Certificate of Eligibility for Providing Personal Data Processing Services: Conditions, Application Dossier and Procedures under the Latest 2026 Regulations

From 1 January 2026, the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CPofficially came into effect, establishing a new legal framework for the protection and processing of personal data in Vietnam.

One of the notable developments is that the provision of personal data processing services is now a conditional business activity subject to specialized regulatory requirements. Organizations wishing to provide services within this scope must satisfy the prescribed conditions and obtain a Certificate of Eligibility for Providing Personal Data Processing Services issued by the Ministry of Public Security.

In particular, from 29 April 2026, Resolution No. 22/2026/NQ-CP further reduced and simplified the application dossier for this procedure. Accordingly, enterprises should apply the 2026 regulations rather than relying on previous guidance on personal data protection.

1. What is a Certificate of Eligibility for Providing Personal Data Processing Services?

A Certificate of Eligibility for Providing Personal Data Processing Services is a document issued by the competent authority to an organization that satisfies the applicable requirements regarding legal status, personnel, infrastructure, technology, and compliance with personal data protection regulations, allowing it to provide personal data processing services.

This is a new administrative procedure introduced in 2026. The Ministry of Public Security announced this procedure under Decision No. 778/QD-BCA-A05 dated 9 February 2026, with administrative procedure code 1.014910. The authority directly responsible for implementation is currently the Department of Cybersecurity and High-Tech Crime Prevention and Control.

It is particularly important to distinguish that not every enterprise that collects or processes personal data is required to obtain this Certificate.

An enterprise that processes data relating to its customers, employees, or partners for the purposes of its own business activities must comply with personal data protection laws, but this does not automatically mean that it is engaged in the “business of providing personal data processing services”.

The Certificate applies to organizations providing personal data processing activities as a service to other organizations or individuals within the categories prescribed by law.

2. Which services fall within the scope of personal data processing services?

Article 21 of Decree No. 356/2025/ND-CP identifies 09 categories of personal data processing services, including:

  1. Services involving the provision and operation of automated systems or software to process personal data on behalf of a data controller or a data controller and processor;
  2. Services involving scoring, ranking, or assessing the credibility or trustworthiness of data subjects;
  3. Services involving the online collection and processing of personal data from websites, applications, software, and social networks;
  4. Services involving the collection and processing of personal data through websites, applications, or software relating to healthcare, health monitoring, or medical services;
  5. Services involving the collection and processing of personal data through educational applications or software incorporating monitoring functions such as attendance tracking, video recording, behavioral scoring, or emotion recognition;
  6. Personal data analysis and exploitation services, including the use of analytical tools to identify information, trends, and data patterns, or the exploitation of data to predict user behavior or optimize services;
  7. Personal data encryption services during transmission and storage;
  8. Automated personal data processing services based on big data, artificial intelligence, blockchain, or metaverse technologies;
  9. Application platform services that provide personal location data.

Accordingly, enterprises operating in technology, data analytics, online platforms, education technology, healthcare technology, location services, user scoring, or outsourced data-processing systems should carefully assess whether their services fall within any of the above categories.

3. Conditions for obtaining the Certificate

Under Article 22 of Decree No. 356/2025/ND-CP, an organization providing personal data processing services must simultaneously satisfy the following groups of conditions:

3.1. Conditions regarding legal status

The organization or enterprise must:

  • be established and operate in accordance with Vietnamese law; and
  • satisfy the specialized conditions applicable to the business of providing personal data processing services.

This means that the applicant for the Certificate must have legal status in Vietnam.

3.2. Conditions applicable to the person in charge of professional matters

The head responsible for professional matters relating to personal data processing must:

  • be a Vietnamese citizen; and
  • permanently reside in Vietnam.

This requirement is separate from the position of legal representative. Depending on the enterprise’s organizational structure, the person responsible for professional matters may be the legal representative or another person appointed by the enterprise, provided that all statutory requirements are satisfied.

3.3. Conditions regarding the management and executive team

The enterprise must have a management and executive team that satisfies the professional requirements applicable to personal data processing.

In addition, the enterprise must have at least 03 personnel who satisfy the competency requirements for personal data protection.

Under Clause 2, Article 13 of Decree No. 356/2025/ND-CP, these personnel must simultaneously:

  • hold a college degree or higher;
  • have at least 02 years of working experience from the date of graduation in one or more of the following fields: legal affairs, information technology, cybersecurity, data security, risk management, compliance control, human resources management, or personnel organization; and
  • have received training and professional development in personal data protection law and professional skills.

Accordingly, the enterprise is not limited to employing information technology personnel. Personnel from various professional backgrounds may qualify, provided they satisfy the requirements regarding education, experience, and specialized training.

4. Conditions regarding facilities and technology

The enterprise must have:

  • infrastructure;
  • equipment systems;
  • physical facilities; and
  • technology

appropriate to the type of personal data processing services it intends to provide.

