Personal data processing impact assessment (DPIA) is one of the most systematic new obligations that the Personal Data Protection Law 91/2025/QH15 imposes on companies. Law 91/2025 directly regulates the obligation to prepare, archive and send dossiers to the specialised authority within 60 days from the first day of data processing (Article 21). For operating companies, especially FDI companies, correctly understanding who must prepare, what to prepare, whom to send to and how to update is the condition for avoiding violations from the very first months the Law takes effect (01/01/2026).
What is a personal data processing impact assessment
Under Clause 12 Article 2 of the Law, personal data processing impact assessment is the analysis and assessment of risks that may occur during personal data processing to apply risk mitigation measures and protect personal data. This is not a descriptive report, but a methodical risk analysis: what data is being processed, what risks may arise for data subjects, and what mitigation measures are applied.
Two types of dossiers must be distinguished: personal data processing impact assessment dossiers (Article 21) for processing activities in general, and cross-border personal data transfer impact assessment dossiers (Article 20) for transferring data outside Vietnam’s territory. Companies that both process domestically and transfer data abroad (e.g. using group systems with servers overseas) may have to prepare both. Clause 4 Article 5 clarifies: once assessed under this Law, no separate risk assessment under data legislation is required — avoiding duplicate obligations.
Who must prepare dossiers and who is exempt
Article 21 places the obligation on controllers and controller-processors: to prepare, archive and send 01 original to the specialised authority. Processors — e.g. outsourced service providers — prepare and archive dossiers under agreement with the controller, without sending directly to the specialised authority. Contracts with providers need to clearly specify cooperation responsibilities in dossier preparation, provision of technical information and updating upon changes.
The Law provides three groups exempted or deferred from the obligation. Competent state agencies are not required to implement impact assessment regulations (Clause 6 Article 21). Small companies and startups may choose not to implement Articles 21, 22 and Clause 2 Article 33 for 05 years — except when doing data processing service business, directly processing sensitive data, or processing data of a large number of subjects (Clause 2 Article 38). Business households and micro-enterprises are not required to implement these regulations, with the same exceptions (Clause 3 Article 38).
The 60-day deadline: counted from when
Clause 1 Article 21 sets the dossier submission deadline at 60 days from the first day of processing personal data. For companies established after the Law’s effective date, the “first day of processing” is usually tied to when data collection begins — e.g. the day the first candidate’s application is received, the day the CRM records the first customer’s data, or the day a biometric attendance system is deployed.
For companies operating before 01/01/2026, note the transition provision in Article 39: dossiers prepared under Decree 13/2023 and received by the specialised authority before the Law’s effective date continue to be used, without re-preparation — but subsequent updates follow the new Law. Companies that never prepared dossiers under Decree 13/2023 should treat 01/01/2026 as the reference point for calculating the 60-day deadline and proactively complete their dossiers. For continuous, multi-system processing activities, the timeline should be recorded in internal documents (deployment decisions, acceptance minutes) as a basis for explanation.
Contents required in impact assessment dossiers
Clause 7 Article 21 assigns the Government to regulate dossier components, conditions, procedures and processes for impact assessment — the details are in Decree 356/2025/ND-CP. Logically, a complete dossier needs to answer groups of questions: (1) information on the controller and personnel in charge of personal data protection; (2) description of processing activities — data types, purposes, methods and processes; (3) assessment of the necessity and proportionality of processing activities against the determined purposes; (4) identification of risks to the lawful rights and interests of data subjects; (5) risk mitigation measures — governance, technical, personnel.
The key point: the risk assessment and mitigation measures must be proportionate to each other. If the dossier states leakage risk at a high level but the measures are only “general internal regulations”, lacking specific technical measures (encryption, access control, access logs), the dossier is unlikely to be considered satisfactory. Clause 4 Article 21 allows the specialised authority to request dossier completion when incomplete — so invest in quality from the first preparation.
Controller-processor relationship in dossier preparation
In outsourcing models — cloud services, HR software, outsourced marketing — the controller (the company) bears the submission obligation, but the technical content largely depends on the processor (the provider). Clause 3 Article 21 provides that processors prepare and archive dossiers under agreement with the controller; Article 37 also provides that processors may only receive data after an agreement or contract and must process strictly under the signed agreement.
Contracts should provide: provision of technical information for dossier preparation; notification when processing methods or systems change; cooperation when the specialised authority requests completion; support for periodic updates. If current contracts lack these, companies should sign supplemental annexes — part of the general compliance framework of the Personal Data Protection Law.
Updating dossiers: every 06 months and immediate updates
Clause 2 Article 21 provides that assessment is conducted once for the entire operation period but must be updated under Article 22: updated every 06 months when there are changes, or updated immediately when: reorganisation, termination, dissolution, bankruptcy; changes in information of the data protection service provider; arising/changing business lines related to registered data processing.
