Which Enterprises Are Exempt from Preparing a DPIA Under the Latest Regulations?
Which enterprises are exempt from, or may elect not to perform, the obligations to prepare, update and submit a Personal Data Processing Impact Assessment (DPIA) dossier? CBI Law Firm provides an update on the exemptions, deferrals and exceptions under the 2025 Law on Personal Data Protection and Decree No. 356/2025/ND-CP.

Illustrative image
1. Legal Basis for the DPIA Exemption Mechanism
The Law on Personal Data Protection No. 91/2025/QH15 (the “2025 PDP Law”) took effect on 1 January 2026. Decree No. 356/2025/ND-CP dated 31 December 2025 of the Government (“Decree 356/2025/ND-CP”), which also took effect on 1 January 2026, provides detailed regulations and measures for implementing certain provisions of the 2025 PDP Law.
Accordingly, the 2025 PDP Law imposes obligations to prepare, retain, update and submit a Personal Data Processing Impact Assessment (DPIA) dossier on entities falling within its scope of application. At the same time, Decree 356/2025/ND-CP establishes mechanisms under which certain groups of entities may be exempt from, or elect not to perform, certain obligations prescribed under Articles 21, 22 and Clause 2, Article 33 of the 2025 PDP Law, subject to the conditions specified therein.
2. Entities Eligible for Exemption or Deferral from the DPIA Obligation
Pursuant to Article 38 of the 2025 PDP Law, entities eligible for the exemption mechanism or permitted to elect not to perform obligations relating to DPIA may be classified as follows:
- Household businesses and micro-enterprises: Not required to perform the obligations prescribed under Articles 21, 22 and Clause 2, Article 33 of the 2025 PDP Law, except for cases subject to the exceptions prescribed under Decree 356/2025/ND-CP and analyzed in Section 3 below.
- Small enterprises and start-ups: May elect to perform or not to perform the obligations prescribed under Articles 21, 22 and Clause 2, Article 33 of the 2025 PDP Law for a period of five (05) years from the effective date of the 2025 PDP Law, i.e., from 1 January 2026 to 31 December 2030.
3. Three Cases Not Eligible for the Exemption Mechanism
However, the above exemption or election mechanism does not apply where an enterprise falls into any of the following cases. In such circumstances, the enterprise is required to perform its DPIA obligations in accordance with applicable laws:
3.1. Provision of Personal Data Processing Services
This applies to enterprises whose business activities are directly related to personal data processing, including:
- providing and operating systems or software for processing personal data on behalf of customers;
- providing personal data scoring, ranking or creditworthiness assessment services;
- collecting and processing data online from websites, applications, social media, healthcare and education platforms;
- analyzing and exploiting personal data;
- providing data encryption services;
- conducting automated processing using Big Data, AI, blockchain or virtual-world technologies; and
- providing personal location data, among other services.
3.2. Direct Processing of Sensitive Personal Data
Sensitive personal data includes categories of data such as health information, biometric data, genetic data, location data, financial and banking information, information relating to private life, political opinions, religious beliefs, criminal records, and other categories of data that are subject to strict confidentiality requirements under applicable laws.
3.3. Large-Scale Processing of Personal Data
The exemption or election mechanism also does not apply to enterprises processing personal data on a large scale, meaning enterprises processing data relating to 100,000 or more personal data subjects, as determined based on the cumulative total amount of personal data processed in accordance with applicable regulations.[1]
This is a criterion that enterprises, particularly those operating digital platforms, e-commerce businesses, technology companies, recruitment services, marketing businesses or customer service platforms, should proactively review to properly determine their DPIA obligations.
4. Legal Recommendations for Small and Medium-Sized Enterprises
An incorrect assessment of the scope of application of the DPIA exemption or election mechanism may result in an enterprise overlooking its compliance obligations under personal data protection regulations.
CBI Law Firm recommends that enterprises:
- Review the actual scale and scope of personal data processed: Determine the number of personal data subjects processed based on the cumulative results to assess whether the enterprise has reached the threshold of 100,000 personal data subjects, while also reviewing whether sensitive personal data is being processed.
- Properly identify data processing activities and roles: Determine whether the enterprise processes personal data for its own purposes or provides data processing services to customers, partners or third parties.
- Proactively establish a compliance framework: Even where an enterprise is not required to prepare and submit a DPIA dossier, it must still comply with other personal data protection requirements and establish appropriate policies, procedures and security measures to mitigate the risks of data breaches or unlawful use of personal data.
5. Data Protection Risk Assessment & Compliance Advisory Services
Are you unsure whether your enterprise is eligible for an exemption from, or may elect not to perform, the obligation to prepare a DPIA dossier?
The lawyers of CBI Law Firm can assist enterprises in reviewing their business models, data processing roles, types and volume of data, and personal data processing activities, thereby determining the appropriate compliance obligations under the 2025 Law on Personal Data Protection and Decree 356/2025/ND-CP.
This article is provided for general informational purposes only and does not constitute legal advice for any specific case. The laws and regulations referred to in this article are effective as of the date of publication but may have been amended, supplemented, replaced or expired at the time readers access this article. Accordingly, readers are advised to seek advice from qualified legal counsel before applying the information herein.
For any questions or legal assistance relating to personal data impact assessment procedures and other related legal services, please contact CBI Law Company Limited for further support.
[1] Clause 1, Article 41 of Decree 356/2025/ND-CP.