Personal data processing enterprises: Compliance reviewprocess to avoid penalties

Table of Contents

Long Phan Consulting regularly receives inquiries from businesses regarding their legal obligations when collecting, storing, and using customer and employee data. As of January 1, 2026, personal data processing enterprises must comply with both the Law on Personal Data Protection 2025 and Decree No. 356/2025/ND-CP, which introduce various new obligations concerning consent, impact assessments, incident notification, and penalties of up to VND 3 billion. This article summarizes the key regulations businesses need to understand, together with the latest updates on enterprise regulations, to help businesses promptly review and strengthen their compliance measures.

Personal data processing enterprises reviewing consent, impact assessments, data subject requests, and incident response
Enterprises processing personal data should obtain valid consent, prepare impact assessment records, handle data subject requests, and respond proactively to incidents.

Key Takeaways:

  • There are five cases in which personal data may be processed without consent under Clause 1, Article 19 of the Law on Personal Data Protection 2025.
  • The personal data processing impact assessment dossier must be submitted to the competent specialized authority within 60 days from the date of first processing the data, pursuant to Clause 1, Article 21 of the Law on Personal Data Protection 2025.
  • When a personal data protection violation occurs or is detected, businesses must notify the Ministry of Public Security no later than 72 hours, pursuant to Decree No. 356/2025/ND-CP.
  • The maximum fine for purchasing or selling personal data is 10 times the proceeds obtained from the violation. If the proceeds cannot be determined or the calculated amount is lower than VND 3 billion, the maximum fine of VND 3 billion applies, pursuant to Clause 3, Article 8 of the Law on Personal Data Protection 2025.

What Counts as a Personal Data Processing Enterprise

A personal data processing enterprise is any organization that performs an activity affecting personal data, including collecting, recording, analyzing, storing, editing, using, sharing, transferring or deleting data belonging to customers, employees or partners. The Law on Personal Data Protection 2025  applies to Vietnamese agencies, organizations and individuals, as well as foreign organizations and individuals connected to the processing of Vietnamese citizens’ personal data.

Compliance obligations arise as soon as an enterprise begins collecting data, regardless of company size or industry. A website with a registration form, a CRM system storing customer information, timekeeping software or an e-commerce application are all personal data processing activities within the scope of the Law.

Core Principles Enterprises Must Follow

Article 3 of the Law on Personal Data Protection 2025 sets out six principles that enterprises must observe whenever personal data is processed. These principles form the reference framework for assessing whether any data collection or storage activity is lawful.

  • Comply with the Constitution, the Law on Personal Data Protection 2025 and related regulations.
  • Collect and process personal data only within a specific, clear and lawful scope and purpose.
  • Ensure data accuracy, update it when necessary, and store it only for as long as the processing purpose requires, unless the law provides otherwise.
  • Apply institutional, technical and human measures consistently and effectively to protect personal data.
  • Proactively prevent, detect, deter and promptly handle violations.
  • Protect personal data in a manner aligned with national interests and the lawful rights of related agencies, organizations and individuals.

Legal basis: Article 3 of the Law on Personal Data Protection 2025 (Law No. 91/2025/QH15).

Data Subject Rights Enterprises Must Respect

Alongside the processing principles, enterprises must fully respect the rights that customers and employees, as data subjects, may invoke if those rights are violated.

Under Clause 1, Article 4 of the Law on Personal Data Protection 2025, data subjects have the right to know how their data is processed, and to give or withdraw consent. They may also access, correct, request, delete or restrict their data, object to processing, and complain, denounce, sue or claim damages when their rights are infringed.

Silence or non-response from a data subject is not deemed consent. Enterprises must be able to prove valid consent in case of a dispute, so keeping consent evidence such as written records, messages or system logs is a practical requirement.

When Enterprises May Process Data Without Consent

Not every processing activity requires consent. Clause 1, Article 19 of the Law on Personal Data Protection 2025 sets out five exceptions:

  • Protecting the life, health, honor and lawful rights of the data subject or others in an emergency.
  • Addressing emergencies or threats to national security that have not reached the level of a declared state of emergency, or preventing riots, terrorism or crime.
  • Performing state administrative management functions under the law.
  • Implementing an agreement between the data subject and a related agency, organization or individual as provided by law.

Enterprises should treat these as exceptions, not a basis for open-ended expansion. Clause 2, Article 19 requires enterprises to establish a separate monitoring mechanism when relying on this exception, including a processing procedure, periodic risk assessment, compliance checks and a complaint-handling mechanism. Before invoking Article 19 to bypass consent, enterprises should carefully verify the applicable grounds to avoid being found in breach of the data protection rules.

Legal basis: Clauses 1 and 2, Article 19 of the Law on Personal Data Protection 2025.

Specific Obligations When Processing Personal Data

Beyond respecting data subject rights, personal data processing enterprises must proactively perform three groups of obligations: responding to data subject requests on time, preparing an impact assessment dossier, and notifying incidents. These are the obligations most prone to violation in practice because they are tied to specific deadlines.

Responding to Data Subject Requests

Article 5 of Decree No. 356/2025/ND-CP sets separate response deadlines for each type of request, rather than a single 72-hour deadline as previously applied under the now-expired Decree No. 13/2023/ND-CP. In every case, the enterprise must confirm receipt of the request within 2 working days.

Type of Request Standard Deadline With a Third-Party Processor Involved
Withdraw consent, restrict or object to processing 15 days 20 days
Access, correct or provide data 10 days 15 days
Delete personal data 20 days 30 days

An enterprise may extend the deadline once if the request is complex, but must state the reason and bear responsibility for proving the extension is necessary and reasonable.

Legal basis: Article 5 of Decree No. 356/2025/ND-CP.

Impact Assessment and Cross-Border Data Transfer

Personal data controllers, controller-processors and processors must prepare and retain a personal data processing impact assessment dossier and submit one original copy to the competent authority within 60 days of the first date of processing. This dossier only needs to be prepared once for the entire operating period, but must be updated every 6 months when changes occur. It must also be updated immediately in the event of major changes to the purpose, method or technology of processing under Article 22 of the Law.

When transferring personal data abroad, including to foreign software providers or cloud storage platforms, enterprises must prepare a cross-border data transfer impact assessment dossier in the form prescribed by the Government. They must also notify the Department of Cybersecurity and Hi-tech Crime Prevention (A05), Ministry of Public Security. The competent authority issues its assessment result within 15 days, Procedures for Notification of Personal Data Protection Violations.

Legal basis: Articles 21 and 22 of the Law on Personal Data Protection 2025; Clause 1, Article 19 of Decree No. 356/2025/ND-CP.

Notifying Violations and Data Incidents

When a violation of personal data protection rules is detected, the data controller or controller-processor must notify the Ministry of Public Security (Department A05). This must occur no later than 72 hours after the violation occurs or is discovered. For incidents involving location data or biometric data, the enterprise must also notify affected data subjects directly within 72 hours, or publish the notice through electronic media if individual notification is not feasible in time.

The incident record must cover the type of data affected, scope, risk level, cause and remedial measures. It must be retained for at least 5 years from the date the incident is resolved, to support inspection and audit. Specific notification procedures are guided on the Ministry of Public Security’s public service portal.

Legal basis: Decree No. 356/2025/ND-CP.

Before a fine is imposed, you may share your business sector, the types of data collected, and your current compliance documentation. Adding your desired consultation timeline lets Long Phan Consulting provide a preliminary risk assessment.

Personal data processing enterprises managing data subject requests, impact assessments, transfers, and incident notifications
Key compliance duties include responding to data subject requests, maintaining impact assessment records, monitoring cross border data transfers, and reporting incidents.

Prohibited Acts Enterprises Must Avoid

Article 7 of the Law on Personal Data Protection 2025 lists acts that are strictly prohibited, forming boundaries enterprises should check against periodically:

  • Undermining the State of the Socialist Republic of Vietnam through personal data processing.
  • Obstructing the lawful personal data protection activities of competent agencies, organizations or individuals.
  • Exploiting personal data protection activities to violate the law.
  • Processing personal data in violation of personal data protection regulations.
  • Using or allowing others to use another person’s personal data to commit a legal violation.
  • Buying or selling personal data, except where otherwise permitted by law.

In consulting practice, the fourth act, unlawful processing, is the most common risk for ordinary enterprises. It typically arises not from intent but from the absence of a valid consent procedure or adequate technical security measures, leading to unintended data leaks.

Legal basis: Article 7 of the Law on Personal Data Protection 2025.

>>>See more: List of Sensitive Personal Data Effective from January 1, 2026

Fines Enterprises May Face for Violations

This is the section that brings most personal data processing enterprises to this article. Article 8 of the Law on Personal Data Protection 2025 divides fines into three brackets, with a ceiling of VND 3 billion or a percentage of revenue.

Bracket Violation Maximum Fine
Clause 3, Article 8 Buying or selling personal data 10 times the illicit proceeds; if the proceeds cannot be determined or the calculated amount is below VND 3 billion, a fine of VND 3 billion applies
Clause 4, Article 8 Violating cross-border personal data transfer rules 5% of the preceding year’s revenue; if there is no revenue or the calculated amount is below Clause 5, the Clause 5 level applies
Clause 5, Article 8 Other violations VND 3 billion

Fines for Buying or Selling Personal Data

The maximum fine is 10 times the proceeds obtained from the violation. If the proceeds cannot be determined, or the calculated amount is below VND 3 billion, the enforcement authority applies the maximum level of VND 3 billion.

Legal basis: Clause 3, Article 8 of the Law on Personal Data Protection 2025.

Fines for Cross-Border Data Transfer Violations

The maximum fine is 5% of the violating organization’s revenue for the preceding year. If the organization has no revenue for that year, or the calculated fine is lower than the maximum under Clause 5, Article 8, the enforcement authority applies the Clause 5 level instead.

Legal basis: Clause 4, Article 8 of the Law on Personal Data Protection 2025.

Fines for Other Violations

Remaining violations in the field of personal data protection, such as late preparation of the impact assessment dossier, late incident notification or an invalid consent mechanism, carry a maximum fine of VND 3 billion.

Legal basis: Clause 5, Article 8 of the Law on Personal Data Protection 2025.

Fine Levels for Organizations and Individuals

The maximum fines under Clauses 3, 4 and 5, Article 8 apply to violating organizations. An individual committing the same violation is subject to a maximum fine equal to one-half of the level applicable to organizations. The Government prescribes the method for calculating illicit proceeds used as a basis for enforcement.

Legal basis: Clauses 6 and 7, Article 8 of the Law on Personal Data Protection 2025.

Practical Lessons From Advising Enterprises on Compliance Reviews

Through supporting personal data processing enterprises with compliance reviews, several recurring gaps appear across industries.

First, an enterprise may have a privacy policy published on its website that does not match its actual data collection practices. A common gap is omitting phone numbers collected through a chatbot or location data gathered via a mobile app.

Second, the consent mechanism is set up in an invalid form, such as a pre-ticked default checkbox or ambiguous wording that fails to let users clearly distinguish between consenting and not consenting.

Third, many enterprises have already been processing data but have never prepared a personal data processing impact assessment dossier. This creates a risk of breach even when the underlying processing activity itself is unremarkable.

Fourth, enterprises transfer customer data to third parties or foreign software providers, such as email marketing services, CRM platforms or cloud storage services. They often fail to recognize this as a cross-border data transfer requiring a separate dossier and procedure.

When an enterprise encounters any of these four situations, it is a signal to conduct a legal review immediately, because the risk lies not in intent to violate but in gaps in the compliance process.

Compliance Review Process Enterprises Should Start Now

To reduce risk, personal data processing enterprises should implement a compliance review following these steps:

  1. Inventory all personal data being collected and stored, identifying the source, purpose of processing and actual retention period.
  2. Review the current consent mechanism against the requirements for valid consent form and the ability to prove consent in a dispute.
  3. Determine whether the enterprise must prepare a personal data processing impact assessment dossier or a cross-border data transfer impact assessment dossier.
  4. Build an internal procedure for receiving and handling data subject requests, ensuring correct response deadlines for each request type.
  5. Build an incident response procedure, ensuring the ability to notify the Ministry of Public Security within 72 hours of a violation.
Personal data processing enterprises conducting compliance reviews of data, consent mechanisms, records, and internal procedures
A structured compliance review helps enterprises inventory processed data, verify consent mechanisms, assess impact assessment records, and establish effective internal procedures.

