IS A DPO CERTIFICATION MANDATORY? WHAT CONDITIONS MUST ENTERPRISES MEET WHEN APPOINTING PERSONAL DATA PROTECTION PERSONNEL?
One of the issues of great interest to many enterprises is the appointment of personal data protection personnel (Data Protection Officer – DPO), especially concerning professional standards and training requirements.
Currently, the market offers numerous training programs with names such as "DPO Training," "DPO Certification," "Personal Data Protection Expert," or certification programs in privacy and data governance.
This raises three important legal questions:
(1) Does Vietnamese law mandate that DPO personnel must possess a specific type of certification?
(2) Is completing a training course and receiving a certificate sufficient to qualify as a DPO?
(3) What documents does an enterprise need to prepare to prove that the appointed personnel meet legal requirements?
1. Does the law mandate DPO certification?
1.1. Training is required, but a specific DPO certification is not mandatory
According to Point c, Clause 2, Article 13 of Decree 356/2025/ND-CP, personal data protection personnel appointed by agencies or organizations must meet the following condition:
“Having been trained and updated on legal knowledge and professional skills in personal data protection.”
Thus, the law establishes a requirement for training and professional development for personal data protection personnel.
However, it is necessary to distinguish between the condition of being trained and the possession of a specific certification.
Decree 356/2025/ND-CP currently does not regulate:
-
A mandatory DPO professional certificate template;
-
A fixed list of DPO training institutions recognized by the State;
-
A minimum number of training hours generally applicable to all DPO personnel;
-
A single examination or certification program to be appointed as a DPO.
Therefore, enterprises should not assume that merely purchasing a training course and receiving a "DPO Certificate" fulfills the legal requirements for personal data protection personnel.
Conversely, the absence of a mandatory specific certification does not mean enterprises can disregard the obligation to provide training and professional development.
1.2. What is the legal value of a training certificate?
A certificate of course completion can be used as documentation to prove that an individual has participated in and completed a training program.
However, the evidentiary value of such a document depends on various factors, including the program content, the organizing entity, the training format, the assessment results, and the degree of relevance to the actual job.
For example, a legal specialist who attends a popular Personal Data Protection Law course for a few hours may have acquired basic legal knowledge.
But that is not enough to affirm that this person is capable of performing tasks such as assessing the impact of personal data processing, developing data management processes, evaluating risks, or coordinating information security incident response.
The issue an enterprise needs to evaluate is not just which course the personnel took, but also what knowledge and skills that program equipped them with to perform their assigned duties.
2. Conditions for appointment as personal data protection personnel
According to Clause 2, Article 13 of Decree 356/2025/ND-CP, personal data protection personnel appointed by agencies or organizations must simultaneously meet three groups of conditions.
2.1. Professional qualifications
The appointed personnel must have a college degree or higher.
This is a fundamental condition and must be demonstrated through valid diplomas or documents regarding educational qualifications.
2.2. Work experience
The personnel must have at least 02 years of work experience since graduation, related to one of the following fields:
Legal affairs, information technology, cybersecurity, data security, risk management, compliance control, human resources management, or personnel organization.
This regulation allows enterprises to select personnel with diverse professional backgrounds, rather than limiting the DPO position exclusively to legal specialists or IT personnel.
However, the duration of experience must be linked to a relevant field of work. An individual having many years of work experience at an enterprise does not automatically prove that they meet the DPO experience requirement.
2.3. Professional training and development
The personnel must be trained and updated on both legal knowledge and professional skills in personal data protection.
These two groups of competencies are complementary.
Regarding legal knowledge, a DPO needs to understand the principles of personal data processing, the legal basis for processing activities, the rights of data subjects, the responsibilities of parties involved in processing, and related legal requirements.
Regarding professional skills, a DPO needs to be able to coordinate with operational departments to identify data processing activities, assess risks, develop protection measures, and monitor compliance obligations.
Additionally, Clause 1, Article 13 requires that the appointment of personal data protection personnel or department must be made in an official written document, specifying the assignment, functions, duties, and powers.
Therefore, meeting the competency conditions and being duly appointed are two issues enterprises need to address concurrently.
Article 14 of Decree 356/2025/ND-CP stipulates the duties of the personal data protection department and personnel.
For DPO personnel, the duties focus on advising, participating in, and implementing personal data protection activities within their assigned scope of responsibility.
From a corporate governance perspective, these can be categorized into four core competency groups.
3.1. Legal and compliance management capabilities
A DPO needs to be able to analyze legal regulations and apply them to actual data processing activities.
This work may include advising on the development of personal data protection policies, data collection and processing procedures, notification forms, consent mechanisms, and procedures for exercising data subject rights.
This is not merely a document drafting activity. A DPO needs to understand the purpose of data collection, who is authorized to process it, how long the data is retained, and which processing activities pose potential legal risks.
3.2. Data impact assessment and risk management capabilities
A crucial duty of a DPO is to participate in developing personal data processing impact assessment reports and cross-border personal data transfer impact assessment reports as required.
This activity often requires coordination among legal, IT, and departments directly involved in data processing.
A DPO needs to understand how to identify processing purposes, relevant data types, involved parties, scope of data sharing and transfer, and potential risks to individuals' rights and interests.
3.3. Technical coordination and incident response capabilities
While a DPO does not necessarily need to be a programming or cybersecurity expert, they need to have appropriate understanding to coordinate with the technical department.
For example, in the event of a customer data breach, a DPO needs to coordinate in identifying the type of data affected, the scope of the incident, notification obligations, and necessary remediation measures.
A lack of basic technical knowledge can lead to incomplete risk assessments or incident handling.
3.4. Monitoring and internal training capabilities
A DPO needs to participate in compliance status assessments, recommend improvements, and engage in training and professional development programs on personal data protection.
In practice, data risks arise not only from technology systems but also from the activities of personnel, business, marketing, customer service, recruitment, and service providers.
Therefore, a DPO needs to be able to coordinate across departments, explain legal requirements, and support the implementation of appropriate control measures.
4. How should enterprises choose a DPO training program?
The choice of training program should stem from job requirements and the current capabilities of the personnel intended for appointment.
Not all personnel require the same training program.
For example, a legal specialist with experience in contracts, compliance, and data protection may need to supplement skills in data mapping, technology risk assessment, and incident response.
Meanwhile, an IT specialist with data security experience may need to focus on the legal basis for data processing, data subject rights, impact assessment obligations, and enterprise responsibilities.
When choosing a program, enterprises should evaluate the following factors:
First, the training provider. Identify the entity responsible for delivering the program, the professional competence of the instructors, and the certificate-issuing body.
Second, content and learning outcomes. The program should clearly state the scope of knowledge, skills, duration, practical content, and expected learning outcomes.
Third, assessment methods. Prioritize programs with tests, case studies, or appropriate learning outcome assessments, rather than just attendance confirmation.
Fourth, legal update level. The training content must be consistent with the Personal Data Protection Law, Decree 356/2025/ND-CP, and related regulations.
Fifth, relevance to the job position. The program should help personnel enhance their capabilities to perform DPO duties, not just meet certification needs.
Enterprises can also combine various training formats, including external programs, internal training, regular legal updates, and practical guidance for specific operational groups.
A single course does not necessarily have to cover all DPO competencies, as long as the enterprise can assess and demonstrate that the personnel have received appropriate training and professional development.
5. Distinguishing between internal DPO personnel and external DPO service providers
This is an issue enterprises need to pay particular attention to when deciding whether to assign internal personnel or outsource.
According to Clause 2, Article 13 of Decree 356/2025/ND-CP, personal data protection personnel appointed by agencies or organizations must meet the requirements of a college degree or higher, at least 02 years of relevant experience, and having been trained and updated on legal knowledge and professional skills.
Meanwhile, Article 15 stipulates the conditions for individuals providing personal data protection services, who are hired by organizations as personal data protection personnel.
For this group, the experience requirement is at least 03 years from graduation in the specified fields, and they must have received in-depth training and professional development in legal knowledge and professional skills in personal data protection.
Thus, hiring an individual to provide DPO services from outside is not merely choosing an expert with a training certificate.
Enterprises need to assess the individual's competency conditions, define the scope of services, enter into a contract, and fulfill related requirements according to Article 15.
6. What documents does an enterprise need to prepare to demonstrate DPO capability?
A suitable approach is to build a Data Protection Officer (DPO) Qualification File.
This is a suggested name for an internal management file, not a separate mandatory document type stipulated by Decree 356.
The file should be structured into three groups of documents.
