The Law on Personal Data Protection has recently come into effect, and many small business owners in Vietnam are wondering whether a company with only a few employees is required to prepare impact assessment dossiers, appoint dedicated personnel for personal data protection, or obtain any licenses or approvals. This article by Lexsol summarizes the key legal issues that small enterprises should understand to ensure full and proper compliance.
The Law on Personal Data Protection 2025 is a legal normative document promulgated by the National Assembly, adopted at the 8th Session of the 15th National Assembly, and officially came into effect on January 01, 2026. The Law establishes the principles governing the processing of personal data, the rights and obligations of data subjects, the responsibilities of Personal Data Controllers and Personal Data Processors, and administrative penalties for violations.
In parallel with the Law, the Government promulgated Decree No. 356/2025/ND-CP dated December 31, 2025, which took effect on January 01, 2026, providing detailed guidance on several articles of and measures for the implementation of the Law on Personal Data Protection. .
Regardless of their size, enterprises are still required to comply with the principles and legal requirements on personal data protection under the Law on Personal Data Protection 2025 and its implementing regulations. However, small enterprises should pay particular attention to the following legal issues.
Pursuant to Article 38 of the Law on Personal Data Protection 2025 and Article 41 of Decree No. 356/2025/ND-CP, small enterprises may choose whether or not to perform the following obligations:
2.1. Personal data processing impact assessment.
2.2. Updating the personal data processing impact assessment dossier and the cross-border personal data transfer impact assessment dossier.
2.3. Appointing a department or personnel that satisfy the statutory qualifications for personal data protection, or engaging an organization or individual providing personal data protection services.
In addition, small enterprises are entitled to enjoy the above preferential mechanism only for a period of five (05) yearsfrom the effective date of the Law on Personal Data Protection 2025. Accordingly, upon the expiry of such five-year period, small enterprises must fully perform the above procedures in accordance with the law.
However, this exemption does not apply to small enterprises or startup enterprises that provide personal data processing services, directly process sensitive personal data, or process the personal data of a large number of data subjects. Enterprises falling within these circumstances are required to carry out the above procedures.
An enterprise acting as a personal data controller, personal data processor, or personal data controller-cum-processor must prepare and maintain a personal data processing impact assessment dossier.
3.1.1. Dossier components:
a. A personal data processing impact assessment Report (Form No. 10 enclosed with this Decree)
b. A copy of the contract or agreement on the processing of personal data;
c. Other relevant documents.
3.1.2. Procedures
Submit one (01) original of the above dossier together with the Notice of Dossier Submission (Form No. 02a enclosed with this Decree) through one of the following methods:
a. Via the Ministry of Public Security Public Services Portal; or
b. Directly to the Department of Cybersecurity and High-Tech Crime Prevention and Control, Ministry of Public Security.
The competent authority shall assess the dossier and notify whether it is satisfactory or unsatisfactory within 15 days. If the dossier is incomplete or unsatisfactory, the authority shall request the enterprise to supplement and complete the dossier within 30 days.
Once the dossier has been accepted, the enterprise shall update and supplement the personal data processing impact assessment dossier in accordance with Section 3.2 below.
3.2.1. Cases requiring periodic updates every six (06) months from the date of the initial submission include:
a. A new purpose for transferring or processing personal data arises;
b. There is a change in, or addition of, a personal data controller, personal data controller-cum-processor, personal data processor, or third party.
3.2.2. Cases requiring immediate updates within ten (10) days include:
a. The enterprise undergoes reorganization, terminates its operations, is dissolved, or is declared bankrupt;
b. There is a change in the information relating to the personal data protection department;
c. A business line relating to personal data processing is added or amended.
3.2.3. Dossier components:
a. A notice of update to the impact assessment dossier (Form No. 03a enclosed with this Decree);
b. A cross-border personal data transfer impact assessment report (Form No. 09 enclosed with this Decree)
c. Other relevant documents.
3.2.4. Procedures
Submit one (01) original of the above dossier together with the notice of dossier submission (Form No. 02a enclosed with this Decree) through one of the following methods:
a. Via the Ministry of Public Security Public Service Portal; or
b. Directly to the Department of Cybersecurity and High-Tech Crime Prevention and Control, Ministry of Public Security.
The competent authority shall review the updated dossier within 15 days. Upon completion of the review, the authority shall issue a notification of the assessment result. If the dossier is incomplete, the authority shall request the enterprise to supplement and complete the dossier within 30 days.
