Vietnam PDPL

Controller and Processor Roles Under Vietnam's PDPL

  • Data Protection
  • Data Governance
  • Privacy

Who decides why personal data is processed? Who performs the processing? And what happens when the same organisation does both?

These questions sit at the centre of Vietnam’s Law on Personal Data Protection, Law No. 91/2025/QH15 - often referred to as the Vietnam PDPL.

The law took effect on 1 January 2026. It uses controller and processor concepts that will look familiar to anyone who works with the GDPR, but the Vietnamese framework has its own terminology and requirements. Most notably, it expressly recognises a third role: the personal data controller and processor.

The Law is supplemented by Decree No. 356/2025/ND-CP, promulgated on 31 December 2025 and effective on the same date as the PDPL. The decree provides the detail the statute leaves to secondary legislation and formally replaced Decree No. 13/2023/ND-CP.

Understanding these roles is not simply a matter of choosing wording for a contract. The classification affects responsibilities for contracts, protection measures, individual rights, impact assessments, violations and accountability.

The three roles under Vietnam’s PDPL

Article 2 of Law No. 91/2025/QH15 identifies three relevant roles.

1. Personal data controller

A personal data controller is an agency, organisation or individual that decides the purposes and means of processing personal data.

In practical terms, the controller determines why the processing takes place and the important parameters governing it.

2. Personal data processor

A personal data processor is an agency, organisation or individual that processes personal data at the request of the personal data controller - or the personal data controller and processor - through a contract.

The processor therefore performs processing for another party and within the contractual arrangement.

3. Personal data controller and processor

A personal data controller and processor is an agency, organisation or individual that decides the purposes and means and directly processes the personal data.

This category recognises a common operational reality: an organisation may decide why and how processing should occur and also carry out the processing itself.

The roles at a glance

Question Controller Processor Controller and processor
Decides the processing purpose Yes No Yes
Decides the means of processing Yes No, although it may make implementation decisions within the arrangement Yes
Directly performs the processing Not necessarily Yes, at another party’s request Yes
Operates through a processing contract Appoints and governs the processor Yes May appoint a processor and may also process directly
Carries controller responsibilities under Article 37 Yes No Yes
Carries processor responsibilities under Article 37 No Yes Yes

The table is a starting point. The correct role must still be determined from the particular activity and arrangement.

Note also that the PDPL does not draw an express distinction between essential and non-essential means in the way EDPB guidance does under the GDPR. The suggestion that a processor may make implementation decisions without becoming a controller is a reading of the statutory definitions, not a stated rule of the Law.

What makes an organisation a controller?

The defining feature is decision-making authority over the purposes and means.

Questions that may indicate controller status include:

  • Who decided why the personal data should be processed?
  • Who decided which individuals’ data would be involved?
  • Who determined which categories of information were necessary?
  • Who decided who may access or receive the data?
  • Who established the retention requirements?
  • Who decides whether the data may be disclosed or reused?

Article 37 requires a controller to decide the purposes and means of processing in documents and agreements with personal data subjects, in accordance with the principles and requirements of the Law.

The controller must also specify the parties’ responsibilities, rights and obligations in processing-related agreements and contracts.

What makes an organisation a processor?

The processor performs personal data processing at the request of the controller, or the controller and processor, through a contract.

Two elements are therefore central:

  1. The processor is acting at another party’s request.
  2. The activity is governed by the required contractual arrangement.

Article 37 provides that a processor may receive personal data only after an agreement or processing contract is in place. It must then process the data according to that agreement or contract.

A service provider does not become a processor merely because it receives personal data from a customer. The actual relationship must fit the statutory definition.

For example, a provider that determines its own independent purpose for using the information may not be acting only as a processor for that additional activity.

What is a “controller and processor”?

The combined controller-and-processor category is one of the most important features to understand in the Vietnamese framework.

It applies where the same party:

  • Decides the purposes of processing
  • Decides the means of processing
  • Directly performs the processing

Consider an employer that decides to collect employee information for recruitment, payroll and employment administration and then processes that information using its own systems and staff.

The employer is not only making the controlling decisions. It is also directly carrying out the processing. Under the statutory definitions, it may therefore be a personal data controller and processor.

