StartNewsDecree 356/2025/ND-CP: The Next Chapter in Vietnam’s Personal Data Protection Framework
07.10.2026Dr. Tobias Höllwarth

Decree 356/2025/ND-CP: The Next Chapter in Vietnam’s Personal Data Protection Framework

Vietnam’s data protection landscape just got sharper. Decree No. 356/2025/ND-CP delivers the detailed rules businesses have been waiting for, tighter timelines, clearer roles and fewer grey areas. Now is the time for organisations to put their policies, people and data practices to the test before the new regime takes hold.

Decree 356/2025/ND-CP: The Next Chapter in Vietnam’s Personal Data Protection Framework

Implementation of data subject rights

Decree No. 356/2025/ND-CP (Decree 356) introduces specific procedures and timelines for the data controller, and the data controller and processor, to respond to and implement data subject requests. In particular, they must respond within two (2) working days from receipt of a request and provide information on the procedures for fulfilling such request.

Unlike Decree No. 13/2023/ND-CP (Decree 13), which generally required data subject requests to be fulfilled within seventy-two (72) hours of receipt, Decree 356 provides different processing times for different types of requests, including withdrawal of consent, restriction or objection to processing, access, rectification, provision and erasure of personal data. Extensions may be permitted once where necessary.

Personal data protection workforce

Decree 356 sets out, for the first time, the conditions and qualifications for the internal data protection department (DPD) and the data protection officer (DPO).

An internal DPO must have a college degree or higher; at least two (2) years of relevant work experience in prescribed fields, and training in legal knowledge and professional skills relating to personal data protection.

Personnel in the internal DPD must also satisfy the conditions applicable to the DPO.

In addition, Decree 356 expressly allows enterprises to engage personal data protection services offered by either an individual or an organisation, provided that the relevant statutory conditions are met.

Cross-border personal data transfer impact assessment

Decree 356 provides additional cases that are exempt from conducting a cross-border personal data transfer impact assessment. These include, among others:

  • journalism and communication activities in accordance with law;
  • cross-border transfer of personal data that has been disclosed in accordance with law;
  • emergency transfers necessary to protect life, health or property safety, or to perform tasks and obligations as prescribed by law;
  • cross-border transfer for personnel management in accordance with labour rules and regulations, and collective labour agreements; and
  • provision of personal data across borders for contract conclusion or procedures related to transportation, logistics, remittance, payment, accommodation, visa applications or scholarship applications.

Personal data processing services

Decree 356 introduces new provisions on personal data processing services, which include, among others, credit scoring services, personal data encryption services, and automated data processing using AI, big data, blockchain, or the metaverse. Such services are subject to strict conditions and are required to complete relevant procedures for obtaining certificates of eligibility for providing personal data processing services.

Exempt obligations

Decree 356 significantly broadens the scope of exempt obligations, the types of entities eligible, and the duration of exemptions compared with Decree 13.

In particular, eligible business households, micro enterprises, small enterprises and start-ups may be exempt from the designation of DPD and DPO, or engagement of personal data protection services, as well as the obligation to conduct personal data processing impact assessments. Small enterprises and start-ups may enjoy exemptions for five (5) years from the effective date of the Personal Data Protection Law, i.e., 1 January 2026, while business households and micro enterprises may be fully exempt.

However, these exemptions are not applicable where the relevant entity provides personal data processing services, directly processes sensitive personal data, or processes personal data reaching a scale of 100,000 or more data subjects based on the cumulative amount of personal data processed.

Article provided by INPLP member: Huong Duong Thi Mai (Frasers Law Company, Vietnam)

Von Dr. Tobias Höllwarth← Alle News