Guide · June 17, 2026
Employee data protection training under PDPL: who, frequency, content, evidence
Guide to PDPL employee data protection training for Vietnamese SMEs: who needs it, content, frequency, evidence for A05 and 72-hour incident response.
Quick answer
PDPL employee data protection training
This is a role-based training program that helps employees understand and apply the PDPL in their day-to-day work. The goals are to reduce risk, meet legal requirements (e.g., data breach notification within 72 hours), and maintain records to demonstrate compliance when A05 audits.
- Focus on execution processes inside the business: from collection, processing, and sharing to deletion of data.
- Emphasize obligations “as required by law” rather than pure theory; all content should be tied to existing work tools (CRM, marketing automation, codebase, HRIS).
Who needs to be trained in the company?
All personnel who touch personal data and decision-makers involved. Prioritize by risk group:
- Management/Founder: approve policies, budgets, and risk acceptance.
- Dev/IT/SRE/Data: system design, logging, encryption, storage, deletion.
- Marketing/Product Growth: cookies/SDKs, email/SMS, analytics, A/B testing.
- Sales/Customer Support: data collection, call recording, identity verification, DSAR.
- HR/Recruitment: candidate/employee records, background checks, cameras/VMS.
- Legal/Procurement: contracts with third-party processors, vendor assessments.
- Other internal staff/Contractors/Interns: minimum on security, data classification, and incident reporting channels.
What should PDPL training include?
It must be enough for employees to “do the right thing in their work.” Suggested framework:
- PDPL overview: scope, effective date (01/01/2026), replacing Decree 13/2023/ND-CP, A05 as the enforcement authority; penalties will be specified in the implementing decree.
- Processing principles: specific purpose, data minimization, transparency, security, appropriate retention.
- Legal bases and consent: when consent is needed, how to evidence consent, withdrawal of consent; examples: cookie banners, sign-up forms.
- Data subject rights and DSAR: access, rectification, deletion, objection/restriction; intake process, identity verification, logged responses.
- Sensitive data and children’s data: risk assessment, consent requirements/additional measures as required by law.
- Cross-border and third-party sharing: conditions, contracts; do not send data to vendors before assessment.
- Technical and organizational security: access control, MFA, encryption, backups, logging with minimal personal data, test environments without real data.
- Incident response and 72-hour reporting: detection, containment, record-keeping, reporting to A05 as required, and notifying users when needed.
- Compliance record-keeping: records of processing, DPIA where appropriate, incident register.
Role-based modules:
- Dev/IT: privacy by design, access controls, pseudonymization, key management, TTL/retention, secure deletion, secrets management.
- Marketing: configure analytics/SDKs based on consent, manage UTM, email/SMS opt-in/out, limit enrichment without a legal basis.
- HR/CS: minimize collection fields, identity verification scripts, no sharing data over personal channels, camera rules.
How often should training be delivered?
Following compliance management practice, train at onboarding and periodically, and update when there are major changes.
- Onboarding: within the first month with core content and internal procedures.
- Periodic: at least annually for all; every 6 months for higher-risk groups (Dev/IT, Marketing operating trackers, CS handling DSARs).
- Supplemental: when policies are updated, tools change, incidents occur, or when PDPL/implementing guidance is updated.
- Incident drills: quarterly or semiannually, focusing on the 72-hour process and scenarios like email leaks/wrong recipients/public links.
How to retain training evidence so you’re ready when A05 inspects?
The key is “provable and traceable.” Store systematically, linking person–course–time–result.
- Approved Training Policy/Regulation and training material versions (with version numbers, effective dates).
- Attendance lists, duration, test/assessment scores, internal certificates.
- System records (LMS/CSV export, e-signatures, screenshots of completion).
- Role-based competency matrix and assigned mandatory modules.
- Incident drill plans/minutes, DSAR logs, post-training improvements.
- Centralized storage with access control; retention long enough to satisfy inspections/audits as required and to mitigate dispute risks.
Implementation process for a PDPL training program for SMEs
A lean, measurable process helps maintain discipline and evidence.
Map data and risks:
Identify collection sources, storage systems, third parties, sensitive data; score risks by scale and purpose.
Build a role-based training matrix:
List job titles, risk levels, mandatory modules, and completion deadlines.
Design short, task-focused modules:
10–15 minute videos, job checklists, Vietnam-relevant scenarios; include a 5–10 question quiz.
Choose delivery tools:
Internal LMS/Google Classroom/Notion + test forms; ensure logs and certificates can be exported.
Communicate and set due dates:
Send schedules, completion SLAs, automated reminders; manage exceptions with direct manager approval.
Assess understanding:
Require a passing quiz score (e.g., 80%) before granting access to process sensitive data; re-test if not met.
Run 72-hour incident drills:
Tabletop exercises: leaked customer file, exposed tokens; measure time to detect, internal notification, draft A05 report.
Recordkeeping and improvements:
Export completion reports, lessons learned, update modules when tools/processes change.
Quick examples in Vietnam
- Small e-commerce marketplace: Marketing learns to configure CMP/cookie banners, disable auto-tracking without consent; CS learns DSAR scripts; Dev redacts data in logs and implements auto-delete for expired orders.
- Clinic chain: Reception and doctors learn to classify sensitive data; patient-calling procedures minimize exposure; drill on lab result leak and 72-hour notification process.
- Fintech: Data/Dev learn encryption at-rest/in-transit, environment segregation; role-based access control; vendor contracts require processors to provide training evidence.
Tip: use consent.vn to display purpose-based cookie banners, store consent evidence, and handle DSARs; export logs to demonstrate compliance.
Source: the Personal Data Protection Law (Law 91/2025/QH15) https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Luat-Bao-ve-du-lieu-ca-nhan-2024-583364.aspx; Decree 13/2023/ND-CP https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Nghi-dinh-13-2023-ND-CP-bao-ve-du-lieu-ca-nhan-756124.aspx; A05 (Ministry of Public Security) https://bocongan.gov.vn
Get started — set up in 5 minutes.
Need help with PDPL compliance?