The Draft Law on Personal Data Protection: Who is a Data Protection Officer?

Insights
The Draft Law on Personal Data Protection: Who is a Data Protection Officer?
Posted on: 28/05/2025

    In the rapid digital technological advancement, personal data has become a valuable resource but also has many potential risks. The protection of personal data is not only a legal requirement but also a vital factor to maintain user trust and ensure national security. The Draft Law on Personal Data Protection of Vietnam (the "Draft"), is expected to be approved by the National Assembly in 2025 and take effect on January 1, 2026. One of the key highlights of the draft is the regulation on data protection officer (DPO) – a new but decisive role in the enforcement of data protection laws. In this article, we will analyze in detail the content related to DPO according to the latest Draft being submitted to the National Assembly at the 9th session, May 2025.

     

     

    Who is a DPO ?

    According to Article 39 of the Draft Law on Personal Data ProtectionDPO is defined as an individual who is capable of protecting personal data, which is classified into three main groups based on professional capacity, including:

    Firstly, Experts are technologically and legally competent.

    This is a group of officers with comprehensive knowledge and skills, both knowledgeable about technical aspects (such as system security, data encryption, cybersecurity) and mastering legal regulations related to personal data protection. Perhaps one of the conditions for an individual to be considered a technologically and legally competent officer is that they must have a degree and/or certificate that is recognized in both the technologically and legally fields by the competent authority.

    Second, Technically competent officers.

    This group focuses on technical skills, such as implementing encryption measures, monitoring data access, or developing technological solutions to prevent unauthorized access.

    Thirdly, the expert is legally competent.

    This team specializes in legal aspects, including advising on legal compliance, drafting data protection policies, and handling disputes or breaches related to personal data. Individuals will generally be considered legally competent professionals if they have a bachelor's degree in law and undergo a training course by an authorized body for personal data protection training.

    This classification reflects the Draft's flexible approach, which allows organizations to select officers that are tailored to their needs and industry specificities. However, the Draft does not specify specific criteria for assessing "competence", which may be specified in detail by the Government or specialized agencies in future guiding documents.

    Mandatory requirements for DPO of the Draft

    One of the notable provisions in Clause 2, Article 39 is to require each organization, business, or individual involved in the processing of personal data to have at least one DPO suitable for their industry, profession or business field. This emphasizes the role of experts as a core factor in ensuring comply with legal regulations on data protection.

    However, the Draft also makes some exceptions to reduce the burden on small and start-up businesses. Specifically, in Clause 3, Article 39 and Clause 1, Article 68, small businesses and start-ups are exempt from the requirement to have a personal data protection expert in the first 5 years from establishment. However, this regulation does not apply to businesses directly engaged in personal data processing, such as technology companies or social media platforms. In addition, in the first 1 year from the effective date of the Law (i.e. until January 1, 2027), all agencies, organizations and businesses are exempt from this requirement to have time to prepare[1].

    These regulations show a balance between ensuring legal compliance and enabling businesses, especially small businesses, to adapt to the new regulatory framework. However, in the context of Vietnam, we believe that this regulation is difficult to enforce in practice, although there is an exemption, the exemption period is negligible and after the exemption period, almost all organizations must have a DPO. Not to mention the very confusing provision in Clause 2, Article 39 of the Draft that requires individuals to also have at least one DPO[2]. This is perhaps an unacceptable negligence of the Draft when it has been submitted to the National Assembly for consideration.

    For millions of businesses, not to mention tens of thousands of different organizations to be able to meet the number of experts required by this regulation, it is extremely difficult for Vietnamese organizations and businesses at least in the next 5 years to be able to comply with this regulation seriously.

    Roles and responsibilities of a DPO

    Although the Draft does not list in detail the specific duties of the DPO, through the relevant regulations, it is possible to visualize the important role of the DPO in the data protection ecosystem. Based on the provisions of the Draft, the personal data protection officer may assume the following responsibilities:

    Consulting and developing data protection policies

    Experts, especially those with legal capacity, have the role of advising the organization on the development of internal regulations on personal data protection, ensuring compliance with the principles in Article 3 of the Draft such as transparency, limitation of purposes, security, etc ...

    Implementation of technical measures

    The technologically competent specialist will be responsible for implementing data protection measures, such as encrypting sensitive data (Article 15, Draft), monitoring data access, or applying technical standards (Article 51, Draft).

    Compliance monitoring

    The expert acts as an internal "gatekeeper", ensuring that the organization complies with the provisions of the Draft, including the preparation and updating of the Personal Data Processing Impact Assessment Record (Article 45, Draft) and the Overseas Transfer of Personal Data Impact Assessment Record (Article 46,  Draft).

    Handling violations and reporting

    In case of violation of regulations on personal data protection, the expert may assist the organization in making a Record of Confirmation and coordinate with the specialized agency in charge of personal data protection to handle the case (Article 37).

    Training and awareness raising

    Professionals may participate in employee training on regulations and best practices in the protection of personal data, as set out in Articles 20 and 56.

    The role of DPO is not only limited to the internal scope of the organization but also extends to coordination with state management agencies, especially the specialized agency in charge of personal data protection under the Ministry of Public Security (Article 52). This emphasizes the importance of the expert as a bridge between the organization and the regulator.

     

    Vice Chairman of the National Assembly, Colonel General Tran Quang Phuong, chaired the plenary discussion session on the Draft Law on Personal Data Protection. Source: National Assembly.

     

    The importance of a DPO

    The appearance of the DPO in the Draft reflects the global trend towards the professionalization of data protection. In the context of the increasing number of personal data breaches, the role of the professional has become especially important for the following reasons:

    First, ensure compliance with the law.

    With administrative penalties ranging from 1% to 5% of the previous year's revenue (Article 4) and strict legal liabilities, experts help organizations avoid legal and financial risks in the process of complying with personal data protection laws.

    Second, strengthen customer trust.

    Having a DPO demonstrates the organization's commitment to customer privacy, thereby improving the reputation and trust of customers for organizations and businesses in the process of operation and business.

    Third, dealing with technological threats.

    In the digital environment, threats such as cyberattacks, data leaks, or unauthorized collection are becoming increasingly sophisticated. Officers with technological capabilities are key to detecting and preventing these risks.

    Fourth, support digital transformation.

    As Vietnam accelerates its national digital transformation, DPO will play an important role in ensuring that technological initiatives, such as artificial intelligence (Article 27) or cloud computing (Article 28), are implemented securely and in compliance with legal regulations to ensure smooth business operations sustainability of the enterprise.

    Challenges and opportunities for DPO

    Currently, Vietnam is still on the journey to complete the legal framework for personal data protection, with an important milestone being Decree 13/2023/ND-CP, followed by the Law on Personal Data Protection which will soon be promulgated. However, a team of well-trained DPO, combining both technological and legal capabilities, almost does not exist or is only at a very limited level, or has not been officially recognized by any agency. Building a force of experts to protect personal data in a short time, meeting the requirements of businesses and management agencies requires long-term and synchronous investment from the State and businesses. If the Draft Law on Personal Data Protection is passed this year, especially at the 9th National Assembly session, the shortage of high-quality human resources in the field of personal data protection will become a major challenge for organizations and businesses in Vietnam.

    Another obstacle is the cost of compliance, especially for small and medium-sized businesses. Hiring or training a DPO can create a significant financial burden, especially when the waiver period ends and the business has not yet met the legal requirements.

    However, it is easy to see that the mandatory regulation for each business to have a DPO is not only a legal requirement but also opens up opportunities to develop a potential new industry in Vietnam. The role of this officer is not only to ensure compliance with the law, but also to contribute to building a safe and sustainable digital ecosystem, and at the same time supporting Vietnam to integrate with global data protection standards.

    In conclusion, we recognize that the drafting agency's addition of the regulation on DPO to the Draft is essential and in line with the global trend of personal data protection. However, requiring all businesses to have a DPO without exception after the exemption period poses a dilemma that the State, with the role of both protecting people's rights and creating a fair and favorable business environment.  It is necessary to consider flexible solutions to support businesses, especially small businesses, in meeting these very new regulations in Vietnam.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm