
Sign up for consultation
Long Phan Consulting regularly receives inquiries from businesses regarding their legal obligations when collecting, storing, and using customer and employee data. As of January 1, 2026, personal data processing enterprises must comply with both the Law on Personal Data Protection 2025 and Decree No. 356/2025/ND-CP, which introduce various new obligations concerning consent, impact assessments, incident notification, and penalties of up to VND 3 billion. This article summarizes the key regulations businesses need to understand, together with the latest updates on enterprise regulations, to help businesses promptly review and strengthen their compliance measures.

Key Takeaways:
A personal data processing enterprise is any organization that performs an activity affecting personal data, including collecting, recording, analyzing, storing, editing, using, sharing, transferring or deleting data belonging to customers, employees or partners. The Law on Personal Data Protection 2025 applies to Vietnamese agencies, organizations and individuals, as well as foreign organizations and individuals connected to the processing of Vietnamese citizens’ personal data.
Compliance obligations arise as soon as an enterprise begins collecting data, regardless of company size or industry. A website with a registration form, a CRM system storing customer information, timekeeping software or an e-commerce application are all personal data processing activities within the scope of the Law.
Article 3 of the Law on Personal Data Protection 2025 sets out six principles that enterprises must observe whenever personal data is processed. These principles form the reference framework for assessing whether any data collection or storage activity is lawful.
Legal basis: Article 3 of the Law on Personal Data Protection 2025 (Law No. 91/2025/QH15).
Alongside the processing principles, enterprises must fully respect the rights that customers and employees, as data subjects, may invoke if those rights are violated.
Under Clause 1, Article 4 of the Law on Personal Data Protection 2025, data subjects have the right to know how their data is processed, and to give or withdraw consent. They may also access, correct, request, delete or restrict their data, object to processing, and complain, denounce, sue or claim damages when their rights are infringed.
Silence or non-response from a data subject is not deemed consent. Enterprises must be able to prove valid consent in case of a dispute, so keeping consent evidence such as written records, messages or system logs is a practical requirement.
Not every processing activity requires consent. Clause 1, Article 19 of the Law on Personal Data Protection 2025 sets out five exceptions:
Enterprises should treat these as exceptions, not a basis for open-ended expansion. Clause 2, Article 19 requires enterprises to establish a separate monitoring mechanism when relying on this exception, including a processing procedure, periodic risk assessment, compliance checks and a complaint-handling mechanism. Before invoking Article 19 to bypass consent, enterprises should carefully verify the applicable grounds to avoid being found in breach of the data protection rules.
Legal basis: Clauses 1 and 2, Article 19 of the Law on Personal Data Protection 2025.
Beyond respecting data subject rights, personal data processing enterprises must proactively perform three groups of obligations: responding to data subject requests on time, preparing an impact assessment dossier, and notifying incidents. These are the obligations most prone to violation in practice because they are tied to specific deadlines.
Article 5 of Decree No. 356/2025/ND-CP sets separate response deadlines for each type of request, rather than a single 72-hour deadline as previously applied under the now-expired Decree No. 13/2023/ND-CP. In every case, the enterprise must confirm receipt of the request within 2 working days.
| Type of Request | Standard Deadline | With a Third-Party Processor Involved |
| Withdraw consent, restrict or object to processing | 15 days | 20 days |
| Access, correct or provide data | 10 days | 15 days |
| Delete personal data | 20 days | 30 days |
An enterprise may extend the deadline once if the request is complex, but must state the reason and bear responsibility for proving the extension is necessary and reasonable.
Legal basis: Article 5 of Decree No. 356/2025/ND-CP.
Personal data controllers, controller-processors and processors must prepare and retain a personal data processing impact assessment dossier and submit one original copy to the competent authority within 60 days of the first date of processing. This dossier only needs to be prepared once for the entire operating period, but must be updated every 6 months when changes occur. It must also be updated immediately in the event of major changes to the purpose, method or technology of processing under Article 22 of the Law.
When transferring personal data abroad, including to foreign software providers or cloud storage platforms, enterprises must prepare a cross-border data transfer impact assessment dossier in the form prescribed by the Government. They must also notify the Department of Cybersecurity and Hi-tech Crime Prevention (A05), Ministry of Public Security. The competent authority issues its assessment result within 15 days, Procedures for Notification of Personal Data Protection Violations.
Legal basis: Articles 21 and 22 of the Law on Personal Data Protection 2025; Clause 1, Article 19 of Decree No. 356/2025/ND-CP.
When a violation of personal data protection rules is detected, the data controller or controller-processor must notify the Ministry of Public Security (Department A05). This must occur no later than 72 hours after the violation occurs or is discovered. For incidents involving location data or biometric data, the enterprise must also notify affected data subjects directly within 72 hours, or publish the notice through electronic media if individual notification is not feasible in time.
The incident record must cover the type of data affected, scope, risk level, cause and remedial measures. It must be retained for at least 5 years from the date the incident is resolved, to support inspection and audit. Specific notification procedures are guided on the Ministry of Public Security’s public service portal.
Legal basis: Decree No. 356/2025/ND-CP.
Before a fine is imposed, you may share your business sector, the types of data collected, and your current compliance documentation. Adding your desired consultation timeline lets Long Phan Consulting provide a preliminary risk assessment.

Article 7 of the Law on Personal Data Protection 2025 lists acts that are strictly prohibited, forming boundaries enterprises should check against periodically:
In consulting practice, the fourth act, unlawful processing, is the most common risk for ordinary enterprises. It typically arises not from intent but from the absence of a valid consent procedure or adequate technical security measures, leading to unintended data leaks.
Legal basis: Article 7 of the Law on Personal Data Protection 2025.
>>>See more: List of Sensitive Personal Data Effective from January 1, 2026
This is the section that brings most personal data processing enterprises to this article. Article 8 of the Law on Personal Data Protection 2025 divides fines into three brackets, with a ceiling of VND 3 billion or a percentage of revenue.
| Bracket | Violation | Maximum Fine |
| Clause 3, Article 8 | Buying or selling personal data | 10 times the illicit proceeds; if the proceeds cannot be determined or the calculated amount is below VND 3 billion, a fine of VND 3 billion applies |
| Clause 4, Article 8 | Violating cross-border personal data transfer rules | 5% of the preceding year’s revenue; if there is no revenue or the calculated amount is below Clause 5, the Clause 5 level applies |
| Clause 5, Article 8 | Other violations | VND 3 billion |
The maximum fine is 10 times the proceeds obtained from the violation. If the proceeds cannot be determined, or the calculated amount is below VND 3 billion, the enforcement authority applies the maximum level of VND 3 billion.
Legal basis: Clause 3, Article 8 of the Law on Personal Data Protection 2025.
The maximum fine is 5% of the violating organization’s revenue for the preceding year. If the organization has no revenue for that year, or the calculated fine is lower than the maximum under Clause 5, Article 8, the enforcement authority applies the Clause 5 level instead.
Legal basis: Clause 4, Article 8 of the Law on Personal Data Protection 2025.
Remaining violations in the field of personal data protection, such as late preparation of the impact assessment dossier, late incident notification or an invalid consent mechanism, carry a maximum fine of VND 3 billion.
Legal basis: Clause 5, Article 8 of the Law on Personal Data Protection 2025.
The maximum fines under Clauses 3, 4 and 5, Article 8 apply to violating organizations. An individual committing the same violation is subject to a maximum fine equal to one-half of the level applicable to organizations. The Government prescribes the method for calculating illicit proceeds used as a basis for enforcement.
Legal basis: Clauses 6 and 7, Article 8 of the Law on Personal Data Protection 2025.
Through supporting personal data processing enterprises with compliance reviews, several recurring gaps appear across industries.
First, an enterprise may have a privacy policy published on its website that does not match its actual data collection practices. A common gap is omitting phone numbers collected through a chatbot or location data gathered via a mobile app.
Second, the consent mechanism is set up in an invalid form, such as a pre-ticked default checkbox or ambiguous wording that fails to let users clearly distinguish between consenting and not consenting.
