In the digital era, personal data has become a valuable asset. The creation and storage of copies of personal data without regulatory compliance pose significant risks of privacy infringement and economic loss. Although the legal framework has clearly addressed these matters, enforcement and supervision remain limited. Therefore, enhancing legal awareness and data security is an urgent necessity.
I. Current situation relating to copies of personal data
With rapid digital transformation, copies of personal data have emerged as a prominent legal issue in Vietnam. Numerous organizations and individuals have stored, duplicated, or shared personal information without authorization, resulting in risks of privacy violations, financial fraud, and consumer harm. Although the legal framework on personal data protection has clearly stipulated responsibilities and sanctions, enforcement and monitoring in practice remain inadequate, leading to widespread violations.

Such reality underscores the urgent need to strengthen legal awareness, implement security measures, and enhance accountability among relevant stakeholders in safeguarding personal data. A thorough understanding of legal risks and regulatory requirements serves as a critical foundation for enterprises and individuals to mitigate disputes and protect their lawful interests.
II. Concept of copies of personal data
1. What are copies of personal data?
Copies of personal data refer to copied versions of an individual’s personal information, which may exist in physical or electronic form. Such data may include full name, date of birth, phone number, address, transaction information, and other sensitive data.
Pursuant to Article 2 of Decree No. 13/2023/ND-CP, personal data is defined as information in the form of symbols, letters, numbers, images, sounds, or similar forms in an electronic environment that is associated with or helps identify a specific individual. Personal data includes both basic personal data and sensitive personal data.
Accordingly, all copies of personal data are legally recognized as personal data and must comply with applicable data protection regulations, including those governing collection, storage, processing, and disclosure.
The creation, retention, or transfer of copies of personal data without the data subject’s consent may lead to legal liabilities, including administrative sanctions or damages. Therefore, copies of personal data are not merely tools for information management but are directly connected to an individual’s privacy rights and data security.
2. How do copies of personal data differ from original personal data?
Copies of personal data differ from original personal data in terms of form and storage function, but not in legal value. Original personal data refers to information initially collected from the data subject, whereas copies are reproductions of such original data for purposes of storage, processing, or backup.
However, both original data and its copies are treated equally as personal data and are subject to the same legal requirements regarding collection, use, security, and transfer. The act of creating copies does not arise additional processing rights nor diminish the data protection obligations of data-controlling entities.
Accordingly, any unlawful processing of copies of personal data is subject to the same legal consequences as violations involving original personal data.
3. What types of information may copies of personal data include?
Copies of personal data may include identifying information or any data relating to an individual, including both basic and sensitive data, as protected under Clause 1, Article 2 of Decree No. 13/2023/ND-CP. Such information may include full name, date of birth, phone number, address, identification documents, health data, biometric data, financial information, or location data. Regardless of whether it is in original or copied form, all such information is classified as personal data and must be collected, processed, stored, and shared in accordance with the law.
Unauthorized processing of copies of personal data may result in administrative or criminal liability and directly affect the privacy and lawful interests of individuals.
Therefore, enterprises and organizations must implement stringent data protection and management measures to ensure legal compliance.
III. Legal regulations governing copies of personal data
1. How does Vietnamese law regulate the creation of copies of personal data?
Vietnamese law, particularly Decree No. 13/2023/ND-CP on personal data protection, provides clear regulations on the processing and storage of personal data, including data copies. Pursuant to Articles 2 and 16, all personal data whether original or copied must be collected, stored, and used for lawful purposes, with the consent of the data subject, and must be safeguarded to ensure security and confidentiality.

Unauthorized copying, retention, or disclosure of personal data constitutes a legal violation and may result in administrative or criminal sanctions.
Accordingly, copies of personal data hold the same legal status as original data, and their creation is only lawful when all data protection requirements are strictly complied with. This serves as an essential legal foundation for enterprises to manage data effectively while maintaining compliance.
2. Are enterprises required to obtain consent before creating copies of personal data?
Under Article 11 of Decree No. 13/2023/ND-CP, enterprises are required to obtain the explicit and voluntary consent of the data subject prior to creating copies of personal data. Such consent must be obtained transparently, clearly specifying the purpose, scope, and method of data processing, and must be recorded as verifiable evidence.
Failure to obtain valid consent before copying or storing personal data may constitute a legal violation, exposing enterprises to administrative sanctions or liability for damages.
Therefore, compliance with consent requirements not only safeguards the rights of customers but also mitigates legal risks for enterprises.
3. What data processing principles must enterprises comply with when creating copies of personal data?
When creating copies of personal data, enterprises must comply with the data processing principles set out in Article 3 of Decree No. 13/2023/ND-CP. Personal data must be processed lawfully, transparently, and for legitimate purposes, within a scope that is strictly necessary. Enterprises are also required to implement appropriate security measures to prevent data leakage, loss, or unauthorized use.
At the same time, the rights of data subjects must be respected, including the right of access, the right to object, and the right to request correction or deletion of data when no longer necessary.
Compliance with these principles enables enterprises to minimize legal risks while ensuring safe and transparent data processing operations.
4. What are the legal requirements regarding retention periods for copies of personal data?
Under Vietnamese law, copies of personal data may only be stored for the duration necessary to fulfill the data processing purpose and must be deleted or destroyed once such purpose has been achieved, unless otherwise required by law. Specifically, Articles 16 and 17 of Decree No. 13/2023/ND-CP stipulate that enterprises must delete personal data upon request by the data subject, except in cases where storage is required for legal obligations or other legitimate interests. Storing data beyond the necessary period without a legal basis may result in administrative or criminal liability.
Accordingly, enterprises must establish clear data storage policies and strictly comply with applicable legal requirements to mitigate risks and protect the rights of data subjects.
IV. Questions regarding copies of personal data
1. Are there restrictions on creating copies of sensitive personal data?
The creation of copies of personal data, including sensitive data, is not strictly prohibited but must comply with stringent legal requirements.
Under Articles 2 and 28 of Decree No. 13/2023/ND-CP, sensitive data, such as health, financial, and biometric information, must be subject to enhanced security measures, with designated departments responsible for data protection and notification obligations to data subjects. Additionally, all data processing activities must comply with the principles of legality, transparency, purpose limitation, data minimization, and confidentiality.
Compliance with these requirements helps enterprises mitigate legal risks, protect customer privacy, and ensure transparency in data processing activities.
2. Who within an enterprise is authorized to access copies of personal data?
Pursuant to Articles 38 and 39 of Decree No. 13/2023/ND-CP, access to copies of personal data is limited to entities responsible for data management and processing within the enterprise, including Data Controllers and authorized Data Processors.
Employees or departments outside this scope are not permitted access, in order to safeguard data confidentiality and privacy. Where third-party service providers are engaged, their access must be strictly limited to the contractual scope and agreed purposes, and they must not use the data for any unauthorized purposes.
Violations of access control regulations may result in administrative, civil, or criminal liability depending on the severity of the breach.
Therefore, enterprises must establish clear access control mechanisms to ensure compliance and minimize legal risks.
3. Are enterprises allowed to transfer copies of personal data to third parties? If so, under what conditions?
Enterprises may transfer copies of personal data to third parties only in full compliance with data protection laws. Under Article 39 of Decree No. 13/2023/ND-CP, data controllers must enter into contracts or agreements with third-party data processors, ensuring that data is used strictly within the agreed purpose and scope, and that appropriate security measures are implemented.
Furthermore, such transfers require the explicit consent of the data subject in accordance with Article 11. Third parties are obligated to protect the data and must not use it beyond the agreed scope. Any violation may result in legal liability for both the transferring enterprise and the receiving party.
4. Is there a limit on the number of copies of personal data that may be created?
Currently, Vietnamese law does not impose a specific limit on the number of copies of personal data that an enterprise may create.
However, all copies must be processed in accordance with the principles of legality, transparency, purpose limitation, and necessity. Storage periods must also align with the intended purpose, ensuring that data is not stored excessively or beyond actual needs.

Therefore, while the number of copies is not restricted, each copy must fully comply with applicable legal requirements on data protection and data subject rights.
5. Can copies of personal data be used to restore original data in the event of technical incidents?
Copies of personal data may be used to restore original data in the cases of technical failures, provided that such use complies with personal data protection regulations.
Both original data and copies must be processed for lawful and transparent purposes, with appropriate security measures in place, as required under Article 3 of Decree No. 13/2023/ND-CP.
Data backup and restoration constitute legitimate technical measures to prevent data loss, system failures, or damage, provided that adequate safeguards are implemented.
Enterprises must ensure that the use of such copies does not infringe upon data subject rights and remains within legally permissible limits. It serves as an important solution for maintaining operational continuity while protecting customer interests.
V. Why seek legal advice from NPLaw on issues relating to copies of personal data
The above analysis provides a comprehensive overview of the legal framework, risks, and key considerations for enterprises in creating, storing, and processing copies of personal data, an area that carries significant potential for disputes and legal liability if not properly managed.
A clear understanding of rights, obligations, and applicable legal grounds is essential for safeguarding customer privacy, minimizing risks, and ensuring transparency in data management practices. However, due to the complexity and evolving nature of data-related transactions, enterprises may face considerable risks if they lack expertise or fail to fully comply with Decree No. 13/2023/ND-CP, the Law on Personal Data Protection 2025, and other relevant legal instruments.
In cases where issues arise concerning the creation, storage, or transfer of copies of personal data, seeking advice from qualified lawyers at NP Law is a prudent solution to ensure full legal compliance and minimize dispute risks. Legal professionals can assist in risk assessment, process review, contract drafting, documentation preparation, and representation in dealings with partners or competent authorities. This approach not only saves time and costs but also establishes a solid legal foundation for enterprises operating in an increasingly stringent data governance environment.
The above information is provided for reference purposes only. For detailed advice tailored to specific cases, please contact NPLaw for prompt legal consultation.