{"id":2697,"date":"2022-11-22T16:12:41","date_gmt":"2022-11-22T09:12:41","guid":{"rendered":"https:\/\/cdlaf.az9s.group\/?page_id=2697"},"modified":"2026-10-01T20:50:47","modified_gmt":"2026-10-01T13:50:47","slug":"cross-border-personal-data-transfer-impact-assessment-services","status":"publish","type":"page","link":"https:\/\/xulydulieu.az9s.com\/en\/expertises\/cross-border-personal-data-transfer-impact-assessment-services\/","title":{"rendered":"Cross-border personal data transfer impact assessment services"},"content":{"rendered":"<p><strong>Entities Required to Conduct Cross-Border Personal Data Transfer Impact Assessment<\/strong><\/p>\n<p>According to the provisions of Clause 1, Article 18 of Decree 356\/2025\/ND-CP, agencies, organizations, and individuals involved in cross-border personal data transfer activities must establish a cross-border personal data transfer impact assessment dossier.<\/p>\n<p>Cases of cross-border data transfer are also mentioned in Clause 1, Article 20 of the Decree, including:<\/p>\n<ul>\n<li><em>Transferring personal data currently stored in Vietnam to a data storage system located outside the territory of the Socialist Republic of Vietnam;<\/em><\/li>\n<li><em>Agencies, organizations, and individuals in Vietnam transferring personal data to foreign organizations and individuals;<\/em><\/li>\n<li><em>Agencies, organizations, and individuals in Vietnam or abroad using platforms outside the territory of the Socialist Republic of Vietnam to process personal data collected in Vietnam.<\/em><\/li>\n<\/ul>\n<table class=\"redTable\">\n<thead>\n<tr>\n<th style=\"text-align: center;\">Implementation content<\/th>\n<th style=\"text-align: center;\"><strong>SERVICE DETAILS AT CDLAF<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Data Mapping<\/td>\n<td>Data experts will work directly with departments (IT, Marketing, HR) to inventory data categories and map out how data &#8220;flows&#8221; within the enterprise.<\/td>\n<\/tr>\n<tr>\n<td>Identifying Roles of Parties<\/td>\n<td>We assist in clarifying contact information and the roles of the Controller, Processor, and Third Parties in accordance with regulations.<\/td>\n<\/tr>\n<tr>\n<td>Determining Legal Status of Data-related Parties<\/td>\n<td>Lawyers identify the detailed information of the Transferor, Recipient, Data Processor, and third parties involved in the cross-border data transfer process.<\/td>\n<\/tr>\n<tr>\n<td>Classification and Legality Assessment<\/td>\n<td>Clearly distinguishing between basic\/sensitive data; reviewing the legal basis for each data processing activity according to the Law on Personal Data Protection and Decree 356.<\/td>\n<\/tr>\n<tr>\n<td>Data Flow Mapping<\/td>\n<td>Our data experts describe processing purposes, data types, and draw data flow diagrams; System diagrams, description of features of the personal data storage and processing system after receiving cross-border personal data.<\/td>\n<\/tr>\n<tr>\n<td>Drafting Data Transfer Assessment Reports (Form No. 09)<\/td>\n<td>Preparing the personal data processing impact assessment report with full mandatory content, ensuring strictness in every argument and data point.<\/td>\n<\/tr>\n<tr>\n<td>Instruction on Documentation with Data Subjects<\/td>\n<td>CDLAF experts will guide you in establishing contracts or agreements on personal data processing, reflecting the binding duties and responsibilities between organizations and individuals in data processing activities.<\/td>\n<\/tr>\n<tr>\n<td>Instruction on Internal Data Governance Documentation<\/td>\n<td>CDLAF data experts will advise you on building policies, processes, regulations, forms, and other relevant documents on personal data protection for the controller, controller and processor, processor, and parties involved in cross-border data transfer.<\/td>\n<\/tr>\n<tr>\n<td>Official Dossier Submission<\/td>\n<td>Representing the enterprise to complete the submission of original copies directly or online to the Department of Cybersecurity (A05) within the statutory timeline.<\/td>\n<\/tr>\n<tr>\n<td>Monitoring and Handling Feedback from the Ministry of Public Security<\/td>\n<td>Monitoring the progress of report processing, directly receiving and handling additional requests from specialized agencies.<\/td>\n<\/tr>\n<tr>\n<td>Dossier Revision upon request (if any)<\/td>\n<td>Performing in-depth adjustments and supplements to the dossier, providing explanations, and working directly with the Department of Cybersecurity.<\/td>\n<\/tr>\n<tr>\n<td>Legal Counsel in Post-inspection Activities<\/td>\n<td>Providing consulting services, orienting explanation content, and guiding the enterprise in preparing documents when there is a request for personal data inspection from competent authorities.