Consumer data privacy: a snapshot of new regulations in Vietnam
31 July, 2023
By Nga Dao
The first half of 2023 has witnessed some key developments in Vietnam’s data privacy legislation. These particularly include the issuance of the first-ever decree on personal data protection (Decree 13/2023/ND-CP or PDPD) in April and the adoption of the Law on E-Transactions and Law on Consumers’ Right Protection in June, both of which contain new provisions aimed to enhance the protection of users’ data in the online environment. This is a snapshot of new data privacy requirements for online service providers from the consumers’[1] perspective.
Consent requirement
Consent is the key principle and primary legal basis for personal data processing under the PDPD. Article 9 of the PDPD provides for the data subject’s right to consent and Article 11 states clearly that a data subject must voluntarily consent and be aware of:
The type of data to be processed;
The purpose of personal data processing;
The organizations and individuals authorized to process personal data; and
His/her own rights and obligations.
The Law on E-Transactions[2] requires all agencies, organizations, and individuals involved in e-transactions to comply with the legislation on cybersecurity and online information security, including the PDPD. Meanwhile, under the Law on Consumers’ Right Protection, a business entity shall have to acquire consumers’ consent in the following cases[3]:
Collecting, storing, using, modifying, updating, or annulling consumers’ information by itself or an authorized third party.
Changing the purpose or scope of the use of consumers’ information.
Sharing, disclosing, transferring consumers’ information to a third party or using consumers’ information for advertisement or other commercial activities, except otherwise provided for by law.
It should be noted that consumers’ information is defined to include both personal and non-personal data[4].
Privacy protection
The PDPD sets out 8 principles for personal data protection[5]:
Personal data shall be processed in accordance with the provisions of the law;
The data subject shall know about activities related to the processing of his/her personal data, except otherwise provided for by law;
Personal data shall be processed for the purposes already registered and declared by the personal data controller, personal data processor, personal data controller-cum-processor, and third party on personal data processing;
Personal data collected must be appropriate and limited to the scope and purpose of data processing. Personal data may not be purchased or sold in any form, except otherwise provided for by law;
Personal data shall be updated and supplemented according to the purpose of the processing;
Personal data shall be subject to protection and security measures during processing, including protection against violations of the regulations on personal data protection and prevention of loss, destruction, or damage caused by incidents, using technical measures;
Personal data shall be stored for a period of time corresponding to the purpose of data processing, except otherwise provided for by law.
Data controller, data controller-cum-processor shall comply with the above-mentioned data processing principles and prove their compliance with these principles.
Meanwhile, the Law on Consumers’ Right Protection[6] requires business organizations and individuals that collect, store, and use consumers’ information to formulate and publish rules on consumers’ information protection. Such rules must cover the purpose of collecting information, scope of using information, information retention period, security and privacy measures. Business entities shall have to prevent the stealing, illegal access, use, modification, update, or annulment of consumers’ information as well as to receive and handle consumers’ reports, requests, or complaints regarding the illegal collection or use of their information. They are also required to respond to consumers’ requests and destroy consumers’ information when the retention period expires[7].
The Law on E-Transactions also prohibits the collection, provision, use, disclosure, display, and trading of data messages in contravention of the law[8].
Notification requirement
Notification of personal data processing is a requirement under PDPD[9]. Accordingly, before conducting data processing, the concerned organizations or individuals shall have to notify data subjects of the following:
The processing purpose
The type of used personal data that is related to the processing purpose
The processing method
Information on other organizations and individuals related to the processing purpose
Potential unintended consequences or damages
The starting and ending time of data processing.
The PDPD also requires that such privacy notices be issued in a printable or duplicative format, including an electronic format or a format that can be verified.
Meanwhile, according to the Law on Consumers’ Right Protection, consumers shall be notified of the purpose and scope of collecting and using their information as well as the information retention period. In case of a change in the purpose or scope of collecting and using consumers’ information, the concerned online service providers shall notify the consumers before making such a change[10].
