From 01/01/2026, the Personal Data Protection Law 2025 (No. 91/2025/QH15) officially takes effect. Clause 2 Article 33 of the Law sets specific personnel requirements: agencies and organisations must designate departments and personnel meeting competency conditions to perform personal data protection tasks, or hire organisations or individuals providing personal data protection services.
For FDI companies, data is scattered across many systems: personnel files on group software, customer data on CRMs hosted abroad, cameras at factories, biometric data used for attendance. Without an accountable focal point, companies easily fall into having policies on paper that nobody operates.
Quick summary
| Main legal bases | Clause 2 Article 33 Law 91/2025/QH15; Article 13 Decree 356/2025/ND-CP; Clauses 2–3 Article 38 |
|---|---|
| Requirement | Designate departments and personnel meeting competency conditions or hire organisations or individuals providing personal data protection services |
| Target audience | FDI companies, foreign investors, in-house legal and HR teams |
Legal requirements: companies must have someone accountable for data
Decree 13/2023/ND-CP previously required data controllers to establish personal data protection departments, but regulations were vague, so many companies merely named an IT officer in dossiers without assigning substantive tasks. Law 91/2025/QH15 tightened this at Clause 2 Article 33, with Article 13 of Decree 356/2025/ND-CP specifying conditions and tasks.
This obligation applies regardless of whether companies process basic or sensitive data. Only cases exempted under Article 38 (small enterprises, startups in their first 5 years, household businesses, micro-enterprises) may choose whether to implement. Designation should be by official written decision, with specific task and authority descriptions.
Two organisational models: internal function and hiring service providers
The internal model suits companies with large data processing volumes, complex systems or regular sensitive data processing. Advantages: the person in charge deeply understands internal operations and reacts quickly to incidents. Disadvantages: high costs and difficulty recruiting people who understand both law and technology. Many FDI companies send existing legal or compliance staff for intensive training, combined with technical support from IT departments.
The outsourcing model suits companies with relatively simple data processing, with advantages of accessing experienced experts and flexible costs. However, outsourcing does not mean transferring legal liability: the company remains the data controller. Service contracts should clearly define work scope, incident response times and confidentiality obligations.
Competency standards for data protection personnel under Decree 356
Article 13 of Decree 356/2025/ND-CP sets three “hard” standards: college degree or higher; at least 02 years of working experience since graduation in legal, information technology, cybersecurity, data security, risk management, compliance control, human resources or personnel organisation; and having been trained in legal knowledge and professional skills on personal data protection.
These three standards show the lawmakers want the person in charge to be “two-footed”: understanding both law and technology or governance. The law has not designated a single mandatory certificate, but companies should keep evidence of personnel attending training courses on Law 91/2025/QH15 and Decree 356/2025/ND-CP to prove “meeting competency conditions” when inspected.
Specific tasks and responsibilities of the data protector
Companies need to translate the legal task framework into job descriptions: advising leadership and departments on data protection obligations; monitoring internal policy and legal compliance; serving as the focal point receiving and handling data subject requests; coordinating the preparation and updating of impact assessment dossiers; participating in data leak incident handling; acting as the working focal point with the specialised authority during inspections.
An often-missed task is reviewing contracts with third parties processing data: software providers, marketing units, outsourced HR service companies. These contracts need data processing clauses compliant with Article 7 of Decree 356/2025/ND-CP. This also overlaps with tech vendor and cybersecurity review work, which should be implemented in sync.
Position in the organisational chart: independence and avoiding conflicts of interest
A common mistake is assigning data protection tasks to the person deciding data processing purposes, e.g. the marketing head also handling customer data protection that their department collects. The conflict of interest is clear: wanting to collect as much data as possible for business, while having to monitor their own compliance with minimum collection principles.
Therefore, the data protector should be placed in a sufficiently independent position, ideally reporting directly to senior leadership. The appointment decision should specify rights to access all systems and documents related to data processing, rights to require departmental coordination, and rights to report directly to top leadership when discovering serious violations. A backup should also be designated for long absences.
Cases of optional implementation: small enterprises, startups, household businesses
Clauses 2 and 3 Article 38 of Law 91/2025/QH15 provide a “soft” policy for small-scale subjects. Small enterprises and startups may choose whether to implement Articles 21, 22 and Clause 2 Article 33 within 05 years from the Law’s effective date. Household businesses and micro-enterprises are fully exempt from these obligations.
However, there is an important exception: exemptions do not apply if companies trade in personal data processing services, directly process sensitive data, or process data of a large number of subjects. And “may choose not to implement” does not mean being allowed to violate other obligations: data processing principles, consent requirements, subject rights protection and incident notification still fully apply from 01/01/2026.
