Data transfer in the context of bankruptcy requires enterprises to strictly comply with applicable legal regulations. Such a process involves information confidentiality and the lawful rights and interests of relevant stakeholders. Failure to implement the transfer properly may expose the enterprise to legal liability and obligations to compensate for damages. A clear understanding of the governing legal framework is therefore essential to mitigate risks and safeguard legitimate interests when conducting data transfer during bankruptcy proceedings.
I. Common legal risks associated with data transfer in bankruptcy proceedings
When an enterprise enters bankruptcy, data transfer is not merely a technical matter but also entails significant legal risks. These risks relate to information confidentiality, data ownership, and the legal responsibilities of the parties involved.

If not managed rigorously, such risks may lead to disputes, administrative sanctions, or claims for damages. Identifying and understanding these common legal risks constitutes a crucial first step in protecting legitimate interests and ensuring legal compliance throughout the data transfer process in bankruptcy.
II. Understanding data transfer in bankruptcy proceedings
To fully comprehend data transfer in bankruptcy proceedings, it is necessary to clarify the nature of the data involved, the categories of data typically transferred, and the principles of confidentiality and information security applicable to such a process. A thorough assessment enables enterprises and relevant stakeholders to minimize legal exposure, safeguard their interests, and comply with current regulations.
1. What is data transfer in bankruptcy proceedings?
Data transfer in bankruptcy proceedings refers to the process by which an enterprise or organization in a state of bankruptcy transfers its information and data to relevant parties such as the bankruptcy administrator, creditors, or purchasers of assets. Pursuant to Clause 2 Article 4 of the Law on Bankruptcy 2014, bankruptcy is defined as the status of an enterprise or cooperative that is insolvent and declared bankrupt by a People’s Court.
The transferred data may include customer information, financial records, contracts, internal data, and other material information. Such a process constitutes “data processing” under Clause 8 Article 3 of the Law on Data 2024, encompassing the receipt, transformation, organization, and other activities relating to data for the purpose of serving the operations of relevant agencies, organizations, or individuals.
Data transfer in bankruptcy must comply with principles of confidentiality, proper authority, and legal obligations concerning personal data, trade secrets, and the legitimate rights and interests of related parties.
2. What types of data are commonly transferred when a company enters bankruptcy?
When a company enters bankruptcy, data transfer is not limited to paper documentation but also includes various categories of digital data as provided under Article 3 of the Law on Data 2024:
- Digital data: Including sounds, images, numbers, text, and digital symbols associated with the company’s operations and transactions (Clause 1). It is the most fundamental category involved in data transfer.
- Shared data: Data that may be accessed and used collectively by agencies and organizations involved in bankruptcy administration, such as regulatory authorities or bankruptcy administrators (Clause 2).
- Internal-use data: Data accessible solely within the internal scope of the enterprise and not disclosed externally, thereby protecting trade secrets and sensitive information (Clause 3).
- Open data: Data that any agency, organization, or individual may access and utilize where needed (Clause 4).
- Original data: Data directly generated in the course of the company’s operations or digitized from original physical documents and records (Clause 5).
- Important and core data: Data having a direct impact on national defense, security, macroeconomic stability, or public health, as specified in the list promulgated by the Prime Minister (Clause 6).
Proper data classification in bankruptcy proceedings assists in determining the scope of transfer, ensuring confidentiality, and maintaining compliance with legal requirements during data handling and handover.
3. Why is information confidentiality critical in bankruptcy data transfer?
When an enterprise becomes bankrupt, its data typically contains sensitive information relating to customers, employees, partners, financial matters, and business operations. Ensuring confidentiality throughout the transfer process is critically important for the following reasons:
- Protection of stakeholders’ rights: Unauthorized disclosure of information may cause damage to customers, shareholders, investors, or business partners, potentially resulting in complaints or legal disputes.
- Compliance with legal regulations: Under Clause 8 Article 3 of the Law on Data 2024, data processing includes receipt, transformation, organization, and related activities. Confidentiality is a mandatory requirement to ensure lawful data processing and to prevent violations of privacy and personal data protection regulations.
- Prevention of legal and financial risks: If data is misused or leaked, the bankrupt enterprise or bankruptcy administrator may incur legal liability, be required to compensate for damages, and face regulatory penalties.
- Ensuring transparency and efficiency in the bankruptcy process: Maintaining confidentiality fosters trust among stakeholders, facilitates smooth data handover, and supports orderly bankruptcy administration.
Information confidentiality is therefore a fundamental element in ensuring legal safety, protecting stakeholder interests, and preventing risks during data handling and transfer in bankruptcy.
4. What forms of data transfer may be applied in bankruptcy proceedings?
In practice, data transfer during bankruptcy may be conducted through the following forms:
- Direct transfer in written or electronic form: Data may be handed over via digital files, hard drives, servers, or data management systems. Such a method is commonly applied to internal, customer, or financial data.
- Transfer through contracts or agreements: The relevant parties may execute data transfer agreements or handover minutes clearly specifying rights and obligations, confidentiality responsibilities, duration, and permitted scope of use. Such a form establishes a transparent legal basis and may serve as evidentiary support in case of disputes.
- Transfer through reputable third parties: Enterprises may engage data management service providers, cloud storage providers, or independent audit firms to receive and hand over data. Such an approach reduces the risk of leakage, loss, or misuse.
- Transfer pursuant to a court decision or bankruptcy administrator’s designation: In many bankruptcy cases, the court or bankruptcy administrator designates the recipient of data for the purpose of asset liquidation and settlement of creditors’ claims. Such a form ensures compliance, transparency, and legal certainty.

The selection of the transfer method must ensure confidentiality, transparency, and compliance with applicable law, while taking into account feasibility, data sensitivity, and the rights and interests of relevant stakeholders.
III. Legal regulations governing data transfer in bankruptcy proceedings
Data transfer in cases where an enterprise enters bankruptcy must be conducted in accordance with applicable legal regulations on bankruptcy, digital data, and personal data protection.
1. What are the regulations on personal data confidentiality in data transfer in bankruptcy proceedings?
Even where an enterprise is undergoing bankruptcy, the transfer of personal data must comply with statutory confidentiality requirements. Pursuant to Clause 2 Article 17 of Decree 356/2025/ND-CP, when transferring sensitive personal data, the parties must implement the following security measures:
- Physical protection of storage and transmission devices to prevent unauthorized access during movement or temporary storage.
- Data encryption to prevent unauthorized reading or use.
- Data anonymization where necessary to reduce the risk of information disclosure.
- Other technical and managerial measures to protect data throughout the transfer process.
Despite the bankruptcy status of the enterprise, strict compliance with confidentiality measures remains mandatory to protect the rights of individuals concerned and to avoid legal liability for participating parties.
2. Are there regulations on the responsibilities of the parties in data transfer in bankruptcy proceedings?
When an enterprise enters bankruptcy, data transfer must still ensure the legal responsibilities of the relevant parties, particularly in relation to personal data. Pursuant to Clauses 4, 5, and 6 Article 13 of Decree 356/2025/ND-CP, the responsibilities include:
- Assessment and appointment of data protection personnel: The agency or organization (or the data-managing party during bankruptcy) is responsible for appointing qualified personnel to supervise and protect personal data.
- Execution of confidentiality responsibility agreements: The agency or organization must conclude agreements with data protection personnel, which may include provisions on liability exemptions in certain circumstances involving violations or damages.
- Training and capacity building: Data protection personnel must receive adequate training in knowledge and skills relating to data protection to ensure proper performance of their duties throughout the data transfer process, even during bankruptcy.
Accordingly, parties involved in data transfer during bankruptcy remain fully accountable for complying with legal obligations concerning confidentiality and data management.
3. How will violations in data transfer in bankruptcy proceedings be handled under the law?
Where violations of personal data protection regulations occur during data transfer in bankruptcy, the responsible parties shall be handled in accordance with Article 8 of the Law on Personal Data Protection 2025:
- Criminal liability, administrative sanctions, and civil compensation: Depending on the nature, severity, and consequences of the violation, organizations and individuals may be subject to administrative sanctions, criminal prosecution, and compensation for damages.
- Specific administrative sanctions:
- Acts of buying or selling personal data: Subject to a fine of up to ten times the unlawful gains derived from the violation; where there are no unlawful gains or such gains are lower than the statutory maximum, the general fine level shall apply.
- Illegal cross-border transfer of personal data: Subject to a fine of up to 5% of the organization’s preceding year’s revenue; where there is no revenue or it is lower than the statutory maximum, the general fine level shall apply.
- Other violations in the field of personal data protection: Subject to a fine of up to 3 billion VND.
Where individuals and organizations jointly commit a violation, the fine imposed on individuals shall equal one-half of that imposed on organizations.

The calculation of unlawful gains from violations shall be determined in accordance with the method prescribed by the Government.
Accordingly, any violation relating to personal data protection in the course of bankruptcy-related data transfer may result in administrative sanctions, criminal liability, and civil compensation in order to ensure information security and protect stakeholder rights.
IV. Questions regarding data transfer in bankruptcy proceedings
When conducting data transfer in bankruptcy proceedings, enterprises often have concerns regarding procedures, legal responsibilities, information confidentiality, and potential risks. The following section addresses common questions to assist relevant parties in understanding their obligations, ensuring legal compliance, and minimizing potential disputes.
1. Is it necessary to execute a contract or agreement when transferring data in bankruptcy?
In the context of data transfer during bankruptcy, executing a contract or agreement is necessary to ensure accountability and data confidentiality. Specifically:
- Confidentiality responsibility agreement: Pursuant to Clause 5 Article 13 of Decree 356/2025/ND-CP, agencies and organizations must execute confidentiality responsibility agreements with personal data protection personnel, which may include provisions on liability exemptions in cases of violations or damages relating to protected personal data.
- Personal data processing contract: Pursuant to Clause 8 Article 2 of the Law on Personal Data Protection 2025, the party processing personal data must act in accordance with the request of the personal data controller or under a contractual arrangement, thereby safeguarding the controller’s rights and ensuring compliance with personal data protection regulations.
Therefore, the execution of contracts or confidentiality agreements is mandatory to ensure legal compliance, protect personal information, and mitigate legal risks.
2. Who takes legal liability if data is misused after transfer in bankruptcy?
If data is misused after transfer in the context of bankruptcy, the relevant parties shall take legal liability depending on the nature and extent of the violation:
- Administrative sanctions under Article 8 of the Law on Personal Data Protection 2025:
- Buying or selling personal data: Fine of up to ten times the unlawful gains.
- Illegal cross-border transfer of personal data: Fine of up to 5% of the preceding year’s revenue.
- Other violations relating to personal data protection: Fine of up to 3 billion VND.
- Criminal sanctions in cases of serious violations or failure to notify data breach incidents:
- Infringement of the secrecy or safety of correspondence, telephone, or telegraph communications (Article 159 of the Penal Code 2015, as amended 2017).
- Illegal provision or use of information on computer or telecommunications networks (Article 288).
- Illegal intrusion into computer networks, telecommunications networks, or electronic devices (Article 289).
- Civil liability for damages: Pursuant to Articles 584 and 585 of the Civil Code 2015, enterprises must compensate for damages where violations cause harm to property, honor, reputation, or facilitate fraudulent exploitation of data.
Thus, enterprises, agencies, or individuals involved may take full administrative, criminal, and civil liability to ensure the protection of data subjects’ rights and information security.
3. What procedures should be implemented to ensure safe data transfer in bankruptcy?
To ensure data security during transfer in bankruptcy, the relevant parties should implement the following procedures in accordance with legal requirements and best practices:
- Data assessment and classification:
- Identifying categories of data to be transferred, such as personal data, important data, core data, shared data, or internal-use data (Article 3 of the Law on Data 2024).
- Classifying data according to sensitivity to apply appropriate security measures.
- Appointment of responsible personnel:
- Pursuant to Clauses 4, 5, and 6 Article 13 of Decree 356/2025/ND-CP, appointing personnel or a department responsible for personal data protection and providing appropriate training.
- Executing confidentiality responsibility agreements with personnel involved in the transfer.
- Development of a data transfer plan:
- Determine the scope, method, timeline, and devices used for transfer.
- Implement technical measures such as encryption, anonymization of personal data, and physical protection of storage and transmission devices (Clause 2 Article 17 of Decree 356/2025/ND-CP).
- Execution of the transfer:
- Implementing the transfer in accordance with the established plan, whether directly, via secure electronic systems, or through authorized intermediaries.
- Recording and retaining documents evidencing compliance with legal requirements.
- Verification and record retention:
- After completion, confirming that the data has been transferred fully and securely.
- Retaining relevant records, contracts, or agreements to ensure transparency and facilitate inspection or dispute resolution if necessary.
- A carefully planned and properly implemented data transfer process significantly reduces legal risks, protects stakeholder interests, and ensures compliance with applicable law.
4. What risks may arise in data transfer in bankruptcy proceedings?
When transferring data in bankruptcy, enterprises and stakeholders may encounter the following legal and practical risks:
- Data confidentiality risks:
- Personal data, important data, or core data may be disclosed or misused if physical protection, encryption, or anonymization measures are not properly applied (Clause 2 Article 17 of Decree 356/2025/ND-CP).
- Insufficiently trained personnel may inadvertently disclose data or violate personal data protection regulations.
- Legal risks:
- Non-compliance with legal regulations may result in administrative sanctions, criminal prosecution, or compensation obligations under the Law on Personal Data Protection 2025, the Penal Code 2015 (as amended 2017), and the Civil Code 2015.
- Disputes may arise among stakeholders regarding data ownership, control, and protection responsibilities.
- Risks affecting stakeholder rights:
- Shareholders, creditors, or purchasers of bankrupt assets may not receive complete or accurate information if data transfer is incomplete or improperly conducted.
- Failure to notify results or conditions of data transfer may lead to disputes and economic losses.
- Bankruptcy procedural risks:
- Data transfer conducted without compliance with bankruptcy procedures may be deemed unlawful, potentially delaying or obstructing asset liquidation.
- Data transfer in bankruptcy therefore entails multiple risks relating to confidentiality, legal compliance, stakeholder rights, and procedural integrity. Careful planning and strict compliance with legal requirements are essential to mitigate such risks.
5. What situations may lead to disputes in data transfer in bankruptcy proceedings?
In the course of data transfer during bankruptcy, disputes may arise in the following situations:
- Data misuse or use for improper purposes, such as where the receiving party uses the data for unauthorized commercial activities.
- Failure to ensure data confidentiality, resulting in personal data breaches or disclosure of important data.
- Non-compliance with transfer agreements or contracts, including incomplete handover, delayed performance, or failure to compensate for damages.
- Lack of transparency in the allocation of responsibilities among stakeholders during the bankruptcy process.
- Most disputes originate from breaches of contractual obligations, confidentiality duties, or improper use of transferred data.
V. Are you seeking a reputable law firm to assist with data transfer in bankruptcy proceedings?
If you are facing challenges in handling, securing, or transferring data during bankruptcy proceedings, NPLaw is ready to accompany you. With a team of experienced legal professionals specializing in bankruptcy, digital data, and personal data protection, we provide comprehensive advisory services from transfer planning and security review to dispute resolution. Let NPLaw assist you in protecting your interests, minimizing legal risks, and conducting secure and effective data transfers in all circumstances.
The above information is provided for reference purposes only. For detailed advice tailored to your specific case, please contact: