Skip to content
Blog

A PDPL compliance checklist for businesses: what to do, who owns it, by when

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··10 min read
A PDPL compliance checklist for businesses: what to do, who owns it, by when

Photo: Anastassia Anufrieva / Unsplash

Vietnam's Personal Data Protection Law (Law 91/2025/QH15) and Decree 356/2025/ND-CP both took effect on 1 January 2026. This is an execution-grade PDPL compliance checklist: every item states the task, the owner, the evidence to keep, and the statutory deadline where the law sets one. The legal background and the architecture argument live in why on-premise is the safer path to compliance; this piece is only about the work.

Two questions come up first. Compliance does not start with writing a policy — it starts with knowing what data you hold, because every filing you owe later draws on that inventory. And do small businesses have to comply: yes, the law applies in full; only three obligations are relaxed by company size, as set out in group 0.

Diagram of the workstreams in the PDPL compliance checklist

Group 0. Establish which regime you fall under

  • Confirm your company size. Household businesses and micro-enterprises are not required to perform Articles 21, 22 and clause 2 of Article 33 of the Law — impact assessment records, their updates, and the appointment of data protection personnel. Small businesses and startups may choose whether to perform those three obligations for five years from the Law's effective date: a time-limited grace period, not a permanent exemption. Owner: legal counsel with the chief accountant. Evidence: a minute recording the size classification, filed with the latest financial statements.
  • Check the three disqualifiers. The relief does not apply to businesses that provide personal data processing services, that directly process sensitive personal data, or that process the data of 100,000 or more data subjects on a cumulative basis (Article 41, Decree 356/2025/ND-CP). Because the threshold is cumulative, it needs continuous tracking rather than a one-off assessment. Owner: the data protection officer. Evidence: a quarterly count of data subjects.
  • Confirm what you do not have to redo. Consent validly obtained under Decree 13/2023/ND-CP before 1 January 2026 remains valid and need not be collected again (Article 39 of the Law). Do not spend budget re-consenting your legacy customer base.

Group 1. Data map and legal basis

  • Build a processing inventory. For each system, record what personal data you collect, from whom, for what purpose, on what legal basis, who can access it, where it lives, how long it is kept, and who it is shared with. Owner: each process owner (HR, sales, support, finance), consolidated by legal. Evidence: a versioned inventory with review dates.
  • Flag sensitive data. Compare against the list of sensitive personal data in Article 4 of Decree 356, which covers biometric data, health status, location determined through positioning services, bank account details and transaction history, and images of identity cards. Many organisations are surprised that fingerprint attendance systems and scanned ID cards in HR files fall inside this category.
  • Record where the data physically sits. Note which systems run inside Vietnam and which rely on platforms located abroad. This is required input for group 3. If the hosting question is open, on-premise or cloud under data compliance rules goes deeper.

Group 2. Collecting consent from data subjects

  • Standardise how consent is captured. Article 6 of Decree 356 lists the accepted methods: in writing, by recorded call, by SMS keyword, by email or a technical consent mechanism on a website or app, and other methods that can be printed or copied. The common requirement is verifiability of who consented, when, and to what.
  • Remove every pre-ticked box. The Decree prohibits default-consent settings and instructions that blur consent and refusal. Owner: product and marketing. Evidence: before-and-after screenshots of each form, with release dates.
  • Give a separate notice for sensitive data. When seeking consent to process sensitive personal data, the data subject must be told explicitly that the data in question is sensitive.
  • Store the proof. Controllers must retain consent records, and in a dispute the burden of proving consent falls on the controller. Evidence: a timestamped consent log, not a status field that gets overwritten.

Group 3. Impact assessment records

  • File the DPIA within 60 days. Controllers and controller-processors must prepare and retain a processing impact assessment record and send one original to the specialised personal data protection authority within 60 days from the first day of processing (Article 21 of the Law). The file contents and report template, Form No. 10, are set out in Article 19 of Decree 356.
  • File a TIA if data leaves the country. Article 20 of the Law defines cross-border transfer broadly, including the use of a platform located outside Vietnam to process data collected in Vietnam. A customer support system running on foreign servers already triggers the obligation. The record is due within 60 days from the day the transfer begins, using Form No. 09 under Article 18 of Decree 356.
  • Schedule the updates. Records are updated every 6 months from the first filing when a new processing purpose arises or the parties change. Some changes require an update within 10 days: corporate reorganisation, a change of data protection service provider, and any new or changed line of business involving personal data processing (Article 20 of Decree 356). Owner: the data protection officer. Evidence: reminder schedule and filing receipts.
  • Leave room for the review cycle. The authority returns a pass or fail result within 15 days and may require the file to be completed within 30 days if it is incomplete. Do not file on day 59.

Group 4. Appointing data protection personnel

  • Issue a written appointment. The appointment of data protection personnel or a data protection unit must be made by a formal written document setting out the assignment, functions, duties and powers (Article 13 of Decree 356). Evidence: a decision signed by the legal representative.
  • Verify the qualification criteria. The appointee must hold at least a college-level qualification, have at least two years of post-graduation experience in legal affairs, IT, cybersecurity, data security, risk management, compliance or HR, and must have been trained in data protection law and practice.
  • Assign the right duties. Article 14 of Decree 356 covers policies and templates, delivering data subject rights, periodic compliance self-assessments, preparing DPIA and TIA records, reporting breaches, and running training. Where in-house capacity is short, the Law allows engaging an external data protection service provider (Article 33, clause 2).
  • Sign a confidentiality agreement. The organisation signs a confidentiality undertaking with its data protection personnel.

