Skip to content
Blog

PDPL compliance from 2026: why on-premise is the safer architecture

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··9 min read
PDPL compliance from 2026: why on-premise is the safer architecture

Photo: Towfiqu barbhuiya / Unsplash

Vietnam's Personal Data Protection Law (Law 91/2025/QH15, "PDPL") and Decree 356/2025/ND-CP both took effect on 1 January 2026, replacing Decree 13/2023. The question most organizations are asking is practical: what does PDPL compliance actually require, and which infrastructure choice carries less risk. The short answer is that the heaviest duty is proving you control the data — impact assessment records, a designated officer, a working process for data subject rights, and a breach notification procedure. An on-premise architecture does none of that for you, but it narrows what you have to prove and removes the hardest category of obligations altogether: cross-border transfers.

This article separates three layers: what the law says, what the decree turns into operational duties, and how far infrastructure design contributes to personal data protection. It ends with a checklist and the misreadings spreading fastest right now.

Diagram: on-premise data and PDPL compliance duties

What Law 91/2025 requires

Vietnam's first standalone statute on personal data was passed on 26 June 2025. Four parts matter most to people who build systems.

  • Scope. Article 1 covers Vietnamese entities and individuals, foreign entities operating in Vietnam, and foreign entities directly involved in or connected to the processing of Vietnamese citizens' personal data. Where your servers sit does not put you outside the law.
  • Data classification. Article 2 splits personal data into basic and sensitive, with the catalogues issued by the Government. The sensitive catalogue sits in Article 4 of Decree 356 and is broader than most teams assume: health status, biometric data, location determined through positioning services, images of identity cards, bank account details and transaction history, and behavioural data from the use of online services. HR records, geolocated attendance systems and scanned ID archives all fall inside it.
  • Legal basis. Consent is the default. Article 19 lists the cases where consent is not required: urgent protection of life and health, emergencies and national security, state agency operations, and performance of an agreement entered into by the data subject. The clause many teams miss is Article 19.2, which still requires a supervision mechanism even when consent is waived.
  • Data subject rights. Article 4 grants the rights to be informed, to consent or withdraw consent, to view and correct, to request provision, deletion, restriction of processing, to object, and to complain or claim damages. Each right maps to an operation your system must perform inside a fixed deadline.

On penalties, Article 8 sets maximum administrative fines: ten times the illicit gain for buying or selling personal data, 5% of prior-year revenue for organizations that breach cross-border transfer rules, and VND 3 billion for other violations, with individuals liable for half the organizational ceiling. Those three figures are routinely conflated; the closing section explains why they should not be.

What Decree 356/2025 turns into operational duties

The law sets principles; Decree 356/2025 is what legal and IT teams should actually read. Three duty groups carry hard deadlines.

  • Data processing impact assessment records. Under Article 21 of the law, controllers and controller-processors must prepare, retain and file one original copy with the specialised authority within 60 days of the first day of processing. Article 19 of Decree 356 specifies the contents, which include a data flow diagram, retention and deletion policy, and a security plan with system design diagrams. Article 20 requires an update every six months from the first filing, and an update within 10 days when the organization is restructured, dissolved, or changes lines of business that touch personal data processing.
  • Data protection personnel. Article 33.2 of the law requires organizations to designate a qualified unit or officer, or to contract an external provider. Article 13 of Decree 356 makes the bar concrete: designation by formal written decision, a college degree or higher, and at least two years of experience in legal affairs, IT, cybersecurity, data security, risk management, compliance, or HR. Article 14 sets the duties, including periodic written assessments of the organization's compliance posture.
  • Personal data breach notification. Article 23 of the law requires notifying the specialised authority within 72 hours of detecting a violation capable of harming national security or the life, health, dignity or property of data subjects. Article 28 of Decree 356 specifies the notification contents and form. For location and biometric data, Article 29 adds a duty to notify affected data subjects within 72 hours and to retain breach records for at least five years after remediation.

Response deadlines for data subject requests sit in Article 5 of Decree 356 and differ sharply from old Decree 13. For withdrawal of consent, restriction or objection: acknowledge within two working days, act within 15 days, or 20 days where processors and third parties must also stop. For access, correction or provision: acknowledge within two working days, act within 10 days, or 15 days where a third party is involved. One extension of up to 15 days is allowed, and you must justify it.

Why on-premise makes PDPL compliance easier

Every duty above shares one property: you must prove what you claim about the data. Proof is an evidence problem, and evidence exists only where you have control.

