Vietnam’s Personal Data Law and its Implementing Decree (Decree 356/2025/ND-CP)
Vietnam’s Personal Data Protection Law 2025 and Decree 356/2025/ND-CP establish a comprehensive data protection framework. SAP supports compliance with these regulations through robust technical and organizational measures, ensuring data security and privacy for its customers. Faça o download do documento
PUBLIC
Vietnam’s Personal Data Law and its
Implementing Decree (Decree 356/2025/ND-
CP)
Updated Frequently Asked Questions
May 2026
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
Vietnam’s Personal Data Law and its
Implementing Decree (Decree 356/2025/ND-
CP)
Updated Frequently Asked Questions
May 2026
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
Vietnam has entered a new phase in personal data protection with the Personal Data Protection
Law 2025 (PDPL) and its implementing regulation, Decree 356/2025/ND-CP, which took effect
on 1 January 2026. Together, these instruments replace the previous Personal Data Protection
Decree (Decree 13/2023/ND-CP) and establish a more consolidated and transparent data
protection framework. The new regime introduces clearer definitions and classifications of
personal data, including updated distinctions between basic and sensitive personal data. It
also sets out more detailed procedural and compliance requirements, giving organizations
greater regulatory certainty while strengthening protections for individuals. Overall, the PDPL
aims to promote more consistent and accountable handling of personal data across all sectors
in Vietnam.
Key Compliance Expectations under Vietnam’s PDPL and Decree 356
Under the PDPL and Decree 356, organizations processing personal data in Vietnam are now subject to more
clearly defined compliance obligations. As with the earlier PDPD, the framework remains consent-centric, but
with strengthened expectations around data security and governance, revised timelines for responding to data
subject requests, and formalized requirements to prepare Data Processing Impact Assessment (DPIA) and Cross-
Border Transfer Impact Assessment (CTIA) reports. Both assessments must follow official templates and are
subject to review by the Ministry of Public Security, reflecting a shift toward a more standardized and predictable
regulatory environment for managing personal data.
SAP remains committed to meeting its privacy, security, and global compliance obligations in this evolving
regulatory landscape. SAP’s internal policies and governance frameworks are designed to support compliance
with data protection requirements worldwide, including those under Vietnam’s PDPL and Decree 356. SAP
implements robust technical and organizational measures and maintains comprehensive audit and certification
programs, demonstrating its ongoing commitment to data protection and privacy. Customers can learn more
about SAP’s privacy posture through SAP’s Data Protection and Privacy resources.
Customer PDPL Frequently Asked Questions (FAQ)
Building on these commitments, the following Customer PDPL Frequently Asked Questions address common
questions about SAP’s approach to personal data protection and compliance under Vietnam’s Personal Data
Protection Law.
• Given that customers must choose a data processor with appropriate personal data
protections, what agreement does SAP enter into with customers before processing any
personal data?
SAP’s Data Processing Agreement explains how SAP processes personal data of customers and end users
when providing SAP Cloud Services, Support, and Professional Services. The agreement clarifies the
respective roles and responsibilities of SAP and its customers, establishes contractual safeguards for
personal data, and supports compliance with applicable data protection and privacy laws worldwide.
By setting clear expectations for how personal data is handled and protected, the agreement helps promote
consistency and accountability for both SAP and its customers. For this reason, it applies to every customer
transaction involving the processing of personal data and forms an integral part of SAP’s overall contractual
framework.
Please read the SAP DPA FAQs here: https://www.sap.com/about/trust-center/data-
privacy.html?pdfasset=d46da9fc-157f-0010-bca6-c68f7e60039b&page=7.
Law 2025 (PDPL) and its implementing regulation, Decree 356/2025/ND-CP, which took effect
on 1 January 2026. Together, these instruments replace the previous Personal Data Protection
Decree (Decree 13/2023/ND-CP) and establish a more consolidated and transparent data
protection framework. The new regime introduces clearer definitions and classifications of
personal data, including updated distinctions between basic and sensitive personal data. It
also sets out more detailed procedural and compliance requirements, giving organizations
greater regulatory certainty while strengthening protections for individuals. Overall, the PDPL
aims to promote more consistent and accountable handling of personal data across all sectors
in Vietnam.
Key Compliance Expectations under Vietnam’s PDPL and Decree 356
Under the PDPL and Decree 356, organizations processing personal data in Vietnam are now subject to more
clearly defined compliance obligations. As with the earlier PDPD, the framework remains consent-centric, but
with strengthened expectations around data security and governance, revised timelines for responding to data
subject requests, and formalized requirements to prepare Data Processing Impact Assessment (DPIA) and Cross-
Border Transfer Impact Assessment (CTIA) reports. Both assessments must follow official templates and are
subject to review by the Ministry of Public Security, reflecting a shift toward a more standardized and predictable
regulatory environment for managing personal data.
SAP remains committed to meeting its privacy, security, and global compliance obligations in this evolving
regulatory landscape. SAP’s internal policies and governance frameworks are designed to support compliance
with data protection requirements worldwide, including those under Vietnam’s PDPL and Decree 356. SAP
implements robust technical and organizational measures and maintains comprehensive audit and certification
programs, demonstrating its ongoing commitment to data protection and privacy. Customers can learn more
about SAP’s privacy posture through SAP’s Data Protection and Privacy resources.
Customer PDPL Frequently Asked Questions (FAQ)
Building on these commitments, the following Customer PDPL Frequently Asked Questions address common
questions about SAP’s approach to personal data protection and compliance under Vietnam’s Personal Data
Protection Law.
• Given that customers must choose a data processor with appropriate personal data
protections, what agreement does SAP enter into with customers before processing any
personal data?
SAP’s Data Processing Agreement explains how SAP processes personal data of customers and end users
when providing SAP Cloud Services, Support, and Professional Services. The agreement clarifies the
respective roles and responsibilities of SAP and its customers, establishes contractual safeguards for
personal data, and supports compliance with applicable data protection and privacy laws worldwide.
By setting clear expectations for how personal data is handled and protected, the agreement helps promote
consistency and accountability for both SAP and its customers. For this reason, it applies to every customer
transaction involving the processing of personal data and forms an integral part of SAP’s overall contractual
framework.
Please read the SAP DPA FAQs here: https://www.sap.com/about/trust-center/data-
privacy.html?pdfasset=d46da9fc-157f-0010-bca6-c68f7e60039b&page=7.