Your benefits – Our top priority
0913449968 0913419996 legal@nplaw.vn

In the context where personal data has become one of the most valuable “digital assets” of enterprises, the General Data Protection Regulation of the European Union (the “GDPR”) is regarded as the gold standard for establishing principles on data security and privacy.

In the context where personal data has become one of the most valuable “digital assets” of enterprises, the General Data Protection Regulation of the European Union (the “GDPR”) is regarded as the gold standard for establishing principles on data security and privacy.

I. Current situation relating to the GDPR

The General Data Protection Regulation (GDPR) is a legislative of the European Union regulation that establishes measures to protect the privacy and security of personal data of individuals operating within the European Economic Area (“EEA”) and applies to certain organizations outside the EEA that process personal data of individuals in the EEA.

Since officially taking effect in 2018, the EU’s General Data Protection Regulation has created one of the most stringent and influential legal frameworks in the world in the field of personal data protection. In practice, the implementation of the GDPR has revealed several notable aspects, including:

  • Uneven levels of corporate compliance: Many enterprises, particularly large corporations in the technology, finance, and e-commerce sectors, have developed structured data governance systems to comply with the GDPR. However, the majority of small and medium-sized enterprises still face difficulties in: clearly identifying the scope of personal data they collect and process; implementing appropriate technical measures such as encryption and anonymization; and standardizing consent mechanisms in accordance with GDPR requirements. As a result, numerous violations have been detected through inspections or following data breach incidents.
  • An increasing number of violations and higher penalties: According to statistics from EU supervisory authorities, the number of reported GDPR violations has steadily increased over the years. The main causes include: non-transparent data collection or processing beyond the notified purposes; failure to ensure users’ rights to access, rectify, or erase their data; and failure to promptly notify competent authorities of data breach incidents.
  • A rise in litigation and individual complaints: The GDPR strengthens the rights of data subjects, allowing individuals to: request enterprises to provide full information about the data being held; request data erasure (the “right to be forgotten”); and lodge complaints when data is unlawfully collected or used. This has led to a significant increase in privacy-related litigation, particularly in countries such as Germany, France, and Spain.
  • Spillover effects beyond the EU: Although the GDPR is an EU regulation, it has global influence due to its principle of extraterritorial application. Many countries have enacted new laws similar to the GDPR (such as Brazil, Japan, and South Korea) or amended existing laws to enhance compatibility, thereby facilitating business operations in the EU market. In Vietnam, Decree No. 13/2023/ND-CP on Personal Data Protection and the 2025 Law on Personal Data Protection have also been significantly influenced by the GDPR model.
  • Emerging challenges in the context of rapid technological development: The rapid growth of AI, Big Data, IoT, and cloud computing has created new legal scenarios that the GDPR does not fully address, such as: automated data processing using complex algorithms; automated decision-making processes that affect users’ rights; and cross-border data collection and processing through digital platforms.

From the above realities, it can be seen that although the GDPR has established an advanced and highly deterrent legal framework, practical compliance still faces numerous difficulties and challenges. This requires both enterprises and regulatory authorities to continue improving enforcement mechanisms in order to ensure more comprehensive and effective protection of personal data rights.

II. Concept of the GDPR

To properly understand the issues arising in implementation and the impact of the GDPR on enterprises, it is first necessary to grasp the fundamental concepts underlying this regulation. The following core concepts help define how the GDPR operates and its scope of application in practice.

1. What is the GDPR?

The GDPR (General Data Protection Regulation) is a general data protection regulation issued by the European Union (EU),  effective from 25 May 2018. It is a legal instrument that establishes a unified standard framework for the collection, storage, processing, and protection of personal data of individuals within the EU.

The GDPR is considered one of the most stringent regulations in the world on privacy and data security, applying directly in all EU Member States and exerting significant influence on all organizations worldwide that process the personal data of EU citizens.

2. To whom does the GDPR apply?

Pursuant to Article 2 of the GDPR, this Regulation applies to the processing of personal data wholly or partly by automated means, and to the processing of personal data other than by automated means which form part of a filing system or are intended to form part of a filing system.

