In the context of the rapid digitalization of the tourism sector, the transfer of data among enterprises, business partners, and management systems has become increasingly prevalent. However, such activities also entail numerous legal requirements that enterprises cannot afford to overlook.
I. Current situation of data transfer in the tourism industry
As the tourism industry accelerates digital transformation and service-chain integration, data transfer activities are occurring more frequently among travel agencies, accommodation providers, booking platforms, and intermediary service providers.
In practice, however, many enterprises still conduct data transfers without standardized procedures, without clear legal agreements, and without adequately assessing risks relating to personal data protection. It exposes them to potential legal violations and disputes.
II. The concept of data transfer in the tourism industry
To properly understand the scope, nature, and resulting legal obligations, it is first necessary to clarify what constitutes data transfer in the tourism industry, the types of data involved, and the specific service relationships in which such transfers take place.
1. What is data transfer in the tourism industry?
Data transfer in the tourism industry refers to the provision, sharing, or transmission of tourists’ data by organizations, enterprises, or individuals involved in tourism activities to third parties during the process of service provision. It is conducted for purposes such as reservation management, itinerary coordination, payment processing, customer care, or compliance with statutory obligations.
2. What factors lead to the need for data transfer within the tourism service supply chain?
Within the tourism service supply chain, the provision of all-inclusive services requires close coordination among multiple stakeholders, thereby creating the need for data transfer between relevant parties.
- Participation of multiple service providers: Travel agencies, hotels, transportation companies, tourist attractions, and other service providers must share reservation data, itineraries, and customer information to synchronize service delivery.
- Personalization of travel experiences: The use of data regarding tourists’ preferences and consumption behaviors necessitates data transfers among parties in order to tailor appropriate service packages.
- Real-time service operation and management: Information relating to room availability, flight schedules, and transportation status must be continuously updated and transmitted to ensure uninterrupted service.
- Payment and financial reconciliation: Electronic payment activities and revenue-sharing arrangements among service providers require the exchange of transaction data, invoices, and related accounting information.
- Compliance with legal and regulatory requirements: Certain tourism data must be transferred to competent authorities for purposes of security, statistical reporting, and market management.

Accordingly, the need for data transfer within the tourism service supply chain arises from multi-party coordination requirements, customer experience optimization, operational efficiency, and compliance with legal obligations in tourism business activities.
3. Why has data transfer in the tourism industry become so prevalent?
In an increasingly digitalized tourism industry operating on technological platforms, data transfer is no longer merely supportive in nature but has become a common and indispensable requirement.
- Strong digital transformation trends in tourism: Reservation systems, tour booking platforms, e-ticketing systems, and OTA platforms require enterprises to continuously connect and share data.
- Growing demand for seamless customer experiences: Customers expect a consistent service journey from booking and payment to after-sales support, necessitating data transfers across multiple stages of the supply chain.
- Advancements in data and connectivity technologies: Cloud computing, APIs, and centralized management platforms facilitate faster, more secure, and more cost-efficient data exchange.
- Competitive pressures and business optimization: Enterprises must leverage shared data to conduct market analysis, forecast demand, and improve service quality.
- Regulatory compliance and governance requirements: Data sharing enables enterprises to fulfill reporting, record-keeping, and customer protection obligations under applicable laws.
Therefore, the widespread nature of data transfer in the tourism industry is an inevitable result of digital transformation, market demand, and modern governance requirements, contributing to enhanced competitiveness and service quality.
III. Legal regulations governing data transfer in the tourism industry
Data transfer in the tourism industry is not merely a technical or managerial matter; it is subject to strict legal regulation to ensure information security, protect customer rights, and define the responsibilities of entities participating in the tourism service supply chain.
1. Circumstances permitting data transfer in the tourism industry
Pursuant to Article 17 of the Law on Personal Data Protection 2025 (as guided by Article 7 of Decree No. 356/2025/ND-CP), the transfer of personal data in the tourism industry may only be conducted in cases permitted by law, irrespective of whether a fee is charged, in order to safeguard tourists’ rights and the responsibilities of service providers.
- Consent of the tourist: Tourism enterprises may transfer personal data where valid consent has been obtained from the tourist, for example when transferring information to hotels, carriers, or related service partners under a travel program.
- Internal data sharing within an enterprise: Personal data may be shared among departments within the same tourism enterprise (sales, operations, customer service, etc.) for purposes consistent with the notified processing objectives.
- Data transfer in corporate restructuring: In cases of division, separation, merger, consolidation, or termination of a tourism enterprise, personal data may be transferred to ensure the continuation of lawful operations by the successor entity.
- Transfer to data processors or third parties: Travel agencies and hotels may transfer data to technology partners, system management providers, or booking platforms for processing in accordance with contractual agreements and legal requirements.
- At the request of competent state authorities: Personal data may be transferred for purposes of management, inspection, supervision, and maintenance of security and order in tourism activities.
- Other cases as prescribed by law: Including circumstances in which personal data may be processed without the data subject’s consent pursuant to Article 19 of the Law on Personal Data Protection 2025.
Accordingly, in the tourism industry, personal data transfers are only lawful when conducted in the cases permitted by law. Whether or not a fee is charged, such transfers are not deemed the buying or selling of personal data, thereby ensuring legality and transparency in tourism business operations.
2. Is a written contract mandatory for data transfer in the tourism industry?
Under Clause 3 Article 9 of the Law on Personal Data Protection 2025, as guided by Article 6 of Decree No. 356/2025/ND-CP, personal data transfers between parties must be established on the basis of a written agreement. The consent of the personal data subject must be clearly and specifically expressed and capable of being printed or reproduced in writing, including in electronic or verifiable formats.

The written data transfer agreement must clearly specify:
- Purpose of the data transfer: Clearly defining the specific activities within the tourism service supply chain for which the data is transferred.
- Scope of the transferred data: Identifying the types of data, the level of detail, and the data subjects involved.
- Responsibilities for personal data protection: Allocating confidentiality obligations, protective measures, and liability in the event of data-related risks.
- Related undertakings: Commitments to legal compliance, prohibition of misuse, and mechanisms for handling violations.
Therefore, according to Clause 3 Article 9 of the Law on Personal Data Protection 2025, personal data transfer in the tourism industry is not merely a civil agreement but a mandatory legal obligation that must be formalized in writing to safeguard the rights of data subjects and the legal responsibilities of the participating parties.
3. What steps are involved in the data transfer process in the tourism industry?
The data transfer process in the tourism industry must follow clearly defined steps to ensure legality, data security, and protection of tourists’ rights, particularly where data is shared across multiple systems and entities.
Typical steps include:
- Identifying the purpose and scope of the transfer: Clarifying the operational purpose, the categories of data, and the recipients.
- Verifying the legal basis and obtaining consent: Assessing whether the transfer falls within legally permitted circumstances or obtains valid consent from the tourists.
- Executing a written agreement: Concluding a contract or data transfer agreement specifying the purpose, scope, data protection responsibilities, and obligations of each party.
- Implementing security measures and transferring the data: Applying appropriate technical and organizational safeguards to ensure secure and accurate transmission.
- Monitoring, storage, and post-transfer management: Supervising data usage, correcting inaccuracies, and ensuring data subjects’ rights throughout the process.
With respect to cross-border data transfers, according to Article 20 of the Law on Personal Data Protection 2025, if personal data is transferred abroad (including transferring data stored in Vietnam to foreign jurisdictions; transferring data to foreign organizations or individuals; or using overseas platforms to process data collected in Vietnam), enterprises must additionally:
- Prepare an impact assessment dossier of cross-border personal data transfer and submit one original copy to the specialized personal data protection authority within 60 days from the first date of transfer.
- Conduct the impact assessment once for the entire operational period and update the dossier in accordance with legal requirements upon any changes.
- Comply with inspections by the specialized personal data protection authority, including periodic inspections not exceeding once per year or sudden inspections in the cases of violations or data breaches.
- Comply with decisions of competent authorities, including suspension of cross-border data transfers where such transfers pose risks to national defense or security.
Thus, the data transfer process in the tourism industry includes fundamental steps from determining purpose and legal basis to implementing safeguards and post-transfer management. In the case of cross-border transfers, enterprises must additionally conduct impact assessments and remain subject to regulatory supervision to ensure data security and legal compliance.
4. Rights of tourists regarding transferred personal data in the tourism industry
During personal data transfer in the tourism industry, tourists are personal data subjects and are protected under Clause 1 Article 4 of the Law on Personal Data Protection 2025, which grants them the following rights:
- Right to be informed of personal data processing: Tourists have the right to be clearly notified of the collection, use, and transfer of their data, including the recipients and purposes.
- Right to consent or refuse: Tourists may grant, withhold, or withdraw consent for the transfer and processing of personal data, except where consent is not required by law.
- Right to access and amend data: Tourists may request access to, updating of, or correction of their personal data to ensure accuracy and completeness.
- Right to request provision, erasure, or restriction of processing: Data subjects may request copies of their data, deletion of unnecessary data, restriction of processing, or objection to continued processing.
