Skip to content
Blog

Decree 356 guiding PDPL: turning the law into operational duties

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··1 min read
Decree 356 guiding PDPL: turning the law into operational duties

Photo: Claudio Schwarz / Unsplash

A law sets principles; a decree turns principles into daily tasks. Decree 356/2025/ND-CP guides the Personal Data Protection Law (PDPL), also effective from 1 January 2026, and makes the compliance duties concrete for businesses.

What Decree 356 makes concrete

  • Data protection impact assessment records — businesses must prepare, keep and present them on request.
  • Data protection personnel/unit (DPO): qualifications and responsibilities are clarified.
  • Breach notification within the statutory window (72 hours for the specified cases).
  • Cross-border personal-data transfers: the duty to prepare an impact assessment.

From knowing the law to complying

Decree 356 is why PDPL compliance cannot stop at reading the law. Turn these into operational processes — see the PDPL compliance checklist to start, and PDPL 2026 in effect for why on-premise helps.

How Tetra helps

Tetra eOffice and Manta Security run on-premise, supporting permissions, access logs and keeping data in your systems — the basis for meeting these duties. For advice, book a consultation.

Note: this article is for reference only and is not a substitute for legal advice.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist