Your benefits – Our top priority
0913449968 0913419996 legal@nplaw.vn

Besides personal privacy rights, data management policies also have a direct impact on cybersecurity, corporate reputation, and legal liability in business operations.

Besides personal privacy rights, data management policies also have a direct impact on cybersecurity, corporate reputation, and legal liability in business operations.

I. Current issues related to data management policies

In the context of rapid digital transformation, data has become one of the most valuable assets of enterprises and regulatory authorities. However, Vietnam’s current data management policy framework still reveals numerous shortcomings. Certain regulations on the collection, storage, sharing, security, and processing of personal data remain inconsistent across various laws, such as the Law on Cybersecurity 2018, the Law on Personal Data Protection 2025, the Law on Electronic Transactions 2023 (as amended in 2024), the Law on Data 2024, and others. Such an inconsistency results in ineffective application in practice, creating difficulties for both regulators and enterprises.

At the same time, many enterprises haven’t established a standardized internal data governance system yet, relying mainly on manual management methods and lacking effective supervision and access control mechanisms. It significantly increases the risk of data leakage, illicit trading, or misuse of customer data. Numerous cases involving the widespread sale of personal information online have been recorded, directly infringing upon individuals’ privacy rights and damaging corporate credibility.

In addition, awareness among users and enterprises regarding the importance of data protection remains limited. Many individuals readily provide personal information without sufficient consideration of its purpose of use, while enterprises often lack adequate control procedures, staff training programs, or fail to implement advanced security measures as required by law.

II. Concept of data management policies

As data increasingly becomes a critical corporate asset, establishing a strong governance framework is a decisive factor in ensuring information security, legal compliance, and customer trust. Accordingly, data management policies play a foundational role in the overall data operation system of enterprises.

1. What is a data management policy?

Pursuant to Clause 1, Article 3 of the Law on Data 2024, digital data means data relating to objects, phenomena, and events, including one or a combination of sounds, images, numbers, letters, symbols, represented in digital form (hereinafter referred to as “data”).

At the same time, Article 15 of the Law on Data 2024 provides that:

  • Data governance includes the development of policies, plans, programs, processes, and standards regarding data by data owners and data administrators to manage data in a continuous and effective manner, ensuring the completeness, accuracy, integrity, consistency, uniformity, standardization, safety, security, and timeliness of data.
  • Data management is the organization and implementation of data governance activities as stipulated in Clause 1 of this Article.

Accordingly, a data management policy is a set of principles, rules, and orientations promulgated by an enterprise to govern the entire data, ensuring that data is collected, used, stored, and protected in a standardized, consistent, and lawful manner.

In other words, it is a foundational document that reflects how an enterprise controls data to ensure its completeness, accuracy, integrity, security, and confidentiality throughout operational processes.

2. Why do enterprises need to promulgate data management policies?

Enterprises need to promulgate data management policies because such policies constitute a crucial foundation for protecting information assets that are one of the most valuable forms of assets today. Having the policy helps enterprises mitigate risks of data leakage, misuse, or misappropriation by third parties.

Moreover, the clear policy enables enterprises to comply with applicable laws (such as the Law on Personal Data Protection 2025 and the Law on Cybersecurity 2018), thereby avoiding severe administrative sanctions. 

Furthermore, data management policies enhance internal operational efficiency and strengthen trust among customers and partners by demonstrating that data is protected in a transparent and professional manner.

3. How does a data management policy differ from a data management procedure?

A data management policy is a high-level strategic document that establishes rules applicable throughout the organization and protection of data. In contrast, a data management procedure provides technical and detailed guidance on how such requirements are implemented.

For example, while the policy may require the enterprise to ensure customer data security, procedures will specify encryption methods, access authorization mechanisms, storage methods, and incident response processes.

Thus, policies are mandatory and strategic in nature, whereas procedures are detailed and implementation-oriented.

