Data Governance Toolkit — F&B
This Package B toolkit helps businesses move from 'worrying about data law' to 'knowing what data you hold and what to do to comply' — map, assess, respond to incidents, track and act.
What this tool does
Co-designed with Data Protectify (data protection & compliance experts): deep legal understanding combined with a hands-on approach for SMEs.
It comes with a 5–10 hour consulting package with Data Protectify experts for a real-world review and to deepen the results.
How it works — 3 sessions with an expert
- 01
Session 1 — Mapping
Build the Data Map and see which personal data you actually hold. Start the Compliance Assessment (CRITICAL items).
- 02
Session 2 — Assessment
Complete the Assessment & review real data collection points (POS/HR/website/app). Set up the incident-response process.
- 03
Session 3 — Action
Finalise the Risk Board, the 90-day plan & determine DPO/DPIA obligations for your company size.
Sheets in the file
- Data Map
List personal data: source, purpose, legal basis, storage, access.
- Compliance Assessment
40 questions in 6 groups, mapped to PDPL 2025 → compliance score %.
- Incident Response
8-step process + 72-hour notification + incident log.
- Legal Tracker
Calendar of data & legal obligations: reviews, renewals, owners.
- Risk Board
Automatic summary: score & risk level per group.
- 90-day Plan
9 suggested actions + 30/60/90 review milestones.
Current legal framework: the Law on Personal Data Protection (Law 91/2025/QH15) & Decree 356/2025/NĐ-CP — effective 01/01/2026, replacing Decree 13/2023.