Article 37(3) makes the consequence clear: a controller and processor must fulfil both the controller responsibilities and the processor responsibilities set out in that article.

This is not the same as a GDPR joint controller

Vietnam’s controller-and-processor category should not be confused with joint controllership under the GDPR.

Under the GDPR, joint controllers are two or more parties that jointly determine the purposes and means of processing.

Vietnam’s controller-and-processor category describes one party that both determines the purposes and means and directly performs the processing.

The terms answer different questions:

  • Joint controller: Are multiple parties jointly making the controlling decisions?
  • Controller and processor: Is the same party deciding and directly processing?

Treating these expressions as interchangeable can produce an incorrect role assessment.

Does the contract decide the role?

Under Vietnam’s PDPL, the contract has a substantive legal role.

The processor definition in Article 2 refers to processing at the controller’s request through a contract. Article 37 also requires the processor to receive and process personal data according to an agreement or contract.

This differs from saying that the contractual label alone determines the classification.

If an agreement calls a service provider a processor but the provider independently determines the purpose and means of an activity, the arrangement may not fit the processor definition for that activity.

Reading Articles 2 and 37 together supports a practical approach:

Assess who decides and who processes, assign the appropriate role, and ensure the contract accurately establishes the processing arrangement.

The contract is essential, but its terminology and obligations must correspond with the way the parties operate.

Controller responsibilities under Article 37

Article 37 gives the controller a broad set of responsibilities. These include:

  • Stating the parties’ responsibilities, rights and obligations in relevant agreements and contracts
  • Deciding the purposes and means in accordance with the law
  • Implementing appropriate management and technical protection measures
  • Reviewing and updating those measures when necessary
  • Notifying qualifying violations in accordance with Article 23
  • Selecting a suitable processor
  • Ensuring the rights of personal data subjects
  • Accepting responsibility to personal data subjects for damage caused during processing
  • Preventing unlawful collection from its systems, equipment and services
  • Cooperating with the Ministry of Public Security and other competent authorities

These duties show why controller status is more than a contractual description. It carries decision-making authority and direct accountability.

Processor responsibilities under Article 37

The processor has its own direct responsibilities. These include:

  • Receiving personal data only after a processing agreement or contract is in place
  • Processing the data according to the signed agreement or contract
  • Implementing the legally required personal data protection measures
  • Accepting responsibility to the controller, or controller and processor, for damage caused during processing
  • Preventing unlawful collection from its systems, equipment and services
  • Cooperating with the Ministry of Public Security and other competent authorities

The processor is therefore not merely a passive service provider. It must be able to demonstrate that its operations stay within the agreed processing arrangement and satisfy its own protection duties.

Impact assessments differ by role

Article 21 allocates impact-assessment duties according to role.

  • The personal data controller and the personal data controller and processor must establish and store a personal data processing impact assessment dossier and send one original to the personal data protection authority within 60 days of first processing personal data.
  • The personal data processor establishes and maintains its dossier in accordance with its agreement with the controller or the controller and processor.

Article 38 then provides transitional relief. Business households and micro-enterprises are not required to comply with Articles 21 and 22 or Clause 2 of Article 33. Small enterprises and start-ups may choose whether to apply them for five years from the effective date. Both carve-outs exclude parties that provide personal data processing services, directly process sensitive personal data, or process the personal data of a large number of data subjects.

Responsibility when a violation occurs

Role classification also affects the reporting path.

Under Article 23, a processor that discovers a violation must promptly notify the controller or controller and processor.

Where a controller, controller and processor, or third party discovers a violation that may harm national defence, national security, social order and safety, or infringe the life, health, honour, dignity or property of the personal data subject, it must notify the personal data protection authority — which sits under the Ministry of Public Security — no later than 72 hours from discovery.

This threshold is not the same as the GDPR’s. Article 33 of the GDPR is triggered by a risk to the rights and freedoms of natural persons; Article 23 of the PDPL is framed around specific categories of harm.

The allocation matters operationally. Incident-response procedures and contracts should identify who detects, escalates, assesses, documents and makes any required notification.

Practical example 1: payroll processing

An employer decides which employee information is necessary, why it will be used and how long it should be retained.

When the employer uses its own system

If the employer also processes the information using its own systems and personnel, it may be acting as the controller and processor.

