Data transfer for research purposes offers significant benefits but may also create legal risks if not implemented in compliance with applicable regulations. The following article summarizes current practices, explains the importance of data transfer, outlines main legal considerations and regulatory requirements, and addresses common questions to help enterprises conduct data transfers safely, transparently, and while protecting the rights of relevant individuals.

I. Current situation of data transfer for research purposes

At present, data transfer for research purposes is becoming increasingly common, particularly in the healthcare, economic, educational, and technology sectors. Data collected from customers, users, or organizations is subsequently shared with researchers to support scientific studies, product development, service improvement, or market analysis.

However, in practice, many enterprises and organizations still lack full awareness of their responsibilities regarding personal data protection. Common issues include:

  • Data being transferred without obtaining clear consent from data subjects;
  • Insufficient transparency regarding the purpose and method of data usage by the receiving party;
  • Inadequate security measures, creating risks of data leakage or misuse;
  • Absence of procedures for handling unauthorized use of data or objections raised by data subjects.

These circumstances increase the risk of privacy violations, potentially resulting in legal consequences and reputational damage for enterprises. Therefore, understanding the current landscape is an important first step toward establishing a secure, transparent, and legally compliant data transfer mechanism.

II. What is data transfer for research purposes?

1. The importance of data transfer for research purposes

Data transfer for research purposes plays a crucial role in advancing knowledge and technological innovation. Accurate and comprehensive data enables researchers to analyze trends, draw scientific conclusions, and develop solutions to improve products, services, or public policies.

In addition, data sharing promotes collaboration among research institutions, enterprises, and regulatory authorities, creating opportunities for innovation and improving research outcomes. However, it also comes with the responsibility to safeguard individuals’ privacy rights and ensure that data usage remains transparent, purpose-driven, and compliant with legal requirements.

2. Main considerations regarding data transfer for research purposes

Important considerations include:

  • Protecting individual privacy: Personal data should be processed under the principle of data minimization, using only information necessary for research purposes and avoiding disclosure of sensitive information unless strictly required.
  • Using data only for defined research purposes: Data must be utilized solely for the identified research objectives and must not be repurposed or transferred to unrelated third parties.
  • Ensuring legal compliance: All data transfer activities must comply with the Personal Data Protection Law 2023 and implementing regulations, including notification and obtaining consent from data subjects where required.
  • Establishing clear contracts and agreements: Data-sharing arrangements should be governed by agreements that clearly define confidentiality obligations, permitted purposes of use, and consequences of non-compliance.
  • Applying security and storage measures: Data should be encrypted, access-controlled, and securely stored to reduce risks of loss, leakage, or unauthorized access.

III. Legal regulations relating to data transfer for research purposes

1. Regulations enterprises should pay attention to regarding data transfer for research purposes

To lawfully transfer data for research purposes, enterprises must comply with applicable legal requirements, particularly the Personal Data Protection Law 2025 and Decree No. 13/2023/ND-CP providing implementation guidance.

Personal Data Protection Law 2025

  • Personal data transfer is permitted only where data subject consent has been obtained or in situations specifically authorized by law, such as internal data sharing between departments, continued processing following organizational restructuring, or compliance with requests from competent authorities (Article 17).
  • Whether or not compensation is involved, transferring personal data does not automatically constitute the sale or purchase of personal data (Clause 2, Article 17).
  • The Law also provides for international cooperation in personal data protection, including human resource development, scientific research, and scientific and technological applications (Article 6).

Decree No. 13/2023/ND-CP

  • It provides detailed guidance regarding international cooperation, including conferences, workshops, and scientific research activities supporting enforcement of personal data protection regulations (Article 7).
  • It assigns responsibilities to the Ministry of Science and Technology to coordinate the development of personal data protection standards and propose measures aligned with scientific and technological advancement (Article 35).

2. Violations relating to data transfer for research purposes

In practice, organizations and enterprises may unintentionally or intentionally engage in unlawful data transfer activities. Identifying prohibited conduct is essential to preventing legal risks and ensuring lawful research practices.

According to Article 7 of the Personal Data Protection Law 2025, common violations include:

  • Unlawful processing of personal data: Including the use of personal data for activities against the State, affecting national defense, security, public order, or infringing upon lawful rights and interests of organizations or individuals.
  • Obstructing or abusing personal data protection activities to facilitate unlawful conduct.
  • Using another person’s personal data unlawfully or permitting others to use one’s personal data for unlawful purposes.
  • Buying or selling personal data contrary to legal requirements.
  • Misappropriating, intentionally disclosing, or causing loss of personal data, resulting in harm to data subjects.

IV. Questions regarding data transfer for research purposes

1. What information must be protected when transferring data for research purposes?

Pursuant to Article 2 of the Law on Personal Data Protection 2025, when transferring data for research purposes, the following categories of information must be protected:

  • Personal data refers to digital data or information in other forms that identifies or helps identify a specific individual, including basic personal data and sensitive personal data (Clause 1, Article 2).
  • Basic personal data includes information reflecting personal identity and commonly used background information in transactions and social relations, as specified under the list promulgated by the Government (Clause 2, Article 2).
  • Sensitive personal data consists of information closely connected to an individual’s privacy, where unauthorized disclosure or infringement may directly affect the lawful rights and interests of individuals, agencies, or organizations (Clause 3, Article 2).

2. If data is used for purposes other than the stated research purpose, which party bears responsibility?

If data is used beyond the stated research purpose, legal liability will generally be determined based on the party directly committing the violation, specifically:

  • The receiving party takes primary responsibility if it uses the data for purposes inconsistent with the agreed scope or the purposes disclosed to the data subject, as this constitutes unlawful personal data processing.
  • The transferring party may also take joint liability if it knew or should reasonably have known that the data would be used improperly but nevertheless proceeded with the transfer, or failed to implement appropriate control mechanisms and contractual safeguards governing the transfer.

Therefore, the party directly misusing the data is primarily liable; however, liability of the transferring party may also arise where there is negligence in management, supervision, or contractual arrangements concerning the data transfer.

3. Is it necessary to notify the relevant individual when their data is transferred for research purposes? Why?

As a general principle, enterprises must notify individuals when their data is transferred for research purposes since such transfer constitutes a form of personal data processing, and data subjects have the right to be informed (Clause 1, Article 9 of Decree No. 13/2023/ND-CP).

The notification must be made before processing occurs and should clearly specify the purpose of the research, the categories of data being used, the processing methods, relevant parties involved, potential risks that may arise, and the duration of processing. The notification must also be presented in a format capable of being stored and verified (Article 13 of Decree No. 13/2023/ND-CP).

However, notification may not be required where the individual has already been fully informed and has previously provided consent or the data is processed by a competent State authority in accordance with applicable law (Clause 4, Article 13 of Decree No. 13/2023/ND-CP).

4. How is the notification procedure for data transfer for research purposes regulated?

The notification procedure regarding personal data transfer for research purposes (under Article 13 of Decree No. 13/2023/ND-CP) generally includes the following steps:

- Step 1: Determining whether the transfer activity constitutes personal data processing

Transferring personal data for research purposes is regarded as a personal data processing activity and therefore falls within the scope of Article 13 of Decree No. 13/2023/ND-CP.

- Step 2: Preparing the notification content for data subjects

The data controller or data controller-processor must prepare a complete notice containing:

  • Purpose of the transfer for research activities;
  • Categories of personal data being transferred;
  • Methods of processing and use during research;
  • Information regarding receiving organizations or individuals (research institutions or collaborating entities);
  • Possible risks or adverse consequences (if any);
  • The commencement and completion period of processing activities.

- Step 3: Providing notification before transferring the data

Notification must generally be provided once and prior to transferring data for research purposes, unless an exemption applies.

- Step 4: Ensuring the notification is presented in a legally acceptable format

The notice must be capable of being printed, copied, and verified, including paper documents, electronic documents, or other verifiable electronic formats.

- Step 5: Assessing whether any exemption from notification applies

Notification is not required if:

  • The data subject already clearly understands and has consented to all notification contents under Article 9 of Decree No. 13/2023/ND-CP; or
  • Processing is implemented by competent State authorities for official governmental functions.

5. If one party breaches contractual terms relating to data transfer for research purposes, what is the handling process?

If one party breaches contractual terms governing data transfer for research purposes, the handling process generally includes:

  • First, identifying the breach and assessing its severity: Depending on the nature, seriousness, and consequences of the violation, the breaching party may be subject to disciplinary action, administrative sanctions, or criminal liability under personal data protection laws (Article 4 of the Law on Personal Data Protection 2025).
  • Second, applying contractual remedies: If the breach constitutes a material breach or falls within agreed termination conditions, the non-breaching party may terminate the contract without compensation obligations (Article 423 of the Civil Code 2015), provided that timely notice is given.
  • Third, addressing legal consequences following termination: After termination, parties must restore the status quo by returning what has been received, compensating for damages where applicable, and continuing to comply with provisions relating to sanctions, compensation, and dispute resolution (Article 427 of the Civil Code 2015).

V. Why consult NPLaw regarding data transfer for research purposes?

If a business has difficulties in transferring data for research purposes, particularly in determining notification obligations, defining the permissible scope of transferred data, or assessing related legal responsibilities, seeking advice from a legal professional is advisable.

NPLaw’s legal team, with experience in personal data protection and compliance with Decree No. 13/2023/ND-CP, can assist in:

  • Reviewing data transfer procedures and internal compliance mechanisms;
  • Assessing legal and regulatory risks;
  • Preparing documents and governance frameworks;
  • Designing compliant consent and notification processes.

Professional legal support helps enterprises reduce compliance risks, avoid administrative sanctions, and ensure research activities are conducted lawfully and effectively.

The above information is provided for reference purposes only. For case-specific advice, please contact NPLaw for timely and comprehensive legal support.