Article · June 17, 2026

What are a data controller's obligations under the PDPL?

Summary of data controller obligations under the PDPL: legal basis, security, rights, records, and breach reporting.

consent.vn Editorial6 min read

Quick answer

Under the PDPL, data controllers must have a clear legal basis for processing, protect data security, respond to data subject requests, keep compliance records, and notify breaches within 72 hours upon discovery. These are foundational obligations under the Personal Data Protection Law (Law 91/2025/QH15), effective 01/01/2026.

What are a data controller's obligations under the PDPL?

A data controller decides the purposes and means of processing personal data, so their responsibilities are usually the broadest in the processing chain. By law, you must demonstrate a lawful basis for processing, organize appropriate security, respond to individuals’ requests, and be ready to provide records when requested by competent authorities.

For Vietnamese businesses, this is not just about “having a nice policy.” It requires real processes: collecting for the right purposes, internal access control, access logs, contracts with vendors, and mechanisms to receive requests from customers/employees.

What is the legal basis that gives rise to a data controller’s obligations?

A data controller’s obligations arise from the Personal Data Protection Law (Law 91/2025/QH15), adopted on 26/06/2025 and effective from 01/01/2026, replacing/upgrading the current framework under Decree 13/2023/ND-CP. During the transition period, businesses should review processes against the new standards to avoid last-minute fixes when the law takes effect.

Note that specific penalty levels will be set by a Government guiding decree, so it is premature to “estimate” fixed figures. For serious violations, criminal liability may apply under related provisions. The primary enforcement authority is the Ministry of Public Security — the Department of Cybersecurity and Prevention of High-Tech Crime (A05).

Obligation groupWhat the data controller must doPractical tips for SMEs
Legal basis for processingDefine purposes, legal basis, and data scopeMap each processing flow to a form/campaign/internal record
SecurityApply technical and organizational measuresMFA, role-based access, encryption, backups, access logs
Data subject rightsReceive and respond to requests on timeCreate a DSAR form, internal SLA, identity verification checklist
Compliance recordsKeep evidence, decisions, minutesStore consent logs, DPIA/risk assessments, vendor records
Data breachesDetect, assess, notify72-hour playbook, incident response scenarios

How must a data controller secure data?

You must apply security measures appropriate to the risk level of the data and systems. There is no “one-size-fits-all” template for every business, but at a minimum you should have:

  • role-based access control; no shared accounts;
  • multi-factor authentication for admin systems;
  • encryption of sensitive data at rest and in transit;
  • access and change log management;
  • periodic backups and restoration testing;
  • procedures for deletion/anonymization when processing purposes end;
  • training for personnel with data access.

Example: a typical e-commerce marketplace in Vietnam holds customer data, shipping addresses, purchase history, and support tickets. If a CRM export file is shared via internal email without download controls, it will be hard for the business to prove it “protected data as required” in the event of an incident.

How must a data controller handle data subject rights?

A data controller must provide mechanisms for individuals to exercise core rights such as to be informed, access, rectify, erase, restrict processing, object to processing, or withdraw consent in cases permitted by law. It’s crucial to have a clear intake channel and processing deadline so requests don’t get “lost” between customer support, sales, and IT.

In practice, design a concise DSAR process:

  1. Intake:

    Allow submission via form, email, or a support channel that records a timestamp.

  2. Identity verification:

    Match phone number, email, documents, or authenticate the account.

  3. Categorize the request:

    Access, rectification, erasure, objection, withdrawal of consent.

  4. Locate relevant data:

    Search CRM, ERP, ticketing, cloud drive, and system logs.

  5. Respond and execute:

    Send results, update systems, and keep evidence of handling.

If your business uses multiple providers, specify who is responsible for which part of the data. For example: marketing holds consent; operations holds orders; the cloud provider holds infrastructure. But ultimate responsibility to the data subject still lies with the data controller.

What records must a data controller keep?

Record-keeping is what many SMEs skip, thinking a “policy” is enough. In fact, when authorities inspect, you must prove the processes exist and are operating — not just show a prepared document.

At a minimum, keep:

  • a register of data processing activities;
  • the legal basis for each activity;
  • user notices/consents, if any;
  • contracts and addenda with processors and third parties;
  • risk assessments or impact assessments as required;
  • logs of DSAR intake and handling;
  • training, access control, and security review records;
  • incident records and remediation measures.

For digital product companies, this is where legal and engineering should work closely: consent logs, form versioning, the timestamp when a user clicked agree, checkbox content, and privacy notice change history.

When must you notify a data breach?

Upon discovering a personal data breach, the data controller must notify within 72 hours from the time of discovery, as required. If you cannot fully establish the incident details immediately, you should still send an initial notice on time and follow up with updates.

A minimal playbook should have four steps:

  • isolate affected systems or accounts;
  • identify the data types, number of records, and scope of impact;
  • assess risks to individuals;
  • notify competent authorities and relevant parties as required.

Do not wait to “finish the investigation before reporting.” For incidents with signs of customer data exposure, the longer the delay, the harder it is to control legal and operational damage.

The controller decides the purposes and means of processing, so is primarily responsible for legal basis, information to data subjects, and risk governance. The processor mainly follows instructions and the contract.
Yes. SMEs should still keep a register of processing activities, legal bases, consent logs, vendor contracts, and procedures for handling customer requests.
Typically the data controller must proactively trigger the process required by law and notify within 72 hours of discovery, while coordinating with the provider to verify the cause.
Recommended, especially if you process sensitive data, use tracking/ads, or have many third parties. Where the legal basis is hard to determine, consult a lawyer before implementation.

If you need to review cookie banners, store consent evidence, or design DSAR flows for your website/app, consent.vn can help standardize them for both legal and engineering teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — thuvienphapluat.vn; Ministry of Public Security — bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started