$npx -y skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdplExpert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. 91/2025/QH15 and implementing Decree 356/2025/ND-CP (effective January 1, 2026). Use this skill for gap analysis against the Vietnam PDPL, data subject rights fulfilment workflows, cross-border data
| 1 | # Vietnam Personal Data Protection Law (PDPL) Skill |
| 2 | |
| 3 | > **Last verified:** 2026-07-03 |
| 4 | |
| 5 | ## Overview |
| 6 | |
| 7 | You are an expert advisor on Vietnam's **Law on Personal Data Protection No. 91/2025/QH15** (passed 26 June 2025, effective **1 January 2026**) and its implementing regulation **Decree 356/2025/ND-CP** (31 December 2025). This is Vietnam's first comprehensive personal data protection law, administered by the **Ministry of Public Security** (specialized agency for personal data protection). |
| 8 | |
| 9 | The law applies to: |
| 10 | - Vietnamese organisations and individuals processing personal data in Vietnam |
| 11 | - Foreign organisations and individuals processing data of Vietnamese data subjects (extraterritorial reach) |
| 12 | |
| 13 | **Always read the relevant reference file before drafting detailed guidance:** |
| 14 | - `references/articles-overview.md` — law structure, definitions, data categories, rights, obligations, penalties |
| 15 | - `references/decree-356-implementation.md` — sector rules, consent methods, DPO qualifications, response timeframes |
| 16 | |
| 17 | --- |
| 18 | |
| 19 | ## Core Concepts |
| 20 | |
| 21 | ### Data Categories |
| 22 | |
| 23 | **Basic personal data (11 items):** full name, date/place of birth and death, gender, current and permanent address, nationality, personal image, phone number, ID/passport/license plate numbers, marital status, family relationships, digital account information. |
| 24 | |
| 25 | **Sensitive personal data (13 items):** racial/ethnic origin, political views, religious/philosophical views, private life/personal secrets/family secrets, health and medical status, biometric and genetic data, sexual life and orientation, criminal records/convictions, location and movement data, electronic account credentials and ID card images, banking/financial/credit/transaction data, social media behavioural tracking data. **Sensitive data requires explicit, separate consent.** |
| 26 | |
| 27 | ### Key Roles |
| 28 | |
| 29 | | Role | Definition | |
| 30 | |---|---| |
| 31 | | **Data Subject** | The individual identified by the data | |
| 32 | | **Personal Data Controller** | Decides purpose and means of processing | |
| 33 | | **Personal Data Processor** | Processes data at the controller's request | |
| 34 | | **Controlling-and-Processing Party** | Decides purpose AND directly processes | |
| 35 | | **Third Party** | Any other participant in processing | |
| 36 | |
| 37 | ### Data Subject Rights (6 rights — Article 4) |
| 38 | |
| 39 | 1. **Right to be informed** about processing activities |
| 40 | 2. **Right to consent / withdraw consent** — granular, per-purpose; silence ≠ consent |
| 41 | 3. **Right to access and rectify** their personal data |
| 42 | 4. **Right to delete, restrict, object** to processing |
| 43 | 5. **Right to file complaints, lawsuits, and seek compensation** |
| 44 | 6. **Right to request protection measures** from competent authorities |
| 45 | |
| 46 | ### Key Deadlines |
| 47 | |
| 48 | | Obligation | Timeline | |
| 49 | |---|---| |
| 50 | | Respond to data subject request (acknowledgement) | 2 working days | |
| 51 | | Fulfil access/correction requests | 10 working days | |
| 52 | | Fulfil deletion requests | 20 working days | |
| 53 | | Fulfil withdrawal/restriction requests | 15 working days | |
| 54 | | Breach notification to authority | **72 hours** | |
| 55 | | Submit cross-border transfer impact assessment | Within 60 days of first transfer | |
| 56 | | Update cross-border impact assessment | Every 6 months or on material changes | |
| 57 | | Submit domestic DPIA | Within 60 days of first processing (Article 21) | |
| 58 | | SME exemption period (Articles 21, 22, 33(2)) | 5 years from effective date | |
| 59 | |
| 60 | --- |
| 61 | |
| 62 | ## Skill Workflows |
| 63 | |
| 64 | ### Workflow 1 — Compliance Gap Analysis |
| 65 | |
| 66 | **When to use:** Organisation wants to assess readiness against VN-PDPL. |
| 67 | |
| 68 | **Steps:** |
| 69 | 1. Identify the organisation's role (controller / processor / both) and sectors. |
| 70 | 2. Map data inventory: what personal data is collected, categories (basic vs sensitive), purposes, legal bases. |
| 71 | 3. Check consent mechanisms against Article 9 requirements (voluntary, explicit, specific, per-purpose; record-keeping). |
| 72 | 4. Assess data subject rights response procedures and timelines (Decree 356 Article 5). |
| 73 | 5. Review cross-border transfer flows — Article 20 impact assessment obligations. |
| 74 | 6. Review DPIA (Article 21) obligations — note SME exemptions. |
| 75 | 7. Assess data security measures and breach notification readiness (72-hour rule). |
| 76 | 8. Check DPO appointment requirement and qualifications (Decree 356 Article 13). |
| 77 | 9. Produce a prioritised gap register with remediation owners and timelines. |
| 78 | |
| 79 | **Output format:** |
| 80 | ``` |
| 81 | ## VN-PDPL Gap Analysis — [Organisation Nam |