When personal data processing services become a conditional line of business

Resources
    When personal data processing services become a conditional line of business
    Posted on: 01/04/2026

    The Law on Personal Data Protection No. 91/2025/QH15 dated June 26, 2025 of the National Assembly ("Law on PDP") and the Government's Decree No. 356/2025/ND-CP dated December 31, 2025 detailing a number of articles and measures to implement the Law on PDP ("Decree 356") have established personal data processing services as a conditional business field for the first time, are directly governed by specialized laws on PDP. This regulation has a significant impact on many businesses operating in the digital economy.

     

    The current legislation does not provide a general definition of "personal data processing services".

     

    First of all, the current legislation does not provide a general definition of "personal data processing services". Instead, the regulation is built in the direction of specifically listing the types of services based on the nature of the data processing activity, regardless of the product name, business model or how the business identifies itself. This means that the regulator may not care what the business calls its services and only directly consider whether this activity includes the processing of personal data.

    How to understand the business of personal data processing services correctly?

    Specifically, Article 21 of Decree 356 lists services within the scope of regulation, including: providing and operating data processing systems and software on behalf of the controller; scoring and rating the credit of personal data subjects; collect and process data from websites, applications, social networks; data processing in the field of health and education with supervisory elements; analyzing and exploiting user data; encryption of personal data; processing personal data based on big data technology, artificial intelligence, blockchain, virtual universe; and application platform services that provide personal location data.

    Decree 356 also does not provide a specific definition of "business in personal data processing services". Therefore, to clarify this concept, it is necessary to refer to relevant legal regulations. According to  the 2005 Commercial Law[1], commercial activities (including the provision of services) are activities for the purpose of profit. Meanwhile,  the Law on Enterprises 2020[2] defines "business" as the continuous implementation of one, some or all stages of the investment process, from production to consumption of products or provision of services in the market for the purpose of seeking profits". On that basis, it can be understood that an enterprise is considered to be in the business of personal data processing services when it provides data processing activities to other subjects as an independent service, which is carried out regularly and for the purpose of making profits. On the contrary, if an enterprise only processes data to serve its internal activities (customer management, human resources, system operation, etc.), it is not a "personal data processing service business", although it must still comply with general regulations on personal data protection.

    Which businesses may be affected?

    In fact, the regulation on business conditions for personal data processing services under Decree 356 is likely to affect many groups of businesses that are operating in the market. For example, the group of enterprises providing technology infrastructure services, cloud computing, such as Viettel IDC, VNPT IDC, FPT Telecom, CMC Telecom...; the group of businesses providing digital advertising services, analysis and exploitation of user data such as Admicro, Novaon, YouNet...; businesses operating in the field of finance and fintech such as Momo, Zalopay, Trusting Social; or application platforms that provide personal location data such as Google Maps, Apple Maps as well as ride-hailing/delivery platforms such as Grab, Be, Xanh SM. If these businesses carry out personal data processing activities of the types of services specified in Article 21 of Decree 356 and provide such services under contract to the organization,  other individuals for the purpose of making a profit, such activity may be regarded as "business of personal data processing services", thereby giving rise to the corresponding compliance obligation.

    However, whether a specific business falls into this category or not depends on the actual operating model, role in the data processing process and the scope of services provided. Therefore, the businesses mentioned above are only illustrative of potentially related business models. Enterprises need to actively review their operations to assess the possibility of falling within the scope of Decree 356 and fulfill compliance obligations in accordance with the law.

     

    Source: The Saigon Times

     

    Required requirements: Certificate of eligibility for business

    According to Decree 356, an organization providing personal data processing services is an organization or enterprise established and operating under the laws of Vietnam (hereinafter collectively referred to as "enterprise"), which must meet the basic conditions of (1) personnel; (2) infrastructure, equipment systems, facilities and technologies suitable for personal data processing services; (3) There are satisfactory results for the dossier of impact assessment of the processing of personal data and the dossier of impact assessment of cross-border transfer of personal data in case of cross-border transfer of personal data[3]. However, the above conditions are only necessary conditions. To be allowed to do business, enterprises must be granted a certificate of eligibility to provide personal data processing services. The competence to grant, re-grant, renew and revoke this certificate is currently assigned to the Ministry of Public Security[4]. Dossiers, order, procedures and forms for administrative procedures related to the certificate of eligibility to provide personal data processing services have also been specified in Decree 356. This shows that the state management agency is strengthening the pre-inspection mechanism for this high-risk sector.

    This mechanism contributes to screening businesses to participate in the market and creating a clear legal framework for the business of personal data processing services. However, it can be seen that this certificate requirement places an additional burden on enterprises in terms of compliance costs, requiring enterprises to invest significant time, human resources and financial resources to review, evaluate and complete legal documents, especially in the early stages of law enforcement without practical experience of both enterprises and enterprises State management agencies.

    One of the notable business conditions in this field is the requirement for personnel. According to Decree 356, enterprises must have: (1) the head in charge of personal data processing of the organization who is a Vietnamese citizen and permanently residing in Vietnam; (2) having a management and executive team that meets the professional requirements for handling personal data; (3) and have at least three personnel who meet the qualifications specified in Clause 2, Article 13 of Decree 356 (5), including the requirement that "have been trained and fostered legal knowledge and professional skills in personal data protection".

    However, the specific criteria to determine what is "meeting professional requirements" or the standards of "having been trained and fostered in legal knowledge and professional skills" are still not guided in detail. This gap can make it difficult for businesses to self-assess the level of meeting the conditions, and at the same time there is a potential risk of inconsistent application in practice. From a market perspective, finding or training personnel to meet the requirements is also a significant challenge for businesses, especially when regulations are new and human resources with deep expertise in personal data protection are not really abundant.

    Compliance for sustainability in the data era

    The inclusion of personal data processing services in the group of conditional business lines marks an important shift in personal data management policies in Vietnam. At the same time, this creates a significant impact on many businesses in the digital economy. In the short term, businesses may encounter confusion in determining the scope and conditions of application as well as face cost and resource pressures to review, evaluate and implement compliance measures. However, in the long term, the standardization of personal data processing activities contributes to improving transparency, strengthening the trust of customers and partners, and creating a stronger legal foundation for the sustainable development of businesses in the digital economy.

    It is necessary for enterprises to proactively review their business models, develop internal criteria for professional capacity and organize training and retraining for the team in charge of personal data protection in the current context. In addition, businesses should consider developing internal criteria for professional competence, training materials and evidence proving the professional capacity of personnel. This will be an important basis when carrying out procedures for applying for a certificate of eligibility for business, as well as when the management agency conducts inspections.

    Lawyer Nguyen Ngoc Tra My

    HM&P Law Firm

     

    Read more: Khi dịch vụ xử lý dữ liệu cá nhân trở thành ngành nghề kinh doanh có điều kiện


     

    [1] Clause 1, Article 3 of the Commercial Law No. 35/2005/QH11 dated June 14, 2025 of the National Assembly.

     

    [2] Clause 21, Article 24 of the Law on Enterprises No. 59/2020/QH14 dated June 17, 2020 of the National Assembly.

     

    [3] Article 22 of Decree 356

     

    [4] Article 24 of Decree 356