November 7, 2023
Decree 13/2023/ND-CP on the Protection of Personal Data (“Decree”) has finally been issued with many completely new regulations designed to protect personal data and control the “flow” of personal data, as well as set obligations that every business must comply with. In particular, an issue that businesses are especially concerned about is the regulation on controlling the transfer of personal data across borders. Here is an overview of the regulations that businesses are required to comply with from July 1, 2023:
Personal data is information that is tied to a particular person or helps to identify a particular person. Some examples of personal data include full name, date of birth, nationality, phone number, photo, place of residence, etc. Personal data includes basic and sensitive data. Processing of personal data is defined as one or more activities affecting personal data which may include: collection, recording, analysis, confirmation, storage, correction, disclosure, association, access, retrieval, encryption, decryption, copy, sharing, transmission, provision, transfer, deletion, destruction of personal data or other related actions.
The Decree stipulates that the transfer of personal data abroad is the use of cyberspace, equipment, electronic means, or other forms of transferring personal data of Vietnamese citizens (not applicable to personal data of foreigners) to a location outside the territory of Vietnam or use a location outside the territory of Vietnam to process personal data of Vietnamese citizens, including:
1. Organizations, enterprises, and individuals transferring personal data of Vietnamese citizens to overseas organizations, enterprises and management departments for processing in accordance with the purposes agreed upon by the data subject;
(Example: Company A in Vietnam collects data about the user’s name, phone number, email, address and send this information via the internet to company B in a foreign country for company B to process the data and send back the statistics for company A to use)
2. Processing personal data of Vietnamese citizens by automatic systems located outside the territory of the Socialist Republic of Vietnam of the Data Controller, the Data Controller-cum-Processor, the Data Processor in accordance with the purposes agreed to by the data subject.
(Example: Company A – not based in Vietnam, operates a website on the internet that collects data of Vietnamese citizens directly through the website and processes the data using a server located abroad)
Yes.
All individuals and organizations, when transferring personal data abroad, must carry out the following procedures:
The Data Transfer Dossier includes the following contents:
Yes.
Based on the specific situation, the Ministry of Public Security will decide to check the transfer of personal data abroad once a year. However, extraordinary inspections can be performed in case of detecting violations of the provisions of the law on the protection of personal data, or the disclosure or loss of Vietnamese citizens’ personal data.
The first risk when not complying with the above regulations on cross-border data transfer is that the party transferring data abroad will have to stop transferring data abroad, disrupting business operations.
The Decree also stipulates that depending on the level of violation, enterprises can be sanctioned at different levels from administrative to criminal. It is expected that the Vietnamese Government will soon issue detailed regulations on specific sanctions for each violation. In the spirit of the previous drafts, administrative sanctions can be very strict and greatly affect the finances of the business.[1]
PrivacyCompliance provides solutions related to ensuring compliance with personal data, assessing the impacts of personal data processing, drafting impact assessment dossiers, cross-border data transfer dossiers. |
PrivacyCompliance
#Decree13 #personaldata #crossborder #dossier #privacy #impactassessment
[1]According to previous drafts, the highest fine can be up to 5% of the annual revenue of the violating enterprise/organization.
🔥 HAVE YOU GOT YOUR PERSONAL DATA PROTECTION HANDBOOK YET? The Personal Data Protection Handbook is officially launched! This is an essential resource if you want a comprehensive understanding of personal data regulations in Vietnam. 💡 One of the key highlights of the Handbook is the protection of personal data in specific sectors […]
Learn more
🔥 OFFICIALLY LAUNCHED: VIETNAM PERSONAL DATA PROTECTION HANDBOOK! The first and most comprehensive Personal Data Protection Handbook in Vietnam is now officially available! This handbook provides a complete overview of personal data protection regulations both in Vietnam and globally. 📌 What’s inside this 80+ page Handbook? ✅ Overview of personal data protection laws […]
Learn more
Exciting News: Vietnam Data Protection Handbook – Coming in 2 days! Following the official release of the Draft Personal Data Protection Law in March 2025, packed with groundbreaking provisions, our 80+ page Vietnam Personal Data Protection Handbook is your key to staying ahead of the curve! Why You Need This Handbook: It’s more than just […]
Learn more