Personal Data Processing Certificate in Vietnam: Conditions and Procedure

Table of Contents

Long Phan Consulting provides detailed guidance on the procedure for applying for a Personal Data Processing Certificate under Decree No. 356/2025/ND-CP, the current regulation on personal data protection, effective from January 1, 2026. Not all businesses collecting customer data are required to obtain this certificate; only 09 groups of services specified in Article 21 are subject to mandatory certification. This article analyzes the eligibility requirements, application documents, procedures, and common reasons for application rejection in practice.

Data Processing Certificate requirements, documents, and application process overview
The infographic highlights key requirements, mandatory documents, and submission methods for obtaining a Data Processing Certificate.

Important Notes:

  • Only 09 service groups listed in Article 21 of Decree No. 356/2025/ND-CP are required to obtain a Personal Data Processing Certificate, not all activities involving personal data collection and processing.
  • The authority to issue the Certificate belongs to the Ministry of Public Security. The Minister of Public Security assigns the specialized personal data protection authority to carry out the issuance, reissuance, replacement, and revocation of certificates under Article 24 of Decree No. 356/2025/ND-CP.
  • The specialized authority reviews the application within 10 days. After receiving a complete and valid application, the evaluation and decision on certificate issuance must be completed within 30 days according to Clauses 3 and 4 Article 25 of Decree No. 356/2025/ND-CP.
  • Small enterprises, micro-enterprises, and startups are not exempt if their main business activity involves these services, processing sensitive personal data, or processing data of 100,000 or more data subjects, according to Article 41 of Decree No. 356/2025/ND-CP.

Which Services Require a Personal Data Processing Certificate

Article 21 of Decree 356/2025/ND-CP lists exactly 09 service groups that must obtain a personal data processing certificate before commencing business. Outside these 09 groups, an organization is not required to obtain this certificate even if it regularly processes personal data in its operations.

09 Service Groups Requiring the Certificate Under Article 21

  • Providing and operating automated systems or software to process personal data on behalf of a data controller or a data controller-cum-processor.
  • Scoring, ranking, or assessing the creditworthiness of data subjects.
  • Collecting and processing personal data online through websites, applications, software, and social networks.
  • Collecting and processing personal data through healthcare, health-monitoring, or medical service applications.
  • Collecting and processing personal data through education applications with supervisory features (attendance tracking, video recording, behavior scoring, emotion recognition).
  • Analyzing and mining personal data using analytical tools to predict behavior or optimize services.
  • Encrypting personal data during transmission and storage.
  • Automated processing of personal data based on big data, artificial intelligence, blockchain, or the metaverse.
  • Providing platforms or applications built on personal location data.

Enterprises must accurately compare their business model against the 09 groups above. A business that only uses an internal CRM system to store customer information, without selling data-processing services to third parties, typically does not fall within the scope requiring this certificate.

No Exemption for Small, Micro and Start-Up Enterprises

Clauses 1 and 2 of Article 41 of Decree 356/2025/ND-CP allow small enterprises and start-ups to choose whether to perform certain obligations for 05 years after the Law on Personal Data Protection takes effect. The same clauses fully exempt household businesses and micro enterprises. However, both clauses clearly exclude cases where an enterprise’s core business is personal data processing services, where it directly processes sensitive personal data, or where it processes cumulative data of 100,000 or more data subjects. In other words, a newly established start-up that sells personal data processing services must still obtain the certificate on the same basis as a large enterprise.

Conditions for Certificate Issuance

Article 22 of Decree 356/2025/ND-CP sets out 04 mandatory condition groups: legal status, personnel, technology infrastructure, and impact assessment dossiers. An organization must satisfy all 04 groups simultaneously to be eligible for the certificate.

Legal Status Condition (Clause 1, Article 22)

The applicant organization must be an entity lawfully established and operating under Vietnamese law. Individuals and household businesses are not eligible to apply directly for this certificate in their own name.

Specialized Personnel Condition (Clause 2, Article 22; Clause 2, Article 13)

The person in charge of personal data processing expertise must be a Vietnamese citizen permanently residing in Vietnam. The organization must have a management and operating team meeting professional requirements, including at least 03 personnel who satisfy the competency conditions under Clause 2, Article 13. These personnel must hold a college-level degree or higher, at least 02 years of experience in legal compliance, information technology, cybersecurity, data security, risk management, or compliance control, and completed training on personal data protection. Many small and medium enterprises find this condition difficult to meet when first launching such a service.

Infrastructure and Technology Condition (Clause 3, Article 22)

The organization must have infrastructure, equipment, facilities, and technology appropriate to the personal data processing service it intends to provide. The Decree does not fix specific technical parameters, so the level of infrastructure investment should be proportionate to the scale and type of data processed.

Impact Assessment Dossier Condition (Clause 4, Article 22)

The organization must hold a satisfactory personal data processing impact assessment dossier under Article 19. Where it transfers personal data abroad, it must also supplement a cross-border personal data transfer impact assessment dossier under Article 18. This is a prerequisite condition: if the impact assessment dossier has not been confirmed as satisfactory by the specialized agency, the certificate application will not be eligible for review.

Data Processing Certificate conditions with organization compliance requirements
Organizations must satisfy legal status, technology infrastructure, personnel, and impact assessment conditions before certificate approval.

Licensing Authority and Application Methods

Article 24 of Decree 356/2025/ND-CP designates the Ministry of Public Security as the competent authority for issuing, reissuing, replacing, and revoking the personal data processing certificate. In practice, application receipt and appraisal are carried out by the specialized personal data protection agency as assigned.

Authority of the Ministry of Public Security and the Specialized Agency (Article 24)

Clause 1, Article 24 provides that the Ministry of Public Security issues, reissues, replaces, and revokes the certificate. Clause 2, Article 24 assigns the Minister of Public Security to designate the specialized personal data protection agency, a unit under the Ministry pursuant to Article 39, to directly carry out these procedures.

Three Application Methods (Clause 3, Article 25)

An organization submits 01 application dossier through one of three methods: online, in person, or by postal service, sent to the specialized personal data protection agency. No method carries greater legal priority; choosing the appropriate method helps the enterprise track processing progress more effectively.

>>>See more: Exemptions from Data Processing Impact Assessment

Application Dossier for the Certificate

Clause 1, Article 25 of Decree 356/2025/ND-CP specifies 05 mandatory documents in the application dossier; missing any one document renders the application incomplete.

Dossier Components Under Clause 1, Article 25

No. Document Legal Basis
1 Application form for the certificate under Form No. 04 in the Appendix to Decree 356/2025/ND-CP Point a, Clause 1, Article 25
2 Copy of the Enterprise Registration Certificate Point b, Clause 1, Article 25
3 Document designating a personal data protection unit, or a service contract for personal data protection services Point c, Clause 1, Article 25
4 Project proposal for the certificate application Point d, Clause 1, Article 25
5 Qualifications and documents evidencing the competency of specialized personnel Point dd, Clause 1, Article 25; Point c, Clause 2, Article 22

Point e, Clause 1, Article 25 allows an organization to omit the copy of the Enterprise Registration Certificate if the competent authority can retrieve this information from the national database.

Mandatory Content of the Project Proposal (Clause 2, Article 25)

The project proposal for the certificate application must clearly state the following:

  • The necessity and objectives.
  • The content and field for which approval is sought.
  • The business line and business plan.
  • The intended scale of data processing activities.
  • The risk management framework.
  • The periodic compliance assessment plan.
  • The application of data security standards.
  • The plan for using electronic identification and authentication services.
  • The organization’s responsibilities and authority.
  • Information on qualified personnel.

A proposal that is superficial or omits any of these items is a common reason applications are requested to be supplemented.

Data Processing Certificate application documents and required records checklist
The visual explains essential records and supporting documents prepared for the Data Processing Certificate application procedure.

Procedure and Timeline for Certificate Issuance

Clauses 3 and 4, Article 25 of Decree 356/2025/ND-CP set out a 03-step process. Total processing time is up to approximately 40 days from the initial submission date, provided the dossier is satisfactory from the outset.

Step Content Timeline Legal Basis
1 Submit 01 application dossier online, in person, or by postal service Clause 3, Article 25
2 The specialized agency assesses whether the dossier is complete; if incomplete, it issues a written request for supplementation 10 days for review; 15 days to supplement if requested Clause 3, Article 25
3 Content appraisal and decision to issue the certificate under Form No. 05, from the date of receipt of a complete and valid dossier Up to 30 days Clause 4, Article 25

The certificate is issued in either paper or electronic form. A paper certificate is issued when the organization submits the dossier in person, by postal service, or upon request when submitting online through the public service portal. Where the certificate is not issued, the specialized agency must provide a written notice stating the reasons.

Reissuance and Replacement of the Certificate

Article 26 of Decree 356/2025/ND-CP distinguishes two cases: reissuance where the certificate is lost or damaged, and replacement where the information on the certificate is incorrect or its content has changed.

