What problem does it solve? Organisations processing personal data of Vietnamese data subjects must comply with Law No. 91/2025/QH15 and Decree 356/2025/ND-CP effective January 1, 2026, but navigating consent rules, response deadlines, impact assessments, and sector-specific obligations is complex and error-prone. ## Core Features & Use Cases - Compliance Gap Analysis: Maps data inventories, consent mechanisms, and security controls against VN-PDPL requirements and produces a prioritised gap register. - Data Subject Rights Fulfilment: Guides handling of the 6 statutory rights with correct acknowledgement and fulfilment deadlines (2, 10, 15, and 20 working days). - Impact Assessments & Breach Response: Structures DPIA and cross-border transfer impact assessment dossiers for the Ministry of Public Security and walks through the 72-hour breach notification sequence. - Use Case: A fintech company expanding into Vietnam asks whether its cloud-hosted customer data flows comply; the skill identifies sensitive financial data categories, checks the Article 20 transfer assessment obligation, and flags the finance sector's dual 72-hour breach notification duty. ## Quick Start Ask the skill to run a VN-PDPL gap analysis for your organisation's processing of Vietnamese customer data, including cross-border transfer obligations.