In summary, consumers may get better protection in the online environment thanks to the above-mentioned regulations but online service providers may feel that the extra operational burden for them is disagreeable. Given that the Law on E-Transactions and the Law on Consumers’ Right Protection are still waiting for their guiding decrees and won’t take effect until July 1st, 2024, it’s now the time for digital platforms to review and update their privacy policies and notices based on the new requirements while monitoring relevant regulatory developments and preparing for full compliance with the new legislation in the near future.
[1] Consumers are defined as people who purchase, use products, goods, services for consumption, daily-life purposes and not for commercial purposes (Article 3.1 of the Law on Consumers’ Right Protection)
[3] Articles 15.2, 18.1, 18.4 of the Law on Consumers’ Right Protection
[4] Article 3 of the Law on Consumers’ Right Protection stipulates: “Consumers’ information includes personal information of consumers, information on the process of buying, using products, goods, services of consumers and other information related to the transactions between consumers and business organizations, individuals.”
ASEAN is a remarkably diverse region. With over 655 million individuals and 11 official languages across ten states, AI is expected to have a significant impact on every facet of life in ASEAN. AI is already changing how we think about safety, governance, and public discourse, among many other aspects of our social, political, and […]
In recent years, the Vietnamese financial sector has experienced a wave of innovation driven by FinTech (financial technology), RegTech (regulatory technology), and SupTech (supervisory technology). These technologies promise to enhance the efficiency, transparency, and accessibility of financial services while supporting regulatory compliance and improving oversight. However, to ensure that these developments remain beneficial for customers […]
By Mark Chan Now that we are a few years past the height of the pandemic, the concept of digital nomads is no longer novel. The shift to remote work has reshaped how many people choose to live and travel, which has led to lasting change even as workplace norms continue to evolve. Digital nomads […]
jQuery(function(jQuery){jQuery.datepicker.setDefaults({"closeText":"Close","currentText":"Today","monthNames":["January","February","March","April","May","June","July","August","September","October","November","December"],"monthNamesShort":["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec"],"nextText":"Next","prevText":"Previous","dayNames":["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"dayNamesShort":["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],"dayNamesMin":["S","M","T","W","T","F","S"],"dateFormat":"d MM, yy","firstDay":1,"isRTL":false});});
var gform_i18n = {"datepicker":{"days":{"monday":"Mo","tuesday":"Tu","wednesday":"We","thursday":"Th","friday":"Fr","saturday":"Sa","sunday":"Su"},"months":{"january":"January","february":"February","march":"March","april":"April","may":"May","june":"June","july":"July","august":"August","september":"September","october":"October","november":"November","december":"December"},"firstDay":1,"iconText":"Select date"}};
var gf_legacy_multi = [];
var gform_gravityforms = {"strings":{"invalid_file_extension":"This type of file is not allowed. Must be one of the following:","delete_file":"Delete this file","in_progress":"in progress","file_exceeds_limit":"File exceeds size limit","illegal_extension":"This type of file is not allowed.","max_reached":"Maximum number of files reached","unknown_error":"There was a problem while saving the file on the server","currently_uploading":"Please wait for the uploading to complete","cancel":"Cancel","cancel_upload":"Cancel this upload","cancelled":"Cancelled"},"vars":{"images_url":"https:\/\/ps-engage.com\/wp-content\/plugins\/gravityforms\/images"}};
var gf_global = {"gf_currency_config":{"name":"U.S. Dollar","symbol_left":"$","symbol_right":"","symbol_padding":"","thousand_separator":",","decimal_separator":".","decimals":2,"code":"USD"},"base_url":"https:\/\/ps-engage.com\/wp-content\/plugins\/gravityforms","number_formats":[],"spinnerUrl":"https:\/\/ps-engage.com\/wp-content\/plugins\/gravityforms\/images\/spinner.svg","version_hash":"c8e6739cc393d67db1a2db79d11eb8af","strings":{"newRowAdded":"New row added.","rowRemoved":"Row removed","formSaved":"The form has been saved. The content contains the link to return and complete the form."}};
var gform_theme_config = {"common":{"form":{"honeypot":{"version_hash":"c8e6739cc393d67db1a2db79d11eb8af"}}},"hmr_dev":"","public_path":"https:\/\/ps-engage.com\/wp-content\/plugins\/gravityforms\/assets\/js\/dist\/"};