Personal data legal services for businesses
Personal Data Processing Impact Assessment
From 01/01/2026, the 2025 Law on Personal Data Protection (No. 91/2025/QH15) officially takes effect, replacing the legal framework of Decree 13/2023/ND-CP. Under Article 21 of the Law, a personal data controller must prepare a personal data processing impact assessment (DPIA) file and submit one original to the specialised personal data protection authority within 60 days from the first day of data processing. This is not a formality: the file must reflect the company’s actual data flows, assess risks seriously and propose concrete remedial measures — otherwise, the file will be required to be completed, and the company faces sanctions at a high deterrence level. FLAT LAW FIRM helps companies prepare DPIA files in the correct form (Form 10 under Decree 356/2025/ND-CP), on time and true to actual operations.

Personal data processing impact assessment: who is this service for?
- Technology, SaaS and digital platform companies collecting and analysing user data at scale.
- Insurance companies, banks, credit institutions and consumer finance companies processing sensitive customer data.
- Hospitals, clinics and medical facilities processing health data — a typical sensitive data group (see Healthcare Law).
- Retail and e-commerce companies with loyalty programmes and behaviour-based marketing.
- FDI companies operating HR systems and customer data on the group’s global platforms.
- Companies using AI cameras and biometrics (fingerprints, facial recognition) for timekeeping and access control.
- Companies that prepared files under Decree 13/2023/ND-CP and need to review and update them to the new forms of Decree 356/2025/ND-CP.
Common legal issues clients face
The most common mistake is treating the impact assessment file as a “form” to fill in and be done with. In reality, the specialised personal data protection authority is responsible for evaluating the file and requesting completion if it is incomplete or non-compliant. A file copied from a generic template — not reflecting the types of data the company collects, not identifying who is the controller and who is the processor, not substantively assessing risks — is almost certain to be returned, costing the company time to redo while the 60-day deadline keeps running.
The second confusion is equating the personal data processing impact assessment (DPIA) file with the cross-border personal data transfer impact assessment file. These are two separate files under Law 91/2025/QH15 (Forms 10 and 09 of Decree 356/2025/ND-CP respectively): a company transferring data abroad — for example storing it on servers outside Vietnam or syncing it to the parent company’s systems — may have to prepare both.
The third group is small businesses that believe they are fully exempt. The Law has specific policies for small businesses, start-ups and micro enterprises (Article 38), but these policies do not apply if the company is in the business of processing personal data, directly processes sensitive personal data, or processes data of a large number of data subjects. A tech start-up processing user data at scale still falls within the obligation to prepare the file.
Which companies must prepare an impact assessment file?
Article 21 of the 2025 Law on Personal Data Protection provides: personal data controllers, and personal data controllers-cum-processors, have the obligation to prepare and retain the personal data processing impact assessment file and to submit 01 original to the specialised personal data protection authority within 60 days from the first day of processing personal data. A personal data processor prepares and retains the file as agreed with the personal data controller.
- Broad scope: this obligation applies to all personal data controllers, without limitation by industry or processing scale — a fundamental difference from the “only large companies must do it” understanding under Decree 13/2023/ND-CP.
- Prepare once, update when changed: the impact assessment is carried out once for the entire operating period and is updated and supplemented when there are changes to the contents of the submitted file (Articles 21, 22).
- Competent State agencies are not required to comply with the provisions on personal data processing impact assessment (Clause 6, Article 21).
- Small businesses and start-ups: may choose to comply or not within 05 years from the Law’s effective date — except where they are in the business of processing personal data, directly process sensitive personal data, or process personal data of a large number of data subjects (Clause 2, Article 38).
- Business households and micro enterprises: are not required to comply — except for similar exceptions as above (Clause 3, Article 38).
Determining whether a company falls within the obligation, the opt-in, or the exemption — especially for companies processing sensitive data or data at scale — requires direct cross-checking against the text and the actual situation of each company. See Data, Technology & Compliance.
What does the impact assessment file contain?
