The Law on Personal Data Protection 2025 and Decree 356/2025/ND-CP have created a clearer legal basis for the use of external organizations to provide personal data protection services. For businesses that do not have enough resources to build a dedicated apparatus, outsourcing DPO (Data Protection Officer) can be a quick way to add legal, technological and data governance capacity. Therefore, outsourced DPO is becoming the choice of many businesses when personal data protection is no longer just a compliance requirement but has become a content of corporate governance. However, the popularity of this model also leads to a fairly common misconception: hiring a DPO means that the business has solved the problem of data protection.

Businesses should not choose a DPO based solely on the price of services, a portfolio of work, or a general commitment that the provider has "experience in data protection".
In fact, businesses can outsource expertise and monitoring functions, but they can't outsource responsibility for their data decisions. So it's not just a matter of choosing the right provider, but also designing a model for the DPO to truly create value in data governance.
Not only choose the right DPO, but also understand the right role
Businesses should not choose a DPO based solely on the price of services, a portfolio of work, or a general commitment that the provider has "experience in data protection". What is more important is whether the DPO's capabilities are aligned with the business's own data risk structure.
The risks of a manufacturing business that primarily handles HR data are significantly different from banks, e-commerce platforms, technology businesses, or medical organizations. Therefore, industry experience, the ability to understand systems, and how data is actually used in business operations are often just as important as legal knowledge.
Data protection is no longer a purely legal problem. An incident can simultaneously be related to system architecture, access decentralization, contracts with providers, data subject rights, and administrative responsibilities. DPOs only understand the law but do not understand how data operates, it will be difficult to fully identify risks; on the contrary, technical competence cannot replace the ability to assess legal liability. What businesses need is not a "DPO title", but a data risk management capacity that is suitable for their operations.
Businesses also need to determine exactly what function the supplier is performing.
A common misconception is to implicitly treat an outsourced DPO as a "Personal Data Processor" simply because the DPO has access to customer, employee, or records containing personal data.
"Data Processing" is an activity, while "Personal Data Processor" is a legal status defined by the actual role. The fact that the DPO looks at the data to review the DPIA, [1]evaluate a process, or determine the cause of the problem does not automatically mean that the DPO is processing the data on behalf of the business.
Conversely, if the vendor in fact also performs data processing activities on behalf of the business, the responsibility must be determined in accordance with that function, regardless of what the contract calls them. In other words, we must look at the actual activity, not just the name of the service.
DPO loses its independence, the monitoring function also loses its meaning
The value of a DPO lies in its ability to issue a warning even if it is not favorable to the business department, management, or the supplier itself. Therefore, conflicts of interest are one of the most notable risks of the outsourced DPO model.
If a company is both a DPO and provides a data processing system, when evaluating that system, the DPO may have to examine its own services. Similarly, if the DPO directly designs a data processing process and then evaluates the suitability of the process itself, the objectivity of the monitoring function may be impaired.
The question is therefore not just whether the supplier has a conflict of interest on paper, but whether the relationship structure allows the DPO to make an adverse but necessary opinion. The DPO's independence depends on the reporting route, access to information, the de-escalation mechanism when there is a disagreement, and also the commercial relationship with the supplier.
If an organization provides multiple services, the business may have to separate the HR team, set up its own reporting route, or stipulate issues that need to be independently assessed. With high-risk issues, the DPO also needs to be able to take the opinion to the appropriate management level instead of being blocked by the department that owns the business.
A DPO who can't give an independent opinion is more likely to be the one who legitimizes the decision in place, rather than a layer of risk control.
Having a DPO but not having an operating mechanism is still a DPO on paper
Even a competent and independent DPO is difficult to create value if it is outside of the operational processes of the business.
A good DPO contract should therefore not just state that the supplier is obliged to "advise and support compliance". What is more essential is to be able to answer: when problems arise, who does what?
When is the DPO notified if something goes wrong? When a business implements a new system or uses data for a new purpose, is the DPO consulted first? If the DPO warns of a high-risk activity but the sales department does not agree, where does the matter be escalated?
The most important thing is to delineate the DPO's right to advise and the business's decision-making power. The DPO can warn of a marketing campaign with legal risks, but the business decides whether to proceed or not. The DPO can propose fixing the vulnerability, but the business must allocate resources to do so. The DPO can detect an incomplete DPIA, but the relevant departments must provide information and adjust the process.
The DPO does not run the business. Therefore, the clause requiring the DPO to be "responsible for ensuring the business complies with the law" is both too broad and easy to create a false sense of security. The DPO must also have access to enough information to work, but "enough" does not mean unlimited.
With an outsourced DPO, each access also creates an additional point of contact between the data of the business and the external organization. Access must be tied to the task, controllable, and revoked when it is no longer needed. If this is not done well, the business may fall into a paradox: hiring a DPO to reduce data risk, but it is the way DPO is implemented that creates additional risk.

DPO outsourcing therefore does not lose the need for internal capacity; it only changes the type of capacity that the business needs to maintain.
DPO outsourcing doesn't mean empty inside.
Another misconception is that when hiring a DPO, businesses may not need internal resources for data protection. However, external DPOs do not know that the business has changed its recruitment and marketing systems and integrated AI and IT tools and switched to a new cloud service, or the business department is preparing to share data with partners. Without information, the DPO cannot monitor.
DPO outsourcing therefore does not lose the need for internal capacity; it only changes the type of capacity that the business needs to maintain. Businesses also need to establish "trigger points" that require DPO consultation, such as when implementing a new system, using data for new purposes, sharing data with partners, moving data overseas, adopting high-risk technology or incidents.
If the DPO is only called after the contract has been signed, the system has been purchased, and the product has been launched, many of the recommendations, even if they are right, become difficult and expensive to implement. The DPO may be outside the personnel structure, but their function must be inside the decision-making process.
Don't measure DPO by the number of records
Another risk is turning the DPO into a producer or signing a compliance document.
DPIA is in place. Policy issued. Training organized. Report prepared. On paper, the system appears complete. But the effectiveness of the DPO should not be measured by the number of documents completed, but by the quality of data decisions made after the DPO is involved.
Are risks identified before the project is implemented? Is unnecessary data discarded? Is access reduced? Is the retention period adjusted? Are post-incident recommendations actually implemented?
A good DPO doesn't just help businesses create more documentation. They must contribute to changing the way businesses make decisions about data.
An outsourced DPO is not a solution to transfer compliance responsibilities, but rather a way to add expertise and supervision to the business. The value of a DPO therefore does not lie in the number of documents completed, but in its ability to help businesses identify risks earlier and make better decisions about data. After all, businesses can outsource the DPO function, but they cannot outsource their own data governance responsibilities.
[1] DPIA stands for Data Protection Impact Assessment. This is a systematic process that helps organizations and businesses identify, analyze and mitigate privacy risks to personal data before implementing data processing activities.