III. Legal regulations related to data management policies

1. Fundamental principles for developing and implementing data management policies

When developing data management policies, enterprises are required to comply with the principles governing data creation, development, protection, governance, processing, and use as set out in Article 5 of the Law on Data 2024, including:

  • Compliance with the Constitution, this Law, and other relevant legal regulations; ensuring human rights, citizens’ rights, and other lawful rights and interests of agencies, organizations, and individuals.
  • Ensuring transparency, openness, and equality in data access, exploitation, and use in accordance with law.
  • Ensuring accurate data collection, updating, and adjustment; maintaining data integrity, reliability, security, and safety.
  • Implementing data protection in a synchronized and integrated manner with data development and expansion.
  • Ensuring that data storage, connection, coordination, sharing, exploitation, and use are efficient, simple, and convenient for agencies, organizations, and individuals in the provision of public services, administrative procedures, and other activities.

These principles serve as the legal basis for enterprises to develop lawful and effective data management policies while minimizing data governance risks.

2. Entities involved in the data management policy process

Pursuant to Clauses 3 and 4, Article 15 of the Law on Data 2024 and the guidance provided in Article 14 of Decree No. 165/2025/ND-CP, entities involved in the data management policy process include:

  • Data owners and data administrators that are State agencies, which are responsible for coordinating with the National Data Center in data management activities.
  • Data owners and data administrators that are organizations or individuals, which shall conduct data governance and management based on actual conditions for data they collect, generate, and own.

The involvement and coordination of multiple departments ensure that data management policies are effectively implemented in practice rather than merely existing in written form.

3. How does Vietnamese law regulate the development and implementation of data management policies in enterprises?

Although Vietnamese law does not explicitly define the term “data management policy”, it does contain provisions governing the development and implementation of data management mechanisms within enterprises, such as:

  • Clause 4, Article 15 of the Law on Data 2024 stipulates that data owners and data administrators that are organizations or individuals shall conduct data governance and management for data they collect, generate, and own based on actual conditions.
  • Article 37 of the Law on Personal Data Protection 2025 regulates the responsibilities of personal data controllers, personal data processors, and entities that both control and process personal data.

Compliance with the above legal obligations effectively necessitates the establishment and application of a data management policy.

4. Are enterprises required to promulgate data management policies under current regulations?

Enterprises are not explicitly required to promulgate data management policies under current regulations. However, attention should be paid to legal requirements related to data management, particularly personal data, such as:

  • Personal data processing impact assessment (Article 60 of the Law on Personal Data Protection 2025): Personal data controllers and entities that both control and process personal data must prepare, retain, and submit one original copy of the personal data processing impact assessment dossier to the specialized personal data protection authority within 60 days from the date of initial data processing.
  • Data protection management during processing (Article 17 of the Law on Data 2024): Data administrators must establish a system for managing data protection throughout the entire data processing; implement data protection measures during data collection and generation; store data in accordance with legally prescribed methods and retention periods; and develop data storage procedures specifying backup, recovery, and logging processes; establish data storage management systems; and apply technical tools and measures to protect data during storage, including automated backup and recovery mechanisms.

Accordingly, although the law does not expressly use the term of data management policy, its requirements effectively compel enterprises to maintain equivalent internal documentation.

IV. Questions regarding data management policies

1. Do enterprises need separate data management policies for each type of data?

In practice, the law does not require enterprises to develop separate policies for each type of data. However, personal data is categorized into basic personal data and sensitive personal data, each subject to different levels of protection and technical requirements. Accordingly, enterprises should:

  • Classify data within their policies;
  • Apply appropriate protective measures for each data category;
  • Establish corresponding processing procedures for each data type.

Thus, while multiple separate policies are not required, a unified policy must clearly reflect data classification and differentiated handling methods.

2. How and when may enterprises amend data management policies?

Enterprises may amend data management policies at any time, provided that:

  • The amended provisions do not contravene applicable laws;
  • Employees or data subjects are notified if amendments affect their rights;
  • Internal systems and related technical procedures are updated accordingly;
  • In cases involving sensitive personal data processing, the personal data impact assessment report may need to be updated.

Common circumstances requiring policy amendments include:

  • Adoption of new technologies (AI, cloud computing, etc.);
  • Changes in business models;
  • Engagement of new partners involving data sharing;
  • Occurrence of data security risks or incidents.

Data management policies should be flexibly updated in response to practical developments and technological advancements, rather than treated as static documents.

3. Should enterprises apply new technologies (cloud, AI) in data management policies?

Enterprises are encouraged to adopt new technologies such as cloud computing and AI in data management policies. However, such adoption must be approached cautiously, as these technologies may entail higher data leakage risks. When incorporating cloud or AI solutions, enterprises should:

  • Clearly specify data storage locations (onshore or offshore);
  • Assess the security processes of service providers;
  • Control data access rights on cloud platforms;
  • Clearly regulate AI use of personal data in accordance with principles of data minimization and transparency.

While technological adoption is necessary, it must be clearly regulated within policies to manage legal and technical risks.

4. Does failure to establish the data management policy constitute a legal violation?

As analyzed above, enterprises are not explicitly required to promulgate data management policies under current law.

However, failure to comply with legal requirements related to data collection, use, and processing may result in administrative or criminal sanctions depending on the nature and severity of the violation. Pursuant to Article 8 of the Law on Personal Data Protection 2025, organizations and individuals committing violations related to personal data protection may be subject to administrative sanctions or criminal liability, and must compensate for damages in accordance with law.

5. If an enterprise shares data with partners, must the data management policy clearly stipulate data protection responsibilities?

Where data is shared with partners, the data management policy must clearly stipulate data protection responsibilities. In such cases, the policy should specify:

  • Confidentiality obligations of partners;
  • Purpose of data use;
  • Commitments not to further disclose data to third parties;
  • Data protection and encryption measures;
  • Liability for damages in the event of data leakage.

In addition to internal policies, enterprises must also enter into data processing agreements (DPAs) with partners, clearly defining each party’s legal responsibilities. All data-sharing activities must be governed by clear contractual provisions to protect enterprises from legal risks.

V. Why seek legal advice from NPLaw on data management policy issues?

The development and operation of data management policies require in-depth expertise in law, cybersecurity, and technology. NPLaw is a reputable legal service provider capable of offering comprehensive support to enterprises, including:

  • Advising on the development of data management policies tailored to business models and legal requirements;
  • Assessing legal risks related to the processing of personal data and sensitive data;
  • Assisting in the establishment of data processing procedures, access controls, and technical compliance measures;
  • Drafting confidentiality agreements and data-sharing agreements between enterprises and partners;
  • Protecting enterprises in disputes related to data violations.

The above information is provided for reference purposes only. For specific legal advice tailored to particular cases, clients are encouraged to contact NPLaw for prompt consultation.

NGOC PHU LAW COMPANY LIMITED
Phone Hotline 1: 0913449968 Hotline 2: 0913419996

Related services

Opening an english language center

  In the era of economic integration, increasing globalization, and the c...

Issues related to loan agreements

Currently, many Clients are interested in issues related to loan agreements. Und...

Law on bidding and things needing to be understand

  Currently, the sane competition of businesses has strongly contributed...

The regulations for the commercial arbitration award in vietnam

According to the general principle, a judgment (arbitral award or arbitration aw...

The franchising agreement according to the law in vietnam

Along with the current economic development, commercial businesses and franchisi...

Regulations for a false advertisement

An advertisement has an important role and a significant meaning for giving deve...

Fraudulent behaviors of renting at high prices in vietnam

Rent is always an essential choice and demand for almost all students coming to...

The regulations for the commercial arbitration center

When arising dispute issues, the parties will always seek and require competent...

WhatsApp WeChat Zalo hotline 0913449968 hotline
0
Bạn đang quan tâm đến

Chúng tôi sẵn sàng tư vấn miễn phí cho bạn!

Tư vấn điện thoại Zalo Tư vấn qua Zalo