WHICH BUSINESSES ARE REQUIRED TO APPOINT A DATA PROTECTION OFFICER (DPO)?

June 1, 2025

Here is the English translation of your content, localized for clarity and professional tone:


πŸ”’ WHICH BUSINESSES ARE REQUIRED TO APPOINT A DATA PROTECTION OFFICER (DPO)?

πŸ‘‰ Under Decree No. 13/2023/NĐ-CP, any organization that processes sensitive personal dataβ€”such as health information, biometric data, financial data, religious beliefs, etc.β€”is required to appoint a Data Protection Officer (DPO) as a mandatory safeguard for handling such data.
Examples: fintech companies, hospitals, or businesses that process employee health records (a type of sensitive data) must all appoint a DPO.

πŸ‘‰ According to the draft Law on Personal Data Protection, the appointment of a DPO becomes mandatory for all businesses, regardless of the type of personal data being processed. Specifically, businesses will be required to appoint either an internal DPO with sufficient expertise or outsource the function to a qualified individual or organization (external DPO).

πŸ’‘What should your business do today?

  • Review the categories of personal data your organization is currently processing.
  • Assess whether the data is considered β€œsensitive” (under Decree 13) or falls under the expanded scope (in the draft Law).
  • Develop a plan to appoint an internal or external DPO based on your organization’s specific needs.

πŸ‘‰ Contact PrivacyCompliance for guidance on appointing your DPO!


Privacy Compliance

Draft Decree on Data Exchanges: Proposed Legal Framework for Data Transactions in Vietnam

Draft Decree on Data Exchanges: Proposed Legal Framework for Data Transactions in Vietnam The draft Decree on data exchange operations is currently open for consultation and proposes a framework for organizing, operating, and governing data transactions in Vietnam in a more transparent, controlled, and secure manner. A notable feature of the draft is the proposed […]

Learn more

Privacy Compliance

REDDIT FINED Β£14.47 MILLION FOR CHILDREN’S PRIVACY FAILURES β€” A LANDMARK UK ENFORCEMENT ACTION

πŸ” π—₯π—˜π——π——π—œπ—§ π—™π—œπ—‘π—˜π—— Β£14.47 π— π—œπ—Ÿπ—Ÿπ—œπ—’π—‘ 𝗙𝗒π—₯ π—–π—›π—œπ—Ÿπ——π—₯π—˜π—‘β€™π—¦ 𝗣π—₯π—œπ—©π—”π—–π—¬ π—™π—”π—œπ—Ÿπ—¨π—₯π—˜π—¦ β€” 𝗔 π—Ÿπ—”π—‘π——π— π—”π—₯π—ž π—¨π—ž π—˜π—‘π—™π—’π—₯π—–π—˜π— π—˜π—‘π—§ π—”π—–π—§π—œπ—’π—‘ Recently, the Information Commissioner’s Office (ICO) imposed a fine of approximately Β£14.47 million (~USD 19.5 million) on Reddit for processing the personal data of users under 13 without implementing appropriate age verification measures. This is reported to be the largest […]

Learn more

Privacy Compliance

RECRUITMENT ANNOUNCEMENT – MARKETING INTERN

Privacy Compliance Joint Stock Company is recruiting a Marketing Intern to support communication and brand development activities in the field of personal data protection and privacy. Job Description Assist in developing and implementing communication plans and content (website, LinkedIn, Facebook, email marketing, etc.). Coordinate in editing articles on data protection, compliance, and risk management (under […]

Learn more