As the legal framework governing data is continuously amended and updated, enterprises’ data transfer activities are directly and profoundly affected. Failure to promptly adjust data transfer processes may result in regulatory breaches, administrative sanctions, or legal disputes. A proper understanding of the concept, scope, and methods of data transfer in the context of changing laws is therefore mandatory. It also serves as the basis for enterprises to ensure compliance with new regulations and to safeguard their lawful rights and interests.

I. Current situation of data transfer in the context of changing laws

In a context where data-related legislation is continuously amended and supplemented, many enterprises have difficulties in handling the transfer of data under their management.

In practice, a considerable number of entities continue to apply outdated transfer practices, without updating them to reflect new legal requirements regarding the scope of data, eligible recipients, and data security measures. The absence of legal impact assessments prior to data transfer exposes enterprises to risks of regulatory non-compliance, legal liability, and disputes with partners and data subjects.

II. Concept of data transfer in the context of changing laws

To correctly understand and properly apply new regulations, it is first necessary to clarify the concept of data transfer in the context of changing laws, thereby determining its scope, legal nature, and the compliance requirements that enterprises must satisfy when performing such activities.

1. What is data transfer in the context of changing laws?

Data transfer in the context of changing laws refers to the act whereby organizations or enterprises transfer, hand over, or share data with another subject in order to comply with newly enacted or amended legal regulations.

Such transfer typically arises when the law changes in relation to data governance, personal data protection, data storage, access, or use, thereby requiring the data controller to adjust its data processing practices to ensure legal compliance.

2. Which factors determine the data to be transferred when laws change?

The determination of which data must be transferred following changes in the law is generally assessed based on the content of new legal provisions and the enterprise’s actual data governance practices, including:

  • First, the regulatory scope of the new legal provisions. Laws or implementing regulations clearly define which categories of data fall within the scope of mandatory transfer, such as personal data, important data, sector-specific data, or data generated in particular business activities.
  • Second, the legal purpose of the transfer. Data should only be transferred to the extent necessary to comply with new legal requirements, such as for state management purposes, adjustment of data access rights, or protection of data subject rights.
  • Third, the entities entitled or obliged to receive the data. Legal provisions specify whether data must be transferred to state authorities, successor entities, authorized processors, or data subjects, thereby forming the basis for determining the content of data to be transferred.
  • Fourth, the nature and sensitivity of the data. The more sensitive the data, the more limited the scope of transfer, and the stricter the requirements on security, anonymization, or encryption under the new legal regime.
  • Fifth, the time of data generation and retention periods. Only data generated within the period covered by the regulatory requirements for management, retention, or transfer is subject to mandatory transfer, unless the law provides for retroactive application or specific obligations in respect of pre-existing data.

From the above, it can be concluded that the identification of data subject to transfer in the context of changing laws is not discretionary but must be based on a close alignment between the requirements of new legislation and the enterprise’s actual data management and storage practices.

3. How does data transfer in the context of changing laws differ from ordinary data transfer?

Data transfer in the context of changing laws differs from ordinary data transfer in three main respects:

  • First, mandatory nature. The transfer is implemented to comply with newly enacted legal requirements and is not solely dependent on the enterprise’s intent or contractual arrangements, as is the case with ordinary data transfer.
  • Second, scope and recipients of data. The data subject to transfer is determined by statutory requirements and may include categories of data that must be transferred to state authorities or legally designated subjects, rather than merely to contractual partners.
  • Third, legal liability. Data transfer in the context of changing laws entails statutory compliance obligations, security duties, and clearly defined sanctions for non-compliance, whereas ordinary data transfer primarily leads to contractual liabilities between the parties.

Accordingly, data transfer in the context of changing laws is not merely a technical operation or a civil arrangement, but a mandatory legal obligation requiring enterprises to proactively review their data systems, adjust internal processes, and ensure full compliance with new legal requirements to mitigate legal risks.

III. Legal provisions governing data transfer in the context of changing laws

Current legislation establishes a regulatory framework to control data transfer following policy changes, ensuring compliance with new legal requirements, information security, and a proper balance between the lawful rights and interests of relevant stakeholders.

