Vietnam’s Personal Data Law and its Implementing Decree (Decree 356/2025/ND-CP)
PUBLIC
Vietnam’s Personal Data Law and its
Implementing Decree (Decree 356/2025/ND-
CP)
Updated Frequently Asked Questions
May 2026
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
Vietnam’s Personal Data Law and its
Implementing Decree (Decree 356/2025/ND-
CP)
Updated Frequently Asked Questions
May 2026
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
Vietnam has entered a new phase in personal data protection with the Personal Data Protection
Law 2025 (PDPL) and its implementing regulation, Decree 356/2025/ND-CP, which took effect
on 1 January 2026. Together, these instruments replace the previous Personal Data Protection
Decree (Decree 13/2023/ND-CP) and establish a more consolidated and transparent data
protection framework. The new regime introduces clearer definitions and classifications of
personal data, including updated distinctions between basic and sensitive personal data. It
also sets out more detailed procedural and compliance requirements, giving organizations
greater regulatory certainty while strengthening protections for individuals. Overall, the PDPL
aims to promote more consistent and accountable handling of personal data across all sectors
in Vietnam.
Key Compliance Expectations under Vietnam’s PDPL and Decree 356
Under the PDPL and Decree 356, organizations processing personal data in Vietnam are now subject to more
clearly defined compliance obligations. As with the earlier PDPD, the framework remains consent-centric, but
with strengthened expectations around data security and governance, revised timelines for responding to data
subject requests, and formalized requirements to prepare Data Processing Impact Assessment (DPIA) and Cross-
Border Transfer Impact Assessment (CTIA) reports. Both assessments must follow official templates and are
subject to review by the Ministry of Public Security, reflecting a shift toward a more standardized and predictable
regulatory environment for managing personal data.
SAP remains committed to meeting its privacy, security, and global compliance obligations in this evolving
regulatory landscape. SAP’s internal policies and governance frameworks are designed to support compliance
with data protection requirements worldwide, including those under Vietnam’s PDPL and Decree 356. SAP
implements robust technical and organizational measures and maintains comprehensive audit and certification
programs, demonstrating its ongoing commitment to data protection and privacy. Customers can learn more
about SAP’s privacy posture through SAP’s Data Protection and Privacy resources.
Customer PDPL Frequently Asked Questions (FAQ)
Building on these commitments, the following Customer PDPL Frequently Asked Questions address common
questions about SAP’s approach to personal data protection and compliance under Vietnam’s Personal Data
Protection Law.
• Given that customers must choose a data processor with appropriate personal data
protections, what agreement does SAP enter into with customers before processing any
personal data?
SAP’s Data Processing Agreement explains how SAP processes personal data of customers and end users
when providing SAP Cloud Services, Support, and Professional Services. The agreement clarifies the
respective roles and responsibilities of SAP and its customers, establishes contractual safeguards for
personal data, and supports compliance with applicable data protection and privacy laws worldwide.
By setting clear expectations for how personal data is handled and protected, the agreement helps promote
consistency and accountability for both SAP and its customers. For this reason, it applies to every customer
transaction involving the processing of personal data and forms an integral part of SAP’s overall contractual
framework.
Please read the SAP DPA FAQs here: https://www.sap.com/about/trust-center/data-
privacy.html?pdfasset=d46da9fc-157f-0010-bca6-c68f7e60039b&page=7.
Law 2025 (PDPL) and its implementing regulation, Decree 356/2025/ND-CP, which took effect
on 1 January 2026. Together, these instruments replace the previous Personal Data Protection
Decree (Decree 13/2023/ND-CP) and establish a more consolidated and transparent data
protection framework. The new regime introduces clearer definitions and classifications of
personal data, including updated distinctions between basic and sensitive personal data. It
also sets out more detailed procedural and compliance requirements, giving organizations
greater regulatory certainty while strengthening protections for individuals. Overall, the PDPL
aims to promote more consistent and accountable handling of personal data across all sectors
in Vietnam.
Key Compliance Expectations under Vietnam’s PDPL and Decree 356
Under the PDPL and Decree 356, organizations processing personal data in Vietnam are now subject to more
clearly defined compliance obligations. As with the earlier PDPD, the framework remains consent-centric, but
with strengthened expectations around data security and governance, revised timelines for responding to data
subject requests, and formalized requirements to prepare Data Processing Impact Assessment (DPIA) and Cross-
Border Transfer Impact Assessment (CTIA) reports. Both assessments must follow official templates and are
subject to review by the Ministry of Public Security, reflecting a shift toward a more standardized and predictable
regulatory environment for managing personal data.
SAP remains committed to meeting its privacy, security, and global compliance obligations in this evolving
regulatory landscape. SAP’s internal policies and governance frameworks are designed to support compliance
with data protection requirements worldwide, including those under Vietnam’s PDPL and Decree 356. SAP
implements robust technical and organizational measures and maintains comprehensive audit and certification
programs, demonstrating its ongoing commitment to data protection and privacy. Customers can learn more
about SAP’s privacy posture through SAP’s Data Protection and Privacy resources.
Customer PDPL Frequently Asked Questions (FAQ)
Building on these commitments, the following Customer PDPL Frequently Asked Questions address common
questions about SAP’s approach to personal data protection and compliance under Vietnam’s Personal Data
Protection Law.
• Given that customers must choose a data processor with appropriate personal data
protections, what agreement does SAP enter into with customers before processing any
personal data?
SAP’s Data Processing Agreement explains how SAP processes personal data of customers and end users
when providing SAP Cloud Services, Support, and Professional Services. The agreement clarifies the
respective roles and responsibilities of SAP and its customers, establishes contractual safeguards for
personal data, and supports compliance with applicable data protection and privacy laws worldwide.
By setting clear expectations for how personal data is handled and protected, the agreement helps promote
consistency and accountability for both SAP and its customers. For this reason, it applies to every customer
transaction involving the processing of personal data and forms an integral part of SAP’s overall contractual
framework.
Please read the SAP DPA FAQs here: https://www.sap.com/about/trust-center/data-
privacy.html?pdfasset=d46da9fc-157f-0010-bca6-c68f7e60039b&page=7.
• Does SAP use subprocessors and where are they located?
Yes. SAP uses subprocessors to support and deliver its products and services. Customers can access an up-
to-date list of SAP subprocessors through the SAP Support Portal at: https://support.sap.com/en/my-
support/trust-center/subprocessors.html
The subprocessor lists include details on the location and country of each subprocessor per product or
service. Customers may also subscribe to these lists to receive email notifications when changes occur.
Before engaging any subprocessor, SAP conducts a thorough assessment of the subprocessor’s security,
privacy, and confidentiality practices. All subprocessors are required to enter into written agreements with
SAP that include appropriate data protection and security obligations, consistent with SAP’s commitment to
safeguarding personal data.
• Where is personal data physically stored?
Personal data processed as part of SAP cloud solutions is stored in SAP data centers that are assigned to the
relevant service. Customers can view the current data center locations for their selected SAP cloud solutions
via SAP’s data center location information page: SAP Data Center | SAP Trust Center.
• How does SAP comply with its obligation to apply administrative, technical and organizational
measures to protect personal data when acting as a data processor on behalf of its
customers?
SAP implements a comprehensive set of administrative, technical, and organizational measures to protect
personal data in line with its role as a data processor as set forth in its Security Measures for Cloud
Services/Technical and Organizational Measures (TOMs), which can be found here: Policies, Frameworks, TOMs
and Support Schedules.
• What categories of personal data does SAP process?
The categories of personal data processed by SAP depend on several factors, including the specific products
and services a customer subscribes to, the personal data uploaded by the customer in SAP products and
services, and how the customer configures data fields within those products and services.
Schedule 1 of the applicable SAP data processing agreement include a description of the relevant data
subjects and categories of personal data. Customers can access the current documentation for SAP Cloud
Services here:
https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html
Special or sensitive categories of personal data should only be processed in SAP services where this has been
explicitly agreed between the parties in writing as part of the contractual arrangement.