- Right to complain, denounce, initiate legal proceedings, and claim compensation: Where personal data rights are infringed, tourists may file complaints, initiate lawsuits, and seek damages in accordance with law.
- Right to request protective measures: Tourists may request competent authorities or relevant parties to implement technical and organizational measures to safeguard their personal data.
In summary, Clause 1 Article 4 of the Law on Personal Data Protection 2025 empowers tourists to exercise control over their personal data even when it is transferred among entities within the tourism industry, thereby ensuring privacy protection and strengthening the legal accountability of service providers.
IV. Questions regarding data transfer in the tourism industry
During the implementation and operation of data transfer activities in the tourism industry, enterprises and related entities often raise questions concerning scope, conditions, and legal responsibilities. The following clarifications aim to facilitate correct legal application.
1. Is the transfer of data between hotel management systems considered data transfer in the tourism industry?
The transfer of data between hotel management systems (such as PMS systems, booking systems, and OTA channels) constitutes data transfer in the tourism industry.

Such activities involve the sharing and transmission of reservation information, guest details, and service usage history among multiple systems or entities within the tourism service supply chain. Therefore, by nature, it constitutes data transfer and must comply with applicable legal regulations, particularly where the transferred data includes tourists’ personal data.
2. Are enterprises permitted to transfer data to foreign partners?
Enterprises in the tourism industry are permitted to transfer data to foreign partners, provided that they fully satisfy the legal requirements governing cross-border data transfer and processing.
- Pursuant to Article 23 of the Law on Data 2024, Vietnamese agencies, organizations, and individuals are entitled to transfer data to foreign organizations or individuals or to use overseas platforms for data processing, including the transfer of data stored in Vietnam to foreign jurisdictions.
However, cross-border data transfer and processing, particularly with respect to core data and important data, must ensure national defense and security, protect national and public interests, and safeguard the lawful rights and interests of data subjects and data owners in accordance with Vietnamese law and relevant international treaties.
Accordingly, tourism enterprises are not prohibited from transferring data to foreign partners, but such transfers must strictly comply with cross-border data transfer requirements to ensure data security and protect tourists’ rights.
3. Is an enterprise required to notify recipients when transferred data is inaccurate?
If personal data is inaccurate and cannot be rectified, the enterprise must notify recipients of the transferred data.
Under Clause 3 Article 13 of the Law on Personal Data Protection 2025, personal data correction must ensure accuracy. If correction cannot be made for legitimate reasons, the personal data controller or controller-cum-processor must notify the requesting or relevant organizations and individuals.
Therefore, in the context of data transfer in the tourism industry, if inaccurate personal data cannot be promptly corrected, the enterprise must inform data recipients to prevent continued use of incorrect information, thereby protecting tourists’ rights and ensuring compliance with personal data protection laws.
4. Must data synchronization between linked systems be ensured?
In the tourism industry, data transfers between parties generally require synchronization among interconnected systems to ensure accurate and timely sharing and updating of information among service providers (such as travel agencies, booking platforms, and carriers).
In practice, unsynchronized systems may lead to fragmented information, booking errors, service plan discrepancies, and reduced operational efficiency within the tourism service supply chain. Thus, data and system synchronization is a critical factor in enhancing data-sharing efficiency, improving service quality, and supporting unified management across the industry.
5. Can data transfer arise when a tourist changes their itinerary?
Data transfer may arise when a tourist changes their itinerary.
Within the tourism service supply chain, technology systems and service providers (such as travel agencies, carriers, hotels, and tour operators) must update the latest itinerary information to adjust services, confirm reservations, cancel or rearrange registered services, and provide timely responses to relevant parties.
It requires continuous exchange of personal and service-related data among systems to avoid confusion, duplication, and potential harm to customer interests. Such data transfers are common in tour management and booking systems, as travel programs may be modified based on individual requests and systems must coordinate to adjust reservations and services originally designed according to the initial itinerary.
V. Why seek legal advice from NPLaw regarding data transfer issues in the tourism industry?
In the context of increasingly stringent regulations on data protection and transfer, particularly with respect to personal data in the tourism industry, timely consultation with specialized lawyers is essential for enterprises to mitigate legal risks. NPLaw possesses a team of lawyers experienced in personal data protection, cross-border data transfer, and tourism business operations, assisting enterprises in developing compliance procedures, reviewing contracts and data transfer agreements, and handling issues arising with state regulatory authorities.
The above information is provided for reference purposes only. For detailed advice tailored to specific circumstances, please contact NPLaw for prompt consultation.