Updates are made on the National Portal on Personal Data Protection or at the specialised authority (Clause 3 Article 22). For FDI companies, these events occur quite frequently: changing cloud providers, deploying new systems (e.g. switching from fingerprint to facial recognition attendance), adding business lines, group restructuring.
Which authority to send dossiers to, through which channel
The receiving authority is the specialised personal data protection authority — under Article 33, an authority under the Ministry of Public Security, the focal point responsible to the Government for state management in this field (Article 36). Dossiers are sent as 01 original within 60 days; subsequent updates are made on the National Portal on Personal Data Protection or directly at the specialised authority.
Distinguish “sending dossiers” from “being approved”: the Law regulates the sending obligation and the specialised authority’s right to assess and request completion (Clause 4 Article 21), with no “licensing” procedure for dossiers. Sending complete dossiers on time is important evidence of compliance goodwill — meaningful for mitigation when violations occur or inspections take place.
Transition provisions from Decree 13/2023
Article 39 provides transition for two groups. First, processing activities consented to by subjects or under agreements under Decree 13/2023 before the Law’s effective date continue, without re-obtaining consent. Second, data processing impact assessment dossiers and cross-border data transfer impact assessment dossiers under Decree 13/2023 received by the specialised authority before the Law’s effective date continue to be used, without re-preparation; subsequent updates follow the new Law.
Even dossiers already received still need review under the new framework — e.g. supplementing risk assessments for the expanded sensitive data in Article 4 of Decree 356/2025, or updating protection measures under sector-specific regulations (Articles 24–32).
Risks of not preparing or sending dossiers on time
Not preparing, not sending or sending dossiers late directly violates Article 21, subject to administrative fines of up to VND 3 billion for organisations (Clause 5 Article 8 — the “other violations” group). In addition to fines: being required to complete dossiers during inspections; losing the basis to prove prevention when incidents occur; reputational impact when partners require compliance proof in due diligence.
For FDI companies, many groups require subsidiaries to prove local data law compliance in global compliance programmes; lacking dossiers under Vietnamese law may cause subsidiaries to be assessed as “non-compliant” in internal audits.
Practical checklist for preparing impact assessment dossiers
The suggested implementation sequence is as follows. Step 1 — Inventory: list personal data being processed, classify basic/sensitive under Articles 3 and 4 of Decree 356/2025, determine collection sources and circulation flows. Step 2 — Determine roles for each data flow: controller, processor or controller-processor; list related processors and third parties. Step 3 — Assess risks by data type and stage (collection, storage, use, sharing, deletion). Step 4 — Determine mitigation measures: governance (procedures, access control), technical (encryption, access logs, backups) and personnel (training, confidentiality commitments) — including designating qualified personal data protection personnel and functions as required by Article 33.
Step 5 — Draft and internally approve and submit to the authorised person. Step 6 — Send to the specialised authority 01 original within 60 days, keeping the receipt. Step 7 — Update schedule: review every 06 months, update immediately upon Article 22 events. See also the in-depth article on impact assessment. FLAT LAW FIRM supports data inventory, dossier drafting and building periodic update procedures.
Frequently asked questions
Must a data processor (service provider) send the DPIA dossier to the specialised authority?
No. Under Clauses 1 and 3 Article 21, the obligation to send 01 original rests on controllers and controller-processors. Processors prepare, archive dossiers under agreement and cooperate in providing technical information.
Must companies that prepared dossiers under Decree 13/2023 redo them?
It depends. Under Clause 2 Article 39, dossiers prepared under Decree 13/2023 and received by the specialised authority before 01/01/2026 continue to be used, without re-preparation; subsequent updates follow the new Law. If not sent or not received, prepare new dossiers under Law 91/2025 and Decree 356/2025.
From when is the 60-day submission deadline counted for operating companies?
The Law sets 60 days “from the first day of processing personal data” (Clause 1 Article 21). For companies operating before the Law’s effective date that never prepared dossiers, the practical reference point is 01/01/2026. Record the timeline in internal documents, proactively send dossiers within the deadline and keep receipts as compliance evidence.
Must the impact assessment dossier be updated when changing cloud providers?
Yes, in many cases. Article 22 requires immediate updates when changing information of the data protection service provider, or when arising/changing business lines related to registered data processing. Changing cloud providers — especially when changing storage location or security methods — alters dossier contents, so updates are needed on the National Portal or at the specialised authority.
What is the fine for not sending impact assessment dossiers?
Not preparing or sending dossiers may be subject to administrative fines of up to VND 3 billion for organisations (Clause 5 Article 8 — the “other violations” group). In addition to fines, companies are required to complete dossiers during inspections and lose the basis to prove prevention when incidents occur.
