
FOREWORD
DPO stands for the phrase "Data Protection Officer" in English, roughly translated as "personal data protection officer". According to international legal experience and practice on personal data protection, the DPO is often likened to a "conductor", playing a central role in the management and protection of personal data of the organization that appointed or appointed them.
The current Vietnamese law, specifically the Law on Personal Data Protection 2025 ("Law on PDP") and Decree 356/2025/ND-CP detailing a number of articles and measures to implement the Law on PDP ("Decree 356") does not mention the above concept, but instead other concepts include: Personnel protecting personal data, personal data protection departments in agencies and organizations; and organizations and individuals providing personal data protection services (outsourced). Within the scope of this document, the term DPO will be used by us to refer to individuals who are appointed by agencies and organizations (hereinafter collectively referred to as "companies") as internal DPOs or hired to provide personal data protection services to the company, depending on the specific context.
Although the current law on personal data protection has initial regulations related to the conditions and tasks of DPOs, in fact, the application of these regulations is still relatively new in Vietnam. Properly understanding the nature and role of the DPO is important in appointing DPOs, thereby ensuring compliance with the law on personal data protection.
On the basis of practical requirements in implementing the DPO function, HM&P compiled the publication "Q&A on Legal Issues Related to DPO" to provide reference materials for businesses and individuals in the position of DPO. The content is presented in the form of questions and answers, combining analysis of legal regulations and practical experience, illustrated with tables, diagrams and accompanied by appendices including supporting tools such as a list of questions when selecting a DPO and a form of decision on the appointment of a DPO.
Through this publication, HM&P aims to provide businesses with a practical reference to help identify the role of DPOs and implement personal data protection requirements in accordance with their operating conditions.
If you have any questions about the contents of this document, please contact HM&P using the information below:
Our Managing Partner:
Lawyer Nguyen Van Phuc
Phone: 0932 768 630
Email: phuc.nguyen@hmplaw.vn
HM&P Law Firm
Address: 7th Floor, ITAXA House, 126 Nguyen Thi Minh Khai, Xuan Hoa Ward, HCMC
Phone: +84 28 73080839
Email: counsel@hmplaw.vn
Website: hmplaw.vn
TABLE OF CONTENTS

ABOUT DPO
1. What are the duties of a DPO?
HM&P:
According to the provisions of Article 14.2 of Decree 356, the company's DPO must perform the following tasks and functions:

In general, the function of the DPO under the provisions of Vietnamese law is similar to the regulations on personal data protection of countries and regions around the world, for example, the General Data Protection Regulation of the European Union 2018 ("GDPR").
2. Does the DPO have to do all the work on personal data protection on their own?
HM&P:
In terms of regulations, DPOs are obliged to participate in the implementation of the rights of personal data subjects, receive and report violations of personal data protection and comply with other requirements of competent agencies as prescribed[1]. It can be seen that the DPO acts as a focal point for the company to handle issues of personal data protection. However, DPOs cannot and are not forced to do all the work/solve all data protection requirements on their own. In fact, when receiving a request from a personal data subject or a competent authority, the DPO needs to coordinate with relevant departments/individuals in the company to handle the request.
For example, when receiving requests to "withdraw consent to the use of personal data" and "delete personal data" from customers participating in the survey program, the DPO must notify the departments that are storing the customer's information (sales department/information technology department/communication department, …) to stop the processing of personal data (surveys), and at the same time delete the customer's personal data from the company's storage system.
In addition, currently, Article 33.1.d of the Law on PDP stipulates that the personal data protection force also includes organizations and individuals mobilized to participate in the protection of personal data. Therefore, it can be said that the work of the DPO will involve many different organizations and individuals and when necessary, these organizations and individuals will also participate in the process of protecting personal data.

DPO APPOINTMENT
3. Is it mandatory for every company to appoint a DPO?
HM&P:
Article 33.2 of the Law on PDP stipulates: "Agencies and organizations are responsible for appointing departments and personnel who are qualified to protect personal data or hiring organizations and individuals to provide personal data protection services". However, the Law on PDP also excludes a number of cases in which the company is not required to appoint a DPO, including:

3.1. How to identify a small business, micro business, startup business?
To determine whether a company belongs to the case of small enterprises or micro-enterprises, it is necessary to base on the determination criteria specified in the Law on Support for Small and Medium Enterprises 2017 and Decree 80/2021/ND-CP.
For start-ups, there are currently no specific regulations for this type of business, except for the concept of innovative start-up enterprises. Accordingly, an innovative start-up enterprise is an enterprise established in accordance with the law to implement ideas on the basis of exploiting intellectual property, technology, new business models and capable of rapid growth[2].
3.2. How to identify a company that provides personal data processing services or directly handles sensitive personal data?
The current law does not provide a general definition of "personal data processing services", but only lists some specific types of services, and at the same time establishes a separate legal regime for organizations providing personal data processing services, including personnel conditions,infrastructure and requires a Certificate of eligibility for business. In this context, the determination of whether a company is in the business of personal data processing services or not needs to be carefully evaluated, based mainly on the actual nature of its activities, namely whether the company performs personal data processing activities for customers for the purpose of profit.to ensure legal safety and limit compliance risks.
For the case of direct processing of sensitive personal data, the current law does not have specific guidance, while the scope of sensitive personal data is regulated very widely, covering many types of common and necessary data in civil transactions such as health information, images of identity documents or banking transaction data. Therefore, in practice, the scope of application of the exemption mechanism is significantly narrowed, and even small or micro enterprises, if they directly process these types of data, have little basis to be exempt from the obligation to appoint DPOs.
In summary, the current obligation to appoint a DPO still stipulates exceptions, but it is not simple to identify an exceptional company because most companies are now directly dealing with sensitive personal data.
4. Who can the company appoint to be an internal DPO?
HM&P:
To be able to become an internal DPO of the company, the appointed personnel must meet the following conditions[3]:

For the conditions of education and seniority in related fields, it can be found that it is not difficult for the company to find suitable personnel to be appointed to the position of DPO. Regarding the conditions on training and fostering legal knowledge and professional skills on personal data protection, there are currently no regulations that set specific criteria and content on knowledge and skills that personnel need to be trained to become DPOs. Therefore, the company can take the initiative to decide on the criteria for its internal DPO or the training courses that the company sends personnel to participate in to be eligible to become an internal DPO.
Based on the requirements of professional expertise, it can be seen that there are many positions in the company that can be appointed to the position of internal DPO, for example, personnel from the legal department, human resource administration, and information technology,... including staff or managerial personnel positions.
In fact, the position of internal DPO is usually undertaken by personnel of the legal or compliance department, due to the nature of the work related to consulting and supervising the company's legal compliance, including personal data protection. However, we note that, because the scope of legal expertise does not include specific technical solutions, the DPO in this case still needs the coordination and support of the technical department such as the department/expert in information technology to implement and ensure the implementation of technical data protection measures in accordance with legal regulations law.
5. Do I need any certifications to become an in-house DPO?
HM&P:
The current law does not have specific regulations on the specific certificates that an individual must have to be eligible to be appointed to the position of internal DPO, but only general regulations that this individual must be trained and fostered in legal knowledge and professional skills in personal data protection. Thus, the satisfaction of this condition will be proven by the individual or the company.
Currently, there are many training courses and fostering of legal knowledge and professional skills on personal data protection that have been implemented by organizations and individuals to serve the needs of DPOs. Participating in these training courses not only helps to cultivate the necessary knowledge and skills for DPOs, but also serves as a "plus" to prove that they meet the conditions prescribed by law.
6. How can a company appoint an employee to become an internal DPO?
HM&P:
The appointment of a DPO is an important procedure, because this will establish the position of the DPO for the company, thereby, the DPO's information will be recorded during the processing of personal data. Current legislation does not provide for a specific process for the appointment of an internal DPO of a company, therefore, based on practical experience, we provide the following internal DPO appointment process for reference purposes:

Step 1: Choose the right DPO
In order to be able to select a suitable individual to be appointed to the position of internal DPO, the company needs to screen for meeting the conditions prescribed by law for the position of DPO. Particularly for the requirement of training and retraining, as we have mentioned, the company can arrange for its personnel to participate in training and refresher courses to meet this condition.
However, the consideration of the above conditions is only at the screening stage. To choose a suitable DPO, the company needs to consider the following additional factors:
Personnel's interest in the position of DPO:
The appointment of personnel to become the DPO of the company is carried out on the principle that there is an agreement between the company and the personnel, therefore, the company must ensure that the personnel that the company is expected to select are also interested in becoming the DPO of the company.
Conditions for performing the work of the DPO:
With its duties and obligations, the DPO position requires the ability to access and process personal data at a deep and wide level, including sensitive personal data. Not only that, this position requires the ability to work inter-departmentally to coordinate and effectively handle personal data protection issues. Therefore, the personnel that the company is expected to select must be individuals who meet the above conditions.
Company Knowledge:
In addition to the statutory conditions, knowledge of the company is extremely important for the DPO position. The selected personnel must be someone who understands the entire process of collecting and processing personal data of the company and the relationship between departments and departments in handling personal data.
Other criteria depend on each company:
In addition to the above criteria, each company may have other criteria for selecting DPOs, for example, considering the selection of personnel who have worked at the company for a long time or working under an indefinite-term labor contract,... to ensure the stability of the DPO position.
In order for companies to be able to select suitable personnel for the DPO position, we attach a list of questions to be answered when selecting a DPO (Appendix 1) for reference purposes.
Step 2: Formally appoint a DPO
After selecting the right personnel, the next thing the company needs to do is to issue a written decision on the appointment or designate a DPO. This decision should reflect the assignment, functions, tasks, powers and other requirements for personal data protection in the company. At this step, there will be quite a lot of work that the company has to do. This includes the identification of the individual or authority authorized to appoint the DPO; drafting documents for the appointment such as the adjustment of the labor contract (adjustment of the scope of work), the appointment decision, the confidentiality agreement, the waiver agreement, other regulations and regulations on the powers and activities of the DPO; archive the decision on appointment of the DPO and related documents.
Step 3: Notification of DPO Appointment
Although not a statutory obligation, the announcement of the appointment of a DPO is extremely important in practice, because:
- Official announcement on the focal point for handling personal data protection issues of the company: The announcement of the appointment of the DPO along with the disclosure of the DPO's contact information is a necessary condition for the subject of personal data and related third parties to be able to grasp information about the focal point for receiving and handling issues of personal data protection of the company.
- Indirect way to empower DPO: Although legally, an appointment decision is valid enough to empower the DPO. However, if it is not made public within the company, the exercise of the DPO's rights can be difficult. As mentioned, the DPO is a position that requires close coordination with other individuals/departments in the company, so an internal announcement, accompanied by documents on the tasks and functions of the DPO will be meaningful to spread the message about the DPO's authority when working within the company on the issue of personal data protection.
Step 4: Notify the competent authority
Currently, Vietnamese law does not stipulate that a company must notify the competent authority when appointing a DPO. However, the DPO's information will be mentioned in other administrative documents that the company must submit to the competent authority, including the dossier of impact assessment of the handling of personal data, the dossier of assessment of the impact of cross-border transfer of personal data, and the notice of violation of regulations on personal data protection. Therefore, if after the appointment of the DPO and the company has not carried out the above administrative procedures, the DPO's information will also be included in the notices sent to the competent authorities.

7. Can the company appoint multiple personnel as internal DPOs and each person holds a different task?
HM&P:
The DPO position requires quite specific knowledge and skills that in the short term, it is difficult for an individual to meet. Therefore, in order to take advantage of available resources, some companies choose to appoint multiple personnel for the position of DPO (of course, each employee meets the minimum conditions prescribed by law). At that time, each DPO will undertake different work items under the DPO's tasks. Legally, this is not restricted or prohibited by law. Not only that, this is also the foundation of the establishment of the company's personal data protection department, including DPOs. At that time, between these DPOs, or in other words, the company's personal data protection department, there will need to be a specific division of powers, obligations, and responsibilities for each member and these should be specified in the appointment/establishment decisions related to the DPO and the personal data protection department.
8. An internal DPO of one company is also an internal DPO of another company, is this allowed?
HM&P:
As a new field that requires many professional and technical factors at work, many companies choose to recruit personnel who are in charge of the work of the DPO without concurrently holding other jobs in the company. At that time, a part-time DPO was born as a solution for an individual to become a DPO for many different companies (working in the form of an employment contract), helping the company save costs compared to recruiting a full-time DPO. Legally, this is not prohibited or restricted by law, so the appointment of a full-time or part-time DPO is entirely up to the suitability and discretion of the company.
However, the company also needs to pay attention to the work allocation of the DPO to ensure that the part-time DPO can still take care of the work throughout, avoiding any bottlenecks in personal data protection activities. In addition, information security and conflicts of interest are also issues that need to be taken into account, in the context that DPOs are allowed to access and access personal data from many different companies. Therefore, the inspection and evaluation of the input of personnel recruited for the position of part-time DPO (at the time of recruitment and in the process of performing the job) can be carried out by the company to understand the number and information about the units that the DPO is concurrently holding the job.thereby making a decision to select/replace an appropriate DPO to avoid information security risks and conflicts of interest.
9. If an internal DPO takes leave or quits his job, how should the company handle it?
HM&P:
With its important role, maintaining the stability of the DPO position is extremely important for the company. However, in the process of working, it is inevitable that the DPO will take leave or quit his job. In these cases, the company needs to have appropriate responses to ensure that the protection of personal data is smooth.
Basically, the current law does not have specific regulations on requirements for companies when DPO takes leave or resigns. Therefore, the solution in this case will be decided by the company itself, based on the situation of continuing to perform the DPO's duties in each case.

Case 1: DPO leave
This is a case where the DPO is temporarily not performing his or her work at the company. As with other leave cases, the DPO must ensure that its work is handed over and handled by the appropriate personnel when on leave. However, unlike other jobs that employees undertake, the jobs of the DPO position require requirements related to security, so the selection/decision of the recipient of the DPO's work handover also needs to be carefully calculated.
To ensure that the "backup" for the DPO is carried out continuously and limit interruptions, businesses can note:
- The selection of the handover recipient can be taken into account by the company as soon as the DPO is selected. The recipient of the handover can be one or several personnel of the department or the nature of the work similar to the DPO, which ensures that they have a certain understanding to perform some of the handed-over work.
- The selection of the handover recipient should also be clearly stipulated in the company's internal documents to ensure that there is a basis for binding the obligations of the handover recipient as well as a basis for the handover recipient to perform his or her work.
- The handover activity should be notified to the subjects of the personal data in a reasonable manner. Depending on the duration of the leave as well as the ability to perform the work, the company may notify different DLCN subjects of the leave and handover of the DPO.
- Only consider handing over for some jobs that need to be handled urgently that the DPO cannot do. After all, giving access to information to a person who is not a DPO of the company should not happen, therefore, the company needs to limit the work items that can be handed over to the "backup", and at the same time, it is necessary to pay attention to the commitment to confidentiality corresponding to the amount of information. DLCN is accessed.
- Neutralizing the DPO's contact information is also something that the company needs to take into account. In order to ensure that the communication and exchange of information from the subject of the personal data and the competent authority for the DPO is not interrupted and the recipient still receives this information, the contact information of the DPO should not be their personal information. Instead, the company should use neutral, company-controlled information such as company address, phone number, email provided by the company.
Based on practical experience, we believe that the company may consider appointing more than one DPO to ensure that when a DPO is on leave or resigns, the remaining DPOs can still take over the job, without affecting the company's personal data protection activities.
Case 2: DPO quits
Unlike leave, when the DPO only temporarily does not perform some of his work at the company for a short time, taking leave poses a problem for the company when the current DPO will not continue to perform his work at the company. In this case, to ensure compliance with regulations on personal data protection, the company is forced to choose a new DPO, replacing the resigning employee. The process of replacing a DPO is generally similar to the appointment of a new DPO, however, the company should pay attention to the process of terminating the employment contract with the DPO, when all information, documents, and access of the DPO to the company's personal data should be handed over/deleted/terminated appropriately. In addition, the current regulations do not require the company to notify the competent authority when changing the internal DPO. The company must only update information about the new DPO when updating administrative records on impact assessment or notification of violations of regulations on personal data protection arises.
10. Does the appointed personnel have the right to refuse to become the DPO of the company?
HM&P:
Legally, an internal DPO works for the company in the form of an employment contract. Therefore, the fact that an employee has the right to refuse to become a DPO should be considered in employment relations.
In case the employee is recruited from the beginning with a DPO position not mentioned in this content; instead, it is the case that the employee is holding other positions in the company such as legal staff, human resource administration, information technology, etc. and was selected for appointment as DPO.
According to the Labor Code 2019, employees are obliged to perform work in accordance with the content of the signed labor contract, and the company is only allowed to ask employees to perform work within the scope of that contract. The law allows companies to temporarily transfer employees to work other than the contract in certain cases, including production and business needs, but this switch is only temporary and must not exceed 60 cumulative working days in a year.unless there is the written consent of the employee.
Returning to the case of appointing DPO, the basis of "production and business needs" can be invoked to appoint/appoint DPO, but the application of this basis in practice is still limited, because the appointment of DPO is a mandatory legal obligation of the company, regardless of the production situation.business. In case of using this base, the company should note:
- The company's internal labor regulations need to contain the content that the appointment of a DPO is a case belonging to the company's production and business needs.
- If the employment contract (and attached appendices) does not cover the work of the DPO position and the labor regulations also do not contain relevant provisions, the selected employee has the right to refuse the appointment.
- The above rotation is only temporarily carried out for no more than 60 cumulative working days in 01 year (without the consent of the employee).
From a practical perspective, the company should prioritize negotiations and agreements with selected employees to adjust labor contracts and benefits so that employees can easily accept the addition of new positions. The forced appointment not only poses a potential legal risk to labor but also affects the efficiency of performing the role of DPO, which requires high initiative and responsibility.
Please read more and download full content of publication (PDF File) here
