In the context of Vietnam’s rapidly developing digital economy, corporate mergers are becoming increasingly common as a means of optimizing resources and expanding market reach. However, such transactions are accompanied by strict legal compliance requirements in order to avoid risks relating to privacy, data security, and legal liability. We invite readers to follow the article below by NPLaw on data transfer in a merger in accordance with applicable laws.
I. Overview of data transfer in a merger in the current context
At present, data transfer in merger transactions is not only an operational necessity but also a legal requirement to ensure continuity in business operations following the merger.
1. Definition of data transfer in a merger
Data transfer in a merger is understood as the process of handing over all or part of data (such as customer data, employee information, financial and accounting records, technology systems, contracts, and other operational data) from the merged enterprise or the transferring enterprise to the merging (receiving) enterprise.
2. Practical example of issues related to data transfer in a merger
A foreign corporation acquires an e-commerce service chain in Vietnam. In such a transaction, all related data, including customer information, transaction history, account data, management systems, and internal operational data, must be transferred to the merging entity. Such a category of data is sensitive in nature and is subject to regulation under laws on personal data protection, information security, and electronic transactions.

If the data transfer process is not conducted in accordance with prescribed procedures, lacks the consent of data subjects, or fails to meet statutory security standards, the enterprise may take administrative sanctions and be liable for compensation for damages as prescribed by law.
3. Why data transfer is necessary in a merger
Data transfer in a merger is essential to ensure that business operations are maintained continuously and in compliance with the law. Main reasons include:
- Ensuring the continuity of rights and obligations among enterprises;
- Maintaining operations, contracts, services, and customer experience;
- Protecting the legitimate rights and interests of the parties involved in M&A transactions;
- Complying with data governance responsibilities under specialized laws.
In summary, data transfer in a merger is both a legal requirement and a solution to maintain stability and transparency for enterprises after consolidation.
II. Legal regulations governing data transfer in a merger
Vietnamese law has established a relatively comprehensive legal framework to regulate data transfer in mergers, ensuring the protection of stakeholders’ interests and data security.
1. Main legal provisions applicable to data transfer in a merger
Data transfer activities in corporate mergers must comply with multiple legal regulations to ensure legality, transparency, and protection of the parties’ rights. Main provisions include:
- The Law on Enterprise 2020, as amended and supplemented in 2025, Article 201 on company mergers, which regulates merger procedures and the transfer of rights and obligations of enterprises in accordance with the law;
- The Law on Personal Data Protection 2025 (effective from 1 January 2026), Article 17 on personal data transfer, which specifies cases in which data transfer is permitted, including mergers of agencies, organizations, and entities;
- Decree No. 356/2025/ND-CP, Article 7 on personal data transfer.
These provisions aim to ensure that data transfer in corporate mergers is conducted safely and lawfully, helping enterprises mitigate legal risks.
2. Conditions for applying data transfer in a merger
To apply regulations on data transfer in a merger, the following conditions must be satisfied:
- The merger must be conducted in accordance with the law (Article 201 of the Law on Enterprise 2020);
- There must be a clear legal basis and agreement regarding the data transfer, such as M&A agreements or data transfer contracts (Point e, Clause 3, Article 7 of Decree No. 356/2025/ND-CP);
- Appropriate security measures and technical systems must be implemented to protect and transfer data (Clause 2, Article 7 of Decree No. 356/2025/ND-CP).
Only when these legal and security conditions are fully met can data transfer in a merger be considered lawful and secure.
3. Measures for handling violations related to data transfer in a merger
Depending on the nature and severity of the violation, agencies, organizations, and individuals that breach regulations on data transfer in a merger may be subject to the following sanctions:
- Disciplinary measures: For example, employees who violate legal provisions during data transfer in a merger may be subject to disciplinary actions such as reprimand, extension of salary increase period for up to six months, demotion, or dismissal (Article 124 of the Labor Code 2019), depending on the seriousness of the violation.
- Administrative fines: For example, fines ranging from 10,000,000 VND to 20,000,000 VND for collecting personal information without the consent of the data subject regarding the scope and purpose of such collection and use (Point a, Clause 1, Article 84 of Decree No. 15/2020/ND-CP); fines ranging from 20,000,000 VND to 30,000,000 VND for failure to inspect or supervise compliance with regulations on network information security or failure to assess the effectiveness of applied management and technical measures (Point a, Clause 2, Article 87 of Decree No. 15/2020/ND-CP).
