info@cbilaw.vn
+ (84) 028 3979 8855

What is Personal Data Processing Impact Assessment (DPIA)?

Is DPIA a mandatory legal obligation or a risk management solution? Join CBI in exploring the legal basis, implementation process, and DPIA documentation requirements under applicable regulations, helping businesses proactively ensure compliance and manage personal data protection risks in the article below.

Illustrative image

1. Legal Basis Relevant to Personal Data Processing Impact Assessment (DPIA)

Personal Data Processing Impact Assessment activities in Vietnam are currently directly governed by the following legal instruments:

  • Law on Personal Data Protection 2025 (Law No. 91/2025/QH15): Provides for the principles, rights, and obligations of relevant parties in relation to personal data protection and processing activities.
  • Decree No. 356/2025/ND-CP: Provides detailed regulations for the implementation of certain provisions of the Law on Personal Data Protection, including specific requirements on the dossier, forms, and procedures for conducting a Personal Data Processing Impact Assessment (DPIA).

2. From a Legal Perspective: What Is the True Nature of DPIA?

In our consulting practice, we have observed that many businesses still consider a Personal Data Processing Impact Assessment (DPIA) merely as the preparation of a prescribed report for submission to the competent authority.

However, under the Law on Personal Data Protection 2025 (Law No. 91/2025/QH15), DPIA is, in substance, a compliance evidence dossier demonstrating compliance with personal data protection laws (Compliance Evidence). It is a process through which businesses work closely with legal counsel and IT teams to:

  • Establish the legal basis for processing: Review and identify the legal basis for data processing activities, including the consent of data subjects, performance of contracts, or compliance with legal obligations as prescribed under Decree No. 356/2025/ND-CP.
  • Identify operational risks: Assess risks associated with data loss, data leakage, unauthorized access, or processing beyond the permitted scope throughout the data processing lifecycle.
  • Determine the scope and responsibilities of relevant parties: Clearly identify the roles, processing scope, and responsibilities of the Data Controller, Data Processor, and third parties, while establishing relevant obligations through contracts or Data Processing Agreements (DPAs).

3. When Are Businesses Required to Prepare and Update DPIA?

Pursuant to Articles 21 and 22 of the Law on Personal Data Protection 2025, the DPIA obligation is not a one-time requirement but must be reviewed and updated in accordance with the business’s data processing activities. Our legal team recommends that businesses conduct or review their DPIA in the following circumstances:

  • When implementing new activities: When a business launches a new product, mobile application, AI solution, or marketing campaign involving the large-scale collection and processing of personal data.
  • When there are changes to data processing activities: When a business changes its Cloud service provider, modifies its management systems (HRM/CRM), or expands the scope of data sharing with business partners.
  • Periodic updates as required by law: Pursuant to Articles 21 and 22 of the Law on Personal Data Protection 2025, the Personal Data Processing Impact Assessment Dossier (DPIA) must be updated every 06 months, or immediately upon the occurrence of changes prescribed by law, such as corporate restructuring, cessation of operations, dissolution, or bankruptcy; changes to information relating to the personal data protection service provider; or the emergence or modification of business sectors, lines of business, or services involving registered personal data processing activities.
  • Mandatory submission deadline: Businesses must submit 01 original copy of the Personal Data Processing Impact Assessment Dossier to the Department of Cybersecurity and Hi-Tech Crime Prevention and Control (A05) under the Ministry of Public Security within 60 days from the date on which personal data processing is commenced.

4. Five-Step Process for Preparing a DPIA Dossier in Compliance with Applicable Regulations

To ensure that the DPIA dossier not only satisfies the prescribed documentation requirements under Decree No. 356/2025/ND-CP but also assists businesses in controlling risks arising from their business operations and being prepared to provide explanations when requested by competent authorities, businesses may follow the five steps below:

  1. Audit and Map Data Flows (Data Mapping): Review the entire data lifecycle, from collection → storage → use → sharing → deletion.
  2. Assess the Lawfulness of the Processing Basis: Review and standardize Consent Forms, Privacy Policies, and Terms of Service to ensure compliance with applicable laws and regulations.
  3. Analyze Legal and Information Security Risks: Assess potential risks of complaints, disputes, or administrative sanctions in the event of data leakage or infringement.
  4. Standardize Compliance Documents and Procedures: Develop and promulgate internal Personal Data Protection Regulations, Data Breach Incident Response Procedures, and enter into Data Processing Agreements (DPAs) with service providers (Vendors).
  5. Finalize the Dossier and Provide Regulatory Support: Prepare the official DPIA Report and provide support and representation to the business in working with A05 in the event of any request for review, clarification, explanation, or amendment of the dossier.

5. CBI’s Comprehensive DPIA Consulting & Dossier Preparation Services for Businesses

Self-implementation of DPIA may expose businesses to compliance risks due to incomplete updates or understanding of the latest requirements under the Law on Personal Data Protection and Decree No. 356/2025/ND-CP. CBI’s dedicated legal team is ready to work alongside businesses to conduct practical assessments, review and standardize data processing procedures, and complete DPIA dossiers in accordance with applicable legal requirements and the specific characteristics of each business.

This article is for general informational purposes only and does not constitute legal advice for any specific case. The laws and regulations referred to herein are effective as of the date of publication but may have been amended, supplemented, replaced, or ceased to be effective at the time of reading. Accordingly, readers are advised to seek advice from qualified legal counsel before applying the information contained herein.

For any inquiries or consultation needs regarding Personal Data Processing Impact Assessment procedures or other related legal services, please contact CBI Law Company Limited for further assistance.

Leave a Reply