Group 5. Reviewing contracts with processors

  • Review cloud contracts. For contracts involving personal data processing signed with cloud providers, Article 12 of Decree 356 requires the contract to state compliance with Vietnamese data protection law, name the data protection contact, define the processing flow and each party's role, specify security measures, require immediate notice of changes affecting personal data, set retention and deletion terms, guarantee data subject rights, and provide tiered access control.
  • Check the encryption requirement. Personal data in cloud environments must be encrypted at rest and in transit, with strict access control. Evidence: encryption configuration and a permission matrix exported from the system.
  • Paper the data transfers. When personal data is passed to another party, Article 7 of Decree 356 requires an agreement stating the purpose, the categories of data subjects and data, the processing period, the deletion requirement once the purpose is met, and the legal basis.
  • Push it into procurement. The durable fix is to make these clauses a selection condition for vendors — see the third-party risk checklist for SaaS. Owner: procurement and legal.

Group 6. Handling data subject requests

Article 5 of Decree 356 sets precise clocks, and this is where summaries most often get it wrong. In every case the organisation must respond within 2 working days and explain the procedure.

  • Access, correction, data portability. Complete within 10 days; 15 days if a processor or third party has to make the correction. One extension only, of no more than 10 days.
  • Withdrawal of consent, restriction, objection. Complete within 15 days; 20 days if a processor or third party has to stop processing. One extension only, of no more than 15 days.
  • Deletion. Complete within 20 days; 30 days if a processor or third party is involved. One extension only, of no more than 20 days.
  • Justify any extension. The burden of proving that an extension was necessary sits with the controller, so the reason has to be written down. Evidence: a request register with received, responded, completed dates and the handler's name.

Group 7. The breach notification template and the 72-hour clock

  • Prepare the template in advance. Article 28 of Decree 356 sets the required content of a breach notification: the time, place and nature of the breach, the parties involved, the categories and volume of data, the data protection contact, the potential consequences, and the remediation measures taken. It is submitted on Form No. 08, to the specialised authority or through the national personal data protection portal.
  • Get the 72-hour trigger right. Where a breach may harm national defence, national security, social order, or the life, health, honour, dignity or property of data subjects, the authority must be notified no later than 72 hours from discovery (Article 23 of the Law). The clock starts at discovery, not at the end of the investigation.
  • Treat location and biometric data separately. For incidents involving location or biometric data, in addition to reporting to the authority you must notify affected data subjects within 72 hours of discovery and retain the incident file for at least 5 years from the date the incident is resolved (Article 29 of Decree 356).
  • Record the incident formally. The controller must draw up a minute confirming the breach and coordinate with the authority. Owner: head of IT with the data protection officer. Evidence: the minute, system logs from the incident window, and a copy of the notification sent.
  • Rehearse once a year. A two-hour tabletop exercise surfaces what matters most: who may send the notification outside office hours.

Group 8. Infrastructure, access control and logging

  • Review access on a least-privilege basis. Each account should see only the data its job requires. Evidence: an exported role-permission list with a review date and an approver.
  • Log access to personal data. Without logs you can prove nothing in an inspection, and you cannot scope the blast radius during an incident.
  • Test that deletion actually works. Run one deletion request end to end, including backups and reporting systems. Many organisations discover the data still sitting in the analytics warehouse after it was removed from the system of record.
  • Shrink your cross-border footprint. Every system brought back onto domestic infrastructure is one TIA you do not have to file and one risk cluster you do not have to manage. The operational duties under Decree 356 are summarised in Decree 356 and its operating obligations.

Prioritise by penalty exposure, not evenly

Article 8 of the Law sets three maximum penalty regimes, and reading it correctly helps sequence the work. Buying or selling personal data carries a maximum of 10 times the proceeds of the violation. An organisation's breach of the cross-border transfer rules carries a maximum of 5% of its prior-year revenue, and only this category is revenue-based. Other violations carry a maximum of 3 billion VND. An individual committing the same conduct faces half the organisational maximum. So cross-border transfer records and control over data leaving the country are the largest financial exposure, and they go first. The full texts are available for the Personal Data Protection Law No. 91/2025/QH15 and Decree 356/2025/ND-CP for article-by-article checking before you decide anything.

Conclusion

A PDPL compliance checklist is not a binder on a shelf. Most of the work is recording what you already do in a way you can prove: a versioned data inventory, consent logs, filing receipts, a request register, incident minutes. When an inspection arrives, those are the only things you need to open.

Tetra eOffice and Manta Security run on-premise with role-based permissions, access logging and data kept inside your own systems, which makes the group 8 evidence easier to produce. To review where you stand and build a roadmap against this checklist, book a consultation.

Note: this article is for reference only and is not a substitute for legal advice.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist