Your benefits – Our top priority
0913449968 0913419996 legal@nplaw.vn

In the context where enterprises are increasingly dependent on data for operations, business activities, and collaboration, data transfer agreements have become an essential legal instrument to ensure that information exchange is conducted in a transparent, secure, and lawful manner. 

In the context where enterprises are increasingly dependent on data for operations, business activities, and collaboration, data transfer agreements have become an essential legal instrument to ensure that information exchange is conducted in a transparent, secure, and lawful manner. 

I. Current situation regarding data transfer agreements

Strong digital transformation, the demand for data transfer among enterprises, partners, and service providers is continuously increasing. However, in practice, the execution and performance of data transfer agreements still reveal various shortcomings.

First, many enterprises have not clearly defined the scope of data to be transferred, leading to risks of disclosing information beyond the original purpose or in violation of personal data protection regulations. Second, parties often lack mechanisms to control, monitor, or assess the data recipient’s security capacity, thereby increasing the likelihood of misuse or data leakage.

Additionally, numerous enterprises merely enter into general cooperation agreements while overlooking specific annexes or provisions governing data transfer. It creates difficulties in dispute resolution, as the rights and obligations of each party are not clearly stipulated.

This reality demonstrates that, without properly establishing and strictly complying with data transfer agreements, enterprises are highly exposed to legal risks, financial losses, and reputational damage.

II. Concept of data transfer agreements

1. What is a data transfer agreement?

A data transfer agreement is a legal document recording the provision, sharing, or transfer of data from one party to another based on specific terms regarding purpose of use, scope of data, security measures, and responsibilities of the parties. It serves as a tool to ensure that data processing activities comply with legal regulations and principles of transparency.

2. In which cases are data transfer agreements used?

Such agreements are commonly applied in various situations, including: Transferring data to service providers (IT, marketing, customer care), business cooperation, mergers and acquisitions, outsourcing of data processing, or transferring datasets for analysis and reporting purposes. In general, any activity involving data sharing between two or more parties requires such agreements to control risks and responsibilities.

3. Which parties typically participate in data transfer agreements?

Parties typically involved in data transfer agreements include:

  • Data controller: The entity that owns and determines the purposes and means of data processing;
  • Data recipient or processor: The individual or organization assigned to process data upon request;
  • Relevant third parties such as service partners, platform providers, or system operators.

Data transfer agreements often involve coordination among multiple parties; therefore, it is necessary to clearly define each party’s role to avoid conflicts and ensure the security of transferred information.

III. Legal regulations governing data transfer agreements

1. Legal conditions for data transfer under current law

Pursuant to Article 17 of the Law on Personal Data Protection 2025, personal data may be transferred under the following conditions:

  • Transfer of personal data with the consent of the data subject;
  • Sharing of personal data within departments of the same organization for processing consistent with the established purpose;
  • Transfer of personal data for continued processing in cases of division, separation, merger, consolidation, reorganization of agencies or organizations, or transformation of state-owned enterprises;
  • Transfer by data controllers or joint controllers/processors to data processors or third parties for processing in accordance with the law;
  • Transfer upon request of competent state authorities;
  • Transfer in cases specified under Clause 1, Article 19 of this Law.

These conditions ensure that data is shared only when necessary and subject to strict control.

2. What types of data are restricted or prohibited from transfer under the law?

Current regulations impose certain limitations on data transfer, including:

  • Sensitive data (e.g., financial data, health data, biometric identification data, real-time location data) may only be transferred when enhanced security measures are applied and with the data subject’s consent under Article 9 of the Law on Personal Data Protection 2025;
  • Data classified as state secrets is strictly prohibited from being transferred without authorization from competent authorities under Article 5 of the Law on Protection of State Secrets 2018.

Such restrictions aim to prevent risks of disclosure of highly sensitive data and to protect public interests.

3. What mandatory clauses must a data transfer agreement include?

To meet legal requirements, a data transfer agreement should include at least the following provisions:

  • Scope of transferred data: Types, level of detail, and format;
  • Purpose of data transfer: Clear and specific;
  • Data processing duration and permitted storage period;
  • Security and information protection measures: Encryption, access control, technical monitoring;
  • Responsibilities of each party in data protection and incident handling;
  • Notification and response mechanisms for data breaches (including the 72-hour notification requirement under Clause 1, Article 23 of the Law on Personal Data Protection 2025);
  • Sub-transfer provisions where the recipient intends to share data with third parties;
  • Dispute resolution and liability for damages.

These essential provisions ensure the agreement’s legal validity and help prevent potential risks. 

4. What minimum level of security is required by law for data transfer?

Currently, the law does not prescribe a specific minimum level of security for data transfer. However, enterprises are required to apply security measures appropriate to the type of data, including:

  • Performing encryption during transmission and storage;
  • Establishing access control mechanisms, including role-based access and multi-factor authentication;
  • Logging and monitoring of all data processing activities;
  • Conducting Data Protection Impact Assessment (DPIA) for sensitive data or large-scale transfers;
  • Applying measures to prevent unauthorized access, such as firewalls and anti-malware systems;
  • Applying backup and recovery mechanisms to ensure data integrity.

These measures are implemented based on a risk-based approach to ensure data protection throughout the transfer process.

IV. Questions regarding data transfer agreements

1. Is consent of the data subject required for personal data transfer?

Under Point (a), Clause 1, Article 17 of the Law on Personal Data Protection 2025, the transfer of personal data requires the consent of the data subject. However, consent is not required in certain cases specified in Clause 1, Article 19, such as:

  • Protecting life, health, dignity, reputation, and lawful rights and interests of the data subject or others in urgent situations;
  • Responding to emergencies, threats to national security, or preventing crimes and legal violations;
  • Serving activities of state authorities or public administration;
  • Fulfilling agreements between the data subject and relevant entities in accordance with the law.

Thus, personal data transfer generally requires explicit, voluntary, and informed consent, except where otherwise permitted by law.

2. Must a data transfer agreement be in writing?

The law does not specifically mandate the form of data transfer agreements.

However, such agreements should be made in writing (contracts, annexes, minutes, or electronically signed documents) to clearly define responsibilities, security measures, retention periods, and breach handling. It also serves as critical evidence in case of disputes or data breaches.

3. Are there stricter conditions for transferring sensitive personal data?

Under Clause 3, Article 2 of the Law on Personal Data Protection 2025, sensitive personal data is data closely associated with an individual’s privacy, and any infringement may directly affect lawful rights and interests.

The transfer of such data requires stricter conditions, including:

  • Separate and explicit consent from the data subject;
  • Enhanced security measures such as encryption, restricted access, or segregated storage;
  • Data Protection Impact Assessment (DPIA) prior to transfer;
  • In certain cases, reporting to or obtaining approval from competent data protection authorities.

Thus, sensitive data transfer requires significantly higher levels of control compared to ordinary data.

4. Upon termination of a data transfer agreement, must the transferred data be deleted or recovered?

Under Article 14 of the Law on Personal Data Protection 2025, upon termination, the data recipient is required to delete, destroy, or anonymize personal data to prevent misuse after the agreement ends.

5. How should parties handle data breaches after transfer?

Under Article 23 of the Law on Personal Data Protection 2025, in the case of a data breach:

  • The detecting party must notify the competent authority within 72 hours;
  • The parties must document the incident and coordinate to remedy consequences;
  • The enterprise must notify affected data subjects if their rights and interests are at risk;
  • Liability for damages shall be determined based on fault and agreed security obligations.

Handling data breaches is not only a legal obligation but also essential for maintaining reputation, customer trust, and sustainable cooperation.

V. Why enterprises should seek legal advice from NPLaw regarding data transfer agreements

NPLaw possesses a team of lawyers with in-depth expertise in data protection law, information security, cybersecurity, and the latest regulations on personal data transfer. With extensive practical experience, NPLaw is capable of:

  • Drafting and reviewing legally compliant and robust data transfer agreements;
  • Assessing risks and proposing mitigation measures;
  • Handling disputes, data breaches, or violations by data recipients;
  • Providing long-term advisory strategies to ensure compliance and protect business reputation.

Therefore, engaging NPLaw enables enterprises to confidently implement data transfer activities in a lawful and secure manner.

The above information is for reference only. For detailed advice on specific cases, please contact NPLaw for prompt consultation.

NGOC PHU LAW COMPANY LIMITED
Phone Hotline 1: 0913449968 Hotline 2: 0913419996

Related services

Opening an english language center

  In the era of economic integration, increasing globalization, and the c...

Issues related to loan agreements

Currently, many Clients are interested in issues related to loan agreements. Und...

Law on bidding and things needing to be understand

  Currently, the sane competition of businesses has strongly contributed...

The regulations for the commercial arbitration award in vietnam

According to the general principle, a judgment (arbitral award or arbitration aw...

The franchising agreement according to the law in vietnam

Along with the current economic development, commercial businesses and franchisi...

Regulations for a false advertisement

An advertisement has an important role and a significant meaning for giving deve...

Fraudulent behaviors of renting at high prices in vietnam

Rent is always an essential choice and demand for almost all students coming to...

The regulations for the commercial arbitration center

When arising dispute issues, the parties will always seek and require competent...

WhatsApp WeChat Zalo hotline 0913449968 hotline
0
Bạn đang quan tâm đến

Chúng tôi sẵn sàng tư vấn miễn phí cho bạn!

Tư vấn điện thoại Zalo Tư vấn qua Zalo