Group model: one focal point for multiple subsidiaries in Vietnam?
Many multinational groups tend to designate one data protector for the whole region, based in Singapore or Hong Kong, treating Vietnamese subsidiaries as compliant. This approach is risky: Vietnamese law requires agencies and organisations processing data in Vietnam to have their own departments and personnel (or hire services), understanding Vietnamese law and able to work directly with the specialised authority in Vietnamese.
A more feasible model is for each Vietnamese legal entity to designate at least one internal focal point meeting Article 13 Decree 356 standards, while joining the group’s data protection network for policy consistency. Each subsidiary is an independent data controller, so impact assessment dossiers and appointment decisions should be prepared separately for each company. Data transfers between parent and subsidiaries must also comply with cross-border personal data transfer regulations.
Coordination with departments: legal, IT, HR, business
Data is scattered across every department: HR holds employee files, business holds customer data, marketing operates collection campaigns, IT administers systems and access rights. Right after designation, companies should issue internal coordination regulations, where each department appoints a focal point and periodically reports on new or changed data processing activities.
With HR, decisions on data collection in recruitment, labour file management, camera or software monitoring, and data handling upon contract termination should all have the data protector’s input before implementation (see the article on employee data processing in Vietnamese enterprises). With IT, the focus is minimum access rights and sensitive data encryption.
Internal training and compliance proof dossiers
Most data leak incidents stem from human error: sending emails with customer lists to the wrong address, using weak passwords, sharing internal data via personal messaging apps. Training programmes should be designed by group: all employees learn to recognise personal data and basic security principles; departments directly processing data learn their specific procedures; leadership learns about legal liability. Training should be periodic with complete evidence retained.
For proof dossiers, the principle “no dossier means not done” is strictly applied. The minimum dossier includes: appointment decisions with task descriptions; personnel competency evidence; internal data protection policies and data maps; personal data processing impact assessment dossiers sent to the specialised authority; data subject consent document templates; data processing contracts with third parties; training minutes; logs of subject request handling and incidents.
Risks of not designating or formal designation
The most direct risk is administrative sanctions. Law 91/2025/QH15 sets a strict sanction framework including fines and remedial measures such as forced data deletion and processing suspension. Failing to designate data protection departments or personnel when mandatory is an independent violation, sanctionable even without any data leak incident.
The second risk is that when incidents occur, damage will be much greater without an accountable person: incidents hidden or handled late, discovered through customer complaints or the press, leading to both heavier fines and lost market trust. The incident notification deadline is 72 hours from discovery, impossible to meet without a standing focal point.
What FLAT LAW FIRM supports companies with
FLAT LAW FIRM supports companies in comprehensively building the personal data protection function: advising on suitable model selection; drafting appointment decisions, task descriptions and internal coordination regulations; reviewing proposed personnel’s competency against Article 13 Decree 356/2025/ND-CP standards and proposing supplementary training programmes.
We also support preparing impact assessment dossiers and completing submission procedures to the specialised authority; building consent document systems; reviewing data processing clauses in contracts with suppliers and partners; building subject request reception and handling procedures within deadlines; and building incident response plans. For FDI companies, we work in Vietnamese, Chinese and English. See the data and technology compliance checklist or the general legal framework in Personal Data Protection Law and its impact on companies.
Frequently asked questions
Must companies designate personal data protection personnel?
Yes, under Clause 2 Article 33 of Law 91/2025/QH15. Only small enterprises, startups (within 5 years), household businesses and micro-enterprises may choose whether to implement, except when trading in data processing services, processing sensitive data or data of a large number of subjects.
Can the IT head concurrently hold the data protection position?
The law does not prohibit concurrent holding, but the concurrent holder must fully meet the standards at Article 13 of Decree 356/2025/ND-CP and must avoid conflicts of interest.
Can companies hire external consultants to provide data protection services?
Yes, under Clause 2 Article 33 of Law 91/2025/QH15. However, companies remain legally liable as data controllers, so service contracts should clearly define work scope and coordination mechanisms.
How are companies handled if they do not designate data protection personnel?
This is an independent administrative obligation violation, sanctionable even without any data leak incident. When incidents occur without a handling focal point, companies also face late notification and being assessed as lacking compliance goodwill.
Does the data protector bear personal liability when the company violates?
Primary legal liability belongs to the company as the data controller. The data protector may bear internal liability under company regulations and labour contracts if tasks are not completed.
Talk to FLAT LAW FIRM
If your company needs advice on building a personal data protection function or reviewing compliance with Law 91/2025/QH15, FLAT LAW FIRM is ready to support in Vietnamese, Chinese and English.
