November 7, 2023
Decree 13/2023/ND-CP on the Protection of Personal Data (“Decree”) has finally been issued with many completely new regulations designed to protect personal data and control the “flow” of personal data, as well as set obligations that every business must comply with. In particular, an issue that businesses are especially concerned about is the regulation on controlling the transfer of personal data across borders. Here is an overview of the regulations that businesses are required to comply with from July 1, 2023:
Personal data is information that is tied to a particular person or helps to identify a particular person. Some examples of personal data include full name, date of birth, nationality, phone number, photo, place of residence, etc. Personal data includes basic and sensitive data. Processing of personal data is defined as one or more activities affecting personal data which may include: collection, recording, analysis, confirmation, storage, correction, disclosure, association, access, retrieval, encryption, decryption, copy, sharing, transmission, provision, transfer, deletion, destruction of personal data or other related actions.
The Decree stipulates that the transfer of personal data abroad is the use of cyberspace, equipment, electronic means, or other forms of transferring personal data of Vietnamese citizens (not applicable to personal data of foreigners) to a location outside the territory of Vietnam or use a location outside the territory of Vietnam to process personal data of Vietnamese citizens, including:
1. Organizations, enterprises, and individuals transferring personal data of Vietnamese citizens to overseas organizations, enterprises and management departments for processing in accordance with the purposes agreed upon by the data subject;
(Example: Company A in Vietnam collects data about the user’s name, phone number, email, address and send this information via the internet to company B in a foreign country for company B to process the data and send back the statistics for company A to use)
2. Processing personal data of Vietnamese citizens by automatic systems located outside the territory of the Socialist Republic of Vietnam of the Data Controller, the Data Controller-cum-Processor, the Data Processor in accordance with the purposes agreed to by the data subject.
(Example: Company A – not based in Vietnam, operates a website on the internet that collects data of Vietnamese citizens directly through the website and processes the data using a server located abroad)
Yes.
All individuals and organizations, when transferring personal data abroad, must carry out the following procedures:
The Data Transfer Dossier includes the following contents:
Yes.
Based on the specific situation, the Ministry of Public Security will decide to check the transfer of personal data abroad once a year. However, extraordinary inspections can be performed in case of detecting violations of the provisions of the law on the protection of personal data, or the disclosure or loss of Vietnamese citizens’ personal data.
The first risk when not complying with the above regulations on cross-border data transfer is that the party transferring data abroad will have to stop transferring data abroad, disrupting business operations.
The Decree also stipulates that depending on the level of violation, enterprises can be sanctioned at different levels from administrative to criminal. It is expected that the Vietnamese Government will soon issue detailed regulations on specific sanctions for each violation. In the spirit of the previous drafts, administrative sanctions can be very strict and greatly affect the finances of the business.[1]
PrivacyCompliance provides solutions related to ensuring compliance with personal data, assessing the impacts of personal data processing, drafting impact assessment dossiers, cross-border data transfer dossiers. |
PrivacyCompliance
#Decree13 #personaldata #crossborder #dossier #privacy #impactassessment
[1]According to previous drafts, the highest fine can be up to 5% of the annual revenue of the violating enterprise/organization.
🔥 𝗢𝗙𝗙𝗜𝗖𝗜𝗔𝗟𝗟𝗬 𝗟𝗔𝗨𝗡𝗖𝗛𝗘𝗗: 𝗩𝗜𝗘𝗧𝗡𝗔𝗠 𝗣𝗘𝗥𝗦𝗢𝗡𝗔𝗟 𝗗𝗔𝗧𝗔 𝗣𝗥𝗢𝗧𝗘𝗖𝗧𝗜𝗢𝗡 𝗛𝗔𝗡𝗗𝗕𝗢𝗢𝗞! The first and most comprehensive Personal Data Protection Handbook in Vietnam is now officially available! This handbook provides a complete overview of personal data protection regulations both in Vietnam and globally. 📌 𝗪𝗵𝗮𝘁’𝘀 𝗶𝗻𝘀𝗶𝗱𝗲 𝘁𝗵𝗶𝘀 𝟴𝟬+ 𝗽𝗮𝗴𝗲 𝗛𝗮𝗻𝗱𝗯𝗼𝗼𝗸? ✅ Overview of personal data protection laws worldwide & […]
Learn more
🔥 HAVE YOU GOT YOUR PERSONAL DATA PROTECTION HANDBOOK YET? The Personal Data Protection Handbook is officially launched! This is an essential resource if you want a comprehensive understanding of personal data regulations in Vietnam. 💡 One of the key highlights of the Handbook is the protection of personal data in specific sectors […]
Learn more
🔥 OFFICIALLY LAUNCHED: VIETNAM PERSONAL DATA PROTECTION HANDBOOK! The first and most comprehensive Personal Data Protection Handbook in Vietnam is now officially available! This handbook provides a complete overview of personal data protection regulations both in Vietnam and globally. 📌 What’s inside this 80+ page Handbook? ✅ Overview of personal data protection laws […]
Learn more