vn-pdpl

Provides Vietnam PDPL compliance guidance for gap analysis, data subject rights, and cross-border transfers.

869|179|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vn-pdpl
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Organisations processing personal data of Vietnamese data subjects must comply with Law No. 91/2025/QH15 and Decree 356/2025/ND-CP, but the law's consent rules, tight response deadlines, impact assessment duties, and sector-specific overlays are difficult to interpret and operationalize without expert guidance.

Core Features & Use Cases

  • Compliance Gap Analysis: Assess readiness against VN-PDPL by mapping data inventories, consent mechanisms, rights procedures, and security controls into a prioritized gap register.
  • Data Subject Rights & Breach Response: Handle the 6 data subject rights within Decree 356 deadlines (2-day acknowledgement, 10-20 day fulfilment) and execute the 72-hour breach notification workflow.
  • Impact Assessments & Policies: Prepare domestic DPIAs and cross-border transfer impact assessments for the Ministry of Public Security, plus privacy notices, consent forms, and DPO qualification reviews.
  • Use Case: A fintech company expanding into Vietnam asks for a readiness assessment; the skill walks through sensitive data consent requirements, finance-sector obligations under Decree 356 Article 8, and cross-border transfer dossier preparation.

Quick Start

Ask the assistant to perform a VN-PDPL gap analysis for your organisation, describing your data processing activities, sectors, and any cross-border transfers of Vietnamese personal data.

Frequently Asked Questions about vn-pdpl

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a Vietnam PDPL compliance gap analysis?

A VN-PDPL gap analysis maps your data inventory against basic and sensitive data categories, checks consent mechanisms against Article 9, reviews rights response procedures against Decree 356 deadlines, and assesses DPIA, cross-border transfer, and breach notification readiness. The output is a prioritized gap register with remediation owners.

What are the data subject rights under Vietnam PDPL?

Vietnam PDPL grants 6 data subject rights under Article 4: to be informed, to consent or withdraw consent, to access and rectify, to delete, restrict, or object, to file complaints and seek compensation, and to request protection measures. Unlike GDPR, there is no data portability right.

Does Vietnam PDPL require consent for cross-border data transfers?

Cross-border transfers require an impact assessment dossier submitted to the Ministry of Public Security within 60 days of the first transfer, updated every 6 months. Exemptions apply for state agencies, employee HR data in cloud systems, and data subjects transferring their own data.

What is the breach notification deadline under Vietnam PDPL?

Controllers must notify the personal data protection authority within 72 hours of becoming aware of a breach, and notify affected data subjects simultaneously or as soon as practicable. The notification must describe the breach nature, affected data subjects and records, likely consequences, and remediation measures.

Are small businesses exempt from Vietnam PDPL requirements?

Small and micro enterprises may opt out of Articles 21 (DPIA), 22 (security measures), and 33(2) for 5 years from 1 January 2026. The exemption does not apply if they process sensitive personal data or process data at large scale.

How does Vietnam PDPL differ from GDPR?

VN-PDPL is broadly GDPR-inspired but has 6 rights instead of 8, no data portability right, and no legitimate interests legal basis. Cross-border transfers use an impact assessment mechanism rather than adequacy decisions or SCCs, and SME exemptions are time-bound to 5 years.