The rapid development of technology and the cyber environment has made the protection of personal data (PD) an urgent requirement in Vietnam. The draft Law on Personal Data Protection (the "Draft") has been drafted by the Ministry of Public Security to be submitted to the National Assembly for comments and may be approved as soon as this year. The Law on Protection of Personal Data is expected to create a comprehensive legal framework to protect the privacy of individuals, while meeting international standards to which Vietnam is a member. However, some opinions say that this draft is setting too many administrative procedures, creating a burden on businesses, especially small and medium enterprises (SMEs) as well as start-ups, and going against the goals of administrative reform as well as promoting the digital economy set by the Government.

What's in the latest draft?
The latest draft[1] consists of 7 chapters with 68 articles, emphasizing the role of stakeholders, including: (1) Data subjects: Individuals who own the data, have the right to consent, access, correct, delete data, and claim damages. (2) Data control party: Organizations and individuals decide on the purpose and means of data processing. (3) Data Processor: An organization or individual that processes data on behalf of the Controller. (4) Third parties and other specialized organizations, such as the Agency in charge of personal data protection under the Ministry of Public Security.
However, to ensure compliance, the Draft provides many administrative procedures that enterprises must carry out, from making impact assessment documents, notifying violations, to appointing organizations/experts to protect personal data. These requirements are causing debate about the level of burden of administrative procedures on businesses when this Draft is passed.
Main administrative procedures in the Draft
The draft Law on Personal Data Protection sets out a series of administrative procedures that businesses must comply with, especially those operating in the fields of technology, finance, healthcare, and communications.
Assessment of the impact of processing personal data (Article 45 of the Draft)
Enterprises must prepare and keep a dossier of assessment of the impact of data processing right from the start of data processing. This dossier needs to be sent to the Agency in charge of data protection within 60 working days and updated periodically every 6 months or when there are major changes (such as dissolution or merger). The dossier must be established in writing that is legally valid and always available for inspection. The Personal Data Processor must also make a similar dossier if it handles on behalf of the Controller.
Assessment of the impact of data transfer abroad (Article 46 of the Draft)
For businesses that transfer personal data of Vietnamese citizens abroad, they must prepare their own Impact Assessment Dossier, send it to the management agency within 60 days from the date of data processing, and notify the details after the data transfer is successful. This profile also needs to be updated periodically or when there are changes. The specialized agency has the right to conduct annual or irregular inspections if violations are detected.
Notification of personal data protection violations (Article 37 of the Draft)
When detecting a violation of regulations on personal data protection, the enterprise must notify the specialized agency within 72 hours, enclosed with a record of confirmation and description of remedial measures. If the notice is late, the enterprise must explain the reason for the delay. This requires businesses to have an effective monitoring and reporting system in the process of business activities.
Appointment of Personal Data Protection Organizations and Experts (Articles 39, 40, 49 of the Draft)
Enterprises must appoint an Organization or Personal Data Protection Expert, meet the conditions of technological and legal capacity, certified by approved organizations. This certification process is complex, requiring personnel with a university degree and completion of a professional course. SMEs and startups are exempt from this requirement for the first 5 years, unless these subjects are direct business units that handle personal data.
Credit rating and business certification (Articles 43 and 44 of the Draft)
Enterprises providing data protection or handling services must reach the minimum credit level and be granted a certificate of eligibility for business. The conditions include a minimum legal capital of VND 5 billion, a minimum of 3 professional personnel, and 2 personal data protection experts.

The National Assembly hears the proposal and the verification report on the Draft Law on Personal Data Protection. Source: National Assembly
Is it still appropriate to order more administrative procedures?
