Vietnam’s Personal Data Law and its Implementing Decree (Decree 356/2025/ND-CP)

Vietnam’s Personal Data Protection Law 2025 and Decree 356/2025/ND-CP establish a comprehensive data protection framework. SAP supports compliance with these regulations through robust technical and organizational measures, ensuring data security and privacy for its customers. Изтегли документа

PUBLICVietnam’s Personal Data Law and itsImplementing Decree (Decree 356/2025/ND-CP)Updated Frequently Asked QuestionsMay 2026The information contained in this document is for general informational purposes only and isprovided on the understanding that SAP is not engaged in rendering legal advice. SAP acceptsno liability for any actions taken in response to this resource. As such, it should not be used as asubstitute for legal or professional consultation.
Vietnam has entered a new phase in personal data protection with the Personal Data ProtectionLaw 2025 (PDPL) and its implementing regulation, Decree 356/2025/ND-CP, which took effecton 1 January 2026. Together, these instruments replace the previous Personal Data ProtectionDecree (Decree 13/2023/ND-CP) and establish a more consolidated and transparent dataprotection framework. The new regime introduces clearer definitions and classifications ofpersonal data, including updated distinctions between basic and sensitive personal data. Italso sets out more detailed procedural and compliance requirements, giving organizationsgreater regulatory certainty while strengthening protections for individuals. Overall, the PDPLaims to promote more consistent and accountable handling of personal data across all sectorsin Vietnam.Key Compliance Expectations under Vietnam’s PDPL and Decree 356Under the PDPL and Decree 356, organizations processing personal data in Vietnam are now subject to moreclearly defined compliance obligations. As with the earlier PDPD, the framework remains consent-centric, butwith strengthened expectations around data security and governance, revised timelines for responding to datasubject requests, and formalized requirements to prepare Data Processing Impact Assessment (DPIA) and Cross-Border Transfer Impact Assessment (CTIA) reports. Both assessments must follow official templates and aresubject to review by the Ministry of Public Security, reflecting a shift toward a more standardized and predictableregulatory environment for managing personal data.SAP remains committed to meeting its privacy, security, and global compliance obligations in this evolvingregulatory landscape. SAP’s internal policies and governance frameworks are designed to support compliancewith data protection requirements worldwide, including those under Vietnam’s PDPL and Decree 356. SAPimplements robust technical and organizational measures and maintains comprehensive audit and certificationprograms, demonstrating its ongoing commitment to data protection and privacy. Customers can learn moreabout SAP’s privacy posture through SAP’s Data Protection and Privacy resources.Customer PDPL Frequently Asked Questions (FAQ)Building on these commitments, the following Customer PDPL Frequently Asked Questions address commonquestions about SAP’s approach to personal data protection and compliance under Vietnam’s Personal DataProtection Law. Given that customers must choose a data processor with appropriate personal dataprotections, what agreement does SAP enter into with customers before processing anypersonal data?SAP’s Data Processing Agreement explains how SAP processes personal data of customers and end userswhen providing SAP Cloud Services, Support, and Professional Services. The agreement clarifies therespective roles and responsibilities of SAP and its customers, establishes contractual safeguards forpersonal data, and supports compliance with applicable data protection and privacy laws worldwide.By setting clear expectations for how personal data is handled and protected, the agreement helps promoteconsistency and accountability for both SAP and its customers. For this reason, it applies to every customertransaction involving the processing of personal data and forms an integral part of SAP’s overall contractualframework.Please read the SAP DPA FAQs here: https://www.sap.com/about/trust-center/data-privacy.html?pdfasset=d46da9fc-157f-0010-bca6-c68f7e60039b&page=7.