Personal Data Protection Consulting and Business Support Services at Long Phan

Long Phan Consulting provides consulting, review, and support services to help businesses establish legal compliance systems when collecting, storing, using, sharing, and transferring personal data, including:

  • Advising on the legal obligations of businesses when collecting and processing personal data of customers, employees, and partners;
  • Reviewing the types of data collected by the business, processing purposes, data sources, scope of use, and retention periods;
  • Reviewing consent mechanisms, forms, terms of use, privacy policies, and methods for retaining evidence of consent;
  • Advising on the exercise of data subjects’ rights, including access, correction, provision, deletion, restriction, or objection to data processing;
  • Developing internal procedures for receiving and handling requests from customers, employees, and other data subjects;
  • Advising on, preparing, and reviewing personal data processing impact assessment dossiers;
  • Advising on cross-border personal data transfer impact assessments, including cases involving the use of platforms, software, or storage services provided by foreign suppliers;
  • Drafting and updating personal data protection policies, data processing notices, privacy terms, and internal documents;
  • Reviewing contracts with partners, suppliers, data processors, and third parties with access to personal data;
  • Advising on the allocation of rights, obligations, and responsibilities among data controllers, data processors, and relevant parties;
  • Developing procedures for preventing, detecting, handling, and notifying personal data protection incidents;

Clients may send their case documents via email info@longphanpmt.com or Zalo 0906.735.386 for a preliminary assessment.

Frequently Asked Questions About the Obligations of Businesses Processing Personal Data

During the collection, processing, and storage of personal data, businesses often face questions concerning customer consent, data deletion rights, impact assessments, incident handling, and cross-border data transfers. Below are some frequently asked questions to note:

1. Must a business obtain consent in every case when processing customers’ personal data?

No. Clause 1, Article 19 of the Law on Personal Data Protection 2025 provides for five exceptions where personal data may be processed without consent, such as protecting life or health in urgent situations or serving state management activities. Outside these cases, businesses must obtain valid consent and retain evidence of such consent.

2. Does a data subject have the right to request that a business delete their personal data?

Yes. Clause 1, Article 4 of the Law on Personal Data Protection 2025 recognizes the right to request deletion of personal data as one of the fundamental rights of data subjects. Under Article 5 of Decree No. 356/2025/ND-CP, businesses must respond within two working days and complete the deletion within 20 days, or 30 days if a data processor or third party is involved.

3. How long does a personal data processing impact assessment dossier have to be submitted?

Under Clause 1, Article 21 of the Law on Personal Data Protection 2025, a business must prepare, retain, and submit one original copy of the personal data processing impact assessment dossier to the competent specialized authority within 60 days from the date of first processing personal data. The dossier only needs to be prepared once and must be updated when changes occur under Article 22.

4. When a personal data breach occurs, which authority must the business notify and within what timeframe?

The business must notify the Department of Cybersecurity and High-Tech Crime Prevention (A05) under the Ministry of Public Security no later than 72 hours after the violation occurs or is detected, pursuant to Decree No. 356/2025/ND-CP. Records relating to the violation must be retained for at least five years.

5. What is the maximum penalty for purchasing or selling personal data?

Under Clause 3, Article 8 of the Law on Personal Data Protection 2025, the maximum fine is 10 times the proceeds obtained from the violation. If the proceeds cannot be determined or the calculated amount is lower than VND 3 billion, the maximum fine of VND 3 billion applies.

6. Does transferring personal data to a foreign software provider require a cross-border data transfer impact assessment?

Yes. Storing or sharing data through platforms or servers located overseas constitutes a cross-border personal data transfer under Article 22 of the Law on Personal Data Protection 2025. Businesses must prepare a separate impact assessment dossier and notify the Ministry of Public Security before carrying out the transfer.

7. How are individuals penalized compared with organizations for personal data protection violations?

Under Clause 6, Article 8 of the Law on Personal Data Protection 2025, an individual committing the same violation is subject to a maximum fine equal to one-half of the maximum fine applicable to an organization.

Conclusion

Businesses processing personal data should simultaneously review four key groups of obligations: obtaining valid consent, preparing impact assessment dossiers within the prescribed timeframe, establishing procedures for responding to data subject requests, and establishing procedures for notifying incidents within 72 hours. Fines of up to VND 3 billion or 5% of revenue represent a real financial risk rather than merely a formal compliance requirement. Long Phan Consulting is ready to assist businesses in conducting a comprehensive review of their compliance documentation. Clients may contact the hotline at 1900636389 for advice tailored to their specific circumstances.

📚 This article is professionally reviewed based on the following legal documents:

  • Law on Personal Data Protection 2025.
  • Decree No. 356/2025/ND-CP detailing certain provisions and measures for implementing the Law on Personal Data Protection, officially effective from January 1, 2026.
  • Note: Legal regulations may change over time. Please contact Long Phan Consulting directly at Hotline 1900.63.63.89 for the latest legal updates and specific advice.
Table of Contents
CONTACT FORM
Call for consultation now!

Leave a Reply

Your email address will not be published. Required fields are marked *