The Regulation does not apply to the processing of personal data:

  • In the course of activities which fall outside the scope of Union law;
  • By Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the Treaty on European Union (TEU);
  • By a natural person in the course of a purely personal or household activity;
  • By competent authorities for the purposes of the prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

With respect to territorial scope, Article 3 of the GDPR provides that the Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. It also applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities relate to:

  • The offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
  • The monitoring of their behaviour insofar as their behaviour takes place within the Union.

The Regulation further applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

3. What are the main objectives of the GDPR?

The GDPR is designed around three core objectives:

  • Protecting individual privacy by ensuring that personal data are collected and processed in a transparent, lawful, and secure manner;
  • Empowering data subjects by granting them rights such as the right to be informed, the right of access, the right to erasure, and the right to object;
  • Establishing a common data protection standard within the EU, thereby creating a consistent legal environment that facilitates compliance for business while enhancing accountability in data processing in the digital era.

It can therefore be seen that the GDPR not only sets out principles for personal data protection but also aims to build a safe, transparent, and user-centric digital environment, thereby raising global standards for data security.

III. Legal provisions related to the GDPR

To ensure that personal data is processed safely and in compliance with the law, the GDPR establishes a comprehensive and stringent regulatory system. These provisions bind not only EU-based enterprises but also any organization worldwide that processes data relating to individuals in the EU. The following key provisions illustrate how the GDPR shapes modern data protection standards.

1. What conditions must be met to collect personal data under the GDPR?

Pursuant to Article 6 of the GDPR, the collection and processing of personal data is lawful only if there is an appropriate legal basis. Processing is lawful only if, and to the extent that, at least one of the following applies:

  • The data subject has given consent to the processing of his or her personal data for one or more specific purposes;
  • The processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;
  • The processing is necessary for compliance with a legal obligation to which the controller is subject;
  • The processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Accordingly, personal data may not be collected arbitrarily; enterprises must demonstrate an appropriate legal basis and ensure transparency toward users.

2. How does the GDPR regulate the storage of personal data?

Pursuant to Article 5(1)(e) of the GDPR, the data storage must comply with the following principles:

  • Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
  • Personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organizational measures required by the Regulation to safeguard the rights and freedoms of data subjects (the “storage limitation” principle).

In addition, Article 32 of the GDPR requires enterprises to apply security measures in data storage such as encryption, access control, and authorization mechanisms to minimize the risk of data breaches.

These provisions ensure that personal data is not stored excessively, indefinitely, or used for purposes beyond the original scope.

3. What mechanisms must be complied with when transferring personal data outside the EU under the GDPR?

The transfer of personal data outside the EU is considered a high-risk activity and is strictly regulated under Chapter V of the GDPR (Articles 44–50). Such transfers are lawful only if one of the following mechanisms is satisfied:

  • Adequacy Decisions – Article 45: The EU recognizes that a country or territory ensures an adequate level of data protection (e.g., Japan, South Korea).
  • Appropriate Safeguards – Article 46, including: EU Standard Contractual Clauses (SCCs); Binding Corporate Rules (BCRs); or commitments between public authorities.
  • Specific Derogations – Article 49, applicable where the data subject has explicitly consented, where the transfer is necessary for contract performance, or for important reasons of public interest.

Accordingly, transfers of personal data outside the EU cannot be carried out arbitrarily and must be subject to mechanisms that ensure a level of privacy protection equivalent to that guard within the EU.

4. What categories of rights do data subjects have under the GDPR?

The GDPR grants individuals a robust system of rights, primarily set out in Chapter III (Articles 12–23). The main categories include:

  • The right to be informed and the right of access (Articles 13–15): individuals have the right to know what personal data are being collected, for what purposes, and to request copies of such data.
  • The right to rectification and erasure (Articles 16–17), including the “right to be forgotten”.
  • The right to restriction of processing and the right to object (Articles 18–21): individuals may request the suspension of processing or object to processing for marketing or behavioural analysis purposes.
  • The right to data portability (Article 20): individuals may request that their data be transferred to another organization’s system.
  • The right not to be subject to decisions based solely on automated processing that produce significant effects (Article 22): preventing individuals from being assessed entirely by algorithms (e.g., loan rejection based solely on AI-driven assessment).

These rights form the foundation for individuals to control their information in the digital environment.

IV. Questions regarding the GDPR

During the process of GDPR compliance, enterprises and individuals often raise various questions concerning rights, obligations, and the scope of application of the Regulation. The following are common issues and corresponding clarifications that illustrate how the GDPR operates in practice.

1. Can users withdraw their consent to data processing at any time under the GDPR?

Pursuant to Article 7(3) of the GDPR, the data subject has the right to withdraw their consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Data subjects must be informed of this right prior to giving consent, and withdrawing consent must be as easy as giving consent.

2. Must enterprises not established in the EU but having customers in the EU comply with the GDPR?

The GDPR applies under the principle of extraterritorial effect as stipulated in Article 3 of the GDPR.

Accordingly, enterprises not established in the EU but that provide goods or services to individuals in the EU or monitor the behaviour of individuals in the EU must fully comply with the GDPR. This is why many Vietnamese enterprises providing cross-border services are also subject to this Regulation.

3. Does the GDPR apply to data processed for scientific research purposes?

The GDPR applies to personal data processed for scientific research purposes, but with greater flexibility.

Pursuant to Article 89 of the GDPR, data processed for scientific research, statistical purposes, or archiving in the public interest may benefit from certain derogations, such as:

  • Restrictions on the right to erasure;
  • Permission to retain data for longer periods for research purposes;
  • The use of encrypted or anonymized data.

Nevertheless, organizations must still ensure appropriate safeguards to prevent misuse and to protect the rights and freedoms of data subjects.

4. Does the use of third-party software to process data constitute a GDPR violation?

The use of third-party software or data processing services does not in itself constitute a violation. However, enterprises must comply with:

  • Article 28 of the GDPR regarding contracts between Data Controllers and Data Processors;
  • The obligation to ensure that third parties implement appropriate security measures and process data only in accordance with the enterprise’s instructions.

If an enterprise fails to control how third parties process data or selects service providers that do not meet security standards, the enterprise remains legally liable under the GDPR.

5. What is the time limit for reporting personal data breaches under the GDPR?

Pursuant to Article 33 of the GDPR, the controller must notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of a personal data breach.

If notification is delayed, the reasons must be provided. For breaches likely to result in a high risk to the rights and freedoms of individuals, the enterprise must also directly notify the data subjects pursuant to Article 34 of the GDPR.

V. Why seek legal advice from NPLaw on GDPR-related issues?

GDPR compliance requires in-depth knowledge of international law, technology, and data governance. NPLaw is a trusted choice for the following reasons:

  • It has solid expertise in data protection, with in-depth understanding of both the GDPR and Vietnamese law;
  • It provides practical solutions tailored to business operations rather than purely theoretical advice;
  • It helps minimize legal risks, enabling enterprises to avoid substantial GDPR penalties and protect brand reputation;
  • It offers comprehensive support, from contract drafting and privacy policy review to breach handling and staff training.

The support of NPLaw enables enterprises to build a safe, effective, and internationally compliant data protection framework.

The above information is provided for reference purposes only. For detailed advice on specific cases, please contact NPLaw for prompt consultation.

NGOC PHU LAW COMPANY LIMITED
Phone Hotline 1: 0913449968 Hotline 2: 0913419996

Related services

Opening an english language center

  In the era of economic integration, increasing globalization, and the c...

Issues related to loan agreements

Currently, many Clients are interested in issues related to loan agreements. Und...

Law on bidding and things needing to be understand

  Currently, the sane competition of businesses has strongly contributed...

The regulations for the commercial arbitration award in vietnam

According to the general principle, a judgment (arbitral award or arbitration aw...

The franchising agreement according to the law in vietnam

Along with the current economic development, commercial businesses and franchisi...

Regulations for a false advertisement

An advertisement has an important role and a significant meaning for giving deve...

Fraudulent behaviors of renting at high prices in vietnam

Rent is always an essential choice and demand for almost all students coming to...

The regulations for the commercial arbitration center

When arising dispute issues, the parties will always seek and require competent...

WhatsApp WeChat Zalo hotline 0913449968 hotline
0
Bạn đang quan tâm đến

Chúng tôi sẵn sàng tư vấn miễn phí cho bạn!

Tư vấn điện thoại Zalo Tư vấn qua Zalo