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>I<\/em><\/strong><strong><em>nstructions for Preparing Cross-Border Personal Data Transfer Impact Assessment Reports according to Form No. 09 <\/em><\/strong><\/p>\n<p>The report will include the following contents:<\/p>\n<ul>\n<li>Information and contact details of the personal data transferor, personal data recipient, personal data processor, and other parties related to cross-border personal data transfer activities;<\/li>\n<li>Contact details of the personal data protection department and personnel; Organizations and individuals providing personal data protection services (if any) of the personal data transferor and personal data recipient;<\/li>\n<li>Description and justification of the purpose of cross-border personal data transfer, types of cross-border personal data transferred, details of cross-border personal data transfer and processing activities, and personal data processing flow diagrams;<\/li>\n<li>Description and justification for obtaining the consent of the personal data subject, policies for storage, deletion, and destruction of personal data;<\/li>\n<li>Plans to ensure personal data safety after cross-border transfer, personal data protection measures, and applied personal data protection standards;<\/li>\n<li>System diagrams, description of features of the personal data storage and processing system after receiving cross-border personal data;<\/li>\n<li>Procedures for the cross-border personal data recipient to transfer or provide personal data to third parties;<\/li>\n<li>Results of self-assessment of compliance with personal data protection regulations by the agency, organization, or individual involved in cross-border personal data transfer activities;<\/li>\n<li>Assessment of the personal data protection level of the personal data recipient; impact level and risks of cross-border personal data transfer and processing; unwanted consequences and damages that may occur, and measures to mitigate or eliminate those risks and threats<\/li>\n<\/ul>\n<p><strong>WHY CHOOSE PERSONAL DATA SERVICES AT CDLAF?<\/strong><\/p>\n<p>The difference of CDLAF lies in our mission: <strong>&#8220;Understand to Protect.&#8221;<\/strong> We do not just provide legal advice; we provide implementation solutions from the mindset of an <strong>In-house Counsel<\/strong>:<\/p>\n<ul>\n<li><strong>Multidisciplinary Understanding: <\/strong>CDLAF provides internal consulting for many enterprises across diverse fields such as manufacturing, e-commerce, labor sub-leasing, healthcare, education&#8230; therefore, we deeply understand the specific data issues of each business.<\/li>\n<li><strong>Insight into Cross-departmental Operations: <\/strong>We understand the data characteristics of each department, from the technical infrastructure of <strong>IT and Marketing <\/strong>to the security of sensitive records in <strong>Human Resources (HR),<\/strong> accounting, etc<\/li>\n<li><strong>Practical Experience: <\/strong>By performing various personal data services such as consulting, building internal data governance documents, and conducting impact assessment and cross-border data transfer procedures, our experts have diverse experience and in-depth knowledge of domestic personal data laws and the provisions of the EU General Data Protection Regulation<strong> (GDPR<\/strong><strong>).<\/strong><\/li>\n<\/ul>\n<p><strong>CDLAF LAW FIRM \u2013 Protecting data with insight from within<\/strong><\/p>","protected":false},"excerpt":{"rendered":"<p>Entities Required to Conduct Cross-Border Personal Data Transfer Impact Assessment According to the provisions of Clause 1, Article 18 of Decree 356\/2025\/ND-CP, agencies, organizations, and individuals involved in cross-border personal data transfer activities must establish a cross-border personal data transfer impact assessment dossier. Cases of cross-border data transfer are also mentioned in Clause 1, Article [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":2699,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-dich-vu-chi-tiet.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-2697","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/pages\/2697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/comments?post=2697"}],"version-history":[{"count":11,"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/pages\/2697\/revisions"}],"predecessor-version":[{"id":14356,"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/pages\/2697\/revisions\/14356"}],"up":[{"embeddable":true,"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/pages\/2699"}],"wp:attachment":[{"href":"https:\/\/xulydulieu.az9s.com\/en\/wp-json\/wp\/v2\/media?parent=2697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}