NEXORA
· 7 min read

Vietnam's Personal Information Protection Regulation: The Full Picture of Decree No. 13 and the Response Measures Companies Should Take

Vietnam's Personal Information Protection Law (Decree No. 13), which took effect in 2023, imposes new legal obligations on all domestic and foreign businesses. This article provides an accessible explanation, by a Vietnamese attorney, of the structure of Decree No. 13, its scope of application, the responsibilities of data controllers, consent requirements, cross-border data transfer restrictions, and other key points directly relevant to corporate practice, together with a comprehensive overview of the internal systems and risk-avoidance measures Japanese-affiliated companies should implement now. NEXORA LAWFIRM, which has supported legal compliance for numerous Japanese-affiliated companies in Vietnam, presents the priority items companies should focus on from a practical, business-oriented perspective. This is an ideal guide for anyone researching topics such as "Vietnam's Personal Information Protection Law," "the content of Decree No. 13," "data protection obligations in Vietnam," and "obtaining consent for personal information in Vietnam."

With the expansion of the digital economy, the risks of misuse and leakage of personal information have surged in Vietnam. Since July 2023, Decree No. 13/2023/ND-CP ("Decree 13"), aimed at protecting personal data, has been fully in force. This decree constitutes a strict regulatory regime similar to the EU's GDPR, and every business and organization is affected by it in some form.

This article provides a detailed explanation, from the perspective of Vietnamese legal practice, of the key points of Decree 13, the scope of personal data covered, the legal responsibilities of companies, the anticipated sanctions, and the key points for practical compliance.

01 - Overview and Scope of Application of Decree No. 13

◆ Key points:

Applies to all businesses and organizations (covering every business entity that processes personal data within Vietnam)
Two types of data are covered:
 ① Basic personal data (name, address, telephone number, bank account information, etc.)
 ② Sensitive personal data (health information, ideology/beliefs, genetic information, etc.)

◆ Example of data processing (illustration):

Where Company X, in hiring Ms. A and Mr. B, has them submit information such as their names, resumes, and bank account details, and then stores and processes this information internally or shares it with a third party (such as an accounting firm), all of this constitutes data processing. Processing is defined as beginning "from the moment personal data is received," which is an important point — mere receipt or storage is also subject to regulation.

◆ About the data subject

A personal data subject refers to the person to whom the personal data belongs. Such persons can generally be classified as follows.

Capital relationships: individual shareholders, capital contributors, etc.
Employment relationships: employees, probationary staff, interns, interviewees
Business relationships: customers, suppliers
Marketing relationships: website users, survey respondents, etc.
General administrative relationships: other third parties

Those who process personal data are classified into the following four categories.

① Personal data controller

General businesses, organizations, and institutions (representative offices, NPOs, etc.)

② Personal data processor

Data processing businesses (advertising businesses, IT companies, market research/marketing businesses, product development and research businesses, etc.)

③ Combined data controller/processor

A general business that also carries out its own data analysis
A data processing business that also manages its own personal data

④ Third party

Outsourced service providers (accounting firms, law firms), suppliers, partners, and other collaborators

The obligations of each category of person are set out as follows.

Personal Data Controller

Implementing personal data protection measures (organizational and technical measures)
Recording and retaining system logs of data processing
Protecting the rights of data subjects
Reporting violations
Preparing, retaining, and submitting personal data processing impact assessment documents
Selecting an appropriate data processor
Bearing responsibility to the data subject
Cooperating with the competent authorities

Personal Data Processor

Entering into, performing, and complying with the contract with the personal data controller
Implementing measures to keep personal data secure
Deleting the data or returning it to the data controller once processing has ended
Bearing responsibility to the data subject
Cooperating with the competent authorities

Combined Data Controller/Processor

Must perform both the obligations of a data controller and those of a data processor

Third Party

Complying with Decree No. 13
Complying with the contract entered into with the data controller, etc.

As set out above, Decree No. 13 is considered quite strict. Compared with the EU's General Data Protection Regulation (GDPR), the main differences are as follows.

03 - Company Responses

To comply with Decree No. 13, companies are required to take various actions as a data controller (or combined controller/processor). Specifically, the following points may be noted.

04 - The Need to Comply Strictly with Decree No. 13

The need to fully comply with Decree No. 13 can be summarized as follows.

① Legal risk already exists at present

Decree No. 13 on the processing of personal data (effective since July 2023) is already in force, and even though administrative penalty provisions are not yet fully in place at present, there is a constant risk of disputes arising with data subjects (employees, customers, etc.) or third parties as a result of violations. If a proper internal system is not in place at the time of a complaint or a data breach, this could have a serious impact on the company's credibility and continued operations.

② The need to prepare for the future introduction of penalties

A decree on administrative sanctions relating to personal data protection is currently being drafted, and it is expected to come into force sooner or later. This decree is also expected to include substantial fines (in the range of billions of VND), so establishing a proper system now will help avoid future legal and financial risk.

③ The need for a phased response in preparation for full legislation

Vietnam is also currently working on enacting a formal Personal Data Protection Law. This law is likely to include stricter requirements than the current decree, and in order to benefit from any future "transitional period" once the law takes effect, it is advisable to proceed now with preparations based on Decree No. 13.

④ The particular significance of the Ministry of Public Security as the supervisory authority

In Vietnam, supervisory authority over personal data protection rests with the Ministry of Public Security. As the Ministry of Public Security is a state agency responsible for maintaining public order and combating crime, there is also a risk that a personal data violation could trigger investigations or audits into other aspects of the company's business activities. For this reason, early response and system-building are extremely important as a line of defense for companies.

The outline of the forthcoming decree on penalties currently being drafted is as follows.

① Fines

② Remedial measures for the consequences of the violation

Disposal, deletion, or cancellation of the data involved in the violation
Return or payment over of unlawfully obtained profit
Apology

③ Supplementary sanctions

Temporary suspension (1 to 3 months) of the business license required for data processing activities
Temporary suspension (1 to 3 months) of data processing activities
Deportation of the individual responsible for the violation

05 - Points to Note When Responding to Decree No. 13

① Relationship with the personal data subject: When processing personal data, the purpose of processing must be determined in advance and the data subject's consent obtained. However, data may not be processed for any purpose whatsoever. Accordingly, it is necessary to examine the legal basis relevant to the determined purpose of processing, and to prepare a reasonable explanation in case processing exceeds that purpose.

② The department responsible for personal data management established within the company should maintain a certain degree of independence, similar to the company's labor union.

③ It is recommended to seek expert advice regarding documents submitted to the Ministry of Public Security and impact assessments.

④ It is advisable to be aware in advance of the seriousness of dealings with the Ministry of Public Security and of various customary practices.

【Disclaimer】

Articles on this website are based on the laws and regulations in effect at the time of writing. Where laws or policies subsequently change, the content may no longer be accurate and should be reviewed accordingly.

Content on this website does not constitute legal advice. Please consult a qualified professional for guidance on your specific situation. We accept no responsibility for any direct or indirect damages arising from the use of this website's content without appropriate professional review.

info@nexorawoco.com0985 677 501 (Zalo/LINE: m2H6M8wpfJ)