The Government details the file components, conditions, order and procedures of impact assessment in Decree 356/2025/ND-CP (the personal data processing impact assessment file follows Form 10). Structurally, a compliant file typically comprises three main content blocks:
- Description of data processing activities: types of personal data collected (basic data, sensitive data); processing purposes; methods of collecting, storing, using, sharing and deleting data; the parties involved (controller, processor, third parties receiving data); storage duration and geographic scope of processing.
- Risk assessment: identifying risks to the rights and legitimate interests of data subjects arising from processing activities — leaks, unauthorised access, misuse, risks from service providers; assessing the severity and likelihood of each risk.
- Remedial and mitigation measures: technical measures (encryption, access control, system logs) and management measures (internal policies, data processing contracts with processors, staff training, incident response procedures) corresponding to each identified risk.
The detailed file components follow the forms and guidance in Decree 356/2025/ND-CP. The specific contents must be built on the actual data flows of each company — do not copy a generic template.
Step-by-step file preparation process
- Reviewing actual data flows: building a data map — what types of data the company collects, from which sources, where it is stored, who can access it, which third parties it is shared with, and for how long. This is the foundational step determining the quality of the entire file.
- Determining legal roles: distinguishing the personal data controller, the personal data processor, and the controller-cum-processor in each activity — especially important for companies outsourcing IT services, using cloud platforms or belonging to multinational groups.
- Risk assessment: for each processing activity, identifying risks to data subjects and assessing risk levels.
- Building remedial measures: proposing corresponding technical and management measures, with assigned responsibility and an implementation roadmap.
- Preparing the file in the prescribed form: consolidating into the personal data processing impact assessment file under Form 10 of Decree 356/2025/ND-CP.
- Submitting and monitoring: submitting 01 original to the specialised personal data protection authority within 60 days from the first day of data processing; monitoring the evaluation result and completing the file if requested.
- Maintaining and updating: updating and supplementing the file when there are changes to the submitted contents — for example deploying new systems, changing data processing service providers, or expanding processing purposes.
How does FLAT LAW FIRM help?
- Assessing whether the company is required to prepare the file — including reviewing exemption conditions and opt-in application for small businesses and start-ups under Article 38 of Law 91/2025/QH15.
- Reviewing data flows and legal role allocation: identifying the controller and the processor in each processing activity, including relationships with service providers and parent/subsidiary companies.
- Drafting the impact assessment file in the correct form of Decree 356/2025/ND-CP, with risk assessment contents and remedial measures built specifically on actual operations — no copied generic templates.
- Reviewing data processing contracts and agreements with processors and confidentiality terms with suppliers to ensure consistency with the file’s contents.
- Representing the client before the specialised authority: preparing the submission, monitoring the evaluation result, and completing the file when requested.
- Establishing a periodic file update process and updating when changes occur — helping the company maintain continuous compliance rather than doing it once and forgetting.
- For companies transferring data abroad: assessing in parallel the obligation to prepare the cross-border personal data transfer impact assessment file (Form 09) — see the article Personal Data Processing Impact Assessment File.
Documents clients should prepare
- Inventory of systems and applications collecting and storing personal data (CRM, HRM, website, mobile apps…).
- Privacy policies and personal data processing notices currently applied (if any).
- Contracts with IT service providers, cloud services and outsourced data processing units.
- HR policies relating to employee data; rules on surveillance cameras and biometric timekeeping (if any).
- Organisational chart of the data/IT department; information on the personnel in charge of personal data protection (if designated).
- Impact assessment files prepared under Decree 13/2023/ND-CP (if any) for review and updating.
- Power of attorney for FLAT LAW FIRM (we will provide a template).
Expected timeline and costs
Statutory deadline: the file must be submitted to the specialised personal data protection authority within 60 days from the first day of processing personal data. For companies operating before 01/01/2026 (the Law’s effective date), the deadline calculation starting point must be determined carefully under the transition provisions — companies should discuss with a lawyer to avoid miscalculating the deadline.
