Vietnam's Personal Information Protection Regulation: The Full Picture of Decree No. 13 and the Response Measures Companies Should Take
Vietnam's Personal Information Protection Law (Decree No. 13), which took effect in 2023, imposes new legal obligations on all domestic and foreign businesses. This article provides an accessible explanation, by a Vietnamese attorney, of the structure of Decree No. 13, its scope of application, the responsibilities of data controllers, consent requirements, cross-border data transfer restrictions, and other key points directly relevant to corporate practice, together with a comprehensive overview of the internal systems and risk-avoidance measures Japanese-affiliated companies should implement now. NEXORA LAWFIRM, which has supported legal compliance for numerous Japanese-affiliated companies in Vietnam, presents the priority items companies should focus on from a practical, business-oriented perspective. This is an ideal guide for anyone researching topics such as "Vietnam's Personal Information Protection Law," "the content of Decree No. 13," "data protection obligations in Vietnam," and "obtaining consent for personal information in Vietnam."
With the expansion of the digital economy, the risks of misuse and leakage of personal information have surged in Vietnam. Since July 2023, Decree No. 13/2023/ND-CP ("Decree 13"), aimed at protecting personal data, has been fully in force. This decree constitutes a strict regulatory regime similar to the EU's GDPR, and every business and organization is affected by it in some form.
This article provides a detailed explanation, from the perspective of Vietnamese legal practice, of the key points of Decree 13, the scope of personal data covered, the legal responsibilities of companies, the anticipated sanctions, and the key points for practical compliance.
01 - Overview and Scope of Application of Decree No. 13
◆ Key points:
Applies to all businesses and organizations (covering every business entity that processes personal data within Vietnam)
Two types of data are covered:
① Basic personal data (name, address, telephone number, bank account information, etc.)
② Sensitive personal data (health information, ideology/beliefs, genetic information, etc.)
◆ Example of data processing (illustration):
Where Company X, in hiring Ms. A and Mr. B, has them submit information such as their names, resumes, and bank account details, and then stores and processes this information internally or shares it with a third party (such as an accounting firm), all of this constitutes data processing. Processing is defined as beginning "from the moment personal data is received," which is an important point — mere receipt or storage is also subject to regulation.
◆ About the data subject
A personal data subject refers to the person to whom the personal data belongs. Such persons can generally be classified as follows.
Capital relationships: individual shareholders, capital contributors, etc.
Employment relationships: employees, probationary staff, interns, interviewees
Business relationships: customers, suppliers
Marketing relationships: website users, survey respondents, etc.
General administrative relationships: other third parties
02 - The Legal Position of Companies
Those who process personal data are classified into the following four categories.
① Personal data controller
General businesses, organizations, and institutions (representative offices, NPOs, etc.)
② Personal data processor
Data processing businesses (advertising businesses, IT companies, market research/marketing businesses, product development and research businesses, etc.)
③ Combined data controller/processor
A general business that also carries out its own data analysis
A data processing business that also manages its own personal data
④ Third party
Outsourced service providers (accounting firms, law firms), suppliers, partners, and other collaborators
The obligations of each category of person are set out as follows.
Personal Data Controller
Implementing personal data protection measures (organizational and technical measures)
Recording and retaining system logs of data processing
Protecting the rights of data subjects
Reporting violations
Preparing, retaining, and submitting personal data processing impact assessment documents
Selecting an appropriate data processor
Bearing responsibility to the data subject
Cooperating with the competent authorities
Personal Data Processor
Entering into, performing, and complying with the contract with the personal data controller
Implementing measures to keep personal data secure
Deleting the data or returning it to the data controller once processing has ended
Bearing responsibility to the data subject
Cooperating with the competent authorities
Combined Data Controller/Processor
Must perform both the obligations of a data controller and those of a data processor
Third Party
Complying with Decree No. 13
Complying with the contract entered into with the data controller, etc.
As set out above, Decree No. 13 is considered quite strict. Compared with the EU's General Data Protection Regulation (GDPR), the main differences are as follows.
03 - Company Responses
To comply with Decree No. 13, companies are required to take various actions as a data controller (or combined controller/processor). Specifically, the following points may be noted.
04 - The Need to Comply Strictly with Decree No. 13
The need to fully comply with Decree No. 13 can be summarized as follows.
① Legal risk already exists at present
Decree No. 13 on the processing of personal data (effective since July 2023) is already in force, and even though administrative penalty provisions are not yet fully in place at present, there is a constant risk of disputes arising with data subjects (employees, customers, etc.) or third parties as a result of violations. If a proper internal system is not in place at the time of a complaint or a data breach, this could have a serious impact on the company's credibility and continued operations.
② The need to prepare for the future introduction of penalties
A decree on administrative sanctions relating to personal data protection is currently being drafted, and it is expected to come into force sooner or later. This decree is also expected to include substantial fines (in the range of billions of VND), so establishing a proper system now will help avoid future legal and financial risk.
③ The need for a phased response in preparation for full legislation
Vietnam is also currently working on enacting a formal Personal Data Protection Law. This law is likely to include stricter requirements than the current decree, and in order to benefit from any future "transitional period" once the law takes effect, it is advisable to proceed now with preparations based on Decree No. 13.
④ The particular significance of the Ministry of Public Security as the supervisory authority
In Vietnam, supervisory authority over personal data protection rests with the Ministry of Public Security. As the Ministry of Public Security is a state agency responsible for maintaining public order and combating crime, there is also a risk that a personal data violation could trigger investigations or audits into other aspects of the company's business activities. For this reason, early response and system-building are extremely important as a line of defense for companies.
The outline of the forthcoming decree on penalties currently being drafted is as follows.
① Fines
② Remedial measures for the consequences of the violation
Disposal, deletion, or cancellation of the data involved in the violation
Return or payment over of unlawfully obtained profit
Apology
③ Supplementary sanctions
Temporary suspension (1 to 3 months) of the business license required for data processing activities
Temporary suspension (1 to 3 months) of data processing activities
Deportation of the individual responsible for the violation
05 - Points to Note When Responding to Decree No. 13
① Relationship with the personal data subject: When processing personal data, the purpose of processing must be determined in advance and the data subject's consent obtained. However, data may not be processed for any purpose whatsoever. Accordingly, it is necessary to examine the legal basis relevant to the determined purpose of processing, and to prepare a reasonable explanation in case processing exceeds that purpose.
② The department responsible for personal data management established within the company should maintain a certain degree of independence, similar to the company's labor union.
③ It is recommended to seek expert advice regarding documents submitted to the Ministry of Public Security and impact assessments.
④ It is advisable to be aware in advance of the seriousness of dealings with the Ministry of Public Security and of various customary practices.