1. What methods may be used to transfer data in the context of changing laws?

Pursuant to Clause 4, Article 35 of the Law on Data 2024, data transfer in the context of changing laws may be conducted through the following methods:

  • Connection and direct sharing between databases: Data is transferred through technical interconnection between national databases, sectoral databases, and information systems of competent authorities and organizations.
  • Transfer via state digital portals and systems: Including the National Data Portal, the National Public Service Portal, e-portals, and administrative procedure processing systems through which data is accessed and shared for governance and legal compliance purposes.
  • Through electronic identification and authentication platforms: Data is transferred after the data subject or relevant organization has been lawfully authenticated on an electronic identification platform.
  • Via the national digital identification application (such as VNeID): Applicable in cases requiring verification, cross-checking, or provision of personal data to meet new legal requirements.
  • By means of devices or software provided by the National Data Center: Commonly applied where the State requires data standardization, migration, or integration in accordance with new regulations.
  • Other methods as prescribed by law: Including newly arising transfer mechanisms under evolving legal frameworks, provided that security and confidentiality requirements are met and approval is granted by competent authorities.

When the law changes, data must not be transferred arbitrarily, but only via technical channels and platforms controlled or authorized by the State to ensure legality, security, and uniform governance.

2. Are there any limits on the volume or scope of data that may be transferred in the context of changing laws?

In the context of changing laws, data transfer is not unlimited but is constrained by statutory scope, purpose, and necessity.

Specifically, the volume and scope of transferable data depend on the following factors:

  • Purpose of transfer: Only data necessary to comply with new legal requirements may be transferred; excessive or indiscriminate transfer is prohibited (Point a, Clause 3, Article 12 of Decree No. 165/2025/ND-CP).
  • Type of data: Internal-use data, source data, important data, and core data are subject to stricter controls than shared data or open data. In particular, important data and core data that are capable of affecting national defense, security, macroeconomic stability, social order, public health, and safety may only be transferred within the scope, conditions, and to the recipients prescribed by law,  (Article 3 of the Law on Data 2024).
  • Recipients of data: Where the data controller provides or entrusts the processing of core data or important data to organizations or individuals not falling within the categories prescribed by Article 12 of Decree No. 165/2025/ND-CP, transfer may only be implemented upon a clear agreement with the recipient on the purpose, methods, scope of processing, and data security obligations through a contract; the data controller must supervise compliance with such obligations and retain records relating to the processing for at least three years (Clause 3, Article 16 of Decree No. 165/2025/ND-CP).
  • Data protection principles: Transfers must comply with the principles of data minimization, security, confidentiality, and purpose limitation (Article 5 of the Law on Data 2024).
  • Transitional provisions of new legislation: In many cases, new laws permit data transfer only within a defined scope and timeframe.

In summary, when laws change, data may only be transferred to the extent necessary, for legitimate purposes, and to eligible recipients; there is no mechanism permitting wholesale or uncontrolled data transfer.

3. How does data transfer in the context of changing laws help enterprises comply with new regulations?

Properly scoped and targeted data transfer enables enterprises to promptly realign their data systems with new legal requirements, ensuring that data storage, processing, and use conform to prevailing legal standards. It reduces the risk of non-compliance, facilitates timely responses to regulatory authorities, and enhances enterprises’ ability to control, secure, and audit data as legal frameworks evolve.

4. What liabilities do enterprises take if data is leaked during transfer following legal changes?

Where data leakage results from non-compliant transfer practices, enterprises may be subject to severe legal liabilities under Clause 1, Article 8 of the Law on Personal Data Protection 2025.

  • Administrative liability: Enterprises may be subject to substantial administrative fines, depending on the nature and severity of the violation. Specifically, unlawful trading in personal data may be fined up to ten times the amount of illicit gains; violations relating to cross-border transfer of personal data may be fined up to 5% of the preceding year’s turnover; other violations in the field of personal data protection may be fined up to 3 billion VND (Clauses 3, 4, and 5 of Article 8).
  • Criminal liability: Where acts of data leakage, misappropriation, or unlawful use constitute criminal offenses, the enterprise or relevant individuals may be subject to criminal prosecution under the Penal Code 2015 (as amended in 2017), such as the offense of illegal provision or use of information on computer networks or telecommunications networks (Article 288) and the offense of illegal intrusion into computer networks, telecommunications networks, or electronic devices of others (Article 289).