An enterprise may appoint an internal department or personnel to perform personal data protection functions, provided that they satisfy the conditions prescribed in Articles 13 to 16 of Decree No. 356/2025/ND-CP, or engage an organization or individual providing personal data protection services that satisfies the conditions prescribed in Articles 21 to 27 of the same Decree.
To appoint a personal data protection department or personnel, the enterprise must issue a formal written instrument, such as a Decision, an Agreement, or another equivalent document.
Where the enterprise appoints an internal department or personnel to perform personal data protection functions, such department or personnel must satisfy the conditions set out in Article 13 of Decree No. 356/2025/ND-CP as follows.
3.3.1. Personnel must satisfy the following conditions:
a. Hold at least a college degree;
b. Have at least two (02) years of professional experience (counted from the date of graduation) in one of the following fields: legal affairs, information technology, cybersecurity, data security, risk management, compliance control, human resources management, or personnel administration;
c. Have received training in legal knowledge and professional skills relating to personal data protection.
3.3.2. Responsibilities of the Enterprise:
a. Independently assess and select qualified personnel;
b. Enter into a confidentiality agreement with such personnel, which may include provisions on exemption from liability in relation to violations or damage involving personal data;
c. Provide training and professional development on knowledge and skills relating to personal data protection for such personnel.
An enterprise that violates the regulations on personal data protection shall be subject to penalties in accordance with Article 8 of the Law on Personal Data Protection 2025.
4.1. Sale or purchase of personal data generating unlawful proceeds: A fine of up to ten (10) times the unlawful proceeds obtained from the violation may be imposed.
4.2. Organizations committing violations relating to the cross-border transfer of personal data with revenue: A fine of up to five percent (5%) of the revenue of the immediately preceding year may be imposed.
4.3. Violations subject to a maximum fine of VND 3 Billion:
4.3.1. The sale or purchase of personal data generates unlawful proceeds, but the fine calculated based on such unlawful proceeds is less than the maximum fine of VND 3 billion.
4.3.2. The sale or purchase of personal data does not generate unlawful proceeds.
4.3.3. An organization commits a violation relating to the cross-border transfer of personal data and has revenue, but the fine calculated based on such revenue is less than the maximum fine of VND 3 billion.
4.3.4. An organization commits a violation relating to the cross-border transfer of personal data and does not have revenue.
4.3.5. Other violations in the field of personal data protection.
The above are the maximum fines applicable to organizations. Where an individual commits the same violation, the maximum fine shall be equal to one-half of the maximum fine applicable to an organization.
In practice, a number of recurring mistakes are commonly found among small enterprises when they begin complying with the Law on Personal Data Protection 2025:
5.1.Mistakenly assuming that the exemption from conducting a Personal Data Processing Impact Assessment also exempts the enterprise from all obligations under the Law, thereby failing to comply with obligations relating to consent and personal data breach notification.
5.2. Failing to review the statutory exclusion criteria and continuing to apply the five (05)-year preferential mechanism for small enterprises even though the enterprise processes sensitive personal data or the personal data of a large number of data subjects, which are not eligible for such exemption.
5.3. Continuing to use the templates issued under Decree No. 13/2023/ND-CP instead of updating to the new templates prescribed under Decree No. 356/2025/ND-CP.
5.4. Failing to retain records evidencing the process of obtaining consent from customers and employees, resulting in the enterprise being unable to prove compliance during inspections or in the event of complaints.
5.5. Failing to delete the personal data of employees after the termination of their employment contracts or where an applicant is not recruited, as required under Point c, Clause 1 and Clause 2, Article 25 of the Law on Personal Data Protection 2025.
There are also many other legal risks if small enterprises fail to thoroughly understand and comply with the regulations on personal data protection.
See also: Employment & Compliance Legal Services in Vietnam
The Law on Personal Data Protection 2025 does not exempt small enterprises from their legal obligations. Rather, it only allows certain procedures to be deferred for a specified period, subject to statutory conditions. To avoid incorrectly applying the exemption mechanism and exposing your business to the risk of administrative penalties, please contact Lexsol for detailed legal advice. Lexsol can assist in reviewing your specific circumstances before your enterprise undertakes any procedures relating to personal data.
Lexsol is a team of young, dynamic lawyers with over 10 years of experience in advising and resolving legal matters for both domestic and international businesses.
Điền thông tin, chúng tôi sẽ liên hệ tư vấn chi tiết cho bạn trong vòng 24h.