vn-pdpl

Advises on Vietnam PDPL compliance including gap analysis, data subject rights, and cross-border transfer assessments.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill vn-pdpl-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vn-pdpl
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/vn-pdpl
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill vn-pdpl-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Organisations processing personal data of Vietnamese data subjects must comply with Law No. 91/2025/QH15 and Decree 356/2025/ND-CP effective January 1, 2026, but navigating consent rules, response deadlines, impact assessments, and sector-specific obligations is complex and error-prone. ## Core Features & Use Cases - Compliance Gap Analysis: Maps data inventories, consent mechanisms, and security controls against VN-PDPL requirements and produces a prioritised gap register. - Data Subject Rights Fulfilment: Guides handling of the 6 statutory rights with correct acknowledgement and fulfilment deadlines (2, 10, 15, and 20 working days). - Impact Assessments & Breach Response: Structures DPIA and cross-border transfer impact assessment dossiers for the Ministry of Public Security and walks through the 72-hour breach notification sequence. - Use Case: A fintech company expanding into Vietnam asks whether its cloud-hosted customer data flows comply; the skill identifies sensitive financial data categories, checks the Article 20 transfer assessment obligation, and flags the finance sector's dual 72-hour breach notification duty. ## Quick Start Ask the skill to run a VN-PDPL gap analysis for your organisation's processing of Vietnamese customer data, including cross-border transfer obligations.

Frequently Asked Questions about vn-pdpl

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a Vietnam PDPL compliance gap analysis?

Identify your role as controller or processor, map your data inventory into basic versus sensitive categories, then check consent mechanisms, rights response procedures, cross-border transfer flows, DPIA obligations, and DPO appointment. The skill outputs a prioritised gap register with remediation owners and timelines.

What are the data subject request deadlines under Vietnam PDPL?

Acknowledge any request within 2 working days. Fulfil access and correction requests within 10 working days, deletion within 20 working days, and consent withdrawal or restriction within 15 working days, per Decree 356 Article 5. One extension is allowed if the data subject is notified.

Does Vietnam PDPL require a cross-border transfer impact assessment?

Yes, transferring Vietnamese data subjects' personal data abroad requires submitting an impact assessment dossier to the Ministry of Public Security within 60 days of the first transfer, updated every 6 months. Exemptions cover state agencies, employee HR data in cloud systems, and data subjects transferring their own data.

How fast must breaches be reported under Vietnam PDPL?

Controllers must notify the personal data protection authority within 72 hours of becoming aware of a breach, and notify affected data subjects simultaneously or as soon as practicable. The finance sector requires mandatory simultaneous notification to both the authority and data subjects.

Are small businesses exempt from Vietnam PDPL obligations?

Small and micro enterprises may opt out of DPIA, security measure, and certain processor obligations for 5 years from January 1, 2026. The exemption does not apply if they process sensitive personal data or process data at large scale.

What counts as valid consent under Vietnam PDPL?

Consent must be voluntary, explicit, specific per purpose, informed, and recorded through verifiable methods such as signed documents, recorded calls, SMS, email, or web forms. Silence, pre-ticked boxes, and bundled consent for unrelated purposes are invalid.