Guide · June 17, 2026

Business obligations under the Personal Data Protection Law

Checklist of core obligations under the 2025 Personal Data Protection Law: consent, notice, security, DSAR, breaches.

consent.vn Editorial7 min read

Quick answer

If you’re looking for “business obligations under the personal data protection law,” the short answer is: businesses must identify a legal basis for processing, give transparent notices, manage consent, ensure data security, respond to data subject requests, control third parties, and prepare a process to report breaches within 72 hours.

What are a business’s obligations under the Personal Data Protection Law?

Businesses must process personal data for the right purposes, on the right legal bases, and with appropriate safeguards throughout the data lifecycle. The Personal Data Protection Law is the Personal Data Protection Law (Law 91/2025/QH15), passed on 26/06/2025, effective 01/01/2026, replacing/upgrading Decree 13/2023/ND-CP.

For SMEs, these obligations don’t sit only with legal. They pull in product, marketing, HR, sales, customer support, and dev: from cookie popups and sign-up forms, to CRM, system logs, and cloud providers.

What core obligations do businesses need to meet?

The easiest way is to split them into 8 workstreams. If you’re not sure where to start, treat this as a minimum checklist.

  1. Review the data you collect:

    List what you collect, from where, for what purposes, who can access it, how long you keep it, and whether it’s shared with third parties.

  2. Identify the legal basis:

    For each data flow, determine whether consent is needed or another legal basis applies under the rules. Don’t assume “collecting for operations” is enough.

  3. Update privacy notices:

    Spell out purposes, data types, recipients, retention periods, how to withdraw consent, and how to submit data requests.

  4. Manage consent in a provable way:

    Store evidence of consent per purpose; separate consent for marketing, profiling, and partner sharing if applicable.

  5. Implement technical and organizational security:

    Access controls, encryption, access logs, backups, contractor controls, and join/leave access procedures.

  6. Prepare a DSAR process:

    Set up intake and responses for requests to access, correct, delete, restrict processing, and withdraw consent.

  7. Manage third parties:

    Sign data protection terms with vendors/processors, and check any cross-border data transfers.

  8. Have a breach response plan:

    Detect, contain, investigate, remediate, and notify data breaches within 72 hours of discovery as required.

A prioritized checklist of business obligations under the personal data protection law

The table below is a pragmatic checklist for SMEs, especially if you have a website, app, CRM, or run digital ads.

ItemWhat to doSigns you’re ready
Data collectionReview forms, landing pages, app, hotline, offlineKnow what each data field is used for
ConsentSeparate purposes, don’t lump together, keep proof logsHave timestamp, source, consent content
NoticeAdd a privacy notice/notice at collectionUsers can read it before submitting data
RetentionSet retention periods and deletion rulesHave a data retention policy
Access controlLimit who can view/edit/export dataHave an access rights list
VendorsHave data processing terms with partnersHave a DPA or equivalent terms
DSARHave a channel to receive individual requestsHave a ticket/email/form and internal SLA
IncidentHave a playbook for data leaksKnow who decides, who reports, who remediates

Do businesses have to retain proof of consent?

Yes. If you rely on consent to process data, the business should retain evidence that the user was informed and consented for the correct purposes. For websites and apps, this usually means logging consent, the version of the notice content, the time, the device/source, and the change history.

Practical example: an e-commerce marketplace in Vietnam should not use a single “I agree to the terms” checkbox for account creation, sending newsletters, and sharing with advertising partners. These three purposes should be separated, because each has different risks and legal bases.

What should a business do when there’s a request to access, delete, or withdraw consent?

Businesses need a process to receive and respond to data subject requests. In practice, these requests often come from customers, applicants, former employees, or app users.

You should prepare at least:

  • a clear intake channel: email, form, or portal;
  • identity verification of the requester;
  • internal SLAs for each request type;
  • processing logs to prove you responded.

If your systems have multiple data sources, determine in advance which data can be deleted immediately and which must be retained for legal, accounting, tax, or dispute obligations.

What should businesses do about security and data incidents?

Businesses must apply technical and organizational measures proportionate to the level of risk. You don’t have to start with expensive systems; start with the basics, but make them controlled.

Practical priorities for SMEs:

  • enable MFA for admin accounts;
  • encrypt devices and sensitive data;
  • separate admin, dev, and support privileges;
  • limit bulk data exports;
  • log access and changes;
  • have a process to revoke accounts when staff leave;
  • assess the security of SaaS/CRM providers.

If a data breach occurs, the business must act quickly to assess the impact and notify the breach within 72 hours of discovery as required. For serious incidents, consult legal counsel and your compliance lead before making any broad disclosures.

Do companies have to control third parties and cross-border transfers?

Yes. If you use the cloud, send customer data to a CRM, payroll, email marketing, helpdesk, or analytics, you are essentially involving third parties in processing. Businesses need contracts or terms that bind them to data protection obligations, limit purposes, and define incident handling.

For cross-border data transfers, carefully check the procedures, documentation, and requirements under current rules, as this is easy to overlook when using global platforms.

Who enforces, and which authority should businesses work with?

The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05). When facing an inspection or in serious incidents, businesses should have ready: the data protection policy, consent logs, vendor list, incident handling procedures, and internal points of contact.

A 30-day checklist for SMEs

If you need a short implementation plan, follow these four weeks:

  • Week 1: inventory data and systems;
  • Week 2: fix the privacy notice, forms, and consent flows;
  • Week 3: lock down access controls, vendors, and retention;
  • Week 4: build the DSAR process and incident playbook.

After these four weeks, you’ll have covered most of the common SME pitfalls: collecting too much, not knowing what you hold, being unable to prove consent, and lacking a response process when incidents occur.

To collect, use, store, share, and delete personal data in compliance; provide transparent notices; manage consent; ensure security; and respond to individual requests as required.
Yes. Size does not exempt obligations. SMEs must still review their data, provide notices, retain consent evidence, and control processors/vendors.
By law, businesses must notify a data breach within 72 hours of discovery.
The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05).

If you’re preparing a cookie banner, consent evidence, or DSAR flows, consent.vn can help design them to be easy to operate for both product and legal teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP; Ministry of Public Security (thuvienphapluat.vn, bocongan.gov.vn)

Get started — no account needed.

Ready to comply with PDPL?

Get started