In the context where personal data is increasingly collected and processed on a large scale, customers requesting the right to access data has become an important right to ensure transparency and the data subject’s control over their personal information.
In the context where personal data is increasingly collected and processed on a large scale, customers requesting the right to access data has become an important right to ensure transparency and the data subject’s control over their personal information.
I. The current situation of customers requesting the right to access data
In recent years, together with the strong growth of digitalization activities and data exploitation, customers requesting the right to access data has become increasingly common and inevitable. Customers are not only concerned about the quality of products and services but also pay greater attention to how their personal data is being collected, stored, and used. It reflects a clear shift in public awareness regarding personal data protection rights and the right to control one’s own information.

In addition, the increasing legal framework on personal data protection has created a legal basis for customers to proactively exercise their right to access data. In practice, data access requests commonly arise in sectors such as e-commerce, finance and banking, telecommunications, education, and healthcare, where personal data is processed in large volumes. However, many enterprises still have difficulties in receiving, verifying, and responding to such requests, leading to risks of legal violations or disputes with customers.
Moreover, the current situation also shows diversity in the forms and contents of customers requesting the right to access data, ranging from requests for the provision of all stored personal data to requests for clarification of the purpose of processing, data recipients, or data retention periods. It creates an urgent need for enterprises to establish clear and consistent internal procedures to both ensure customer rights and comply with current legal regulations.
II. Understanding customers requesting the right to access data
1. Why do customers want to request the right to access their data from enterprises?
Customers request the right to access data in order to control how their personal information is being collected, stored, and used by enterprises. Through data access, customers can verify the accuracy, legality, and transparency of data processing activities, while also promptly detecting errors, misuse of data for improper purposes, or risks of privacy infringement.
2. What types of data can customers request access to when dealing with an organization?
In principle, customers have the right to request access to all personal data that an organization controls or processes, including identification information, transaction data, service usage history, contact information, and data generated during the provision of products and services. In certain cases, customers also have the right to request information regarding the purpose of processing, data recipients, and data retention periods.
3. What methods can customers use to request the right to access data?
Customers may exercise their right to access data through various methods, such as submitting written requests, using electronic information portals, sending requests through the company’s official email, or through customer service channels. Regardless of the method used, the data access request must clearly identify the requester’s identity and specify the requested data.
4. If customers request the right to access data but their request is not fulfilled, what can they do?
In cases where a data access request is not fulfilled by the enterprise or is rejected without legal grounds, customers have the right to file a direct complaint with the enterprise to request explanation and remediation.
If not, customers may submit complaints or reports to competent State authorities or initiate legal proceedings in accordance with the law to protect their lawful rights and interests.
III. Legal provisions related to customers requesting the right to access data
1. Which law regulates customers’ rights to request access to their personal data?
Customers’ rights to request access to personal data are first recognized under the Law on Personal Data Protection 2025. Clause 1, Article 4 of the Law on Personal Data Protection 2025 provides that the rights of personal data subjects include:
- Being informed about personal data processing activities;
- Agreeing or refusing, and requesting withdrawal of consent for personal data processing;
- Viewing, editing, or requesting correction of personal data;
- Requesting provision, deletion, restriction of personal data processing; submitting objections to personal data processing; etc.