  • No cross-border transfer duty arises. Article 20 of the law defines cross-border transfer broadly, including the use of a platform located outside Vietnam to process data collected in Vietnam. A foreign SaaS tool, an AI API hosted abroad, or a multi-region backup service each triggers a transfer impact assessment filed within 60 days of the first transfer. A system running inside your own infrastructure never creates that obligation, and sits outside the 5% revenue penalty bracket.
  • The data flow is drawable. The impact assessment demands a data flow diagram and a system design diagram. For a self-operated system that is documentation you already hold; for a cloud service you inherit whatever the vendor publishes.
  • Logs and access control are yours. Article 4.2 of Decree 356 requires restricted-access permission rules, processing procedures and security measures for sensitive personal data. Complete access logs, retained as long as you choose, rarely come with a standard service tier.
  • Deletion is real deletion. The right to erasure only means something if you can delete backups and replicas too. On your own infrastructure, you know how many copies exist.
  • No dependence on third-party terms. Article 12 of Decree 356 requires cloud contracts to state compliance with Vietnamese law, define each party's role, specify security measures, set deletion timelines, and guarantee data subject rights. With large foreign providers, that is usually a non-negotiable standard agreement. We covered this trade-off in on-premise or cloud for data compliance and data localization in Vietnam.

On-premise does not equal compliance

This needs saying plainly, because infrastructure is increasingly sold as if it were a certificate. Nothing in Law 91/2025 or Decree 356/2025 requires personal data to sit on-premise. Cloud is lawful, and has its own article explaining how to use it correctly. Conversely, a server in your own machine room with no impact assessment record, no formally designated officer and no intake process for data subject requests breaches just as many articles as a careless cloud deployment. Technical risk may be higher, since patching, backup and monitoring fall to the internal team.

Roles need settling too. The law distinguishes controller, processor and combined controller-processor. The controller decides purposes and means and carries the filing and rights-response duties; the processor acts on instruction and keeps records as agreed. When you hire a vendor to operate your on-premise system, that role belongs in the contract, not in assumption.

Compliance checklist

  • Data map. For each system, record what is collected, whether it is basic or sensitive under Article 4 of Decree 356, where it is stored, who can access it, how long it is kept, and how it is deleted.
  • Role assignment. For each data flow, state whether the organization is controller, processor or both, and which third parties are involved.
  • Legal basis review. Tie each processing purpose to valid consent or a specific case under Article 19; where consent is waived, build the supervision mechanism required by Article 19.2.
  • Impact assessment file. Use Form 10 of Decree 356, attach the data flow and system design diagrams, file within 60 days of first processing, and calendar the six-month update.
  • Designate personnel. Issue a written decision, verify the Article 13 qualifications, sign a confidentiality agreement, and plan training.
  • Rights response process. Publish forms, name an intake owner, set an internal SLA shorter than the statutory deadline, and define how requester identity is verified.
  • Incident process. Define who reports to whom, who decides to notify, the Article 28 notification template, and a separate branch for location and biometric data under Article 29.
  • Vendor review. For each external service, check whether data leaves Vietnam and whether the contract carries the Article 12 clauses. Our third-party SaaS risk checklist has a fuller question set.
  • Bring sensitive systems back under control. Prioritise systems holding HR files, health records, identity document images and customer financial data.

For that last item, Tetra eOffice runs on your own infrastructure, keeps documents and HR data inside internal systems, and ships with the permission model and access logging you need for an impact assessment file.

Common misreadings

  • Every violation risks a 5% revenue fine. No. The 5% of prior-year revenue ceiling in Article 8.4 applies only to organizations breaching cross-border transfer rules. Other violations are capped at VND 3 billion under Article 8.5.
  • All data subject requests must be handled within 72 hours. No. The 72-hour clock is for breach notification under Article 23 of the law. Data subject requests follow Article 5 of Decree 356: acknowledge in two working days, act within 10, 15 or 20 days depending on the request type.
  • Small businesses and startups are exempt. Only partly, and only for a period. Article 38.2 of the law lets small enterprises and startups choose not to apply Articles 21 and 22 and Article 33.2 for five years from the effective date. Household businesses and micro enterprises are exempt without a time limit. Both groups lose the relief if they provide personal data processing services, directly process sensitive data, or reach 100,000 data subjects, per Article 41 of Decree 356. All other duties still apply in full.
  • Consent collected under Decree 13 must be collected again. It does not. Article 39 of the law lets validly consented processing continue. Impact assessment records already accepted by the authority remain usable; only updates must follow the new rules.

Conclusion

PDPL compliance is a governance job, not a procurement line item. Understand the data you hold, settle your legal roles, build the processes and records, and only then decide where the systems live. On-premise grants no exemption, but it shortens the distance between what you declare on paper and what actually happens inside the system — and to an inspector, that distance is exactly what gets examined.

If your organization is reviewing its data landscape and weighing whether to bring sensitive systems in-house, book a consultation with Tetra to map out a plan.

Full texts: Law 91/2025/QH15 on Personal Data Protection, Decree 356/2025/ND-CP, and the national legal documents portal.

This article is for reference only and does not replace legal advice. Organizations should check the current text of the law and consult their legal counsel before acting.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist