Skip to main content
Should You Be Ready for India and Vietnam's New Privacy Laws?Privacy Regulations
7 min readFor Privacy Officers

Should You Be Ready for India and Vietnam's New Privacy Laws?

Your team manages data across borders. If India or Vietnam is part of your processing footprint, or on your expansion roadmap, you now face two new compliance regimes with hard deadlines and specific obligations. India finalized its regulations for the Digital Personal Data Protection Act near the end of 2025. Vietnam's Personal Data Protection Law became effective on January 1, 2026.

This checklist helps you determine if your current data governance framework can accommodate these laws without rework, or if you need to adjust policies, contracts, and controls before you process personal data in either jurisdiction.

What This Checklist Covers

This is a readiness assessment, not a full implementation guide. Use it to identify gaps in your existing program that would prevent you from meeting baseline obligations under India's Digital Personal Data Protection Act and Vietnam's Personal Data Protection Law. Each item references a specific requirement and describes what compliance looks like in practice.

If you operate in the EU or UK, you already have a foundation. Both laws draw structural elements from GDPR, including lawful basis requirements, data subject rights, and cross-border transfer restrictions. But neither law is a clone, and the differences matter.

Prerequisites

Before you start this checklist, confirm:

  • You have a current data inventory. Know what personal data you hold, where it originates, and which processing activities involve India or Vietnam as a data subject location or a processing location.
  • You can identify your lawful basis for each processing activity. Both laws require you to justify why you're processing personal data. Consent is not the only option, but it's heavily regulated.
  • You have a mechanism to respond to data subject requests. Rights fulfillment is mandatory, and timelines are short.

Checklist Items

1. Confirm Your Lawful Basis for Processing

Requirement: Both laws require a valid legal ground before you process personal data.

What to check: Review your data inventory and identify the lawful basis for each processing activity involving Indian or Vietnamese data subjects. India's Act allows processing based on consent or for certain specified purposes, such as fulfilling a contract or complying with a legal obligation. Vietnam's law similarly requires consent or another legitimate basis.

Good looks like: Every processing activity in your register has a documented lawful basis that aligns with the categories defined in the applicable law. If you're relying on consent, you can prove it was freely given, specific, and informed.

2. Verify Your Consent Mechanism Meets the Standard

Requirement: If you rely on consent, it must be freely given, specific, informed, and, in many cases, affirmative.

What to check: Audit your consent collection points (web forms, mobile apps, onboarding flows). Pre-ticked boxes don't count. Bundled consent, where you condition a service on consent for unrelated processing, doesn't count. You need a clear affirmative action.

Good looks like: Your consent request separates each purpose. The user can decline one purpose without losing access to unrelated services. You store a timestamped record of the consent event, including the exact language shown to the user.

3. Map Your Cross-Border Data Flows

Requirement: Both laws restrict transfers of personal data outside the country unless specific safeguards are in place.

What to check: Identify every instance where data collected in India or Vietnam is transferred to another jurisdiction. This includes cloud storage in another region, processing by a third-party vendor, or internal transfers to your headquarters.

Good looks like: You have a documented list of all cross-border transfers, the destination country, the legal mechanism you're relying on (such as standard contractual clauses or an adequacy determination), and evidence that the mechanism is in force (signed contracts, approved certifications).

4. Establish a Data Subject Rights Fulfillment Process

Requirement: Data subjects have rights to access, correct, and delete their personal data. You must respond within the timeframe specified by law.

What to check: Test your current DSAR process against the requirements in India and Vietnam. Can you verify the requester's identity? Can you locate all personal data associated with that individual across your systems? Can you deliver the response in the required format and timeframe?

Good looks like: You have a documented procedure for receiving, verifying, and fulfilling requests. You can produce an audit trail showing when the request was received, how you verified identity, what data you disclosed or deleted, and when you responded. You meet the statutory deadline in every case or document a valid reason for extension.

5. Review Your Data Retention Practices

Requirement: You can only retain personal data as long as necessary for the purpose you collected it.

What to check: Review your retention rules. Do you have a defined retention period for each data category? Do you have a process to purge data when the retention period expires?

Good looks like: Your retention schedule specifies a retention period for each type of personal data, tied to a business or legal justification. You have automated or manual processes to delete data when the period ends. You can demonstrate that you've applied these rules consistently.

6. Assess Your Vendor Contracts for Data Processor Obligations

Requirement: If you share personal data with a third party who processes it on your behalf, that relationship must be governed by a contract that meets specific requirements.

What to check: Pull your contracts with cloud providers, SaaS vendors, and service providers who handle personal data. Do they include the required processor obligations (security measures, confidentiality, deletion upon termination, restrictions on sub-processing)?

Good looks like: Every vendor contract includes a data processing addendum that specifies the scope of processing, the security measures the vendor must implement, the vendor's obligation to delete data upon termination, and your right to audit. The contract prohibits the vendor from using your data for their own purposes.

7. Confirm You Have a Breach Notification Plan

Requirement: If you experience a data breach, you must notify the supervisory authority and, in some cases, affected individuals within a specified timeframe.

What to check: Review your incident response plan. Does it include steps to assess whether a breach involves personal data subject to India or Vietnam's laws? Does it specify who is responsible for notifying the supervisory authority and what information must be included?

Good looks like: Your incident response plan includes a decision tree for determining notification obligations under multiple jurisdictions. You have pre-drafted templates for supervisory authority notifications. You've tested the plan with a tabletop exercise that includes a cross-border breach scenario.

8. Document Your Technical and Organisational Measures

Requirement: You must implement appropriate security measures to protect personal data.

What to check: Review your security controls. Can you demonstrate that you've implemented encryption, access controls, and logging for systems that process personal data? Do you have evidence that these controls are operating effectively?

Good looks like: You maintain a written description of your security measures, mapped to the types of personal data you process and the risks you've identified. You have logs showing that access controls are enforced. You conduct regular security assessments and document the results.

Common Mistakes

Assuming GDPR compliance equals automatic compliance elsewhere. India and Vietnam's laws share structural similarities with GDPR, but the details differ. Consent standards, transfer mechanisms, and enforcement priorities are not identical. Don't copy your GDPR playbook without adaptation.

Treating consent as the default lawful basis. Consent is often the hardest basis to manage because it can be withdrawn at any time. If you can justify processing under a legal obligation or contractual necessity, you'll have a more stable foundation.

Ignoring vendor processing locations. Your vendor may have a data center in Singapore, but if they route data through India or Vietnam, even temporarily, you may trigger local law obligations. Map the full data flow, not just the endpoint.

Delaying cross-border transfer documentation. You can't wait until a supervisory authority asks for proof. Standard contractual clauses and transfer impact assessments must be in place before the first transfer occurs.

Next Steps

If you identified gaps in this checklist, prioritize them based on your current processing activities. If you're already processing data in India or Vietnam, address lawful basis and cross-border transfers immediately. If you're planning to enter these markets, build the documentation and controls before you start processing.

If your organization operates across multiple APAC jurisdictions, consider building a regional compliance framework that accommodates common requirements (consent, rights fulfillment, breach notification) while allowing for jurisdiction-specific variations. This approach scales better than managing each country in isolation.

Finally, monitor regulatory guidance. Both India and Vietnam are early in their enforcement cycles. Supervisory authorities will issue clarifications, and enforcement priorities will emerge. Subscribe to official updates and adjust your program as the landscape develops.

You Might Also Like