- Criminal liability: For example, individuals who illegally use information on computer networks or telecommunications networks and obtain illicit profits from 50,000,000 VND to under 200,000,000 VND, or cause damage from 100,000,000 VND to under 500,000,000 VND, or create negative public opinion damaging the reputation of agencies, organizations, or individuals, may be subject to criminal prosecution for the offense of illegally providing or using information on computer or telecommunications networks, with sanctions including fines from 30,000,000 VND to 200,000,000 VND, non-custodial reform for up to three years, or imprisonment from six months to three years under Point c, Clause 1, Article 288 of the Criminal Code 2015, as amended and supplemented in 2017 and 2025.
In addition, individuals who repeatedly sell personal data, infringing upon the life, health, honor, dignity, reputation, property, or other lawful rights and interests of others and causing damage, must compensate for such damage, unless otherwise provided by law, in accordance with Clause 1, Article 584 of the Civil Code 2015.
Accordingly, the above measures may be applied to violations related to data transfer in the event of a merger.
III. Questions regarding data transfer in a merger
1. Can a data transfer agreement in a merger be executed electronically? Why?
Pursuant to Clause 1, Article 119 of the Civil Code 2015: Civil transactions conducted via electronic means in the form of data messages in accordance with the law on electronic transactions shall be deemed transactions in writing.
Clause 1, Article 9 of the Law on Electronic Transactions 2023 also provides that a data message has the same legal validity as a written document if the information contained therein is accessible and usable for reference.
Accordingly, a data transfer agreement in a merger may be executed electronically in accordance with the above regulations.
2. Is customer consent required for data transfer in a merger?
Pursuant to Point c, Clause 1, Article 17 of the Law on Personal Data Protection 2025, data transfer may be conducted in cases of transfer of personal data for continued processing in the case of division, separation, or merger of agencies, organizations, administrative units, and reorganization or transformation of ownership forms of state-owned enterprises; division, separation, merger, consolidation, or termination of operations of units or organizations; or establishment of units or organizations on the basis of termination of operations of other units or organizations.

In addition, Clause 1, Article 7 of Decree No. 356/2025/ND-CP provides that organizations and individuals transferring personal data in cases specified at Points a, c, and d, Clause 1, Article 17 of the Law on Personal Data Protection must establish an agreement on personal data transfer with the data recipient.
Therefore, data transfer in a merger is conducted in accordance with the law and does not require separate consent from customers. However, enterprises must establish a data transfer agreement between the transferring party and the data recipient and should also transparently notify customers and relevant parties of the transfer to avoid disputes, especially in relation to sensitive customer data.
3. What is the procedure for data transfer in a merger?
Data transfer must follow a strict process to ensure completeness, accuracy, and compliance with legal regulations on data security and ownership. Typically, the process includes the following basic steps:
- Reviewing existing data;
- Classifying data by category and usage value;
- Conducting legal assessment related to ownership rights, security, and transfer conditions;
- Executing data transfer agreements or appendices;
- Performing technical handover in compliance with security standards; and
- Updating management systems to record the data transfer.
In summary, data transfer procedures are not merely technical activities but also legal processes to ensure that the handover is conducted transparently, lawfully, and responsibly.
4. What types of data are commonly transferred in a merger?
Data transfer transactions usually involve important categories of information with significant commercial and legal value in enterprise operations. Common types of data include:
- Customer data and transaction information;
- Contracts and financial–accounting documents;
- Technology data and operational processes;
- Personnel records and internal management information;
- Intellectual property data and related technical systems.
Accordingly, the scope of data transferred is often broad and diverse, requiring the parties to clearly define ownership rights, scope of use, and confidentiality obligations to prevent future disputes.
5. May the parties claim damages for breach of contractual interests in data transfer?
Pursuant to Articles 360 and 584 of the Civil Code 2015, a party in breach of contract must compensate for damages arising from failure to perform, improper performance, or incomplete performance of obligations, or from acts infringing upon the life, health, honor, dignity, reputation, property, or other lawful rights and interests of others.
Therefore, if a breach of data-related commitments during a merger results in damage, the affected party has the right to claim compensation in accordance with the contract and applicable laws.
IV. Are you looking for legal counsel to effectively support data transfer in a merger?
When enterprises conduct mergers, acquisitions (M&A), or take over data systems, compliance with laws on contracts, data security, and privacy is a key factor in preventing dispute-related risks.
With a team of experienced lawyers and legal professionals, NPLaw provides reputable and professional legal services, ensuring optimal protection of clients’ lawful rights and interests. If you require legal assistance, please contact NPLaw for consultation and support.
The above information is for reference only. For detailed advice tailored to specific cases, please contact NPLaw for immediate consultation.