Group 1. Documents regarding personnel conditions and appointment
Includes diplomas, professional resumes, work history information, documents proving experience in relevant fields, and the DPO appointment letter.
The appointment letter should clearly define the scope of work, responsibilities, authorities, and coordination mechanisms with relevant departments.
Group 2. Documents proving the training process
Enterprises should retain certificates of completion along with documents showing the training content.
Documents may include program outlines, lecturer information, duration, study materials, tests, assessment results, and completion confirmations.
The goal is to be able to explain what content the personnel were trained on, through what format, and how well they meet job requirements.
Group 3. Documents demonstrating practical implementation capability
Enterprises can retain documents showing that personnel have participated in activities such as developing data protection policies, preparing impact assessments, reviewing data processing procedures, handling data subject requests, or coordinating incident response.
This group of documents supports the assessment of practical capabilities and is not an additional mandatory condition beyond the legally stipulated conditions.
Documents containing personal data, trade secrets, or internal information must be managed with appropriate access controls.
7. DPO appointment is not a one-time task
A common oversight by enterprises is maintaining personnel competency after completing the appointment procedure.
Clause 6, Article 13 of Decree 356/2025/ND-CP stipulates the responsibility to train and enhance the professional knowledge and skills of appointed personal data protection personnel.
Therefore, enterprises should not view DPO training as merely a procedure to be completed at the time of appointment.
When enterprises expand business operations, implement new technology systems, apply AI, change service providers, or perform cross-border personal data transfers, the scope of data risks can change significantly.
Training and knowledge update activities need to be reviewed in accordance with such changes.
From a compliance management perspective, enterprises should periodically reassess DPO capabilities, update legal requirements, review shortcomings in the implementation process, and organize additional training when necessary.
8. OPLAW's Recommendations
Compliance with personal data protection personnel regulations should not be assessed solely by the presence of a training certificate.
For enterprises building or refining their personal data protection system, OPLAW recommends the following sequence:
Step 1 – Identify legal requirements: Assess the obligation to appoint personnel or a personal data protection department appropriate to the enterprise's operations and legal circumstances.
Step 2 – Personnel assessment: Review the qualifications, experience, knowledge, and existing skills of the personnel designated for appointment.
Step 3 – Develop a training roadmap: Select a training program based on actual competency gaps, combining legal knowledge and professional skills.
Step 4 – Complete documentation: Prepare documents proving competency conditions, training process, and formal written appointment.
Step 5 – Maintain compliance: Establish mechanisms for periodic assessment, legal updates, and competency enhancement when the scope of data processing changes.
CONCLUSION
Decree 356/2025/ND-CP does not establish a single mandatory DPO professional certification. Instead, the law defines specific conditions regarding the qualifications, experience, legal knowledge, and professional skills of personal data protection personnel.
This indicates that the selection and appointment of a DPO should be viewed as a compliance management activity, rather than merely a procedure to complete training documents.
A suitable training program helps enterprises prepare DPO capabilities. A complete set of documents helps enterprises prove the personnel's qualifications. But it is the ability to implement personal data protection activities that ultimately determines the effectiveness of the compliance system in practice.
Related articles
Frequently Asked Questions
What should readers know about IS A DPO CERTIFICATION MANDATORY? WHAT CONDITIONS MUST ENTERPRISES MEET WHEN APPOINTING PERSONAL DATA PROTECTION PERSONNEL??
Learn whether DPO certification is mandatory in Vietnam and the conditions enterprises must meet when appointing personal data protection personnel according to Decree 356/2025/ND-CP.
What should readers know about IS A DPO CERTIFICATION MANDATORY? WHAT CONDITIONS MUST ENTERPRISES MEET WHEN APPOINTING PERSONAL DATA PROTECTION PERSONNEL??
Learn whether DPO certification is mandatory in Vietnam and the conditions enterprises must meet when appointing personal data protection personnel according to Decree 356/2025/ND-CP.
What should readers know about IS A DPO CERTIFICATION MANDATORY? WHAT CONDITIONS MUST ENTERPRISES MEET WHEN APPOINTING PERSONAL DATA PROTECTION PERSONNEL??
Learn whether DPO certification is mandatory in Vietnam and the conditions enterprises must meet when appointing personal data protection personnel according to Decree 356/2025/ND-CP.