Data, Technology and Compliance
Data and technology are moving from a supporting part of the enterprise to one of the main risk sources. Websites, apps, CRMs, customer collection forms, HR data and data sharing with vendors can all trigger legal obligations. Enterprises need to understand what data they collect, for what purposes, where it is stored, who it is shared with, and whether they have a compliance proof mechanism.
Quick summary: data, technology and compliance
| For | Enterprises collecting customer data via websites, apps or CRMs; e-commerce enterprises; and enterprises sharing data with vendors. |
|---|---|
| Key documents | Data flow map, collection forms, published privacy policy, contracts with data-processing vendors and the list of systems in use. |
| What to check | Processing grounds for each data type, consent collection and withdrawal mechanisms, cross-border data transfers and compliance proof files. |
Common needs
- Privacy policies, data processing notices and consent terms.
- Data processing contracts, data sharing and vendor due diligence.
- Reviews of websites, apps, e-commerce and digital advertising.
- Data compliance file checks and internal training.
What does FLAT LAW FIRM do?
- Build data maps and identify key processing flows.
- Draft data-related policies, forms and contracts.
- Review websites/apps, cookies, contact forms and consent collection processes.
- Assess compliance gaps and build remediation plans.
Common risks
- A privacy policy on the website that does not reflect actual operations.
- Collecting more data than needed or lacking proper grounds.
- Sharing data with vendors without control clauses.
- Not keeping proof files when inspected or when customers complain.
Files to prepare
- Data flows, collection forms, privacy policy, data processing contracts and system lists.
- Websites, apps, CRMs, vendors, data recipients and processing grounds in use.
- Incident history, customer requests and existing compliance file sets.
Start from the data map, not from the privacy policy
A beautiful privacy policy that does not reflect actual operations is a risk, not a protection: it becomes evidence of the gap between commitment and reality. So the first step is always building the data map — what the enterprise collects, from whom, through which channels, where it is stored, who can access it and which third parties it is shared with.
Only from that map can processing grounds be determined for each flow, and which flows need consent versus other bases be known. This is also the step that discovers data the enterprise holds but does not really need — the cheapest risk source to eliminate.
The last step is files. In data, the ability to prove you did things right matters as much as doing them right: consent forms with trace, vendor contracts with control clauses, data-subject request handling procedures and incident response procedures.
Current legal framework on personal data
Vietnam has moved from a decree-based to a law-based mechanism: the Personal Data Protection Law No. 91/2025/QH15 is effective from 1 January 2026, with Decree 356/2025/ND-CP (issued 31 December 2025, effective from 1 January 2026) guiding implementation and replacing the former Decree 13/2023/ND-CP. Changes include data subjects’ rights, obligations of data controllers and data processors, personal data processing impact assessment (DPIA) files and rules on cross-border data transfer.
Enterprises that built compliance files under former regulations need to re-review rather than keep them. As guiding documents in this area continue to be issued and amended, the content on this page is directional and should be checked against the regulations in effect at the time of application.
The full text of the 2025 Personal Data Protection Law and guiding decrees can be found at the Government’s legal normative document system.
FAQ
Do small enterprises need data policies?
In principle, every enterprise collecting and processing personal data is subject to the Personal Data Protection Law. However, small enterprises and startups may choose to perform or not perform certain obligations — such as preparing data processing impact assessment files and appointing data protection personnel — within 5 years from 1 January 2026; business households and micro-enterprises enjoy broader exemptions. Exemptions do not apply if the enterprise trades in personal data processing services, directly processes sensitive data or processes data of a large number of data subjects.
Is a cookie banner enough for compliance?
No. It is only one part of the entire data processing system.
Do software vendor contracts need data clauses?
Usually yes if the vendor has access to or processes data for the enterprise.
Should periodic compliance checks be done?
Yes. Data systems change with products, personnel and vendors.
Where to start?
Start by identifying what data you have, its purposes and who is accessing it.
Useful links
Talk to FLAT LAW FIRM
You can send the existing documents, objectives and expected timeline for our team to assess the next steps.
Talk to a lawyer when:
- the enterprise has no data map but has published a privacy policy on the website;
- there is sharing of customer or HR data with vendors or foreign partners;
- the compliance file was built under Decree 13/2023/ND-CP and not re-reviewed under Law 91/2025/QH15;
- the enterprise has received requests from data subjects or signs of a data leak incident.