Are Vietnamese companies ready for the upcoming Personal Data Protection Decree (PDPD)?

Our findings - September 2021



 



50%

say they currently have defined access control policies and procedures in place to ensure restricted access to personal data.

66%

state they are either seeking advice on or have yet to create a roadmap to ensure compliance with the PDPD.

41%

are aware of the pending requirement to inform data subjects of all activities related to processing their personal data but don’t know how to prepare for this.

52%

do not have data breach/incident response procedures in place.

The road towards PDPD compliance will be challenging 

Vietnam recently published the Draft Decree on Personal Data Protection which will impact all entities processing personal data. Companies that fail to protect personal data and comply with PDPD aren’t just risking financial penalties. They also risk operational inefficiencies, intervention by regulators and most importantly permanent loss of consumer trust.

Our survey on PDPD readiness was sent out to the Vietnamese public from 19 July 2021 to 9 August 2021. Participants were asked to answer a list of questions relating to their current treatment of personal data and to ascertain their knowledge of, and readiness of the pending PDPD. The 48 survey respondents were evenly spread across all sectors in Vietnam, with the largest group (21%) coming from the manufacturing sector.

Key findings

Organisations in Vietnam have prepared for PDPD to a certain degree but current data privacy practices vary

How organisations currently take to restrict access to personal data that it holds to the data subject:

  • 50% of respondents say they have defined access control policies and procedures in place to ensure restricted access to personal data. 
  • 29% use passwords and two-factor authentication as technical measures. 
  • 13% conduct personal data risk assessment.

Measures to prevent unauthorised access to devices used to process personal data or to read, copy, alter or delete personal data

  • 65% of respondents state that they defined and implemented access control processes and solutions to prevent unauthorised access. 
  • Only 12% are not aware of the PDPD requirements and currently do not have any measure to manage this process.

What do you need to know about the Draft Decree?

  • Organisations must have a department supervising personal data protection and Data Protection Officer(s) (DPO).
  • Personal Data Processor must develop and issue its own set of personal data regulations.
  • Cross-border transfer of personal data can only be performed when 5 specific conditions are fulfilled.
    • the data subject agreed to the transfer of the data;
    • original personal data is stored in Vietnam;
    • the country of recipient imposes the same or higher level of data protection;
    • Personal Data Protection Commission (PDPC) agrees to the transfer in writing; 
    • the companies will need to register the sensitive personal data with the Personal Data Protection Commission.

Get in touch

Hide

If you have any questions or business inquiries, please fill in the form below and submit to us

Required fields are marked with an asterisk(*)

By submitting your personal data to us, you acknowledge that you have read the Privacy Statement and that you consent to our processing in accordance with the Privacy Statement. If you change your mind at any time,you can send us an email message using the Contact Us page.

Get in touch

Phan Thi Thuy Duong

Partner, PwC Legal Vietnam

Tel: +84 28 3823 0796, Ext.1508

Pho Duc Giang, CISSP, CISA

Partner, Digital Trust and Cybersecurity Services, PwC Vietnam Cybersecurity Services Company

Tel: +84 28 3823 0796