WHICH BUSINESSES ARE REQUIRED TO APPOINT A DATA PROTECTION OFFICER (DPO)?

June 1, 2025

Here is the English translation of your content, localized for clarity and professional tone:


🔒 WHICH BUSINESSES ARE REQUIRED TO APPOINT A DATA PROTECTION OFFICER (DPO)?

👉 Under Decree No. 13/2023/NĐ-CP, any organization that processes sensitive personal data—such as health information, biometric data, financial data, religious beliefs, etc.—is required to appoint a Data Protection Officer (DPO) as a mandatory safeguard for handling such data.
Examples: fintech companies, hospitals, or businesses that process employee health records (a type of sensitive data) must all appoint a DPO.

👉 According to the draft Law on Personal Data Protection, the appointment of a DPO becomes mandatory for all businesses, regardless of the type of personal data being processed. Specifically, businesses will be required to appoint either an internal DPO with sufficient expertise or outsource the function to a qualified individual or organization (external DPO).

💡What should your business do today?

  • Review the categories of personal data your organization is currently processing.
  • Assess whether the data is considered “sensitive” (under Decree 13) or falls under the expanded scope (in the draft Law).
  • Develop a plan to appoint an internal or external DPO based on your organization’s specific needs.

👉 Contact PrivacyCompliance for guidance on appointing your DPO!


Privacy Compliance

RECAP OF THE “PERSONAL DATA PROTECTION” WORKSHOP SERIES

RECAP OF THE “PERSONAL DATA PROTECTION” WORKSHOP SERIES ✨ The specialized Personal Data Protection workshop series organized by PrivacyCompliance has officially concluded, supporting participants in strengthening their legal compliance capabilities in the field of personal data protection. 📚 The program was structured around four key modules: 🔹 Legal framework for personal data protection. 🔹 Establishing […]

Learn more

Privacy Compliance

Legal Update | Guidance on Submitting Soft Copies of Personal Data Protection Impact Assessment Dossiers

Recently, the Department for Receiving and Returning Administrative Procedure Results on Personal Data Protection issued guidance on the submission of soft copies of the Personal Data Processing Impact Assessment Dossier and/or the Cross-border Personal Data Transfer Impact Assessment Dossier. Under the guidance, organizations and enterprises are required to submit the dossier in a .ZIP compressed […]

Learn more

Privacy Compliance

Draft Decree on Data Exchanges: Proposed Legal Framework for Data Transactions in Vietnam

Draft Decree on Data Exchanges: Proposed Legal Framework for Data Transactions in Vietnam The draft Decree on data exchange operations is currently open for consultation and proposes a framework for organizing, operating, and governing data transactions in Vietnam in a more transparent, controlled, and secure manner. A notable feature of the draft is the proposed […]

Learn more