info@cbilaw.vn
+ (84) 028 3979 8855

DPIA & CTIA Filing Process and Procedures

Decree No. 356/2025/ND-CP provides specific regulations on the procedures for preparing and submitting the Personal Data Processing Impact Assessment (DPIA) dossier and the Cross-Border Transfer Impact Assessment (CTIA) dossier. Enterprises should pay particular attention to the filing deadlines, submission methods, assessment process and circumstances requiring dossier updates. CBI Law Firm summarizes the key requirements that enterprises should be aware of to proactively comply with personal data protection regulations.

Illustrative image

1. Legal Basis for the Filing Procedures

Pursuant to the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, enterprises are required to prepare, retain and submit the Personal Data Processing Impact Assessment (DPIA) dossier and/or the Cross-Border Transfer Impact Assessment (CTIA) dossier to the competent personal data protection authority in accordance with applicable regulations.

Specifically, Article 18 of Decree 356/2025/ND-CP provides for the CTIA dossier; Article 19 provides for the DPIA dossier; and Article 20 provides for the updating of DPIA and CTIA dossiers.

Under the current regulations, the competent personal data protection authority is the Department of Cybersecurity and High-Tech Crime Prevention (A05) under the Ministry of Public Security.

2. Filing Deadlines and Submission Methods

2.1. Filing Deadline

For DPIA, the personal data controller, personal data controller-processor, or personal data processor must submit one (01) complete original dossier within 60 days from the date on which personal data processing commences.

For CTIA, the entity conducting the cross-border transfer of personal data must submit one (01) complete original dossier within 60 days from the date on which the cross-border transfer of personal data commences.

Accordingly, the 60-day deadline is calculated from the date on which the relevant processing or data transfer activity commences, rather than from the date on which the enterprise completes the preparation of its internal dossier.

Therefore, enterprises should proactively review their data processing activities, determine whether DPIA and/or CTIA obligations apply, and prepare the relevant dossiers before commencing the relevant activities or from the early stage of implementing the data processing or transfer activities.

2.2. Permitted Submission Methods

Pursuant to Articles 18 and 19 of Decree 356/2025/ND-CP, DPIA and CTIA dossiers may be submitted through one of the following methods:

  1. Online submission;
  2. In-person submission; or
  3. Submission via postal service.

3. Dossier Receipt and Assessment Process

Under Articles 18 and 19 of Decree 356/2025/ND-CP, upon receipt of the dossier, the competent personal data protection authority will assess the dossier and issue the relevant result.

Step 1. Enterprise submits the dossier

The enterprise completes and submits the DPIA/CTIA dossier within the prescribed 60-day period.

Step 2. Competent authority receives and assesses the dossier

The competent personal data protection authority conducts an assessment of the submitted dossier.

For dossiers that satisfy the applicable requirements, as well as dossiers that do not satisfy such requirements, the assessment result will be issued within 15 days.

Step 3. Dossier is incomplete or non-compliant, if applicable

Where the dossier is incomplete or does not comply with the applicable requirements, the competent authority may request the enterprise to supplement and complete the dossier within 30 days.

If the enterprise fails to complete the dossier within the prescribed period, the competent authority may consider applying the regulations on administrative penalties for violations in the field of personal data protection.

Step 4. Competent authority reassesses the dossier and issues the result

After the enterprise has completed the dossier as requested, the dossier will continue to be reviewed in accordance with applicable regulations.

4. Practical Guidance on Dossier Submission

In addition to the requirements under Decree 356/2025/ND-CP, enterprises should note that the practical procedures for receiving DPIA/CTIA dossiers may be subject to specific guidance from the competent authority from time to time.

Under the practical guidance currently applied to DPIA/CTIA submissions, enterprises are required to submit a soft copy of the dossier first for receipt and preliminary review by the competent authority. The soft copy is submitted via the email address instructed by the competent authority and prepared as one ZIP file, with the relevant documents converted into PDF format, including scanned copies bearing valid signatures and seals.

After the soft copy has been received and reviewed, the enterprise will be instructed on the submission of the hard-copy dossier, where required.

Accordingly, when carrying out the procedures in practice, enterprises should check and comply with the latest dossier submission instructions issued by the Department of Cybersecurity and High-Tech Crime Prevention at the time of submission, while ensuring full compliance with the statutory deadlines and dossier requirements under Decree 356/2025/ND-CP.

5. Dossier Retention and Updating Obligations

Pursuant to Clause 2, Article 20 and Clause 2, Article 21 of the Law on Personal Data Protection No. 91/2025/QH15, DPIA and CTIA dossiers are required to be prepared once throughout the period of operation and updated in accordance with Article 22 of the Law. In addition, pursuant to Clause 4, Article 19 and Clause 4, Article 18 of Decree 356/2025/ND-CP, the dossiers must be retained and kept available for inspection and assessment by the competent personal data protection authority.

Under Clause 1, Article 22 of the Law on Personal Data Protection and Clause 1, Article 20 of Decree 356/2025/ND-CP, DPIA and CTIA dossiers must be periodically updated every six (06) months from the date of the initial submission where there is a new purpose for processing or transferring personal data, or where there is a new or changed personal data controller, personal data controller-processor, personal data processor or third party.

Accordingly, where none of the above changes arise, the enterprise is not required to carry out a six-month periodic update of the dossier.

In addition, pursuant to Clause 2, Article 22 of the Law on Personal Data Protection and Clause 2, Article 20 of Decree 356/2025/ND-CP, the enterprise must update the dossier within 10 days from the occurrence of any of the following events:

(i) the relevant agency, organization or unit is reorganized, ceases operation, is dissolved or becomes bankrupt;

(ii) there is a change in information relating to the organization or individual providing personal data protection services; or

(iii) there is a new or changed business line, occupation or service related to personal data processing activities that has been registered in the DPIA or CTIA dossier.

This article is provided for general informational purposes only and does not constitute legal advice for any specific case. The laws and regulations referred to in this article are effective as of the date of publication but may have been amended, supplemented, replaced or expired at the time readers access this article. Accordingly, readers are advised to seek advice from qualified legal counsel before applying the information herein.

For any questions or legal assistance relating to personal data impact assessment procedures and other related legal services, please contact CBI Law Company Limited for further support.

Leave a Reply