Service implementation time depends on data flow complexity: companies with a few simple systems may complete the work in a few weeks; groups with many systems, many processors and cross-border data need a longer review period. Service fees are quoted specifically after the scope is determined — please contact us for a quotation.
Common mistakes that get the file returned for completion
- Copying a generic template: the file does not reflect the company’s actual data types, systems and processes — the first error detected when the specialised authority evaluates it.
- Superficial description of processing activities: missing data flow maps, unclear about which parties data passes through, where it is stored and for how long.
- Pro-forma risk assessment: listing generic risks without analysing levels and without linking to the company’s specific processing activities.
- Disproportionate remedial measures: stating generic measures (“strengthening security”) instead of specific technical and management measures with assigned responsibility and an implementation roadmap.
- Doing it once and forgetting: not updating the file when deploying new systems, changing service providers or expanding processing purposes — while the Law requires updates and supplements when changes occur.
- Confusing the two files: preparing only the DPIA and missing the cross-border personal data transfer impact assessment file when the company actually transfers data abroad.
Notes on cross-border personal data transfers
Many FDI companies and tech companies both process data in Vietnam and transfer data abroad — for example syncing HR data to the parent company’s systems, storing it on servers outside Vietnam’s territory, or using international cloud platforms. In such cases, in addition to the personal data processing impact assessment file (Form 10), the company must also prepare the cross-border personal data transfer impact assessment file (Form 09) under Law 91/2025/QH15 and Decree 356/2025/ND-CP.
The Law also provides cases exempt from cross-border transfer impact assessment — for example transfers of data of competent State agencies, or employees self-storing data on cloud computing services. Determining whether a company falls within an exception requires careful cross-checking of each specific situation. This is a topic FLAT LAW FIRM will develop into a separate service page — contact us for advice on your case.
Risks of not preparing the file or preparing a non-compliant file
- Administrative sanctions under current regulations: the 2025 Law on Personal Data Protection builds a high-deterrence sanction framework, with fines of up to 5% of the total revenue of the immediately preceding year for certain serious violations. The specific penalty for each act (not preparing, not submitting, not updating the file) follows the administrative sanction regulations on personal data protection in force at the time of handling.
- File required to be completed prolongs compliance time while legal obligations continue to arise — particularly risky if the company is fundraising, undergoing M&A or expanding and is asked by partners to demonstrate compliance.
- Risk when incidents occur: when a personal data leak or loss occurs, lacking a valid impact assessment file makes it difficult for the company to prove it implemented adequate protective measures — directly affecting compensation liability and reputation.
Legal update as of September 2026
The 2025 Law on Personal Data Protection (No. 91/2025/QH15) was passed by the National Assembly on 26/6/2025 and took effect on 01/01/2026 (Article 38). The Law replaces the personal data protection legal framework of Decree 13/2023/ND-CP, with many new points: the impact assessment obligation in Article 21, specific policies for small/start-up/micro enterprises in Article 38, and a high-deterrence sanction framework.
Decree 356/2025/ND-CP details certain articles and implementation measures of the Law on Personal Data Protection, including the personal data processing impact assessment file form (Form 10) and the cross-border personal data transfer impact assessment file form (Form 09), along with application guidance for small businesses (Article 41).
Transition provisions (Article 39 of Law 91/2025/QH15): personal data processing activities being carried out under Decree 13/2023/ND-CP before the Law’s effective date may continue; companies that prepared impact assessment files under Decree 13/2023/ND-CP should review and update their files to the new forms and procedures of the Law and Decree 356/2025/ND-CP.
The full texts of the documents above can be found on the Government’s legal normative documents system. The contents of this page should be cross-checked against the documents in force at the time of implementation.
Why choose FLAT LAW FIRM?
An impact assessment file is only valuable when it speaks truthfully about your company — the right data, the right systems, the right risks. FLAT LAW FIRM does not sell off-the-shelf file templates: we start by reviewing actual data flows, work with the company’s technical and legal teams to identify risks, and only then draft the file in the correct form of Decree 356/2025/ND-CP. This approach helps the file both pass the specialised authority’s evaluation and genuinely serve as an internal risk management tool. Our team works in Vietnamese, Chinese and English — suited to FDI companies needing to explain the group’s global data policies to Vietnamese regulators. See Data, Technology & Compliance.
