Personal data protection obligations are a highly important matter closely associated with the right to protection of personal privacy. Who takes responsibility for protecting personal data? How is failure to fulfill personal data protection obligations sanctioned? In the following article, NPLaw provides information related to current personal data protection obligations.

I. Current status of personal data protection obligations

Vietnam is among the countries with a relatively high rate of Internet development and application worldwide. Personal data protection obligations are developing in social practice; however, they remain a relatively new issue in the development and improvement of the legal system.

Personal data protection is closely linked to the right to protection of personal privacy. Acts of violation or infringement of personal data may give rise to liability for damages, administrative sanctions, or criminal prosecution, depending on the nature, severity, and consequences of the violation.

II. Legal provisions on personal data protection obligations

1. How are personal data protection obligations defined?

Pursuant to Clause 5, Article 2 of Decree No. 13/2023/NĐ-CP, personal data protection is defined as follows:

  • Personal data protection means activities of avoiding, detecting, preventing, and handling acts in violation of regulations related to personal data in accordance with the law.

Accordingly, personal data protection obligations refer to the implementation of activities aimed at avoiding, detecting, preventing, and handling violations related to personal data in compliance with legal regulations.

2. Who is responsible for protecting personal data?

Pursuant to Clause 1, Article 2 of Decree No. 13/2023/NĐ-CP, personal data means information in the form of symbols, letters, numbers, images, sounds, or similar forms in the electronic environment that is associated with a specific individual or helps identify a specific individual. Personal data includes basic personal data and sensitive personal data.

Accordingly, personal data refers to information associated with and capable of identifying a specific individual. The primary responsibility for protecting personal data is such an individual itself. In addition, individuals, agencies, and organizations that hold other persons’ personal data are also responsible for protecting such personal data.

3. How are personal data protection obligations in cyberspace currently regulated?

Pursuant to Article 29 of Decree No. 13/2023/NĐ-CP, regulations on the specialized authority for personal data protection and the National Portal on Personal Data Protection are as follows:

  • The specialized authority for personal data protection is the Department of Cybersecurity and Prevention of High-Tech Crime under the Ministry of Public Security, which is responsible for assisting the Ministry of Public Security in performing State management of personal data protection.
  • The National Portal on Personal Data Protection performs the following functions:
  • Providing information on the Party’s guidelines, policies, and the State’s laws on personal data protection;
  • Disseminating and promoting policies and laws on personal data protection;
  • Updating information and the status of personal data protection;
  • Receiving information, dossiers, and data on personal data protection activities via cyberspace;
  • Providing information on the results of assessments of personal data protection activities of relevant agencies, organizations, and individuals;
  • Receiving notifications of violations of personal data protection regulations;
  • Issuing warnings and coordinating warnings regarding risks and acts infringing personal data in accordance with the law;
  • Handling violations of personal data protection regulations in accordance with the law;
  • Performing other activities in accordance with personal data protection laws.

Accordingly, the specialized authority responsible for personal data protection is the Department of Cybersecurity and Prevention of High-Tech Crime under the Ministry of Public Security, which assists the Ministry of Public Security in state management of personal data protection.

III. Questions on personal data protection obligations

1. In cases of information leakage or theft, who takes responsibility for personal data protection?

Under current legal regulations, when information leakage or theft occurs, agencies, organizations, and individuals may take legal liability if personal data is leaked or stolen due to negligence during data security. Depending on the nature and severity of the violation, the violating organization or individual may be subject to corresponding sanctions.

2. What information must enterprises provide regarding personnel responsible for personal data protection in the personal data processing impact assessment dossier?

Pursuant to the Personal Data Processing Impact Assessment Dossier under Form No. 04 in the Appendix to Decree No. 13/2023/NĐ-CP, enterprises must provide the following information regarding personnel responsible for personal data protection:

  • Full name;
  • Position/Title;
  • Contact telephone number (landline and mobile);
  • Email address.

Accordingly, the personal data processing impact assessment dossier must include the above information of the personnel responsible for personal data protection.

3. How is failure to fulfill personal data protection obligations sanctioned?

Pursuant to Article 4 of Decree No. 13/2023/NĐ-CP on handling violations of personal data protection regulations:

  • Agencies, organizations, and individuals that violate personal data protection regulations may, depending on the severity of the violation, be subject to disciplinary measures, administrative sanctions, or criminal prosecution in accordance with the law.

Accordingly, depending on the severity, violations of personal data protection obligations may be subject to administrative sanctions or criminal liability as prescribed by law.

4. Which authority should be notified upon detecting a violation of personal data protection?

Pursuant to Article 23 of Decree No. 13/2023/NĐ-CP regarding notification of violations of personal data protection regulations:

  • Organizations and individuals shall notify the Ministry of Public Security (the Department of Cybersecurity and Prevention of High-Tech Crime) upon detecting the following cases:
  • Detection of acts in violation of laws concerning personal data;
  • Personal data being processed for improper purposes or contrary to the original agreement between the data subject and the Personal Data Controller, the Personal Data Controller and Processor, or in violation of legal regulations;
  • Failure to ensure or properly implement the rights of data subjects;
  • Other cases as prescribed by law.

Accordingly, upon detecting violations of personal data protection, notification shall be made to the Ministry of Public Security (the Department of Cybersecurity and Prevention of High-Tech Crime).

5. How are violations of personal data protection handled?

Acts of violation or infringement of personal data constitute violations of law. Article 4 of Decree No. 13/2023/NĐ-CP provides for handling violations of personal data protection regulations as follows:

  • Agencies, organizations, and individuals that violate personal data protection regulations may, depending on the severity, be subject to disciplinary measures, administrative sanctions, or criminal prosecution in accordance with the law.

Accordingly, violations of personal data protection may result in liability for damages, administrative penalties, or criminal prosecution, depending on the nature, severity, and consequences of the violation.

6. How should enterprises describe acts of violation when notifying violations of personal data protection regulations?

Pursuant to the Notification of Violations of Personal Data Protection Regulations under Form No. 03 in the Appendix to Decree No. 13/2023/NĐ-CP, when notifying violations, enterprises must describe the violating acts with the following details:

  • Time;
  • Location;
  • Description of the act;
  • Organizations, individuals, types of personal data, and quantity of data involved;
  • Personnel responsible for personal data protection, including:
  • Full name;
  • Position/Title;
  • Contact telephone number (landline and mobile);
  • Email address;
  • Consequences arising;
  • Measures applied.

IV. Legal consultancy services related to personal data protection obligations

Ngoc Phu Law Company Limited is one of the reputable law firms providing legal services related to personal data protection obligations. When using our services, clients receive dedicated support from experienced legal specialists and lawyers with strong professional qualifications. Clients will be advised on procedures for resolving issues related to personal data protection obligations. If you require assistance regarding personal data protection obligations to safeguard your lawful rights and interests, please contact NPLaw promptly via the following contact details: