In the context of the Law on Personal Data Protection 2025, which has formally established the legal framework for the appointment and operation of Data Protection Officers (DPOs), practical implementation in Vietnam continues to raise a number of complex issues. These include the DPO’s right to cease performing assigned duties, the choice between an internal and outsourced DPO model, questions of legal liability, and mechanisms to ensure functional independence. The Q&A section below addresses common challenges arising during the appointment process and provides structured legal and governance perspectives on managing the DPO role in Vietnam.
1. Can an employee who is an internal DPO of the company have the right to request that the DPO's duties be stopped?
HM&P:
In our opinion, the internal DPO's request to stop performing the DPO's duties can be considered as an employee requesting a change of job in the labor contract or termination of the labor contract, depending on the part-time or full-time nature of the DPO position.
In case the DPO is a person who concurrently holds other jobs in the company, the request to stop performing the DPO's duties may mean changing the content of the work in the labor contract (not continuing to perform the jobs of the DPO position), in that case, whether or not to agree to change depends on the company's decision. In case of agreement, the employee and the company can enter into an appendix to the labor contract to adjust the corresponding scope of work.
In case the DPO is a full-time employee, the request to stop performing the DPO's duties can be considered as a request to unilaterally terminate the labor contract by the employee. At that time, in order to comply with the law, the employee must comply with the obligation to notify in advance according to the provisions of the Labor Code, corresponding to the type of contract signed. From a practical perspective, when considering whether the DPO's request to stop performing the duties of the DPO, the company needs to carefully review the regulations on job positions and the scope of work in the labor contract to ensure that the employee can only sign a contract to be in charge of the DPO's work. In addition, the company should require the employee to have a formal notice of termination of the labor contract, instead of just requesting to stop performing the duties of the DPO, which can help the company have a clear basis for future legal procedures.

Practical implementation in Vietnam continues to raise a number of complex issues.
2. Should the company appoint a DPO in-house or outsource?
HM&P:
The choice between appointing an in-house DPO or outsourcing completely depends on the situation and conditions of each company. Based on the nature of the DPO's work as well as practical experience, we provide a table of criteria to distinguish between these two forms as well as the comparison table below for the company's reference purposes:
Criteria for distinguishing between in-house DPO and outsourced DPO
|
Criteria |
Internal DPO[1] |
DPO outsourcing[2] |
|---|---|---|
|
Forms of indication |
Designated by the company's appointment/designation decision |
Hire under a service contract |
|
Legal Location |
Personnel or departments of the company's internal structure |
Independent third party (individual or organization) |
|
Company Relations |
Labor Relations/Internal Management |
Civil and commercial relations under contracts |
|
Work experience in related fields |
Minimum 02 years of experience |
Minimum 03 years of experience |
|
Requirements for professional training |
Have been trained and fostered legal knowledge and professional skills in personal data protection |
Have been trained and fostered in depth of legal knowledge and professional skills on personal data protection |
|
Scope of duties |
Fully perform tasks in accordance with the law |
Comply with the scope agreed in the contract |
|
Security mechanism |
Mandatory signing of a confidentiality liability agreement with the company |
Security is established through service contracts and data processing agreements |
|
Disclaimer |
It is possible to agree to waive liability in the event of a breach/damage |
Responsibilities and limitations of liability specified in service contracts |
|
Obligations after the end of work |
No specific regulations, depending on labor relations and internal agreements |
Compulsory deletion and destruction of personal data after completion of the contract |
|
DPO Information Disclosure |
No specific regulations |
Mandatory disclosure of personal information/service providers for personal data subjects and related parties |
Comparison Table Between In-house DPO and Outsourced DPO
|
|
Internal DPO |
DPO outsourcing |
|---|---|---|
|
Pros |
|
|
|
Drawbacks |
|
|
|
Recommendations if selected |
|
|
Based on practical experience, we believe that companies should use internal DPO in cases where personal data processing activities take place frequently, are closely tied to daily operations and have a high level of complexity, especially for medium and large-sized companies, corporations or companies in fields that use/process a lot of personal data. This model is suitable when the company has available human resources that meet the capacity conditions and has the need to directly control the personal data protection function.
In contrast, outsourced DPO is suitable when the company does not have sufficient internal resources or when personal data processing is limited in scale, temporary, or not the focus of the business. This model is especially suitable for small and medium-sized enterprises, start-ups, or businesses that need to quickly meet legal compliance requirements without having to make long-term investments in human resources. At the same time, outsourcing also helps increase objectivity, reduce the risk of conflicts of interest and take advantage of the in-depth and multidisciplinary experience of individuals and organizations providing personal data protection services.
