What Does a Personal Data Processing Impact Assessment (DPIA) Dossier Include? Guidance on Preparing a DPIA Dossier for Businesses
What documents are included in a DPIA dossier? CBI provides an overview of the key components, preparation requirements, and important considerations when preparing a Personal Data Processing Impact Assessment (DPIA) dossier under the Law on Personal Data Protection and Decree No. 356/2025/ND-CP.

Illustrative image
1. Legal Basis for the Components of a DPIA Dossier
Pursuant to the 2025 Law on Personal Data Protection (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP, businesses are responsible for preparing and maintaining a Personal Data Processing Impact Assessment (DPIA) dossier to document their data processing activities and demonstrate compliance with personal data protection regulations.
A DPIA dossier is not merely a standalone report, but rather a comprehensive set of documents combining legal, technical, and operational elements to fully reflect the business’s actual personal data processing activities.
2. Three Mandatory Groups of Documents in a DPIA Dossier
Pursuant to Article 19 of Decree No. 356/2025/ND-CP, a DPIA dossier comprises the following key groups of documents:
Group 1: Impact Assessment Report
The Impact Assessment Report, prepared using Form No. 10 under the Appendix to Decree No. 356/2025/ND-CP, is the core document of the DPIA dossier and covers the following key contents:
- Information on relevant parties: Information and contact details of the Personal Data Controller, Personal Data Controller and Processor, Personal Data Processor, and third parties; as well as information on the department or personnel responsible for personal data protection, the Data Protection Officer (DPO), or a personal data protection service provider (if any).
- Purposes and data processing activities: Description of the purposes, types of data processed, scope, and personal data processing activities, together with a data flow diagram where necessary.
- Consent and data retention policies: Description of the methods used to obtain consent from data subjects and policies concerning the retention, deletion, and destruction of personal data.
- Data protection measures: Description of technical and organizational measures implemented to ensure the security of personal data, as well as system design and applicable data protection standards.
- Compliance assessment: Results of the assessment of compliance with applicable laws and regulations on personal data protection.
- Risk assessment and control: Identification of the potential impact and risks arising from data processing activities; assessment of potential consequences and damages; and preventive, control, or risk mitigation measures.
Group 2: Relevant Contracts and Legal Agreements
Businesses must prepare copies of contracts or agreements relating to personal data processing activities in order to clearly establish the rights, obligations, and responsibilities of the parties throughout the data processing process.
Group 3: Policies, Procedures, and Forms
This group includes policies, procedures, internal regulations, forms, and other documents relating to personal data protection applicable to the Personal Data Controller, Personal Data Controller and Processor, and Personal Data Processor.
3. Common Errors When Preparing a DPIA Dossier
In practice, during the provision of legal advice and support to businesses in preparing and finalizing DPIA dossiers, several common issues may arise, including:
- Using outdated or inappropriate templates that do not reflect actual operations: The dossier is prepared using an outdated template or copied from an existing template without being properly tailored to the business’s actual business model, systems, and data flows.
- Missing required supporting documents: Failure to prepare all required accompanying documents, particularly data processing contracts or agreements and relevant internal policies and procedures.
- Formalistic risk assessment: The assessment does not adequately reflect actual risks or clearly demonstrate the technical and organizational measures implemented by the business to control and mitigate such risks.
4. CBI’s DPIA Dossier Standardization and Preparation Services
A DPIA dossier is not merely a compliance document; it also serves as a basis for businesses to demonstrate and maintain effective control over their personal data processing activities throughout their operations.
With a team of lawyers experienced in personal data protection, CBI works alongside businesses to review their actual data processing activities, assess data flows and risks, standardize relevant policies and procedures, and finalize DPIA dossiers in accordance with applicable laws and regulations. CBI also supports businesses in providing explanations and working with competent authorities when necessary.
This article is provided for general informational purposes only and does not constitute legal advice for any specific case. The legal provisions referred to in this article are effective as of the date of publication but may have been amended, supplemented, replaced, or expired by the time the reader accesses this article. Readers are therefore recommended to seek advice from a lawyer before applying the information herein.
For any inquiries or requests for consultation regarding personal data impact assessment procedures and other related legal services, please contact CBI Law Company Limited for further assistance.