In addition, Article 4 of the Law on Protection of Consumer Rights 2023 provides consumer rights such as:
- Being ensured safety of life, health, honor, dignity, reputation, property, information protection, and other lawful rights and interests when participating in transactions and using products, goods, and services provided by business organizations and individuals;
- Being provided with invoices, documents, and materials related to transactions; timely, accurate, and complete information on products, goods, services, transaction contents, origin, source of products, goods, and services, and information about business organizations and individuals; etc.
2. If customers request the right to access data and the organization refuses, is the organization obligated to explain the reason?
According to the principle of transparency in personal data processing as prescribed in Article 3 of the Law on Personal Data Protection 2025, where an organization refuses or limits compliance with a customer’s request for data access, such organization is obligated to notify and clearly explain the reasons. Refusal is only acceptable in cases with legal grounds, such as for the protection of national security, state secrets, lawful rights and interests of third parties, or upon request of competent state authorities.
Without clear and lawful grounds, refusal to provide data access rights may be considered a violation of obligations to protect the rights of data subjects.
3. If an organization fails to comply with a customer’s request for data access, can it face legal sanctions?
Where an organization fails to comply with or intentionally obstructs customers requesting the right to access data in violation of legal regulations, such organization may take legal consequences under Article 8 of the Law on Personal Data Protection 2025:
- Organizations and individuals committing violations of this Law and other relevant legal provisions on personal data protection may be subject to administrative sanctions or criminal prosecution depending on the nature, severity, and consequences of the violation; if damage is caused, compensation must be made in accordance with the law.
- The maximum monetary fine for administrative violations involving the buying and selling of personal data is ten times the amount of illegal proceeds obtained from the violation; where there is no illegal income or the calculated fine is lower than the statutory maximum fine prescribed in Clause 5 of this Article, the fine level prescribed in Clause 5 shall apply.
- The maximum monetary fine for administrative violations involving organizations violating regulations on cross-border transfer of personal data is 5% of the organization’s revenue of the immediately preceding year; where there is no revenue for the immediately preceding year or the calculated fine is lower than the statutory maximum fine prescribed in Clause 5 of this Article, the fine level prescribed in Clause 5 shall apply.
- The maximum monetary fine for other violations in the field of personal data protection is 3 billion VND.
In addition, where violations are serious and affect the lawful rights and interests of multiple data subjects, the organization may also face disputes leading to civil lawsuits or criminal denunciations if criminal signs are present.
IV. Questions related to customers requesting the right to access data
1. What is the maximum time for a company to respond when customers request the right to access data?
Currently, the law does not provide a specific maximum time for companies to respond when customers request the right to access data. Thus, based on the principle of ensuring the rights of data subjects, once a valid request is received, the company is responsible for responding within the time announced in its personal data protection policy.

The response time must ensure timeliness and avoid obstructing the customer’s exercise of the right to access data; if an extension is necessary, the company must notify the customer and clearly state legitimate reasons.
2. What procedures should be followed when customers request access to their personal data?
Generally, the process includes the following steps: Receiving the data access request; verifying the identity of the requester; reviewing the scope of relevant data; providing the information to the customer in an appropriate form; and maintaining records of the request handling process. Such a procedure should be clearly established, publicly disclosed, and compliant with personal data protection laws.
3. If the data is inaccurate, can customers request correction after accessing it?
After accessing their data, if customers discover that the information is inaccurate, incomplete, or no longer appropriate, they have the right to request the company to correct, update, or supplement their personal data. Such a right is closely associated with the right of data access, ensuring that data is processed accurately, truthfully, and for proper purposes.
4. Are there cases where customers cannot request the right to access data?
In certain special cases prescribed by law, customers’ right to access data may be restricted, such as for the protection of national security, state secrets, lawful rights and interests of third parties, or upon request of competent state authorities. Such restrictions must have clear legal grounds and must be notified to the customer.
5. How long is a company obligated to retain information before customers request the right to access data?
The retention period of personal data depends on the purpose of data processing and agreements with customers. Companies may only retain data for the necessary and appropriate period; during such period, customers still have the right to request access to their data in accordance with the law.
V. Are you looking for a skilled and reputable lawyer to assist with issues related to customers requesting the right to access data?
If you are facing difficulties in receiving, handling, or protecting rights when customers request the right to access data, consulting a lawyer experienced in the field of personal data protection will help you clearly understand your legal obligations, establish appropriate compliance procedures, and minimize legal risks and disputes that may arise in practice.
The above information is for reference purposes only. Should you require detailed consultation regarding your specific case, please contact NPLaw Firm for immediate legal advice.