Handbook on Personal Data Protection

Ngày đăng: Thursday, 08/01/26 Người đăng: Admin
Handbook on Personal Data Protection

HANDBOOK ON PERSONAL DATA PROTECTION 2025

This Handbook on Personal Data Protection 2025 originate from a practical observation: While many enterprises do not commit breach of laws intentionally, they are still exposed to legal risks only because of incorrect understanding and implementation of personal data protection.

Law on Personal Data Protection, which takes effect on 01/01/2026, has made personal data protection into a mandatory requirement, thus significant effect the entire life cycle of data processing within enterprises.

Instead of explaining the laws in an academic manner, the handbook on personal date protection 2025 is designed as a practical document that helps enterprises in answering fundamental questions such as: What is the starting point? Who shall be responsible? How and in what manner would compliance could be demonstrated?

TABLE OF CONTENTS

Preface
List of abbreviations
Chapter 1 - Legal framework and fundamental principles
  • Scope of application and applicable targets
  • Personal data protection principles
  • Prohibited acts
  • Prominent points of PDP Law 2025 in comparison to Decree No. 13/2023/ND-CP
Chapter 2 – Rights and obligations of data subjects
  • Rights and obligations of the Data Subjects
  • Responsibilities of relevant parties
  • Roles and responsibilities of data protection officer
Chapter 3 – Personal Data Processing
  • Concept and personal data processing activities
  • Requirements on the consent of the data subject
Chapter 4 – Internal compliance with laws on personal data protection
  • The role of enterprises in PDPT
  • Establishment of procedures for internal compliance
  • Impact assessment procedures
  • Ensuring the accountability of third parties
Chapter 5 – Personal Data Protection in specialized fields
  • Personal Data Protection in relation to everyday information
  • Personal Data Protection in labor
  • Personal Data Protection in specialized sectors
Chapter 6 – Handling of breaches, incidents and reports
  • Notification of breaches of personal data protection regulations
  • Handling of breaches of personal data protection regulations
  • Competent authorities for personal data protection
Personal Data Protection Services of CNC
Handbook team
Contact

WHY THIS HANDBOOK ON PERSONAL DATA PROTECTION 2025 IS RECOMMENDED FOR CEO/HR?

This Handbook on Personal Data Protection 2025 shall provide CEO/HR aids in the identification of data risks in daily operation, clear assignment of responsibility, and preparation of procedures for handling of incidents.

In the context of digital economy, personal data is no longer considered mere information, instead, it is viewed as core operating assets of the enterprise: candidate data, personnel documents, client data, behavioral data, biometric data.

However, these data also entail severe legal risks and credibility risks if the enterprise could not control the data processing life cycle in accordance with the Law on Personal Data Protection 2025.

In practice, while many enterprises do not commit “intentional breaches”, they are still exposed to risks of penalties, claims, or media crises simply because of:

  • Vague data processing purposes;
  • Absence of proper evidence of consent; or
  • Excessive sharing or use of data.

That is precisely why CNC has prepared the Handbook on Personal Data Protection 2025 to serve businesses, CEOs/HR professionals, and the broader community.

One of the most important changes bring about by the Law on Personal Data Protection 2025 is: compliance shall not stop at the promulgation of policies or internal regulations.

In practice, personal data protection shall only be effective if it is incorporated into the daily operation capacity of the enterprise, which include:

  • Explicit assignment of the data controller and data processor role;
  • Procedures for receipt and processing requests of the data subjects;
  • Mechanism for control of access, sharing, and archiving of data;
  • Plan for data incident response within the 24-72 initial hours of the occurence.

The Handbook on Personal Data Protection 2025 is created to help enterprises transition from “proper documentation” to “proper procedures, accountable personnel, and proof of compliance”.

It is common for existing personal data documents, despite being developed in accordance with international standards such as the GDPR, to face significant challenges when applied in the practical context of Vietnamese enterprises.

Aware of such issues, the Handbook on Personal Data Protection 2025 has been drafred based on:

  • The legal framework of Vietnam, with the Law on Personal Data Protection 2025 at its core;
  • The exclusive traits of enteprises operating in Vietnam: medium and small scale, with limited resources allocated to legal and IT department
  • Common scenarios that occur during recruitment, management of personnel, marketing, and cooperation with the suppliers and technological partners.

Due to the above, the handbook would not only help enterprises to have “correct understanding of laws”, but also enable them to make practial application, instead of simply copying from an unstuiable compliance model.

HR

  • Keeping applicant records longer than necessary
  • Biometric time attendance without notification/consent
  • Upload personnel data to cloud services located outside of Vietnam

Sales/Marketing

  • Lead generation without clear categorization of purposes
  • Sharing data to agency/vendor under vague contracts
  • Use of camera/event recordings for marketing purpoes

PRACTICAL EXAMPLES OF PERSONAL DATA PROTECTION IN 2025

In September 2025, there were reports of a major personal data breach involving the Credit Information Center. This Handbook on Personal Data Protection shall summarize the events and provide key takeaways pertaining to management of data risks.

What could enterprises learn from this incident?

  • Preparation of plans for incident response and communication plan
  • Access logs, permission controls, and internal monitoring mechanisms
  • Transparent liaison with the competent authorities for risk mitigation

CHECKING PERSONAL DATA PROTECTION COMPLIANCE STATUS 2025?

Along with the Personal Data Protection Handbook, CNC has prepared the 5–7 minute self-assessment checklist below to help CEOs/HR determine their organization’s current level and identify the top three priorities for action. This serves as a “starting step” for enterprises to evaluate and adjust their data management and usage policies accordingly.

INTRODUCTION

This self-assessment checklist allows enterprises to check their readiness to comply with the laws of Vietnam on personal data protection

The purpose of this document is to support enterprises to identify potential risks and priorities for action instead of serving as a replacement for legal consulting.

INSTRUCTIONS

For each question, please put  (✔) mark into the most appropriate box

ENTERPRISE INFORMATION

Enterprise name:………………………………………………

Respondent/Position:……………………………………….

Contact email:…………………………………………………

Scale: ☐ <20 ☐ 20–100 ☐ 100–500 ☐ >500

PART I – MANAGEMENT STRUCTURE & LEGAL RESPONSIBILITIES

No Question

Yes

Partially

No

1 Has the enterprise identified which individual/department holds primary legal responsibility for personal data protection?

2 Is this responsibility documented in internal records (policies, decisions, JD, etc)?

3 Does the board of executives recognize that personal data protection is not merely an IT issue, but a responsibility of the legal entity and its managers?

4 Does the enterprise have an internal approval mechanism for new activities involving the collection, processing, or sharing of personal data?

5 When there is an inspection or claim, has the enterprise decided on the offical representative responsible for providing explanations?

 

PART II – DATA DIAGRAM & SCOPE OF APPLICATION

No Question

Yes

Partially

No

6 Has the enterprise classified the currently processed personal protection data (personnel, client, partner, etc)?

7 Does the enterprise know where personal data is being stored (internally, cloud services, or with third parties)

8 Is there a separation between normal personal data and sensitive personal data?

9 Is the data sharing with third parties (vendors, agencies, partners) under supervision and subject to approval?

10 Does the enterprise engage in cross-border transfers of personal data (e.g., to servers, group systems, or headquarters abroad)

 

PART III – LEGAL BASES & CONSENT MECHANISM

No Question

Yes

Partially

No

11 Has the company identified the legal basis for each personal data processing activity (not relying solely on consent)?

12 Can the data subject’s consent be demonstrated (e.g., through logs, documents, or system records)?

13 Are data subjects fully informed about the purpose, scope, and duration of data processing?

14 Does the enterprise have a mechanism to withdraw consent or to receive requests from data subjects?

 

PART IV – PERSONNEL DATA

No Question

Yes

Partially

No

15 Does the enterprise specify who is authorized to access personnel records?

16 Are access rights to data promptly revoked when employees leave the company?

17 Have personnel records ever been shared through uncontrolled channels (personal email, chat, open drives)?

 

PART V – DATA BREACHES & ACCOUNTABILITY

No Question

Yes

Partially

No

18 Does the company have a response plan in place for personal data breaches?

19 Upon the occurence of the incident, have the role, timeframe, and report procedures been identified?

20 “Assuming that inspection or claim is made tomorrow, would the enterprise have sufficient documentation to demonstrate reasonable compliance?

RESULT INTERPRETATION (FOR REFERENCE PURPOSES)

0-6 check marks in “No” boxes: The enterprise already have the foundation established, further improvement is advised

7-12 check marks in “No” boxes: The enterprise is exposed to certain legal risks

More than 12 check marks in “No” boxes: The enterprise faces high risks in the event of inspection or data breaches

The above results are conjectural in nature and do not constitute legal conclusions.

FROM SELF-ASSESSMENT TO IMPLEMENTATION

This self-assessment checklist serves as a starting point to help businesses identify risks and determine action priorities.

Paper compliance is not the purpose of CNC, instead, we aim to support enterprises in developing the capability to withstand issues when they arise. As one of the few law firms in Vietnam specializing in personal data protection, corporate internal compliance, and anti-bribery and anti-corruption, CNC provides comprehensive and effective legal solutions to clients worldwide.

Click here to download the Handbook on Personal Data Protection 2025!

CONTACT

For more information, please contact CNC Vietnam Law Firm Co., Ltd, with the address of 2A1 Nguyen Thi Minh Khai, Sai Gon Ward, Ho Chi Minh City, Vietnam, phone number + 84-028 6276 9900 or email contact@cnccounsel.com or hotline +84-0916 545 618 (Mr. Le The Hung)

    Content Protection by DMCA.com

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.