• For what purposes is customers’ personal data processed?
The purposes for which SAP processes personal data are described in Schedule 1 “Description of Processing”
1 of the applicable SAP data processing agreement, which outlines how and why personal data is processed in
connection with the delivery of the relevant products and services.
• How long does SAP store personal data, given PDPL requirements to delete data certain
circumstances?
Customers determine what personal data is uploaded to SAP Cloud Services and retain control over that data
throughout the term of the applicable order form. Customers can manage and delete personal data directly
within the service during the contract term. Further information regarding data retention, export, and deletion
options is set out in the applicable general agreement and data processing terms concluded with SAP, which
describe how data is handled during and after the provision of SAP products and services.
• Is SAP required to prepare impact-assessment dossiers under Vietnam’s PDPL for personal
data processing and cross-border data transfers, and has SAP done so?
Yes. SAP uses subprocessors to support and deliver its products and services. Customers can access an up-
to-date list of SAP subprocessors through the SAP Support Portal at: https://support.sap.com/en/my-
support/trust-center/subprocessors.html
The subprocessor lists include details on the location and country of each subprocessor per product or
service. Customers may also subscribe to these lists to receive email notifications when changes occur.
Before engaging any subprocessor, SAP conducts a thorough assessment of the subprocessor’s security,
privacy, and confidentiality practices. All subprocessors are required to enter into written agreements with
SAP that include appropriate data protection and security obligations, consistent with SAP’s commitment to
safeguarding personal data.
• Where is personal data physically stored?
Personal data processed as part of SAP cloud solutions is stored in SAP data centers that are assigned to the
relevant service. Customers can view the current data center locations for their selected SAP cloud solutions
via SAP’s data center location information page: SAP Data Center | SAP Trust Center.
• How does SAP comply with its obligation to apply administrative, technical and organizational
measures to protect personal data when acting as a data processor on behalf of its
customers?
SAP implements a comprehensive set of administrative, technical, and organizational measures to protect
personal data in line with its role as a data processor as set forth in its Security Measures for Cloud
Services/Technical and Organizational Measures (TOMs), which can be found here: Policies, Frameworks, TOMs
and Support Schedules.
• What categories of personal data does SAP process?
The categories of personal data processed by SAP depend on several factors, including the specific products
and services a customer subscribes to, the personal data uploaded by the customer in SAP products and
services, and how the customer configures data fields within those products and services.
Schedule 1 of the applicable SAP data processing agreement include a description of the relevant data
subjects and categories of personal data. Customers can access the current documentation for SAP Cloud
Services here:
https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html
Special or sensitive categories of personal data should only be processed in SAP services where this has been
explicitly agreed between the parties in writing as part of the contractual arrangement.
• For what purposes is customers’ personal data processed?
The purposes for which SAP processes personal data are described in Schedule 1 “Description of Processing”
1 of the applicable SAP data processing agreement, which outlines how and why personal data is processed in
connection with the delivery of the relevant products and services.
• How long does SAP store personal data, given PDPL requirements to delete data certain
circumstances?
Customers determine what personal data is uploaded to SAP Cloud Services and retain control over that data
throughout the term of the applicable order form. Customers can manage and delete personal data directly
within the service during the contract term. Further information regarding data retention, export, and deletion
options is set out in the applicable general agreement and data processing terms concluded with SAP, which
describe how data is handled during and after the provision of SAP products and services.
• Is SAP required to prepare impact-assessment dossiers under Vietnam’s PDPL for personal
data processing and cross-border data transfers, and has SAP done so?
Yes. Under the Personal Data Protection Law (PDPL) and Decree 356, organizations are required to prepare and
maintain Personal Data Processing Impact Assessment (DPIA) dossiers and, where applicable, Cross-Border
Transfer Impact Assessment (CTIA) dossiers. These dossiers must be prepared using the prescribed forms and
submitted to the Ministry of Public Security within 60 days from the start of personal data processing or from
the date personal data is transferred outside Vietnam, as applicable.
