Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View

Vietnam Law on Personal Data Protection 2025 (Law No. 91/2025/QH15)

Last Updated on September 17, 2025

Schedule Your
Personal Demo

Learn how you can leverage Securiti’s Data Command Center to address data security, privacy, governance, and compliance.

See a demo
Schedule your demo today

Vietnam’s National Assembly officially passed Law No. 91/2025/QH15 on Personal Data Protection (PDPL) on June 26, 2025.

The PDPL establishes a unified and comprehensive legal framework for the protection of personal data in Vietnam, building upon the framework established by Decree 13. It ensures protections during the processing of personal data, strengthens data subject rights, mandates impact assessments, and establishes special safeguards for vulnerable groups, sensitive data, and sector-specific activities.

The PDPL will come into force on 01 January 2026 and apply to domestic and foreign organizations that process personal data or are involved in the processing of personal data within the territory of Vietnam, regardless of their nationality.


The Solution

Securiti enables organizations to comply with Vietnam’s PDPL through AI-driven PI data discovery, DSR automation, documented accountability, enhanced visibility into data processing activities, and AI-driven process automation.

Securiti supports enterprises in their journey toward compliance with Vietnam’s PDPL through automation, enhanced data visibility, and identity linking.

Vietnam Law on Personal Data Protection 2025

Secure Fulfillment of Data Access & Porting Requests

Article: 4(1)(a)

Create customized web forms to accept and verify DSR requests. Automate the fulfillment of access, correction, deletion, portability, and opt-out requests to ensure full compliance with the PDPL.

Readiness Assessment
Auto Compliance Management

Automate Processing of Rectification & Update Requests & Ensure Accuracy

Articles: 4(1)(c), 13, 3(3)

Utilize automated data subject verification workflows to seamlessly fulfill rectification, completion, and update requests across all instances of personal data.

Automate Erasure/Destruction/Anonymization Requests

Articles: 4(1)(d), 14

Automate data subject requests to minimize compliance violations while saving time and resources.

Privacy Notice Management
Universal Consent Management

Automate Restriction and Objection to Processing Requests

Articles: 4(1)(d), 10

Seamlessly fulfill data rectification requests with automated data subject verification and rectification workflows across all appearances of a subject’s personal data.

Automate Withdrawal Requests

Articles: 4(1)(b),10

Automate withdrawal requests to minimize compliance risks and reduce the operational burden of managing data subject requests.

Cookie Consent Management
Sensitive Data Intelligence

Monitor & Track Consent

Articles: 9, 11

Use a central dashboard to monitor consent across all data processing activities and track revocations, ensuring no data is processed or transferred without permission.

Map Data Flows & Generate RoPA Reports

Article: 11

Trace data flow across your systems, catalog data collection and transfer, and document business process flows internally and externally to the processors. Easily monitor cross-border traffic and key data patterns with dynamic data graphs.

Data Mapping Automation
Data Subject Rights Fulfillments

Automate DPIAs & Risk Assessments

Article:5(4), 21,22, 19(2)(c)

Identify real and potential compliance risks within internal policies and external regulations. Conduct Data Protection Impact Assessments (DPIA), document the entire process, and maintain DPIAs & risk assessment records.

Automate Data Breach Response Notifications

Article: 23

Track and manage potential incidents and data breaches with automated notification guidance based on global regulatory requirements.

Data Protection Assessment Automation
Data Breach Management

Privacy Policy & Notice Management

Article: 9(2), 29

Create and maintain privacy notices and policies for all digital properties using pre-built templates, with automated updates driven by cookie and data mapping modules.

Manage Vendor Risk

Article: 17

Track, manage, and monitor vendors' privacy and security readiness from a single dashboard. Collaborate in real time, automate data requests and deletions, and centrally manage all vendor contracts and compliance documents.

Data Protection Assessment Automation
Data Breach Management

Sensitive Data Requirements

Article: 31

Discover personal and sensitive data stored across all systems within the organization and link it to unique data subjects. Visualize personal data sprawl and identify compliance risks.

