or launch makes the architecture difficult to change. A current, evidence-based file helps management reduce harm, fund remediation, demonstrate responsibility and keep the assessment accurate as technology, vendors, purposes and the legal framework evolve.

Article topics
Article author

JURION & PARTNERS

Editorial Team · Jurion & Partners

Read more

Related Legal Insights

Các nội dung dưới đây mở rộng góc nhìn về vấn đề liên quan, giúp người đọc hệ thống hóa dữ kiện, nhận diện câu hỏi trọng tâm và chủ động chuẩn bị cho quá trình trao đổi chuyên môn.

Illustrate the article Vietnam data privacy compliance: Risk and Controls Guide Phân tích

Personal Data Protection

Vietnam data privacy compliance: Risk and Controls Guide

Vietnam data privacy compliance requires a fact-specific assessment of governance, controls and remediation concerning data privacy compliance. This guide explains the compliance questions to ask, the evidence to organize, the people and approvals to map, the risks to prioritize and the practical steps to consider before obtaining advice tailored to the current circumstances.

Prioritize an appointment

Do you want to talk directly with a lawyer?

Schedule an appointment so the Jurion & Partners team can understand your circumstances, identify the key legal questions, assess the available information and prepare an appropriate consultation approach aligned with your immediate priorities and practical objectives.

Schedule a consultation