HANDBOOK ON PERSONAL DATA PROTECTION 2025
This Handbook on Personal Data Protection 2025 originate from a practical observation: While many enterprises do not commit breach of laws intentionally, they are still exposed to legal risks only because of incorrect understanding and implementation of personal data protection.
Law on Personal Data Protection, which takes effect on 01/01/2026, has made personal data protection into a mandatory requirement, thus significant effect the entire life cycle of data processing within enterprises.
Instead of explaining the laws in an academic manner, the handbook on personal date protection 2025 is designed as a practical document that helps enterprises in answering fundamental questions such as: What is the starting point? Who shall be responsible? How and in what manner would compliance could be demonstrated?
TABLE OF CONTENTS
- Scope of application and applicable targets
- Personal data protection principles
- Prohibited acts
- Prominent points of PDP Law 2025 in comparison to Decree No. 13/2023/ND-CP
- Rights and obligations of the Data Subjects
- Responsibilities of relevant parties
- Roles and responsibilities of data protection officer
- Concept and personal data processing activities
- Requirements on the consent of the data subject
- The role of enterprises in PDPT
- Establishment of procedures for internal compliance
- Impact assessment procedures
- Ensuring the accountability of third parties
- Personal Data Protection in relation to everyday information
- Personal Data Protection in labor
- Personal Data Protection in specialized sectors
- Notification of breaches of personal data protection regulations
- Handling of breaches of personal data protection regulations
- Competent authorities for personal data protection
- Case summary
- Temporary Solution
- Lessons from the case
WHY THIS HANDBOOK ON PERSONAL DATA PROTECTION 2025 IS RECOMMENDED FOR CEO/HR?
This Handbook on Personal Data Protection 2025 shall provide CEO/HR aids in the identification of data risks in daily operation, clear assignment of responsibility, and preparation of procedures for handling of incidents.
In the context of digital economy, personal data is no longer considered mere information, instead, it is viewed as core operating assets of the enterprise: candidate data, personnel documents, client data, behavioral data, biometric data.
However, these data also entail severe legal risks and credibility risks if the enterprise could not control the data processing life cycle in accordance with the Law on Personal Data Protection 2025.
In practice, while many enterprises do not commit “intentional breaches”, they are still exposed to risks of penalties, claims, or media crises simply because of:
- Vague data processing purposes;
- Absence of proper evidence of consent; or
- Excessive sharing or use of data.
That is precisely why CNC has prepared the Handbook on Personal Data Protection 2025 to serve businesses, CEOs/HR professionals, and the broader community.
One of the most important changes bring about by the Law on Personal Data Protection 2025 is: compliance shall not stop at the promulgation of policies or internal regulations.
In practice, personal data protection shall only be effective if it is incorporated into the daily operation capacity of the enterprise, which include:
- Explicit assignment of the data controller and data processor role;
- Procedures for receipt and processing requests of the data subjects;
- Mechanism for control of access, sharing, and archiving of data;
- Plan for data incident response within the 24-72 initial hours of the occurence.
The Handbook on Personal Data Protection 2025 is created to help enterprises transition from “proper documentation” to “proper procedures, accountable personnel, and proof of compliance”.
It is common for existing personal data documents, despite being developed in accordance with international standards such as the GDPR, to face significant challenges when applied in the practical context of Vietnamese enterprises.
Aware of such issues, the Handbook on Personal Data Protection 2025 has been drafred based on:
- The legal framework of Vietnam, with the Law on Personal Data Protection 2025 at its core;
- The exclusive traits of enteprises operating in Vietnam: medium and small scale, with limited resources allocated to legal and IT department
- Common scenarios that occur during recruitment, management of personnel, marketing, and cooperation with the suppliers and technological partners.
Due to the above, the handbook would not only help enterprises to have “correct understanding of laws”, but also enable them to make practial application, instead of simply copying from an unstuiable compliance model.
HR
- Keeping applicant records longer than necessary
- Biometric time attendance without notification/consent
- Upload personnel data to cloud services located outside of Vietnam
Sales/Marketing
- Lead generation without clear categorization of purposes
- Sharing data to agency/vendor under vague contracts
- Use of camera/event recordings for marketing purpoes
PRACTICAL EXAMPLES OF PERSONAL DATA PROTECTION IN 2025
In September 2025, there were reports of a major personal data breach involving the Credit Information Center. This Handbook on Personal Data Protection shall summarize the events and provide key takeaways pertaining to management of data risks.
What could enterprises learn from this incident?
- Preparation of plans for incident response and communication plan
- Access logs, permission controls, and internal monitoring mechanisms
- Transparent liaison with the competent authorities for risk mitigation
CHECKING PERSONAL DATA PROTECTION COMPLIANCE STATUS 2025?
Along with the Personal Data Protection Handbook, CNC has prepared the 5–7 minute self-assessment checklist below to help CEOs/HR determine their organization’s current level and identify the top three priorities for action. This serves as a “starting step” for enterprises to evaluate and adjust their data management and usage policies accordingly.
