The Law on Personal Data Protection 2025 and Decree 356/2025/ND-CP have created a clearer legal basis for the use of external organizations to provide personal data protection services. For businesses that do not have enough resources to build a dedicated apparatus, outsourcing DPO (Data Protection Officer) can be a quick way to add legal, technological and data governance capacity. Therefore, outsourced DPO is becoming the choice of many businesses when personal data protection is no longer just a compliance requirement but has become a content of corporate governance. However, the popularity of this model also leads to a fairly common misconception: hiring a DPO means that the business has solved the problem of data protection.
As personal data protection gradually becomes a requirement of corporate governance, the question is no longer whether businesses need a Data Protection Officer (DPO) or not. What businesses are interested in now is how to organize this function: building an internal DPO, outsourcing or a combination of both.
It is worth noting that Decree 333/2026/ND-CP ("Decree 333") was officially issued on August 19, 2026, not only in the addition of cybersecurity obligations. More importantly, many requirements have been concretized in a way that directly impacts systems, processes and how businesses operate digital services.
This difference is especially obvious when businesses outsource personal data protection (DPO). The question is not really whether the outsourced DPO is a personal data processor or not, but whether the business is correctly determining the role of the DPO in each data processing activity. This is also the starting point of many confusions in practice and the reason why many businesses are designing the whole data management system on a legal premise that is not really accurate.
There is a quite special feature of the aviation industry that many businesses in other fields do not encounter. Each flight transports not only passengers, but also "transports" a huge amount of personal data across borders. From the moment a passenger searches for a flight on the website, makes a booking, makes a payment, checks in online, uses facial recognition to board the plane, connects to in-flight Wi-Fi, earns reward points, requests special meals or provides medical assistance, almost the entire journey is recorded as data.
The announcement on its website by Nova Group Joint Stock Company (NovaGroup) on the list of individuals who are "not re-employed" has quickly become a topic of public interest . Notably, the published list is not the entire identifying information of individuals. Part of the citizen ID number and phone number have been concealed. This gives rise to a fairly common argument that the data has been "anonymized" or "de-identified", and therefore no longer falls under the scope of personal data protection legislation.
Artificial intelligence is turning data into a business's most important asset. The more data you can exploit, the more advantages businesses have in developing products, optimizing operations, and creating new business models. However, this process also puts businesses under increasing compliance pressure as regulations on personal data protection are continuously improved in Vietnam and around the world.
In 2018, the world's hospitality industry witnessed one of the largest data breaches in history when Marriott International announced that Starwood Hotels' booking system had been illegally accessed for a long time before it was discovered . According to published information, the data of hundreds of millions of customers globally has been affected. Not only does it include names, email addresses or phone numbers, but many of the compromised information also involves passports, stay histories, and other data that can reproduce almost the entire customer's travel journey over many years.
When booking a hotel room, most customers only think that they are providing a few basic information to complete the transaction. However, from the time of searching for a room on the online platform, making a reservation, check-in, using the service to check-out, a large amount of personal data has been collected, stored, analyzed and processed by the accommodation business.
For many years, electronic identification has often been seen as a tool to support the settlement of administrative procedures in the digital environment. For the majority of people, electronic identification is associated with the VNeID application, electronic driver's license or the implementation of online public services without presenting paper documents. However, the contents proposed by the Ministry of Public Security in the dossier for the development of the Law on Electronic Identification and Authentication show that the scope and ambition of this policy are much larger.
Just over a year after Decree 94/2025/ND-CP on the sandbox testing mechanism in the banking sector was issued, the State Bank of Vietnam (SBV) has proposed to amend a series of regulations related to participation conditions, dossier composition and procedure processing process for fintech enterprises .
In Vietnam, this situation exists in many fields. National databases, specialized databases and data held by enterprises are formed more and more, but most of them still operate relatively independently. Meanwhile, technology enterprises, research organizations and artificial intelligence developers have the need to access big data sources to build new products and services but lack a transparent and legal transaction mechanism.