The protection of personal data is a crucial issue in today’s digital era. Personal data includes identifying information, preferences, behaviors, financial and health details of an individual. If not well protected, personal data can be exploited, stolen, or disclosed by malicious parties. This can cause harm to the reputation, property, and security of both individuals and the community.

I. Understanding personal data protection

1. What is personal data protection?
Pursuant to Clause 5, Article 2 of Decree No. 13/2023/ND-CP, Personal data protection refers to the activities of preventing, detecting, stopping, and handling violations related to personal data as prescribed by law.

2. How is personal data categorized?
Personal data is categorized into two groups: basic personal data and sensitive personal data.

II. Legal regulations on personal data protection

1. What are the basic components of personal data?
Pursuant to Clause 3, Article 2 of Decree No. 13/2023/ND-CP, basic personal data includes:

- Full name, middle name, birth name, and other names (if any);

- Date of birth and death, or date of missing status;

- Gender;

- Place of birth, place of birth registration, permanent residence, temporary residence, current address, hometown, contact address;

- Nationality;

- Personal photographs;

- Phone number, identity card number, personal identification number, passport number, driver's license number, vehicle registration number, personal tax code, social insurance number, health insurance card number;

- Marital status;

- Information about family relationships (parents, children);

- Information related to the individual's account numbers; personal data reflecting online activities or activity history in cyberspace;

- Other information associated with or enabling the identification of a specific individual not covered in Clause 4 of this Article.

2. What are the measures for protecting personal data?
Pursuant to Clause 2, Article 26 of Decree No. 13/2023/ND-CP, measures to protect personal data include:

- Management measures implemented by organizations and individuals involved in personal data processing;

- Technical measures implemented by organizations and individuals involved in personal data processing;

- Measures implemented by competent state management agencies in accordance with this Decree and relevant laws;

- Investigative and judicial measures implemented by competent state agencies;

- Other legal measures as prescribed by law.

III. Frequently asked questions on personal data protection

1. What are the fines for unauthorized use of protected personal data?
Pursuant to Article 4 of Decree No. 13/2023/ND-CP, unauthorized use of protected personal data may be subject to disciplinary actions, administrative sanctions, or criminal liability depending on the severity of the violation, as prescribed by law.

2. How is sensitive personal data protected?
Pursuant to Article 28 of Decree No. 13/2023/ND-CP, the protection of sensitive personal data is regulated as follows:

- Applying the measures stipulated in Clause 2, Article 26 and Article 27 of this Decree;

- Assigning a department responsible for personal data protection, designating personnel in charge of personal data protection and exchanging information about this department, and personnel with the specialized authority for personal data protection. In cases where the Data Controller, Data Controller and Processor, Data Processor, or a third party is an individual, they must provide the personal data of the responsible individual;

- Informing the data subject about the processing of their sensitive personal data, except for cases regulated in Clause 4 of Article 13, and Articles 17 and 18 of this Decree.

Thus, sensitive personal data is protected through the aforementioned methods.

3. Is self-protection of personal data a right or an obligation of the data subject?
Pursuant to Clause 11, Article 9 of Decree No. 13/2023/ND-CP, regarding the right to self-protection:

- The data subject has the right to self-protection as prescribed by the Civil Code, other relevant laws, and this Decree, or may request competent authorities and organizations to take civil protection measures in accordance with Article 11 of the Civil Code.

According to Clause 1, Article 10 of the same Decree, concerning the obligations of data subjects:

- To protect their own personal data and request related organizations and individuals to do so as well.

Thus, self-protection of personal data is both a right and an obligation of the data subject.

4. What should you do when discovering someone has used your personal data without permission?
If you discover someone is using your personal data without authorization, you may take the following actions:

- Notify the unauthorized user: You may contact the unauthorized party to request that they cease using your information and delete it from their systems.

- Report to competent authorities: If your personal data has been used unlawfully and caused significant harm, you may report the incident to the authorities for assistance and protection of your rights.

- Implement personal data protection measures: You can apply management, technical, and other measures to ensure the security and confidentiality of your personal information as prescribed by law.

IV. Legal consulting and procedures related to personal data protection

The above information is provided by NPLaw to clarify issues related to personal data protection. If you have any further questions concerning procedures and regulations on personal data protection, please contact NPLaw using the contact information below.