The law does not prescribe a fixed list of equipment applicable to every enterprise. The assessment of suitability depends on the type of service, scale of processing, type of data, sensitivity of the data, and risks associated with the processing activities.

In practice, the enterprise should be capable of demonstrating measures such as:

  • access control;
  • user authentication;
  • account authorization;
  • access logging;
  • data encryption;
  • data backup and recovery;
  • incident detection and response;
  • device and system management;
  • ensuring data integrity, confidentiality, and availability;
  • mechanisms for deleting or destroying data upon request; and
  • control over contractors and third parties with access to personal data.

These matters are particularly important when preparing the application proposal for the Certificate.

5. Conditions regarding personal data processing impact assessments

The organization must have a satisfactory result for its personal data processing impact assessment dossier.

Where the business activities involve cross-border transfers of personal data, the organization must also satisfy the requirements applicable to the cross-border personal data transfer impact assessment dossier.

This is an issue that enterprises should address before or concurrently with preparation of the Certificate application.

Even where an enterprise has sufficient personnel and technological systems, failure to complete the required impact assessments may mean that the enterprise has not yet fully satisfied the applicable business conditions.

6. Application dossier for the Certificate under the latest 2026 regulations

Article 25 of Decree No. 356/2025/ND-CP initially prescribed a relatively detailed application dossier, including the application form, Enterprise Registration Certificate, documentation concerning the personal data protection unit, the Proposal, and documents proving personnel qualifications.

However, from 29 April 2026, Resolution No. 22/2026/NQ-CP simplified the application dossier.

Under the new regulations, the application mainly consists of the following documents:

  1. Application for issuance of the Certificate of Eligibility for Providing Personal Data Processing Services;
  2. Document appointing a personal data protection unit or a contract for the use of personal data protection services, as required by law;
  3. Proposal for issuance of the Certificate of Eligibility for Providing Personal Data Processing Services;
  4. Other supporting documents and papers as required by the procedure.

This is a significant change from the original dossier requirements under Decree No. 356/2025/ND-CP.

Although the procedure has been simplified, enterprises must still actually satisfy all conditions relating to personnel, infrastructure, technology, and impact assessment. The removal of a document from the list of independent application components does not mean that the corresponding substantive condition has been abolished.

7. What must the Proposal for issuance of the Certificate contain?

The Proposal is one of the most important documents in the application dossier.

Under Article 25 of Decree No. 356/2025/ND-CP, the Proposal should include the following principal contents:

  • the necessity and objectives;
  • the contents and areas for which approval is sought;
  • business lines, business sectors, and business plan;
  • proposed scale of personal data processing activities;
  • personal data protection risk management framework;
  • plan for periodic assessment of compliance status and credibility in personal data protection;
  • application of standards and technical regulations relating to data security and personal data protection;
  • plan for using electronic identification and authentication services;
  • responsibilities and powers of the organization in personal data processing activities; and
  • personnel satisfying the statutory requirements.

Accordingly, the Proposal should not be prepared merely as a description of the enterprise’s business activities. It should demonstrate the enterprise’s data processing model, governance system, risk-control mechanisms, and compliance capacity.

8. Authority competent to issue the Certificate

Under Article 24 of Decree No. 356/2025/ND-CP:

The Ministry of Public Security has the authority to issue, re-issue, amend, and revoke Certificates of Eligibility for Providing Personal Data Processing Services.

The Minister of Public Security assigns the specialized personal data protection authority to receive, appraise, and process applications.

According to the administrative procedure published by the Ministry of Public Security, the authority directly responsible for implementation is:

The Department of Cybersecurity and High-Tech Crime Prevention and Control – Ministry of Public Security.

9. Methods of submission

The organization submits 01 set of application documents through one of the following three methods:

  • online;
  • directly; or
  • by postal service.

For online submission, the application is filed through the Ministry of Public Security’s public service system in accordance with the published procedure.

Enterprises should check the forms and dossier requirements displayed on the system at the time of submission, particularly because the procedure has been simplified by Resolution No. 22/2026/NQ-CP since 29 April 2026.

10. Procedure

Step 1: Preparation of the application dossier

The organization must accurately identify:

  • the personal data processing service it intends to provide;
  • the scope of service provision;
  • the data processing model;
  • personnel;
  • technological systems;
  • risk management mechanisms; and
  • impact assessment obligations.

Based on the above, the enterprise prepares the Application, Proposal, and relevant supporting documents.

Step 2: Submission of the application dossier

The organization submits 01 set of application documents to the specialized personal data protection authority online, directly, or by postal service.

Step 3: Assessment of completeness of the application dossier

Under Article 25 of Decree No. 356/2025/ND-CP, the specialized personal data protection authority assesses the application dossier within 10 days.

Where the application is incomplete or fails to comply with the regulations, the competent authority must issue a written notice requesting the organization to supplement and complete the dossier within 15 days, clearly stating the reasons.

