132 Free Compliance Generators: Vietnam PDPD + Indonesia PDPA
ComplyKit has added its 131st and 132nd free compliance generators: the Vietnam PDPD Compliance Checker (Decree 13/2023/ND-CP) and the Indonesia PDPA Compliance Checker (UU PDP No. 27/2022). Both generators are free, require no account, and produce AI-generated compliance assessment reports with gap analysis, 90-day remediation roadmaps, and detailed Article references. Together they cover Southeast Asia's two largest personal data protection laws — both now in full enforcement.
Vietnam PDPD Compliance Checker (131st generator)
Vietnam's Decree 13/2023/ND-CP — effective July 1, 2023 — is Vietnam's first comprehensive personal data protection regulation, enforced by the Ministry of Public Security (Bộ Công an) through Department A05. With 100 million people, a 20%-of-GDP digital economy target, and a major tech export/outsourcing sector, Vietnam is a critical market for SaaS companies and multinationals across Southeast Asia. Key obligations that catch organisations off guard: the 72-hour data subject rights response SLA (much faster than GDPR's one month), the mandatory pre-transfer MPS A05 cross-border transfer assessment (no equivalents to GDPR's simple SCCs — actual regulatory registration required), and separate explicit consent for each of 10 sensitive data categories.
The Vietnam PDPD Compliance Checker covers 42 key obligations across six categories:
- Lawful Basis & Consent (Arts. 11–17): 7 valid consent conditions, separate explicit consent per sensitive data category (10 categories including health/HIV, genetic, biometric, sexual orientation, financial), data minimisation, 72-hour withdrawal, children's guardian consent (under 16)
- Data Subject Rights (Arts. 9–10): Access/correction/deletion/restriction/portability/objection — all with 72-hour response SLA; MPS A05 complaint escalation pathway; automated decision-making review
- Controller Obligations & Privacy Notice (Arts. 11–16): Privacy notice before collection (all Art. 13 elements, Vietnamese language), data retention schedule with automated deletion, records of processing activities, processor contracts (Art. 30 clauses), privacy by design and default
- Security & Breach Notification (Arts. 26–27): Technical/organisational safeguards, breach detection plan, MPS A05 notification within 72 hours, individual notification for harmful breaches, incident register, processor breach notification chain
- Cross-Border Transfers (Arts. 25–26): MPS A05 impact assessment registration before transfer, equivalent protection requirement, cross-border transfer inventory, data localisation for CII operators under Cybersecurity Law 2018
- DPO, Governance & MPS Enforcement (Arts. 28–29): DPO appointment and A05 notification, DPIA submission to A05, Vietnamese privacy policy, staff training, MPS A05 registration, criminal penalty risk management (VND 200M + imprisonment)
Who it's for: Vietnamese companies; SaaS companies and e-commerce platforms with Vietnamese users; multinationals with Vietnam operations; tech outsourcing providers processing Vietnamese employee/client data; organisations using cloud providers that transfer Vietnamese data outside the country; compliance teams building PDPD programmes or adapting existing GDPR programmes.
Indonesia PDPA Compliance Checker (132nd generator)
Indonesia's UU PDP No. 27/2022 became fully effective and enforceable on October 17, 2024 — completing its 2-year transition period. With 280 million people and Southeast Asia's largest digital economy, Indonesia's data protection law carries the region's most severe criminal penalties: IDR 60 billion (approx. USD 3.7 million) + 6 years imprisonment for intentional unlawful transfer of sensitive personal data, with corporate liability up to 10× the individual maximum. Enforcement is split between BSSN (cybersecurity/technical standards), Komdigi (administrative/registration), OJK (financial sector), and Bank Indonesia (payment systems).
The Indonesia PDPA Compliance Checker covers 42 key obligations across six categories:
- Lawful Basis & Consent (Arts. 20–27): 6 lawful bases, 5-condition valid consent, separate explicit consent for 8 specific/sensitive data categories, 3-working-day consent withdrawal, children's parental consent and best interest principle
- Data Subject Rights (Arts. 5–18): 8 rights with 3-working-day response SLA — access, correction, erasure, restriction, portability, objection, automated decision review, consent withdrawal; Komdigi complaint escalation pathway
- Controller Obligations & Privacy Notice (Arts. 25–47): Privacy notice at collection (Art. 32 elements, Indonesian language), data retention with automated deletion, accuracy obligation, Records of Processing Activities (Art. 47), processor contracts (Art. 54 clauses), privacy by design (Art. 49)
- Security & Breach Notification (Arts. 35–38): Technical/organisational measures (BSSN SNI ISO 27001, KAMI index), annual security review, 14-day BSSN/Komdigi breach notification, 14-day individual notification, incident register, processor breach notification chain, critical infrastructure enhanced requirements
- Cross-Border Transfers & Processor Management (Arts. 55–56): Equivalent protection or contractual safeguards (BCRs/SCCs), Government Regulation adequacy list (monitor Komdigi), cross-border notification, data localisation (GR 71/2019, OJK POJK 38/2016, BI localisation), vendor due diligence
- DPO, Governance & BSSN/Komdigi Enforcement (Arts. 48–53): DPO appointment (Art. 51), DPIA submission (Art. 34), Indonesian privacy policy, staff training, PSE registration (Permenkominfo 5/2020), penalty risk management (IDR 60B criminal + 2% administrative)
Who it's for: Indonesian companies of all sizes; multinationals with Indonesian operations or Indonesian users; fintech and banking companies (OJK/BI overlay); SaaS companies with Indonesian customers; e-commerce platforms; critical infrastructure operators; compliance teams building UU PDP programmes; organisations that were relying on the transition period and now need to remediate gaps.
Southeast Asia Coverage Now Complete
With these two additions, ComplyKit now covers all five of the major Southeast Asian data protection laws: Singapore PDPA, Thailand PDPA, Japan APPI 2022, Vietnam PDPD, and Indonesia PDPA — plus South Korea PIPA, India DPDP Act, and Australia Privacy Act 2024 for broader Asia-Pacific coverage.
Browse all 132 generators
All 132 free compliance generators are at /generate. No account required. Covers GDPR, CCPA, SOC 2, HIPAA, Brazil LGPD, Mexico LFPDPPP, South Africa POPIA, ISO 27001/27701, EU AI Act, NIS2, DORA, PSD2/PSD3, FCA Consumer Duty, CSRD, NIST CSF 2.0, NIST AI RMF, NIST SP 800-53, CMMC 2.0, PCI DSS v4.0, Singapore PDPA, India DPDP Act, Saudi Arabia PDPL, Australia Privacy Act 2024, Thailand PDPA, Japan APPI, South Korea PIPA, UAE PDPL, Canada PIPEDA, Vietnam PDPD, Indonesia PDPA, and more.