Template · June 17, 2026

ROPA template for data processing under the PDPL

PDPL ROPA template: required fields, how SMEs use it, and a prefilled example.

consent.vn Editorial6 min read

Edit & copy

This is a reference template. Consult a legal advisor before using in production.

Quick answer

You can use a register of processing activities (ROPA) to record who processes personal data, what is processed, why, who it is shared with, and how long it is retained. The template below suits Vietnamese SMEs to get started under the Personal Data Protection Law (Law 91/2025/QH15), before applying detailed requirements under the guiding decree.

What is the data processing activities register template?

A data processing activities register template is an internal table used to list personal data processing activities in the business, from collection, storage, use, and sharing to deletion. Under the PDPL, this is a foundational document to demonstrate you manage data systematically, especially when there are inspections, incident handling, or compliance reviews.

What fields should the data processing activities register template include?

You should record at least the following fields so the ROPA is usable in practice, not just “for show”.

Field to recordContent to fill inWhy it's needed
Name of processing activityExample: order intake, timekeeping, recruitmentClearly define the processing scope
Responsible unit/departmentSales, HR, Customer Support, ITKnow who is accountable
Processing purposeDelivery, customer care, payrollTie to a lawful purpose under the rules
Data typesFull name, phone number, email, Citizen ID, bank accountAssess risk level
Data subjectsCustomers, employees, candidatesKnow whose data it is
Collection sourcesWeb form, Zalo, contract, cameraSupport transparency and traceability
Legal basis/consentConsent, contract, legal obligation...Reduce the risk of lacking a basis
Recipients/data sharingDelivery provider, cloud, accountingControl data transfers
Where storedGoogle Workspace, on-prem server, CRMManage data locations
Retention period12 months, 5 years, per accounting law...Avoid keeping data too long
SafeguardsAccess control, MFA, encryption, logsDemonstrate security
Deletion/anonymization on expirySoft delete, hard delete, anonymizeClose the data lifecycle
Person responsible for updatesName, department, update dateMaintain accuracy

How to prefill the data processing activities register template?

Below is a practical template for SMEs; you can copy it into Excel/Google Sheets or Notion.

  1. Create one row for each processing activity:

    For example, separate “recruitment”, “sales”, “timekeeping”, “customer support” rather than combining them.

  2. State the purpose and data types clearly:

    Don’t write generic phrases like “for business”; specify which data is used for what.

  3. Identify data recipients:

    If using third parties such as a CRM, email marketing, cloud, or a delivery provider, specify them.

  4. Set retention periods:

    Record according to internal policy or related legal obligations; upon expiry, delete/anonymize.

  5. Review regularly:

    Update when switching vendors, adding tracking tools, changing HR processes, or opening new sales channels.

Minimum ROPA table

No. Processing activity Responsible department Purpose Data types Data subjects Collection sources Recipients/shares Where stored Retention period Protection measures Updated by Update date
1 Recruitment HR Screen candidates, interview, sign employment contracts Full name, phone number, email, CV, Citizen ID, bank account Candidates Recruitment form, email, LinkedIn ATS provider, email, e-signature service Google Workspace, ATS 6–12 months if not hired; per personnel file if hired HR access control, MFA, limited storage HR Manager 08/2025
2 Online sales Sales/Customer Support Process orders, deliver, post-sale support Full name, phone number, address, purchase history Customers Website, hotline, Zalo Carrier, payment gateway, CRM CRM, order files According to internal policy Encryption, access control, access logs Ops Lead 08/2025
3 Timekeeping HR/IT Manage working hours, payroll calculation Full name, employee ID, attendance data Employees Time clock device, app Timekeeping software provider On-prem server/SaaS Per employment record retention period Access control, backup, audit log HR Admin 08/2025

How should the data processing activities register be used within a business?

For SMEs, the ROPA should be a living file, not a one-off document left on the shelf. Legal/HR/IT/ops owners should update it when changes occur, such as adding analytics tools, running ads lead forms, using a chatbot, moving data to a new cloud, or engaging external vendors.

A practical example: if the company uses Google Forms to receive candidate information, then pushes it to an ATS and sends automated emails, you should note each data touchpoint. If there are cookies/SDKs tracking behavior on the website, record the collection activity, data types, and recipients as required; do not unilaterally conclude a tracker is “illegal”—you need to check the purpose, notice, and appropriate consent mechanisms.

How is the data processing activities register related to PDPL compliance?

Yes. The ROPA helps the business see the full data lifecycle, thereby addressing obligations such as transparency notices, consent management, controlling data sharing, and reacting to incidents. Under the Personal Data Protection Law (Law 91/2025/QH15), serious violations may be subject to criminal handling; specific penalty levels will be set out in the Government’s guiding decree, and the enforcement authority is the Ministry of Public Security (A05).

If a data violation occurs, the business must notify within 72 hours from discovery, so having an up-to-date ROPA will help you trace quickly: which data was affected, which systems hold it, who received the data, and who needs to be notified.

FAQ about the data processing activities register template

Under the PDPL, businesses should have a ROPA to manage processing activities and demonstrate compliance. The level of detail varies by business model and operations; consult a lawyer if your data systems are complex.
SMEs can start with Excel/Google Sheets if processes are still simple. When data grows, there are many systems, or several departments update it, move to software to facilitate access control, change tracking, and reporting.
Yes. If a third party accesses or processes personal data on your behalf, list the provider name, purpose of sharing, storage location/region, and safeguards as required.
It may leave the business unable to demonstrate compliance when inspected or when incidents occur. This is also a real risk because data changes continuously, especially when adding trackers, chatbots, a CRM, or new vendors.

If you need a ROPA template with prebuilt columns for a cookie banner, consent evidence logging, and DSAR, consent.vn can help you standardize it to your internal process.

Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement agency A05/Ministry of Public Security at bocongan.gov.vn

Access the full template library — no account needed.

Need more PDPL templates?

Get started