In addition, another option that many companies are currently applying is to appoint an internal DPO, but use additional legal and technical consulting services from individuals and organizations providing personal data protection services. This option will take advantage of the strengths of the internal DPO while ensuring the necessary advice from external professional units.
3. If the DPO is not appointed, will the company be subject to any sanctions?
HM&P:
Currently, the Law on PDP and related legal documents do not have specific provisions on sanctioning administrative violations for the act of not appointing a DPO for the company. However, as is known, the DPO acts as a consultant, implementing measures to protect personal data and administrative procedures on personal data in the company's operations. The absence of a DPO can lead to shortcomings and violations of regulations on personal data protection.
Article 8 of the Law on PDP has stipulated the sanctioning levels as well as the principles of sanctioning administrative violations in the field of personal data protection, which can be mentioned as:
- A fine for acts of buying and selling personal data (in sanctioning administrative violations) is up to 10 times the revenue obtained from the violation; in case there is no revenue from the violation or the fine level calculated according to the revenue obtained from the violation is lower than VND 03 billion, the fine level of VND 03 billion shall be applied.
- A fine shall be imposed on a company that violates regulations on cross-border transfer of personal data (in sanctioning administrative violations) up to 5% of its revenue of the preceding year; in case there is no revenue of the preceding year or the fine calculated according to the turnover is lower than VND 3 billion, the fine level of VND 03 billion shall be applied.
- Except for the above 02 cases, other violations in the field of personal data protection will be administratively sanctioned with a maximum fine of VND 3 billion.
In addition to sanctioning administrative violations, depending on the nature, severity and consequences of violations, the company may also be administratively sanctioned or examined for penal liability; if causing damage, they must pay compensation according to the provisions of law.
ENFORCEMENT AND ACCOUNTABILITY
4. How do DPOs ensure they have access to the DLCN to perform their work?
HM&P:
To ensure that the DPO can properly and fully perform its functions, the company needs to approach this issue as a compliance organizational obligation, not merely as a technical permission to access.
Firstly, the company must establish an internal legal basis for the DPO's access to personal data. This right should be clearly documented in the decision to appoint the DPO, the personal data protection regulations or the relevant internal decentralization regulations. The recognition is not only to empower nominally, but also to establish a legal basis for DPOs to have access to personal data, records of personal data processing, reports on impact assessment of personal data processing, cross-border transfer of personal data, system logs and other relevant documents to the extent necessary to perform their duties in accordance with the law.
Secondly, the access rights of the DPO need to be realized by a specific decentralization mechanism on the technical system. The company should grant the DPO an independent access account, clearly define the scope of authority (priority reading, report viewing, or conditional access), and ensure that all access activities are recorded and recorded. This method not only ensures that the DPO has access to the necessary information, but also helps the company control risks and prove the legality of accessing personal data when requested by the competent authority.
Third, the company should establish an internal coordination process so that the DPO can request and receive information from relevant departments. In fact, not all personal data is directly accessed through the system, so it is necessary to clearly define the responsibilities of departments in providing information, documents, and reports to the DPO when serving the inspection, assessment and handling of personal data protection incidents. This process helps to avoid the situation where the DPO's authority is hindered or dependent on the will of other departments. In particular, it is necessary to ensure that the DPO's access to personal data is not dependent on the direct management or the department being supervised. In terms of governance, the DPO should have the right to report directly to the legal representative, the Board of Directors, or the Executive Board, and have access to the data without approval from the relevant business departments. This helps to maintain the relative independence of the DPO, in line with the spirit of compliance supervision of the Law on PDP.
Fourth, the company needs to periodically review and update the access rights of the DPO. When the scope of operation, information technology system or data processing model changes, the DPO's access rights also need to be adjusted accordingly. This periodic review helps to ensure that the DPO always has enough tools to perform its tasks, while avoiding formal, outdated or no longer suitable for operational realities.
In short, securing access to personal data for DPOs is not just a technical issue, but a component part of the company's personal data protection compliance system. The company needs to design a clear, controlled, and demonstrable empowerment mechanism, thereby enabling the DPO to perform its supervisory function while limiting legal risks for the company itself.

The company needs to design a clear, controlled, and demonstrable empowerment mechanism.
5. Does the DPO have to disclose their personal information to perform their work?
HM&P:
From the perspective of the Law on PDP and Decree No. 356, the issue of whether a DPO must disclose its personal information or not needs to be recognized on the basis of the principle of personal data protection applicable to all personal data subjects, including the DPO itself.
Current law does not impose an obligation on DPOs to publicly disclose personal information. The Law on DPO provides for the appointment of DPOs to ensure that there is a focal point responsible for compliance, receipt and processing of requests related to personal data. However, this regulation does not mean that DPOs are forced to disclose all their personal information to the public or to the subject of personal data. The DPO, in essence, is still a personal data subject and is fully entitled to the rights to personal data protection according to the law.
In addition, the current law also does not specify the information of the DPO that the company must disclose to the subject of the personal data or the competent authority. When considering the IP protection infringement notification forms, it can be seen that the DPO information that needs to be provided only includes full name, title, phone number, and email without any additional personal information.
In summary, according to the Law on PDP and Decree 356, DPOs are not obliged to publicly disclose their personal information. The disclosure of information is only necessary to serve the function of contacting and fulfilling legal obligations, including full name, title, telephone number and email.
In practical terms, based on our practice experience, we believe that the company may use neutral, non-personal information of the DPO, such as the phone number and email that the company registers separately for the position of DPO, and the address to receive correspondence is the company's address. On the one hand, this helps the DPO not have to provide its personal information, and on the other hand, it helps the company maintain a consistent and stable communication channel even if there is a change in the DPO in the future.
6. How should the internal DPO handle if there are departments/personnel in the company who do not cooperate in the issue of personal data protection?
HM&P:
Although it is not a strange regulation in the legal system of Europe and other advanced countries, the regulation on personal data protection in general and the DPO position in particular is still basically a relatively new regulation in Vietnam. Therefore, the fact that other departments and personnel in the company are not aware of the role and authority of the DPO is also understandable and often happens in many companies. This leads to a situation where the DPO is unable to perform its powers/duties due to obstruction/non-cooperation from other departments/personnel. This, if not resolved in time, not only affects the quality of the DPO's work but also poses a potential risk of violating the law in the company's personal data protection activities.
The current law does not have appropriate mechanisms to solve this situation, therefore, referring to prominent legal systems on personal data protection as well as practical practice, we provide some handling options that DPO can refer to as follows:

Step 1: Review the regulations on the powers of the DPO and the responsibilities of relevant departments/personnel
This is an important step because the DPO needs to clearly define the grounds for exercising the rights of the DPO, the scope of its authority as well as the corresponding responsibilities of relevant departments/personnel in the company. These regulations are usually included in the decision to appoint a DPO, the company's regulations on personal data protection, and other internal documents of the company.
Step 2: Internal communication with relevant departments/personnel
On the basis of the checked regulations, the DPO should have internal exchanges first, in the spirit of coordinating the implementation of the rights and responsibilities of different job positions in the company.
Step 3: Record the non-cooperation of relevant departments/personnel and propose handling
The archiving of emails, minutes, reports and submitted recommendations is necessary to serve the administration and show that the DPO has fully fulfilled its responsibilities. In the event that non-cooperation is likely to result in a breach or significant risk to personal data, the DPO may recommend the company to take appropriate precautions, such as reviewing the process, temporarily restricting high-risk handling activities, or applying internal management measures in accordance with applicable regulations.
In the long term, international experience shows that improving compliance efficiency needs to be based on building a data protection mechanism and culture across the enterprise rather than relying solely on the role of the DPO. In Europe, many companies tie their responsibility for personal data compliance to the KPIs of their department managers, implement mandatory training on personal data protection, and embed compliance content into their entire operational processes. In this model, the DPO does not have to persuade each department, but plays a coordinating and monitoring role in a system that has been designed to be compliant.
7. Is the internal DPO bound by any obligations to the company?
HM&P:
First of all, it should be affirmed that Vietnamese law does not consider the DPO as the main legally responsible subject for personal data protection violations. Under the Law on PDP, the liability lies with the data controller and/or data processor, i.e. the company itself. However, this does not mean that the DPO does not have any binding obligations to the company. In contrast, the DPO is bound by the obligation to properly, fully and honestly perform the functions assigned to it in accordance with the law and in accordance with the agreement with the company.
Firstly, the internal DPO is obliged to perform its functions within the scope set out by the Law on PDP and Decree 356.
Second, the DPO is bound by the company's legal internal regulations on personal data protection just like other personnel.
Thirdly, the DPO is obliged to keep the information and personal data that it accesses in the course of performing its tasks.
Fourthly, the DPO has the obligation to be honest, objective and not cause a conflict of interest in the process of performing its duties.
Fifth, the DPO is obliged to report and warn risks in a timely manner to the company. In the spirit of the Personal Data Protection Law 2025 and Decree 356/2025, the DPO is not responsible on behalf of the company if a breach occurs, but if the DPO is clearly aware of the risk without reporting, warning, or deliberately silencing, this behavior may be considered a breach of professional and contractual obligations.
Finally, it should be emphasized that the DPO's binding obligations to the company primarily arise from employment relations or service contracts, which are laid out in the legal framework of the PDP Law 2025. The current Vietnamese law does not design the DPO as a subject that is independently responsible to the State, but as a component of the internal compliance system. Therefore, the responsibilities of the DPO are functional and professional obligations, not a substitute legal liability for the company.
In short, according to the current Vietnamese law, the DPO is bound by obligations to the company, but those are the obligations to perform the assigned functions, comply with legal internal regulations, confidentiality of information, honesty and timely risk warning. Understanding the scope of this constraint helps the company design the appropriate DPO role, and helps the DPO protect itself from the risk of being pushed into a position of legal responsibility on behalf of the organization.
8. Can an internal DPO be dismissed, fired, or terminated if a personal data incident occurs?
HM&P:
According to the Law on PDP and Decree 356, the responsibility of the DPO when a personal information incident occurs should be viewed on two different levels, including the responsibility of the DPO in a functional role when the incident occurs and the personal liability of the DPO if there is an independent violation. Therefore, when a personal data protection incident occurs, the company needs to comprehensively and thoroughly assess the cause of the incident.
In case the DPO has been provided with sufficient information, given the necessary access, has properly performed the functions of consulting, warning, supervising and has promptly made recommendations in accordance with the law, the company's failure to comply with or insufficiently implement such recommendations is the company's governance decision. In this situation, the dismissal or dismissal of the DPO just because the incident occurred will pose a serious legal risk to the company in terms of labor, because it can be considered as ungrounded disciplinary action, infringing on the legitimate rights and interests of employees.
On the contrary, if there are grounds to show that the DPO has not performed or has not fully performed its obligations, such as not participating in the supervision of personal data processing activities even though it has been assigned; failing to warn clear and foreseeable risks; failing to give false advice or giving false advice in bad faith; or failing to participate in handling incidents according to legally issued internal processes, then the responsibility of the DPO will be considered within the framework of labor law. In this case, the dismissal, disciplinary action or termination of the labor contract can be considered legal, provided that the company fully complies with the order, procedures and basis in accordance with the provisions of the Labor Code 2019 and relevant guiding documents.

The DPO is forced to identify, understand and know how to apply the current standards and technical regulations of Vietnam as a standard to assess the level of compliance.
9. Technically, are there any standards and regulations that the DPO needs to pay attention to?
HM&P:
From a technical perspective, Vietnamese law has not yet issued a separate set of technical standards only for DPOs, but that does not mean that DPOs are excluded from the system of standards and technical regulations on information security and cybersecurity. On the contrary, in the context that the Law on PDP emphasizes the need for appropriate protection measures, the DPO is forced to identify, understand and know how to apply the current standards and technical regulations of Vietnam as a standard to assess the level of compliance.
Based on practical experience, we believe that DPOs may need to pay attention to existing sets of general information security regulations and standards, such as the national standard TCVN ISO/IEC 27001:2019 on information technology - safety techniques - information security management system - requirements published by the Ministry of Science and Technology; National standard TCVN ISO/IEC 27002:2020 on information technology - safety techniques - code of practice for information security management published by the Ministry of Science and Technology; The national standard TCVN 14423:2025 on cyber security - requirements for critical information systems published by the Ministry of Science and Technology.
|
Note: This publication is intended to provide general information only and is not a substitute for legal advice on a case-by-case basis. Therefore, readers should consult a lawyer or legal expert before applying. Any questions regarding content or intellectual property rights should be directed to: counsel@hmplaw.vn HM&P Law Firm is a professional law firm with experience in providing multi-disciplinary legal advice, including personal data protection. To learn more about the legal services we provide in this field, please contact us by email: phuc.nguyen@hmplaw.vn |
Please read more and download full content of publication (PDF File) here