In addition, where data leakage causes damage to individuals or organizations, enterprises must compensate for damages in accordance with Article 584 of the Civil Code 2015, including material losses and damages arising from the infringement of lawful rights and interests of data subjects.

Accordingly, data leakage during transfer not only undermines reputation but also exposes enterprises to heavy administrative sanctions and potential criminal liability, particularly in the context of increasingly stringent data protection laws.

IV. Questions on data transfer in the context of changing laws

As data-related legislation is continuously amended and supplemented, data transfer raises numerous practical questions for enterprises and organizations. The following addresses common issues relating to legal obligations, compliance scope, and potential risks arising from data transfer under new regulations.

1. Can data transfer in the context of changing laws help prevent legal disputes?

Timely, properly scoped, and legally compliant data transfer enables enterprises to proactively fulfill statutory obligations, thereby reducing the likelihood of disputes.

Specifically, when data is reviewed, classified, and transferred in accordance with new regulations, enterprises can avoid disputes over data governance rights, data usage rights, confidentiality obligations, and complaints from data subjects or partners.

Conversely, delayed or non-compliant transfer may result in conflicts of interest, administrative sanctions, or claims for damages.

2. Must users be notified when data is transferred due to legal changes?

Where the transferred data constitutes personal data. Under Point a, Clause 1, Article 4 of the Law on Personal Data Protection 2025, personal data controllers or controllers-cum-processors must notify data subjects of the reasons, purposes, and scope of data processing, including transfers arising from changes in legal regulations.

Such notification ensures data subjects’ right to be informed and to exercise control over their data. Failure to comply with this obligation may constitute a violation of personal data protection regulations and entail corresponding legal liability.

3. May enterprises postpone data transfer when laws change?

As a matter of principle, postponement is not permitted where new legislation clearly stipulates deadlines, roadmaps, or mandatory transfer obligations. In such cases, enterprises must comply within the prescribed timeframe and scope.

Where no specific deadline is stipulated, enterprises may reasonably schedule the timing of transfer, provided that it does not disrupt statutory compliance, infringe data subjects’ rights, or compromise data security and safety requirements.

4. Must new security standards be observed when transferring data in the context of changing laws?

Enterprises are required to comply with corresponding updated security standards to mitigate risks arising during data transfer under a changed legal framework.

Pursuant to Clause 2, Article 15 of Decree No. 165/2025/ND-CP, data processors and transferors must implement measures such as data backup and security assurance; system maintenance and upgrades; strict access control; deployment of monitoring and intrusion detection tools; periodic risk assessments; incident response planning; and staff training on data protection.

Compliance with these standards is not only a legal obligation but also ensures the continuity, security, and legality of data as enterprises adapt to evolving legal frameworks.

5. May data transfer in the context of changing laws be subject to third-party oversight?

In many cases, the law requires supervision or inspection by competent authorities or third-party organizations before or during data transfer, particularly for data with significant implications for national security or public interests, or in cross-border transfer scenarios.

For example, under Article 22 of the Law on Personal Data Protection 2025, where core data or important data is transferred abroad, the transferring party must prepare a data transfer impact assessment dossier and submit it to competent state authorities for review and approval prior to transfer.

Such authorities assess legality, risks, and security measures, and only upon satisfactory assessment may the data transfer proceed.

V. Why seek legal counsel from NPLaw on data transfer in the context of changing laws?

In an environment where the legal framework on data is continuously evolving and becoming more stringent, data transfer entails substantial legal risks if enterprises misinterpret or misapply regulatory requirements. The legal team at NPLAW has in-depth experience in data governance, cybersecurity, and regulatory compliance, assisting enterprises in accurately determining the scope of data subject to transfer, identifying legal obligations, and developing lawful and secure data transfer mechanisms. Such professional support enables enterprises to minimize regulatory risks and disputes and to proactively adapt to new legal requirements in an effective manner.

The above information is for reference purposes only. For tailored legal advice in specific cases, clients are advised to contact NPLAW for prompt and professional assistance.