Effective 1 January 2026, Decree 356/2025/NĐ-CP (Decree 356) replaces Decree 13/2023/NĐ-CP (Decree 13), providing detailed implementation guidance for the Law on Personal Data Protection 2025 (PDPL).
Decree 356 marks a critical transition in Vietnam’s personal data protection regime. While Decree 13 introduced the foundational framework, Decree 356 (together with the PDPL) moves PDP compliance into an operational and enforceable phase, with clearer standards, defined responsibilities, and time-bound obligations that organisations must be able to demonstrate in practice.
For many organisations, this shift demands far more than just updating policies. It requires meeting multiple regulatory requirements, implementing compliance procedures, appointing responsible personnel, and most importantly, preventing and mitigating data breaches and risks that could lead to severe penalties or other legal liabilities. It calls for a review of data flows, consent mechanisms, internal governance, and response procedures, particularly in light of increased enforcement exposure from 2026 and years forward.
This newsletter outlines the key regulatory changes under Decree 356 and highlights the practical actions organisations should consider now to align their operations with the upcoming compliance expectations.
1. Clarifying the practical approach
Decree 13 emphasised a universal, theory-driven, and interpretative approach, as it represented Vietnam’s first legal framework on personal data protection.
In contrast, Decree 356 introduces more technical and specialised compliance requirements. It sets out new scenarios, obligations, and mandates the use of structured tools such as diagrams, tables, and systematic frameworks that are practical and tailored to each organisation acting as a data controller or processor.
Action required: Organisations should reassess their processes, policies, and governance frameworks, and define responsibilities clearly. Avoid generic or ambiguous approaches that could create compliance gaps or fail to address real-world situations
2. Personal data protection applies to all forms of data
Under Decree 13, compliance efforts were often interpreted as focusing primarily on electronic personal data, resulting in data protection being treated largely as an IT or cybersecurity issue.
Decree 356, read together with the PDPL, removes this ambiguity. Personal data protection obligations apply to all personal data, regardless of:
- Format (electronic or physical);
- Method of storage; or
- Means of processing.
Action required: Enterprises must extend PDP compliance reviews beyond IT systems to include paper files, manual records, HR documentation, and internal operational workflows.
3. Recalibrated classification of sensitive personal data
Decree 356 revises and clarifies the distinction between basic personal data and sensitive personal data compared to Decree 13.
In particular, the scope of sensitive personal data is clarified and expanded to include, among others:
- Financial and banking information;
- Authentication and access credentials;
- Behavioural and usage data in digital environments; and
- Information relating to legal violations, even where criminal liability does not arise.
It is important to note that photos of Vietnam ID/Citizen Cards are classified as sensitive personal data under Decree 356. This classification triggers additional obligations for businesses, such as appointing a personal data protection officer, conducting a personal data processing impact assessment, notifying data subjects about the processing of sensitive data, and implementing strict access controls for handling, transferring, storing, and deleting such data. Collecting ID cards is a common practice for purposes such as verification, onboarding, office access, and KYC.
Action required: Enterprises should reassess their data inventory to confirm whether sensitive personal data is processed in practice, as this directly affects security measures, impact assessment requirements, and eligibility for regulatory exemptions.
4. Fixed timelines for responding to data subject requests
One of the most significant procedural changes under Decree 356 is the introduction of clear and enforceable timelines for responding to requests from data subjects.
Under Decree 13, the regulation only referred generally to a 72-hour timeframe, which led to inconsistent application in practice. Decree 356 replaces this with a structured response and execution mechanism, depending on the type of request.
0评论2026-05-267
0评论2026-05-144
0评论2026-04-214
0评论2026-04-1210
0评论2026-02-262
0评论2026-02-257
0评论2026-02-128
0评论2026-01-309
0评论2026-01-144