When the employer appoints a payroll provider

If a payroll provider calculates salaries at the employer’s request under a processing contract:

  • The employer makes the controlling decisions.
  • The payroll provider acts as the processor for that service.

The payroll provider will still hold a different role for activities it determines itself, such as processing its own employee information.

Practical example 2: cloud hosting

An organisation decides to collect customer information for a defined business activity. It appoints a cloud provider to store the information according to the agreed service and processing terms.

The customer may be the controller - or controller and processor where it also directly processes the information - while the cloud provider acts as processor for the hosting activity.

The provider’s technical discretion does not automatically make it the controller. The more important question is whether it independently determines the purpose and means of a separate processing activity.

Practical example 3: an AI service

An organisation submits personal data to an AI service to summarise documents for a purpose it has established. The service provider processes the data only to deliver that requested function under the contract.

The provider may be acting as a processor for that service.

Suppose the provider also decides to reuse the submitted information to train its own models or develop an independently determined product. That additional use requires a separate assessment. It may not fit the processor role because the provider is no longer acting only at the customer’s request and for the agreed processing purpose.

The result depends on the actual data practices, contractual terms and applicable legal requirements.

A practical Vietnam PDPL role-assessment checklist

For each processing activity, record the answers to the following questions:

  1. What specific personal data processing activity is being assessed?
  2. Who decides its purpose?
  3. Who decides its means?
  4. Who directly performs the processing?
  5. Is one party acting at another party’s request?
  6. Is the required agreement or contract in place?
  7. Does the provider have permission to use the data for any independent purpose?
  8. Which party manages personal data subject requests?
  9. Which party makes any required violation notification?
  10. Do the contract, privacy information, impact assessment and actual workflow describe the same arrangement?

The assessment should be completed at the activity level. An organisation may hold different roles across different services and purposes.

Common classification mistakes

Treating every vendor as a processor

A supplier is not automatically a processor simply because it receives personal data. The relationship must satisfy the statutory definition.

Copying GDPR terminology without checking Vietnam’s categories

The concepts overlap, but the Vietnamese combined controller-and-processor category and its contractual wording require separate attention.

Assigning one role to the entire organisation

The correct role can change between employment, customer administration, hosted services, analytics and other activities.

Treating the contract as a substitute for operational review

The contract is essential under Vietnam’s PDPL, but it must accurately describe the decisions, instructions and processing that occur in practice.

Forgetting that processors have direct responsibilities

Processors must implement protection measures, operate within the agreement and cooperate with competent authorities, among other duties.

Vietnam PDPL and GDPR: the central difference

Both frameworks use the purposes-and-means distinction to identify the controller. Both also recognise a processor that acts for another party under a required contractual arrangement.

The important difference for this discussion is structural:

  • The GDPR does not create a separate role merely because a controller directly processes personal data itself.
  • Vietnam’s PDPL expressly identifies a personal data controller and processor and assigns it both sets of Article 37 responsibilities.

This means a GDPR role assessment can inform a Vietnamese assessment, but it should not be copied without adjustment.

For the broader distinction between the two basic roles, see Controller or Processor? Your Role Depends on What You Do.

Why this is a data governance issue

Role classification establishes who has authority and accountability across the personal data lifecycle.

Organisations should connect the assessment to:

  • Their personal data inventory
  • Processing impact assessments
  • Privacy information and consent records
  • Contracts and vendor-management records
  • Access and sharing decisions
  • Retention and deletion requirements
  • Rights-request procedures
  • Violation and incident-response processes

The role should be documented for each processing activity, together with the reasoning and supporting evidence. A contract that says “processor” without an operational assessment is not a complete governance record.

Final takeaway

Vietnam’s PDPL recognises three distinct roles: controller, processor, and controller and processor.

The classification turns on three practical questions:

  1. Who decides the purposes?
  2. Who decides the means?
  3. Who directly performs the processing, and at whose request?

The contract is an essential part of the processor relationship, but it must align with the decisions and activities of the parties.

Start with the processing activity. Determine the role. Then document and govern it properly.

This article provides general information about Vietnam’s Law on Personal Data Protection, Law No. 91/2025/QH15. Legal requirements depend on the applicable facts, implementing rules and other relevant Vietnamese laws. This is not legal advice.