Step 4: Appraisal and decision on issuance of the Certificate

After receiving a complete and valid application dossier, the specialized authority conducts an appraisal and considers whether to issue the Certificate.

Where all applicable requirements are satisfied, the enterprise will be granted the Certificate of Eligibility for Providing Personal Data Processing Services.

Where the Certificate is not granted, the competent authority must issue a written notice stating the reasons.

11. Processing time

Article 25 of Decree No. 356/2025/ND-CP provides that the specialized authority shall consider and decide on issuance of the Certificate within 30 days from the date of receipt of a complete and valid application dossier.

The National Public Service Portal currently publishes administrative procedure code 1.014910 with a processing time of 30 working days.

Enterprises should note that the processing period is calculated only from the date on which the dossier is complete and valid. Time spent supplementing or completing the dossier may extend the actual period required to obtain the result.

12. Fees and charges

According to the currently published administrative procedure, issuance of the Certificate of Eligibility for Providing Personal Data Processing Services is:

Not subject to any fee or charge.

However, enterprises may incur internal costs in order to satisfy the applicable conditions, including:

  • development of technological systems;
  • security assessments;
  • personnel training;
  • preparation of impact assessment dossiers;
  • development of internal procedures; and
  • compliance reviews and assessments.

13. How long is the Certificate valid?

The form of Certificate issued under Decree No. 356/2025/ND-CP provides that:

The Certificate takes effect from the date of signing.

The Decree does not prescribe a fixed validity period, such as 03 years or 05 years, for this Certificate.

However, the enterprise must continuously maintain the applicable operating conditions, and the Certificate may be revoked in the circumstances prescribed by law.

14. When may the Certificate be revoked?

Under Article 27 of Decree No. 356/2025/ND-CP, the Certificate may be revoked in certain circumstances, notably where:

  • the organization has not provided the relevant services for 12 months or more;
  • the organization is dissolved or declared bankrupt;
  • the organization fails to remedy violations relating to personal data protection, information security, cybersecurity, or data security as required by a competent state authority;
  • the organization voluntarily requests suspension or termination of its operations; or
  • other circumstances prescribed by law apply.

Where the Certificate is revoked, the organization must return the issued Certificate to the specialized personal data protection authority within 05 working days from the date of receipt of the revocation decision.

15. Re-issuance and amendment of the Certificate

In 2026, the procedures for re-issuance and amendment of the Certificate were also simplified.

Resolution No. 22/2026/NQ-CP merged the procedures for re-issuance and amendment into a single procedure, for which the principal application document is:

Application for Re-issuance or Amendment of the Certificate of Eligibility for Providing Personal Data Processing Services.

The processing period is 05 working days from the date of receipt of the application in accordance with regulations.

This is one of the notable procedural reforms compared with the original procedure under Decree No. 356/2025/ND-CP.

16. Important considerations for enterprises

To properly determine their obligations and mitigate legal risks when conducting business activities, enterprises should pay attention to the following matters:

First, it is necessary to distinguish between an enterprise processing data for its own business operations and an enterprise providing data processing services to customers. Not every enterprise that handles personal data is required to obtain this Certificate.

Second, enterprises should determine whether their actual services fall within any of the 09 service categories prescribed in Article 21 of Decree No. 356/2025/ND-CP.

Third, the requirement for at least 03 personnel is not merely a numerical requirement. Each person must satisfy all applicable requirements relating to qualifications, experience, and professional training.

Fourth, enterprises should complete the personal data processing impact assessment dossier and, where applicable, the cross-border personal data transfer impact assessment dossier before submitting the Certificate application.

Fifth, the Proposal for issuance of the Certificate should accurately reflect the enterprise’s actual systems and business model. Preparing a generic dossier that does not correspond with the enterprise’s technological infrastructure and actual operations may result in requests for clarification or supplementation.

Sixth, customer contracts should be reviewed to clearly identify the roles of the parties in the data processing activities, access rights, scope of processing, retention periods, responsibilities for incident handling, and obligations to delete or return data.

Seventh, enterprises must continue to maintain the applicable conditions after obtaining the Certificate. Issuance of the Certificate does not eliminate the enterprise’s ongoing compliance obligations relating to personal data protection, cybersecurity, information security, and data security.

17. Conclusion

From 2026, organizations providing personal data processing services within the scope of Decree No. 356/2025/ND-CP must satisfy the applicable specialized business conditions and obtain a Certificate of Eligibility for Providing Personal Data Processing Services.

In the context of the growing prevalence of data-driven businesses, digital platforms, artificial intelligence, and user analytics, enterprises should review their operating models from the outset to accurately determine whether they are merely processing data for internal business purposes or are providing personal data processing services that require a Certificate.

Correctly identifying the applicable regulatory scope is an important step in mitigating legal risks and ensuring that services are lawfully provided in Vietnam.