Third, many enterprises have already been processing data but have never prepared a personal data processing impact assessment dossier. This creates a risk of breach even when the underlying processing activity itself is unremarkable.
Fourth, enterprises transfer customer data to third parties or foreign software providers, such as email marketing services, CRM platforms or cloud storage services. They often fail to recognize this as a cross-border data transfer requiring a separate dossier and procedure.
When an enterprise encounters any of these four situations, it is a signal to conduct a legal review immediately, because the risk lies not in intent to violate but in gaps in the compliance process.
To reduce risk, personal data processing enterprises should implement a compliance review following these steps:

Long Phan Consulting provides consulting, review, and support services to help businesses establish legal compliance systems when collecting, storing, using, sharing, and transferring personal data, including:
Clients may send their case documents via email info@longphanpmt.com or Zalo 0906.735.386 for a preliminary assessment.
During the collection, processing, and storage of personal data, businesses often face questions concerning customer consent, data deletion rights, impact assessments, incident handling, and cross-border data transfers. Below are some frequently asked questions to note:
No. Clause 1, Article 19 of the Law on Personal Data Protection 2025 provides for five exceptions where personal data may be processed without consent, such as protecting life or health in urgent situations or serving state management activities. Outside these cases, businesses must obtain valid consent and retain evidence of such consent.
Yes. Clause 1, Article 4 of the Law on Personal Data Protection 2025 recognizes the right to request deletion of personal data as one of the fundamental rights of data subjects. Under Article 5 of Decree No. 356/2025/ND-CP, businesses must respond within two working days and complete the deletion within 20 days, or 30 days if a data processor or third party is involved.
Under Clause 1, Article 21 of the Law on Personal Data Protection 2025, a business must prepare, retain, and submit one original copy of the personal data processing impact assessment dossier to the competent specialized authority within 60 days from the date of first processing personal data. The dossier only needs to be prepared once and must be updated when changes occur under Article 22.
The business must notify the Department of Cybersecurity and High-Tech Crime Prevention (A05) under the Ministry of Public Security no later than 72 hours after the violation occurs or is detected, pursuant to Decree No. 356/2025/ND-CP. Records relating to the violation must be retained for at least five years.
Under Clause 3, Article 8 of the Law on Personal Data Protection 2025, the maximum fine is 10 times the proceeds obtained from the violation. If the proceeds cannot be determined or the calculated amount is lower than VND 3 billion, the maximum fine of VND 3 billion applies.
Yes. Storing or sharing data through platforms or servers located overseas constitutes a cross-border personal data transfer under Article 22 of the Law on Personal Data Protection 2025. Businesses must prepare a separate impact assessment dossier and notify the Ministry of Public Security before carrying out the transfer.
Under Clause 6, Article 8 of the Law on Personal Data Protection 2025, an individual committing the same violation is subject to a maximum fine equal to one-half of the maximum fine applicable to an organization.
Businesses processing personal data should simultaneously review four key groups of obligations: obtaining valid consent, preparing impact assessment dossiers within the prescribed timeframe, establishing procedures for responding to data subject requests, and establishing procedures for notifying incidents within 72 hours. Fines of up to VND 3 billion or 5% of revenue represent a real financial risk rather than merely a formal compliance requirement. Long Phan Consulting is ready to assist businesses in conducting a comprehensive review of their compliance documentation. Clients may contact the hotline at 1900636389 for advice tailored to their specific circumstances.
📚 This article is professionally reviewed based on the following legal documents:









Note: The content of the articles published on the website of Long Phan Investment Consulting Company is for reference only regarding the application of legal policies. Depending on the time, subject, and amendments, supplements, and replacements of legal policies and legal documents, the consulting content may no longer be appropriate for the situation you are facing or need legal advice on. In case you need specific and in-depth advice according to each case or incident, please contact us through the methods below. With our enthusiasm and dedication, we believe that Long Phan will be a reliable solution provider for our clients.
Leave your email to receive the latest information from us
CONTACT: 1900.63.63.89
Copyright 2024 © Long Phan Consulting Company. All rights reserved.