Reissuance for Lost or Damaged Paper Certificates (Clause 1, Article 26)

The organization submits a request using the form set out in the Appendix to the Decree, through one of the three application methods described above. The specialized agency considers and reissues the certificate within 05 working days from the date of receiving the request; if not reissued, it must provide written reasons.

Replacement for Incorrect Information or Changed Content (Clause 2, Article 26)

The replacement dossier comprises a request using the prescribed form and documents evidencing the incorrect information or the change. The processing timeline is also 05 working days from the date of receiving a complete dossier.

Grounds for Certificate Revocation

Clause 1, Article 27 of Decree 356/2025/ND-CP sets out 05 grounds for revoking the certificate; organizations should proactively review their compliance to avoid violations that disrupt business operations.

05 Grounds for Revocation (Clause 1, Article 27)

  • No longer satisfying one of the conditions under Clauses 1 and 2, Article 26 (applicable to reissued or replaced certificates).
  • Not conducting the licensed service for 12 months or more.
  • Being dissolved or declared bankrupt under applicable law.
  • Failing to remedy violations of personal data protection, information safety, cybersecurity, or data security requirements upon request of the competent state authority.
  • Voluntarily requesting suspension or termination of operations.

The specialized agency issues a revocation decision under Form No. 07 and publicly announces it on the National Portal on Personal Data Protection.

Obligation to Return the Certificate Within 05 Working Days (Clause 3, Article 27)

An organization whose certificate is revoked must return the issued certificate to the specialized agency within 05 working days from the date of receiving the revocation decision. A delay in returning the certificate does not invalidate the revocation decision but may be subject to handling under other applicable regulations.

Ongoing Obligations After Certificate Issuance

Obtaining the certificate is not the end point of compliance obligations: Article 23 of Decree 356/2025/ND-CP sets out a series of ongoing obligations that apply throughout the operation of the service.

Compliance and Periodic Assessment (Clauses 1–4, Article 23)

The organization must:

  • Fully comply with personal data protection regulations in its capacity as a data controller-cum-processor or a data processor.
  • Build a risk management framework appropriate to the service provided.
  • Conduct an annual assessment of compliance status and creditworthiness in personal data protection.
  • Apply relevant data security and cybersecurity standards.

Obligations to Data Subjects When Acting as a Processor (Clause 7, Article 23)

When acting as a personal data processor for a customer, the organization must require the data controller to obtain the data subject’s consent before providing the service. It must also ensure the data subject is informed of the type of personal data processed, the purpose of processing, and the identity of the organization providing the service.

Common Reasons Applications Are Rejected or Delayed

Comparing Articles 22 and 25 of Decree 356/2025/ND-CP with practical case processing, three groups of causes commonly result in applications being rejected or delayed.

Insufficient Personnel Meeting the Competency Standard Under Clause 2, Article 13

Many enterprises newly launching this service have not yet secured 03 personnel who simultaneously satisfy all three criteria: a college-level degree or higher, 02 years of relevant experience, and completed training on personal data protection. This is a mandatory condition under Point c, Clause 2, Article 22 and cannot be substituted with a commitment to supplement personnel after the certificate is issued.

Impact Assessment Dossier Not Yet Satisfactory Under Article 19

Clause 4, Article 22 requires the personal data processing impact assessment dossier to be confirmed as satisfactory before the certificate application is submitted. If the organization has never prepared this dossier in accordance with Article 19, or if the dossier is assessed as unsatisfactory, the entire certificate application process is suspended until it is completed.

Project Proposal Lacking Mandatory Content Under Clause 2, Article 25

A proposal lacking a risk management framework, a periodic compliance assessment plan, or a clear plan for using electronic identification and authentication services is a common drafting error. The specialized agency may request supplementation within 15 days, significantly extending the processing time beyond the standard 30-day timeline.

Consulting and Authorized Services for Applying for the Certificate

Long Phan Consulting provides comprehensive support for businesses in applying for a Personal Data Processing Certificate, including:

  • Reviewing business models and comparing them with the 09 service groups specified in Article 21 to determine whether the certificate is mandatory.
  • Assessing compliance with personnel and infrastructure requirements under Article 22 and recommending solutions if additional improvements are required.
  • Preparing the certification application proposal dossier in accordance with the 09 mandatory contents required under Clause 2 Article 25.
  • Preparing the Personal Data Processing Impact Assessment dossier under Article 19 and the Cross-Border Personal Data Transfer Impact Assessment dossier under Article 18 (if applicable).
  • Drafting the application form according to Form No. 04 and preparing all supporting documents required for the application dossier.
  • Representing businesses in working with the specialized personal data protection authority during the appraisal process and handling requests for additional documents (if any).
  • Advising on maintaining compliance conditions after obtaining the certificate to avoid cases subject to revocation under Article 27.
  • Developing and reviewing personal data protection policies and internal procedures within the business.
  • Advising on risk management mechanisms, compliance control systems, and periodic compliance assessments.
  • Advising on the rights and responsibilities of data controllers, data processors, and related parties involved in personal data processing activities.
  • Reviewing contracts, agreements, and service arrangements related to personal data processing activities.
  • Advising on obligations toward data subjects, including information provision, consent collection, and protection of data subject rights.
  • Advising on data security requirements, cybersecurity measures, and system governance for personal data processing activities.
  • Representing or being authorized to submit applications, work with the specialized personal data protection authority, and handle requests for additional information.
  • Advising on maintaining conditions and compliance obligations after the certificate is issued.
  • Reviewing risks of certificate revocation and providing corrective solutions when violations occur.
  • Supporting businesses in resolving legal issues arising during the provision of personal data processing services.

Customers may send their case documents via email info@longphanpmt.com or Zalo 0906.735.386 for an initial assessment.

Frequently Asked Questions About the Personal Data Processing Certificate

During the process of applying for and maintaining the Personal Data Processing Certificate, businesses often have concerns regarding validity period, applicable scope, processing time, and exemption cases. The following are key issues under Decree No. 356/2025/ND-CP.

1. How long is the Personal Data Processing Certificate valid?

Decree No. 356/2025/ND-CP does not specify a fixed validity period for the certificate. According to Form No. 05 in the Appendix, the certificate takes effect from the signing date. However, organizations must maintain the certified conditions and conduct annual compliance assessments under Clause 3 Article 23. Failure to maintain compliance requirements may result in certificate revocation under Article 27.

2. Are foreign-invested enterprises (FDI) required to obtain this certificate?

Yes. Under Article 2 of Decree No. 356/2025/ND-CP, foreign organizations, enterprises, and individuals operating in Vietnam are included within the applicable scope. FDI enterprises providing one of the 09 service groups under Article 21 must apply for the certificate and are not exempt under Article 41 if personal data processing services are their main business activity.

3. How long does the certification procedure take?

According to Article 25, the procedure includes 10 days for reviewing application completeness and up to 30 days for substantive appraisal after receiving a valid dossier. Therefore, the total processing period is approximately 40 days if the application satisfies all requirements from the beginning. If additional documents are requested, the actual timeline may be extended by up to 15 days for each supplementation request.

4. What happens if a business provides personal data processing services without obtaining the certificate?

Articles 21 and 22 of Decree No. 356/2025/ND-CP identify this activity as a conditional business sector requiring certification before providing services. Operating without the required certificate may result in administrative penalties under personal data protection regulations and other measures according to applicable law.

5. Are micro-enterprises exempt from obtaining the certificate?

Clause 2 Article 41 provides certain exemptions for households and micro-enterprises from specific obligations under Article 21, Article 22, and Clause 2 Article 33 of the Law on Personal Data Protection. However, this exemption does not apply if the entity mainly provides personal data processing services, processes sensitive personal data, or processes data of 100,000 or more data subjects.

6. Which authority issues and revokes the certificate?

According to Article 24, the Ministry of Public Security has authority to issue, reissue, replace, and revoke the certificate. The Minister of Public Security assigns the specialized personal data protection authority to receive applications, conduct appraisal, and complete certification procedures.

7. What are the common reasons for application rejection?

Common reasons include failure to satisfy personnel requirements under Clause 2 Article 13, incomplete Personal Data Processing Impact Assessment documentation under Article 19, and an incomplete certification proposal that does not contain all mandatory contents required under Clause 2 Article 25.

Conclusion

Obtaining a Personal Data Processing Certificate is a mandatory requirement for the 09 service groups specified in Article 21 of Decree No. 356/2025/ND-CP, rather than an optional procedure. Businesses should prepare personnel conditions, infrastructure requirements, and impact assessment dossiers before submission to avoid additional requests that may extend the processing timeline.Long Phan Consulting is ready to support businesses throughout the entire certification process. Contact hotline 1900636389 for consultation tailored to your business model.

📚 Legal basis:

  • Law on Personal Data Protection 2025.
  • Decree No. 356/2025/ND-CP detailing certain provisions and implementation measures of the Law on Personal Data Protection.
  • Note: Legal regulations may change depending on the applicable period. Please contact Long Phan Consulting via Hotline 1900.63.63.89 for the latest legal updates.
Table of Contents
CONTACT FORM
Call for consultation now!

Leave a Reply

Your email address will not be published. Required fields are marked *