Guide · June 17, 2026

How long to respond to DSARs under the PDPL?

Explains DSAR response time under the PDPL: timeliness, logging, extensions, and a practical workflow template.

consent.vn Editorial6 min read

Quick answer

Businesses must respond to data subject requests (DSARs) on a timely basis, keep full records, and only extend the timeframe when there is a legitimate reason under the rules. If the request relates to a data breach, the business must also handle the incident and notify within 72 hours of discovery.

How long is the PDPL data subject request response timeframe?

Short answer: personal data protection law requires businesses to respond “promptly,” not let requests hang indefinitely, and have an internal process to record, track, and respond within the timeframe required by law.

The key point is that the PDPL should not be treated like a routine customer support email. A DSAR can be a request to access data, rectify data, withdraw consent, restrict processing, erase data, or obtain a copy of data. Each type of request may require multiple handlers: legal, IT, operations, HR, customer care.

For Vietnamese businesses, the risk often does not lie in “not wanting to reply,” but in not knowing who holds the data, having no request log, and having no internal SLA. Therefore, the question “PDPL data subject request response timeframe” should be understood as: having a mechanism to receive, authenticate, triage, respond, and keep evidence within a reasonable period as required.

How should businesses interpret “timely”?

“Timely” means responding within a reasonable period after receiving a valid request, instead of waiting until the data subject has to follow up repeatedly. In practical compliance, you should set an internal SLA shorter than any maximum legal process so you have time to verify identity, review data, and obtain approvals.

Example: a customer requests deletion of their account and purchase history on an e-commerce app. If the data is still tied to accounting or anti-fraud obligations, the business cannot wipe everything immediately. But the business must still respond clearly: the request has been received, which parts are being processed, which parts cannot be deleted and under what legal basis, and when the process is expected to be completed.

In other words, “timely” is not just fast—it’s accurate, justified, and verifiable.

When can you extend the response time?

Businesses should only extend when there is a legitimate reason and must inform the requester. Common situations include: the request is too complex, additional identity verification is needed, data is scattered across multiple systems, or you must reconcile with statutory retention obligations under sector-specific laws.

An extension is not “deal with it later.” If internal alignment is still pending, the business should send an interim response stating clearly:

  • the request has been received,
  • verification is in progress,
  • expected completion within the additional timeframe,
  • a contact channel for updates.

The crux is to have an audit trail: ticket, email, time of receipt, responsible person, reason for extension. When working with A05 or handling complaints, this log helps prove the business acted responsibly.

  1. Receive and record the request:

    Save date/time received, intake channel, request content, requester info, and ticket status. Do not handle via ad-hoc chats.

  2. Verify identity:

    Only provide or modify data after verifying the data subject or a duly authorized representative.

  3. Classify the request:

    Access, copy, rectify, erase, withdraw consent, object to processing, restrict processing, transfer data.

  4. Review legal bases:

    Check retention obligations, contracts, accounting, labor, system security, internal complaints.

  5. Send a preliminary response if needed:

    If you cannot complete immediately, acknowledge receipt and state the reason for ongoing handling/extension.

  6. Close out and keep evidence:

    Record what was sent, who approved, completion time, and attach supporting files.

What DSAR details should businesses record?

At minimum, you need a log or ticket system with the following fields:

Field Example Purpose
Request ID DSAR-2026-001 Quick lookup
Date/time received 01/03/2026 09:12 Calculate handling timeframe
Data subject Nguyen Van A Identify the requester
Request type Data erasure Processing triage
Intake channel email / form / hotline Prove the request source
Status verifying / responded Track SLA
Reason for extension data in 3 systems Basis for justification
Completion date 01/05/2026 Close the request
Evidence sent email / PDF / log Keep records

If the business has a website, the DSAR form should automatically generate a ticket ID and a confirmation email. For SMEs, even Google Forms + a shared inbox + a tracker file is better than handling manually via personal Zalo accounts.

What are the risks of missing the deadline?

The first risk is complaints from customers or employees. The second risk is being assessed as lacking appropriate data protection mechanisms when working with large partners. The third risk is that, during inspections, the business cannot prove it received, handled, and responded to the request.

Under the PDPL and related implementing guidance, violations may be handled under Government decrees; serious cases may even entail criminal liability. Because specific penalty amounts are not fixed in a single figure, businesses should focus on provable processes rather than “guessing the fine.”

If the data subject’s request also indicates a potential data breach, you must activate your incident response process and consider the obligation to notify a data breach within 72 hours of discovery.

A short DSAR response template you can use now

You can use the following as an interim response:

We received your request at [time/date]. The request is being verified and routed to the responsible team. During processing, we will review the relevant legal bases and respond with the result within a timeframe consistent with the regulations. If we need more information/identity verification, we will contact you via [channel].

This template does not replace legal advice, but it is enough to help the business avoid complete silence.

The PDPL emphasizes a timely response and allows extensions when there is a legitimate reason under the rules. Businesses should set an internal SLA and keep evidence of handling.
Not always. You must verify identity and review retention obligations, contracts, accounting, or other legal bases before deciding.
Yes. Acknowledge receipt, state that processing is underway, and explain why more time is needed. Keeping a log and a responsible owner is essential.
It can be. If the request indicates a leak or unauthorized access, the business must activate incident response and consider notifying within 72 hours of discovery.

If you are building a DSAR process for your website/app, consent.vn can help with cookie banners, consent evidence logging, and intake flows to make compliance checks easier.

Source: the Personal Data Protection Law (Law 91/2025/QH15) thuvienphapluat.vn; Decree 13/2023/ND-CP thuvienphapluat.vn; Ministry of Public Security bocongan.gov.vn

Get started — set up in 5 minutes.

Need help with PDPL compliance?

Get started