Frequently asked questions
What is a personal data processing impact assessment (DPIA)?
It is a file in which a personal data controller describes its data processing activities, assesses the risks to the rights and legitimate interests of data subjects, and proposes remedial and risk-mitigation measures. The file is prepared in the prescribed form (Form 10) of Decree 356/2025/ND-CP and one original is submitted to the specialised personal data protection authority.
Which companies must prepare an impact assessment file?
Under Article 21 of the 2025 Law on Personal Data Protection, personal data controllers, and personal data controllers-cum-processors, must prepare the file. The Law has specific policies for small businesses and start-ups (may choose to comply or not within 05 years) and for micro enterprises and business households (not required) — but these policies do not apply if the company is in the business of processing personal data, directly processes sensitive personal data, or processes personal data of a large number of data subjects. Competent State agencies are not required to comply.
What is the deadline for preparing and submitting the file?
Within 60 days from the first day of processing personal data. For companies operating before 01/01/2026, the deadline calculation starting point must be determined carefully under the transition provisions — you should discuss with a lawyer to avoid miscalculating the deadline.
Is the file prepared once or for each processing activity?
The impact assessment is carried out once for the entire operating period of the personal data controller and is updated and supplemented when there are changes to the submitted contents — for example deploying new systems, changing data processing service providers or expanding processing purposes (Articles 21, 22 of Law 91/2025/QH15).
Must companies that prepared files under Decree 13/2023/ND-CP redo them?
Under the transition provisions of Law 91/2025/QH15, processing activities being carried out under Decree 13/2023/ND-CP may continue. However, companies should review and update their prepared files to the new forms and procedures of the Law and Decree 356/2025/ND-CP, as the file components and assessment requirements have changed significantly. FLAT LAW FIRM supports gap reviews between old files and the new legal framework.
How does a DPIA differ from a cross-border personal data transfer impact assessment?
These are two separate files: the personal data processing impact assessment file (Form 10) applies to data processing activities generally; the cross-border personal data transfer impact assessment file (Form 09) applies when a company transfers data outside Vietnam’s territory. A company that both processes data and transfers it abroad may have to prepare both files.
What happens if the impact assessment file is not prepared?
The company may face administrative sanctions under current regulations; the 2025 Law on Personal Data Protection builds a high-deterrence sanction framework. Beyond fines, a non-compliant file makes it difficult for the company to prove it implemented adequate protective measures when a data leak or loss occurs. The specific penalty for each act depends on the sanction regulations at the time of handling — you should discuss with a lawyer for an accurate assessment.
Useful links
You should talk to a lawyer if:
- Your company is processing personal data but has not prepared an impact assessment file under Law 91/2025/QH15.
- You have not determined whether your company falls within the obligation, the opt-in or the exemption under Article 38 of the Law.
- You prepared a file under Decree 13/2023/ND-CP and need to review and update it to the new forms of Decree 356/2025/ND-CP.
- Your company processes sensitive data (health, biometrics, financial) or data at scale.
- You transfer personal data abroad — you need a parallel assessment of the cross-border data transfer file obligation.
- You are preparing for fundraising, M&A or market expansion and need to demonstrate personal data protection compliance to partners.
Talk to a FLAT LAW FIRM lawyer
Describe your company’s current data processing activities — we will assess the file preparation obligation, review compliance gaps and draft the impact assessment file in the correct form and on time.
Send a legal enquiryImplementation timelines may vary depending on the file, the scope of data, the competent authority and the time of implementation. The contents of this website are for general information purposes only and do not substitute legal advice for any specific case.
Legal regulations, the jurisdiction of State authorities and administrative procedures may change over time, by sector and by specific file. You should consult a lawyer before making decisions or carrying out transactions.