INTRODUCTION
This self-assessment checklist allows enterprises to check their readiness to comply with the laws of Vietnam on personal data protection
The purpose of this document is to support enterprises to identify potential risks and priorities for action instead of serving as a replacement for legal consulting.
INSTRUCTIONS
For each question, please put (✔) mark into the most appropriate box
ENTERPRISE INFORMATION
Enterprise name:………………………………………………
Respondent/Position:……………………………………….
Contact email:…………………………………………………
Scale: ☐ <20 ☐ 20–100 ☐ 100–500 ☐ >500
PART I – MANAGEMENT STRUCTURE & LEGAL RESPONSIBILITIES
| No | Question |
Yes |
Partially |
No |
| 1 | Has the enterprise identified which individual/department holds primary legal responsibility for personal data protection? |
☐ |
☐ |
☐ |
| 2 | Is this responsibility documented in internal records (policies, decisions, JD, etc)? |
☐ |
☐ |
☐ |
| 3 | Does the board of executives recognize that personal data protection is not merely an IT issue, but a responsibility of the legal entity and its managers? |
☐ |
☐ |
☐ |
| 4 | Does the enterprise have an internal approval mechanism for new activities involving the collection, processing, or sharing of personal data? |
☐ |
☐ |
☐ |
| 5 | When there is an inspection or claim, has the enterprise decided on the offical representative responsible for providing explanations? |
☐ |
☐ |
☐ |
PART II – DATA DIAGRAM & SCOPE OF APPLICATION
| No | Question |
Yes |
Partially |
No |
| 6 | Has the enterprise classified the currently processed personal protection data (personnel, client, partner, etc)? |
☐ |
☐ |
☐ |
| 7 | Does the enterprise know where personal data is being stored (internally, cloud services, or with third parties) |
☐ |
☐ |
☐ |
| 8 | Is there a separation between normal personal data and sensitive personal data? |
☐ |
☐ |
☐ |
| 9 | Is the data sharing with third parties (vendors, agencies, partners) under supervision and subject to approval? |
☐ |
☐ |
☐ |
| 10 | Does the enterprise engage in cross-border transfers of personal data (e.g., to servers, group systems, or headquarters abroad) |
☐ |
☐ |
☐ |
PART III – LEGAL BASES & CONSENT MECHANISM
| No | Question |
Yes |
Partially |
No |
| 11 | Has the company identified the legal basis for each personal data processing activity (not relying solely on consent)? |
☐ |
☐ |
☐ |
| 12 | Can the data subject’s consent be demonstrated (e.g., through logs, documents, or system records)? |
☐ |
☐ |
☐ |
| 13 | Are data subjects fully informed about the purpose, scope, and duration of data processing? |
☐ |
☐ |
☐ |
| 14 | Does the enterprise have a mechanism to withdraw consent or to receive requests from data subjects? |
☐ |
☐ |
☐ |
PART IV – PERSONNEL DATA
| No | Question |
Yes |
Partially |
No |
| 15 | Does the enterprise specify who is authorized to access personnel records? |
☐ |
☐ |
☐ |
| 16 | Are access rights to data promptly revoked when employees leave the company? |
☐ |
☐ |
☐ |
| 17 | Have personnel records ever been shared through uncontrolled channels (personal email, chat, open drives)? |
☐ |
☐ |
☐ |
PART V – DATA BREACHES & ACCOUNTABILITY
| No | Question |
Yes |
Partially |
No |
| 18 | Does the company have a response plan in place for personal data breaches? |
☐ |
☐ |
☐ |
| 19 | Upon the occurence of the incident, have the role, timeframe, and report procedures been identified? |
☐ |
☐ |
☐ |
| 20 | “Assuming that inspection or claim is made tomorrow, would the enterprise have sufficient documentation to demonstrate reasonable compliance? |
☐ |
☐ |
☐ |
RESULT INTERPRETATION (FOR REFERENCE PURPOSES)
0-6 check marks in “No” boxes: The enterprise already have the foundation established, further improvement is advised
7-12 check marks in “No” boxes: The enterprise is exposed to certain legal risks
More than 12 check marks in “No” boxes: The enterprise faces high risks in the event of inspection or data breaches
The above results are conjectural in nature and do not constitute legal conclusions.
FROM SELF-ASSESSMENT TO IMPLEMENTATION
This self-assessment checklist serves as a starting point to help businesses identify risks and determine action priorities.
Paper compliance is not the purpose of CNC, instead, we aim to support enterprises in developing the capability to withstand issues when they arise. As one of the few law firms in Vietnam specializing in personal data protection, corporate internal compliance, and anti-bribery and anti-corruption, CNC provides comprehensive and effective legal solutions to clients worldwide.
CONTACT
For more information, please contact CNC Vietnam Law Firm Co., Ltd, with the address of 2A1 Nguyen Thi Minh Khai, Sai Gon Ward, Ho Chi Minh City, Vietnam, phone number + 84-028 6276 9900 or email contact@cnccounsel.com or hotline +84-0916 545 618 (Mr. Le The Hung)




