
Công cụ Kiểm tra Tuân thủ Nghị định 13
Assess your organization's compliance with Vietnam's Personal Data Protection Decree. This comprehensive tool evaluates your practices against all key requirements including consent, cross-border transfers, sensitive data processing, and DPO obligations.
Decree 13/2023/NĐ-CP (Nghị định 13) is Vietnam's comprehensive Personal Data Protection Decree, establishing requirements for collecting, processing, storing, and transferring personal data. It applies to all organizations operating in Vietnam or processing Vietnamese citizens' data.
Cơ sở pháp lý & Đồng ý
Do you obtain explicit consent before collecting personal data, clearly stating the purpose?
Is consent recorded in a verifiable format (written, electronic signature, or recorded action)?
Can data subjects withdraw consent easily and at any time?
Quyền của Chủ thể Dữ liệu
Do you provide mechanisms for data subjects to access their personal data upon request?
Can data subjects request correction of inaccurate personal data?
Do you have procedures for data subjects to request deletion of their data?
Dữ liệu Cá nhân Nhạy cảm
Have you identified and classified sensitive personal data (health, biometric, political views, etc.)?
Do you apply enhanced protection measures for sensitive data processing?
Chuyển Dữ liệu Xuyên Biên giới
Do you conduct impact assessments before transferring data outside Vietnam?
Do you notify the Ministry of Public Security before transferring sensitive data abroad?
Do you ensure foreign recipients provide adequate data protection levels?
Biện pháp Bảo mật
Do you implement encryption for personal data at rest and in transit?
Do you have access controls limiting who can view and process personal data?
Do you maintain audit logs of data access and processing activities?
Phản ứng Vi phạm Dữ liệu
Do you have a documented data breach response procedure?
Can you notify authorities within 72 hours of discovering a data breach?
Do you have processes to notify affected data subjects of breaches?
Người phụ trách Bảo vệ Dữ liệu & Trách nhiệm giải trình
Have you designated a person responsible for data protection (DPO equivalent)?
Do you maintain records of data processing activities?
Thông báo & Minh bạch
Do you have a clear, accessible privacy policy in Vietnamese?
Do you inform data subjects of all purposes, recipients, and retention periods?
Do you provide staff training on data protection obligations?
Our Ho Chi Minh City-based consultants specialize in Decree 13/2023 compliance. We help organizations implement compliant systems, conduct gap assessments, and prepare for regulatory inspections.
💬 Get Free Consultation • Tư vấn Miễn phíDecree 13/2023/NĐ-CP (Nghị định số 13/2023/NĐ-CP về bảo vệ dữ liệu cá nhân) is Vietnam's first comprehensive personal data protection regulation. Effective from July 1, 2023, it establishes a framework governing the collection, processing, storage, and transfer of personal data for all organizations operating in Vietnam or handling Vietnamese citizens' data.
The decree introduces several critical obligations for data controllers and processors:
The decree applies to:
Violations of Decree 13/2023 can result in administrative fines up to 100 million VND for organizations, criminal liability for serious violations, and potential business license suspension. The Ministry of Public Security is the primary enforcement authority.
Vietnam's PDPD shares similarities with the EU's GDPR and Singapore's PDPA, including consent requirements, data subject rights, and breach notification obligations. However, it includes Vietnam-specific requirements such as mandatory notification to the Ministry of Public Security for cross-border transfers of sensitive data and the requirement for privacy policies to be available in Vietnamese.