Recently, on May 4, 2025, the Politburo issued Resolution No. 68 on private economic development with the goal of reducing "at least 30% of legal compliance costs, at least 30% of business conditions[2]". Previously, in Resolution No. 66 dated March 26, 2025, the Government requested ministers, heads of ministerial-level agencies, and presidents of People's Committees of provinces and centrally-run cities to focus on reviewing, reducing and simplifying administrative procedures related to production activities, business and internal administrative procedures, ensuring the abolition of at least 30% of business investment conditions, reducing at least 30% of the settlement time of administrative procedures, and 30% of the cost of compliance with administrative procedures[3].
These orientations show that Vietnam is striving to create a favorable business environment, reduce administrative barriers, and promote innovation. However, the administrative procedures in the Draft Law on Protection of Personal Data may create significant challenges to these goals of the Government as well as create additional burdens on businesses
The administrative procedures in the draft can create a significant burden for businesses, especially SMEs and startups, for the following reasons:
Firstly, the number, complexity of the administrative procedures and the cost of compliance. Impact assessment filings, breach notifications, and periodic updates require businesses to invest time and resources in preparing legal documents, implementing monitoring systems, and ensuring compliance with tight deadlines. With these new regulations and the not really good compliance habits of Vietnamese businesses, this is a significant challenge. In addition, the appointment of data protection organizations/experts, the application of technical measures such as data encryption, and employee training increase the operating and compliance costs of businesses in the process of operation and business. According to estimates as well as service delivery practices, we find that small businesses may have to spend hundreds of millions of VND per year to comply with these regulations. Not to mention that businesses take a long time to keep records, prepare for periodic and irregular inspection and inspection activities of the management agency.
Second, barriers to market entry. Requiring credit ratings and business certifications with conditions such as legal capital of VND 5 billion or highly specialized personnel may limit the ability of technology startups or small and medium-sized domestic enterprises to enter the market. With the requirements to support new businesses, as well as small and medium-sized enterprises, these regulations cause more difficulties for businesses that want to join the data business "track" in Vietnam.
Fourth, pressure on SMEs and startups. Although SMEs and startups are exempt from some requirements in the first 5 years, businesses directly dealing with data processing such as mobile applications and social networks are not eligible for this incentives, making it difficult for newly established technology companies.
Necessary adjustments and supplements to the Draft
In order to balance the protection of personal data and the creation of a favorable business environment, in this Draft, the National Assembly as well as management agencies need to consider the following solutions:
Simplify the procedure. The draft needs to consider adjusting to reduce the frequency of updating impact assessment dossiers from 6 months to 1 year and possibly extend the deadline for submitting impact assessment dossiers or transferring personal data from 60 days to 90 or 120 days.
Support SMEs and startups. Extend exemptions to businesses directly dealing with personal data processing in the first 2-3 years, and provide technical and financial support so that these businesses can comply and pioneer good compliance with personal data protection activities at enterprises and in business activities.
Digitize the management of personal data protection activities. Regulatory and responsible agencies should consider developing the National Portal on Personal Data Protection into a digital platform, allowing online submission of documents and receiving feedback not only through the Portal but also through the mobile application to meet the compliance and short compliance time of the Draft.
In addition, we believe that training and guidance on compliance with the law on personal data protection are very important in the early stages of implementing the Law on Personal Data Protection. The Government, as the agency that manages and enforces regulations on personal data protection, can organize free training programs and provide forms on its own or through agencies such as the Ministry of Public Security, the Ministry of Justice, the Ministry of Science and Technology, documents as well as guidelines for preparing standard documents to help businesses comply more easily with these somewhat new and unfamiliar regulations.
We believe that, with these new adjustments and supplements, the Draft Law on Protection of DLCP can both protect the privacy of individuals and support businesses to develop in the digital era, contributing to the implementation of Vietnam's ambitious socio-economic development goals that the Party and the State have set in recent years.
Lawyer Nguyen Van Phuc
HM&P Law Firm
[1] The second draft, published on 28/03/2025, is available at: https://duthaoonline.quochoi.vn/dt/luat-bao-ve-du-lieu-ca-nhan/250328101343391295, accessed 05/07/2025