Automate Data Security Controls

Articles: 34, 3(4)(5), 19(2)(b)

Automate data security controls to manage, protect, and secure sensitive data, reducing manual effort and improving overall data security posture.

Data Protection Assessment Automation
Data Breach Management

Cross-Border Data Transfer

Article: 20

Trace data flow across your systems, catalog data collection and transfer, and document business process flows internally and externally to the processors. Easily monitor cross-border traffic and key data patterns with dynamic data graphs.

AI Governance

Articles: 30

Automate AI governance to oversee and monitor the development and deployment of AI systems, ensuring they are ethical, responsible, and fully compliant with regulatory requirements.

Data Protection Assessment Automation

Vietnam Law on Personal Data Protection 2025

1

The PDPL was passed by the National Assembly on 26 June 2025.

2

The PDPL has territorial and extraterritorial reach. It applies to organizations that process personal data or are involved in the processing of personal data within the territory of Vietnam, regardless of their nationality.

3

The PDPL requires organizations acting as data controllers to formulate contracts, implement data safeguards, report breaches, and cooperate with regulatory and relevant authorities.

4

Data processors must comply with the data controller’s instructions, ensure data security, and assist regulators.

5

The PDPL requires organizations to appoint a Data Protection Officer (DPO).

6

Organizations and individuals who violate Vietnam’s personal data protection law may face administrative sanctions, criminal prosecution, and must compensate for any damage caused. Administrative fines are: up to 10 times the revenue from buying or selling personal data; up to 5% of the organization’s previous year's revenue for cross-border data transfer violations; and up to 3 billion VND for other violations. If there is no revenue or the calculated fine is lower than 3 billion VND, the 3 billion VND fine applies. Individuals pay up to one-third of the organizational fine for the same violation.

7

Under the PDPL, organizations must report any detected violations to the agency responsible for personal data protection within 72 hours.

Analyze this article with AI

Prompts open in third-party AI tools.
IDC MarketScape

Securiti named a Leader in the IDC MarketScape for Data Privacy Compliance Software

Read the Report
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Latest
View More
Building Sovereign AI with HPE Private Cloud AI and Veeam Securiti Gencore AI
How HPE Private Cloud AI, NVIDIA acceleration, and Veeam Securiti Gencore AI support secure, governed enterprise AI with policy enforcement across RAG, assistant, and agentic workflows.
View More
Securiti.ai Names Accenture as 2025 Partner of the Year
In a continued celebration of impactful collaboration in DataAI Security, Securiti.ai, a Veeam company, has honored Accenture as its 2025 Partner of the Year....
Largest Fine In CCPA History_ What The Latest CCPA Enforcement Action Teaches Businesses View More
Largest Fine In CCPA History: What The Latest CCPA Enforcement Action Teaches Businesses
Businesses can take some vital lessons from the recent biggest enforcement action in CCPA history. Securiti’s blog covers all the important details to know.
View More
AI & HIPAA: What It Means and How to Automate Compliance
Explore how the Health Insurance Portability and Accountability Act (HIPAA) applies to Artificial Intelligence (AI) in securing Protected Health Information (PHI). Learn how to...
View More
Agentic AI & Privacy: Governing Autonomous AI Agents in the Enterprise
Learn how to govern agentic AI in the enterprise. Manage privacy risks, control data access, enforce policies and ensure compliance for autonomous AI agents.
View More
Opt-Outs That Stick: Consent Withdrawal Across Marketing, SaaS & GenAI
Securiti's whitepaper provides a detailed overview of various consent withdrawal requirements across marketing, SaaS, and GenAI. Read now to learn more.
View More
ROT Data Minimization
Eliminate redundant, obsolete, and trivial (ROT) data to improve AI accuracy, reduce storage costs, and minimize security and compliance risks at scale.
View More
Agent Commander: Solution Brief
Learn how Agent Commander detects AI agents, protects enterprise data with runtime guardrails, and undoes AI errors - enabling secure, compliant AI adoption at...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New