Does SAP use subprocessors and where are they located?Yes. SAP uses subprocessors to support and deliver its products and services. Customers can access an up-to-date list of SAP subprocessors through the SAP Support Portal at: https://support.sap.com/en/my-support/trust-center/subprocessors.htmlThe subprocessor lists include details on the location and country of each subprocessor per product orservice. Customers may also subscribe to these lists to receive email notifications when changes occur.Before engaging any subprocessor, SAP conducts a thorough assessment of the subprocessor’s security,privacy, and confidentiality practices. All subprocessors are required to enter into written agreements withSAP that include appropriate data protection and security obligations, consistent with SAP’s commitment tosafeguarding personal data. Where is personal data physically stored?Personal data processed as part of SAP cloud solutions is stored in SAP data centers that are assigned to therelevant service. Customers can view the current data center locations for their selected SAP cloud solutionsvia SAP’s data center location information page: SAP Data Center | SAP Trust Center. How does SAP comply with its obligation to apply administrative, technical and organizationalmeasures to protect personal data when acting as a data processor on behalf of itscustomers?SAP implements a comprehensive set of administrative, technical, and organizational measures to protectpersonal data in line with its role as a data processor as set forth in its Security Measures for CloudServices/Technical and Organizational Measures (TOMs), which can be found here: Policies, Frameworks, TOMsand Support Schedules. What categories of personal data does SAP process?The categories of personal data processed by SAP depend on several factors, including the specific productsand services a customer subscribes to, the personal data uploaded by the customer in SAP products andservices, and how the customer configures data fields within those products and services.Schedule 1 of the applicable SAP data processing agreement include a description of the relevant datasubjects and categories of personal data. Customers can access the current documentation for SAP CloudServices here:https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.htmlSpecial or sensitive categories of personal data should only be processed in SAP services where this has beenexplicitly agreed between the parties in writing as part of the contractual arrangement. For what purposes is customers’ personal data processed?The purposes for which SAP processes personal data are described in Schedule 1 “Description of Processing”1 of the applicable SAP data processing agreement, which outlines how and why personal data is processed inconnection with the delivery of the relevant products and services. How long does SAP store personal data, given PDPL requirements to delete data certaincircumstances?Customers determine what personal data is uploaded to SAP Cloud Services and retain control over that datathroughout the term of the applicable order form. Customers can manage and delete personal data directlywithin the service during the contract term. Further information regarding data retention, export, and deletionoptions is set out in the applicable general agreement and data processing terms concluded with SAP, whichdescribe how data is handled during and after the provision of SAP products and services. Is SAP required to prepare impact-assessment dossiers under Vietnam’s PDPL for personaldata processing and cross-border data transfers, and has SAP done so?
Yes. Under the Personal Data Protection Law (PDPL) and Decree 356, organizations are required to prepare andmaintain Personal Data Processing Impact Assessment (DPIA) dossiers and, where applicable, Cross-BorderTransfer Impact Assessment (CTIA) dossiers. These dossiers must be prepared using the prescribed forms andsubmitted to the Ministry of Public Security within 60 days from the start of personal data processing or fromthe date personal data is transferred outside Vietnam, as applicable.SAP has prepared the required DPIA dossiers and, where relevant, CTIA dossiers in accordance with itsobligations under the PDPL and Decree 356. SAP continues to follow the applicable procedures, prescribedforms, and submission timelines, reflecting its ongoing compliance with Vietnam’s personal data protectionrequirements. Does SAP provide copies of its PDPL impact-assessment dossiers to customers, and how doesSAP assist customers with their own assessments?SAP does not share its own regulatory impact-assessment dossiers with customers and does not provide legaladvice. The determination of whether an impact assessment is required, and how such an assessment must beconducted, remains the customer’s responsibility under applicable law where the customer acts as a datacontroller.However, in line with its role as a data processor and its contractual cooperation obligations, SAP will reasonablyassist customers in meeting their data protection obligations. Such assistance is provided based on generallyavailable information and may include supporting customers in understanding SAP’s products and services,security measures, and processing activities as relevant to the customer’s own impact assessments. Thiscooperation is provided in accordance with SAP’s applicable contractual terms and does not replace thecustomer’s independent legal or regulatory assessment. How does SAP demonstrate its commitment to data protection and privacy?SAP demonstrates its commitment to data protection and privacy through a robust global compliance andgovernance approach. SAP continuously monitors developments in data protection and privacy lawsworldwide and implements appropriate safeguards to protect the fundamental rights and freedoms ofindividuals whose personal data it processes.In addition, SAP maintains a portfolio of independent third-party audit reports, certifications, and attestationsthat help demonstrate compliance with data protection and privacy requirements. These externally validatedmeasures support SAP’s ongoing efforts to uphold privacy and data protection standards across itsoperations, products and services. Customers can find further information on SAP’s approach to dataprotection and compliance on the SAP Trust Center and at www.sap.com.© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/3