SAP has prepared the required DPIA dossiers and, where relevant, CTIA dossiers in accordance with its
obligations under the PDPL and Decree 356. SAP continues to follow the applicable procedures, prescribed
forms, and submission timelines, reflecting its ongoing compliance with Vietnam’s personal data protection
requirements.
• Does SAP provide copies of its PDPL impact-assessment dossiers to customers, and how does
SAP assist customers with their own assessments?
SAP does not share its own regulatory impact-assessment dossiers with customers and does not provide legal
advice. The determination of whether an impact assessment is required, and how such an assessment must be
conducted, remains the customer’s responsibility under applicable law where the customer acts as a data
controller.
However, in line with its role as a data processor and its contractual cooperation obligations, SAP will reasonably
assist customers in meeting their data protection obligations. Such assistance is provided based on generally
available information and may include supporting customers in understanding SAP’s products and services,
security measures, and processing activities as relevant to the customer’s own impact assessments. This
cooperation is provided in accordance with SAP’s applicable contractual terms and does not replace the
customer’s independent legal or regulatory assessment.
• How does SAP demonstrate its commitment to data protection and privacy?
SAP demonstrates its commitment to data protection and privacy through a robust global compliance and
governance approach. SAP continuously monitors developments in data protection and privacy laws
worldwide and implements appropriate safeguards to protect the fundamental rights and freedoms of
individuals whose personal data it processes.
In addition, SAP maintains a portfolio of independent third-party audit reports, certifications, and attestations
that help demonstrate compliance with data protection and privacy requirements. These externally validated
measures support SAP’s ongoing efforts to uphold privacy and data protection standards across its
operations, products and services. Customers can find further information on SAP’s approach to data
protection and compliance on the SAP Trust Center and at www.sap.com.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/3
maintain Personal Data Processing Impact Assessment (DPIA) dossiers and, where applicable, Cross-Border
Transfer Impact Assessment (CTIA) dossiers. These dossiers must be prepared using the prescribed forms and
submitted to the Ministry of Public Security within 60 days from the start of personal data processing or from
the date personal data is transferred outside Vietnam, as applicable.
SAP has prepared the required DPIA dossiers and, where relevant, CTIA dossiers in accordance with its
obligations under the PDPL and Decree 356. SAP continues to follow the applicable procedures, prescribed
forms, and submission timelines, reflecting its ongoing compliance with Vietnam’s personal data protection
requirements.
• Does SAP provide copies of its PDPL impact-assessment dossiers to customers, and how does
SAP assist customers with their own assessments?
SAP does not share its own regulatory impact-assessment dossiers with customers and does not provide legal
advice. The determination of whether an impact assessment is required, and how such an assessment must be
conducted, remains the customer’s responsibility under applicable law where the customer acts as a data
controller.
However, in line with its role as a data processor and its contractual cooperation obligations, SAP will reasonably
assist customers in meeting their data protection obligations. Such assistance is provided based on generally
available information and may include supporting customers in understanding SAP’s products and services,
security measures, and processing activities as relevant to the customer’s own impact assessments. This
cooperation is provided in accordance with SAP’s applicable contractual terms and does not replace the
customer’s independent legal or regulatory assessment.
• How does SAP demonstrate its commitment to data protection and privacy?
SAP demonstrates its commitment to data protection and privacy through a robust global compliance and
governance approach. SAP continuously monitors developments in data protection and privacy laws
worldwide and implements appropriate safeguards to protect the fundamental rights and freedoms of
individuals whose personal data it processes.
In addition, SAP maintains a portfolio of independent third-party audit reports, certifications, and attestations
that help demonstrate compliance with data protection and privacy requirements. These externally validated
measures support SAP’s ongoing efforts to uphold privacy and data protection standards across its
operations, products and services. Customers can find further information on SAP’s approach to data
protection and compliance on the SAP Trust Center and at www.sap.com.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/3