Contents to be carefully considered before passing the Draft Law on Personal Data Protection

Insights
Contents to be carefully considered before passing the Draft Law on Personal Data Protection
Posted on: 30/05/2025

    Digital transformation is advancing rapidly in Vietnam, protecting personal data has become a top priority in many countries, including Vietnam. Decree 13/2023/ND-CP on Personal Data Protection has laid the foundation for the legal framework for data protection, and the Draft Law on Personal Data Protection (the "Draft"), [1]which was submitted to the National Assembly at its 9th session (May 2025) and is expected to be adopted at this session,  is expected to complete one of Vietnam's most important laws in personal data protection. With 68 provisions ranging from general regulations to the responsibilities of stakeholders, the Draft represents an effort to build a comprehensive legal framework. However, some contents in the draft are still unclear, difficult to implement, or not in line with the economic, social and legal practices of Vietnam.

     

     

    Contents to be carefully considered in the Draft

    1. Regulations on Personal Data Protection Experts (Article 39 of the Draft)

    Article 39 requires all organizations, businesses and individuals to have at least one (01) Personal Data Protection Expert (DPO) suitable for the business line, except for small businesses and start-ups in the first 5 years (except for cases of direct business processing of personal data). DPOs are divided into three categories: technologically competent and legal, or technological, or legal.

    Issues to consider:

    • Lack of specific standards: Article 39 does not specify professional standards (certificates, experience, or educational qualifications) for DPOs, leading to the risk that organizations appointing DPOs are not qualified, reducing the effectiveness of compliance monitoring.
    • Burden on SMEs: With more than 97% of Vietnamese enterprises being small and medium enterprises (SMEs) (according to the General Statistics Office, 2024), [2]the requirement to appoint a DPO creates great financial pressure, especially in the context that Vietnam does not have specific regulations on standards, training and certification for DPOs. The cost of recruiting or training DPOs is estimated at 50-100 million VND/year, exceeding the ability of many SMEs, especially in rural areas.
    • Lack of human resources: Vietnam's labor market currently lacks data protection experts. According to a recent statistic, Vietnam still lacks about 700,000 trained cybersecurity experts, not to mention that the number of data protection experts is much lower, even not officially recognized as cybersecurity experts. Experienced countries that have enforced personal data protection laws, the majority (about 80%) DPOs are experts from the legal field. Therefore, asking hundreds of thousands, even millions of organizations and businesses in Vietnam to appoint DPOs in a short time is not feasible and causes great waste. Not to mention that when forced, businesses and organizations will find ways to deal without implementing substantive compliance to protect the personal data of employees, users, customers and more broadly of the people.
    • Comparison with GDPR[3]: GDPR only requires the appointment of a DPO in a few specific cases, namely, (1) Public authorities (except courts when performing judicial functions); (2) Organize regular, systematic and large-scale supervision; (3) Organizations that process sensitive data (health, criminal records) or large-scale criminal data. This allows organizations and SMEs to reduce the financial and human burden in the process of complying with regulations. Compared to the GDPR regulations, the provisions in the Draft DPO are too strict, and somewhat inappropriate for the context and of Vietnam's fledgling and developing economy. The GDPR also ensures the independence of the DPO, while Article 39 of the Draft does not mention this issue, making the DPO subject to pressure from business leaders in the process of fulfilling their responsibilities in accordance with the law. In addition, we see that the Draft Regulation on DPOs only targets the private sector, but has not been significantly broadly considered, public sector organizations must also comply with these personal data protection regulations in a stricter way than the private sector. The role of the management agency is not only to monitor and control the private sector but also to create fairness for both areas.

    Propose:

    • Simplify DPO requirements, which are only required for organizations that handle sensitive or large-scale data.
    • Clearly stipulate professional standards and allow outsourcing of DPOs.
    • Compliance regulations for DPOs are not only for the private sector but also for public sectors, where a lot of citizens' data is processed, must also comply with these regulations.
    • Ensure the independence of the DPO through regulations that report directly to the top level and prohibit dismissal for performing duties.

    2. Assessment of the impact of processing personal data (Article 45, Draft)

    Article 45 requires the Personal Data Controller and the Personal Data Controller and Processor to prepare a Data Protection Impact Assessment (DPIA) from the start of the data processing, send the original copy to the Specialized Agency for Personal Data Protection within 60 days,  and periodically update every 6 months when there are changes.

    Issues to consider:

    • DPIA requirements are too broad: Requiring every organization to implement DPIA, regardless of the size or level of data processing, creates an unnecessary administrative burden for SMEs and non-profit organizations. Meanwhile, the GDPR only requires DPIA when processing data that poses a high risk to the rights of the data subject (Article 35 GDPR).
    • Time pressure: The requirement to submit a DPIA in 60 days and update every 6 months is too harsh, especially for organizations that lack specialized personnel or data management tools.
    • Capacity of management agencies: The agency in charge of personal data protection (Ministry of Public Security, A05) has to process hundreds of thousands, even millions of DPIA records from organizations and businesses across the country, while it is unclear that the personnel capacity and infrastructure of this agency is a significant pressure.  whether in a short time the specialized agency will be able to shoulder this responsibility. This is a very important question for the National Assembly to consider carefully before pressing the button to approve this Draft.

    Propose:

    • DPIA is only required for high-risk data processing activities, similar to those specified in the GDPR.
    • Provide a DPIA form and detailed instructions on the National Portal for Personal Data Protection (Article 52).
    • Extend the DPIA submission period (e.g., 120 days) and reduce the frequency of updates (e.g., every 1 year) for SMEs after the exemption period for compliance with personal data protection of these entities.

     

    Representatives of the Drafting Agency and the Appraising Agency listening during the discussion session on the Draft Law on Personal Data Protection. Source: National Assembly.

     

    3. Transfer of Personal Data Abroad (Article 46)

    Article 46 stipulates the transfer of personal data of Vietnamese citizens abroad, requires the preparation of a dossier of impact assessment of data transfer abroad, sending the original within 60 days, and subject to annual inspection by the specialized agency. This agency has the right to stop transferring data if it finds that it violates the national interest.

    Issues to consider:

    • The scope is too broad: Article 46 applies to all activities of transferring data abroad, including the use of international cloud platforms (such as AWS, Google Cloud, Microsoft 365), which are common among Vietnamese technology enterprises as well as ordinary enterprises. This may limit the competitiveness of digital enterprises,  especially in the field of fintech and e-commerce.
    • Lack of clear criteria: Regulations on stopping data transfer when "violating national interests" do not clearly state the criteria, creating the risk of arbitrary application and lack of transparency. We propose codifying these criteria directly in the law, rather than deferring them to subordinate legislation. As these are prohibitive and critical provisions, their inclusion in the law is essential to ensure consistency in future implementation.
    • Comparison with GDPR: The GDPR from Articles 44 to 50[4] regulates the transfer of data outside the EU based on clear mechanisms from (i) the Appropriate Decision, (ii) Standard Contractual Clauses, (iii) Binding Corporate Rules, with detailed guidance from the European Data Protection Board (EDPB). Article 46 of the Draft lacks similar mechanisms causing difficulties for international businesses operating in Vietnam.

    Propose:

    • Develop clear, specific data transfer mechanisms that align with Vietnam’s context and facilitate the lawful business operations of enterprises and multinational corporations operating in the country.
    • Clarify the criteria of "violating national interests" in the Draft to ensure transparency.
    • Exemption from the impact assessment requirement for small-scale data transfer operations or the use of international cloud platforms that other countries have exempted from compliance for these organizations.

    4. Measures to protect Sensitive Personal Data (Article 50)

    Article 50 requires the application of measures to protect sensitive personal data, encourage the use of industry-appropriate standards, notify data subjects, and assess the trust of personal data protection.

    Issues to consider:

    • Lack of specific categories: Although Article 12 assigns the Government to regulate the category of sensitive personal data, the Draft does not provide a definition to have the bases and criteria to be able to identify this type of data that may cause erratic and unpredictable changes for the business organization in the compliance process. We agree with the stipulation that it is up to the Government to regulate this list. However, the National Assembly, in its role, needs to have certain limits on these almost "paramount" definitions in order to help businesses and organizations not have to be too costly and struggle to comply with the constantly changing regulations from the guiding documents.
    • Optional incentives: "Incending" the adoption of protection standards instead of mandatory can lead to inconsistencies in enforcement, especially in sensitive industries such as healthcare, finance, and banking.
    • Burden of credit rating: The credit rating requirement (Article 43) related to sensitive data requires the organization to cooperate with the Credit Rating Agency, but this cost and process has not been clarified, which may create additional barriers for SMEs, as well as businesses as a whole,  organizations in Vietnam have to spend a lot of money and effort on this credit rating assessment.
    • Comparison with GDPR: Article 9 of the GDPR clearly defines sensitive data (health, biometrics, religion, etc.) and applies strict protection measures, accompanied by guidance from the EDPB. Article 50 of the Draft lacks this detail, reducing the effectiveness of protection for sensitive data.

    Recommended:

    • The Draft needs to have criteria and definitions to position the most important list in the Draft, which is basic data and sensitive data.
    • Mandatory standards of protection for sensitive data in the healthcare, financial, and technology industries.
    • Reduce credit rating costs for SMEs through financial support or simplify the process for the type and size of this type of business.

    The draft Law on Personal Data Protection is an important step forward in building a legal framework for data protection in Vietnam. However, the provisions in Articles 39, 45, 46, and 50 need to be carefully reviewed to ensure feasibility and suitability in the context of Vietnam. Issues such as the lack of specific standards, administrative burdens, and resource constraints require flexible adjustments, learning from the GDPR, and strong support from the State. Only by overcoming these challenges can the Draft protect the interests of data subjects and promote digital innovation, enhance Vietnam's position and create favorable conditions for businesses and organizations to operate and develop in the global economy.


    [1] Available at: https://duthaoonline.quochoi.vn/dt/luat-bao-ve-du-lieu-ca-nhan/250328101343391295, accessed on 27/05/2025

    [2] https://www.quanlynhanuoc.vn/2025/02/25/nhu-cau-duoc-ho-tro-tai-chinh-cua-doanh-nghiep-nho-va-vua-viet-nam/#:~:text=l%E1%BA%ADp%20m%E1%BB%9Bi10.-,Theo%20s%E1%BB%91%20li%E1%BB%87u%20%C4%91i%E1%BB%81u%20tra%20c%E1%BB%A7a%20T%E1%BB%95ng%20c%E1%BB%A5c%20Th%E1%BB%91ng%20k%C3%AA,t%E1%BB%B7%20l%E1%BB%87%2097%2C2%25., accessed on 2025/05/27

    [3] GDPR stands for General Data Protection Regulation. It is a legal regulation that has been in effect throughout the European Union (EU) and the European Economic Area (EEA) since May 25, 2018. This regulation is designed to protect the personal data of EU citizens and empower them to control this data.

    [4] https://gdpr-info.eu/chapter-5/, accessed on 29/05/2025