Your benefits – Our top priority
0913449968 0913419996 legal@nplaw.vn

In today’s era of rapid digitalization, the risk of personal data being collected, misused, or leaked has increased significantly, making data protection in online transactions an essential and pressing requirement.

In today’s era of rapid digitalization, the risk of personal data being collected, misused, or leaked has increased significantly, making data protection in online transactions an essential and pressing requirement.

I. Current situation regarding data protection in online transactions

The rapid expansion of the Internet and digital platforms has strongly promoted the growth of online transactions, while simultaneously leading to serious concerns regarding the safety of personal data.

At present, users increasingly share personal information when shopping, making payments, registering accounts, or using digital services. However, the level of data protection in these activities remains disproportionate to the actual risks involved.

  • First, excessive and non-transparent data collection remains widespread. Many websites and applications require users to provide information beyond what is necessary for the transaction or fail to clearly explain the purposes of data usage. Privacy policies are often lengthy and difficult to understand, leading users to consent without fully being aware of their rights or the potential risks.
  • Second, personal data breaches in online transactions are increasing frequently. From payment details, phone numbers, and email addresses to purchase histories, data may be stolen by hackers or leaked from enterprises’ internal management systems. The illegal trading of personal data on the black market has become common, seriously infringing upon users’ privacy rights.
  • Third, the data security capacity of many enterprises remains limited. A considerable number of small businesses, e-commerce platforms, and online service providers have not made adequate investments in cybersecurity. Data encryption, access control, and information security governance processes are often fragmented or insufficient, resulting in a heightened risk of cyberattacks or unauthorized exploitation.
  • Fourth, user awareness of data protection remains inadequate. Many users tend to share personal information indiscriminately, use weak passwords, fail to verify website authenticity, or download unverified applications, thereby exposing themselves to technology-related crimes.
  • Fifth, although a legal framework exists, there remain gaps in enforcement. Despite the issuance of various regulations on personal data protection in Viet Nam, supervision and settlements of violations still face challenges. Many data infringements are not detected in a timely manner or are not handled with sufficient deterrent effect.

From the above realities, it can be seen that data protection in online transactions remains a major challenge, requiring coordinated efforts among enterprises, users, and regulatory authorities to build a safe, transparent, and sustainable digital transaction environment.

II. Understanding of data protection in online transactions 

1. What is data protection in online transactions?

Data protection in online transactions refers to a set of legal, technical, and managerial measures aimed at ensuring the safety of users’ personal data when participating in transactions conducted in the digital environment.

Such data protection includes:

  • Controlling the collection, processing, and storage of data;
  • Ensuring transparency in the use of information;
  • Preventing unauthorized access, data leakage or misuse;
  • Respecting users’ privacy throughout the transaction process.

Such a concept is closely associated with fundamental principles such as security, integrity, transparency, and accountability.

2. Who is the data subject in online transactions?

In online transactions, the data subject is the individual whose information is collected or processed through activities such as:

  • Registering an account;
  • Purchasing goods or making online payments;
  • Using applications, websites, e-wallets, or social networks;
  • Providing information for delivery, receiving OTP codes, or verifying identity.

The data subject is the party directly affected when data is excessively collected, misused, or leaked; therefore, the law designates the data subject as the centre of data protection mechanisms.

3. What role does data protection in online transactions play in safeguarding customer privacy?

Data protection in online transactions plays a particularly important role in protecting customer privacy by:

  • Safeguarding personal information, and reducing the risk of exposure of passwords, payment information, identities, or consumption behaviors;
  • Enhancing customers’ rights in controlling their information, including the rights to consent, refuse, or request correction or deletion of data;
  • Preventing the misuse of data for spam, fraud, behavioral tracking, or unlawful commercial purposes;
  • Building trust in transactions, enabling customers to confidently use online services and promoting the sustainable development of e-commerce;
  • Protecting privacy as a fundamental personal right recognized and safeguarded under both national and international law.

Accordingly, data protection in online transactions is not merely a technical requirement or a legal formality, but a critical foundation for safeguarding privacy rights, maintaining customer trust, and ensuring a safe and transparent digital transaction environment.

III. Legal regulations related to data protection in online transactions

As electronic transactions become increasingly prevalent, both Vietnamese and international laws impose stringent requirements to ensure that users’ data is not infringed upon, unlawfully exploited, or misused. These regulations establish a mandatory legal framework that enterprises must comply with when collecting, processing, and storing personal data in the online market. 

1. What technical measures are included in data protection for online transactions?

Pursuant to Clause 2 Article 34 of the Law on Personal Data Protection 2025, technical standards on personal data protection include standards applicable to information systems, hardware, software, management, operation, processing, and protection of personal data, which are developed, promulgated, and applied in Viet Nam.

Accordingly, technical measures commonly recommended or required by law and cybersecurity standards include:

  • Data encryption, ensuring that stolen data cannot be read or exploited;
  • Firewalls and intrusion prevention/detection systems (IPS/IDS) to control abnormal access;
  • Multi-factor authentication (MFA) to enhance account security in online transactions;
  • Security monitoring to track and promptly detect unauthorized behaviours;
  • Data backup and disaster recovery to ensure the system continuously operates in cases of incidents.

These measures form the foundation for minimizing cyberattack risks and information theft in electronic transactions.

2. What security measures must enterprises implement to comply with online data protection regulations?

To comply with online data protection requirements, enterprises should pay attention to the following security measures:

Pursuant to Clause 2 Article 387 of the Civil Code 2015, where one party receives confidential information of the other party during the contract formation, it is obligated to keep such information confidential and must not use such information for its own purposes or for any other unlawful purposes.

Under the Law on Cyberinformation Security 2015, Article 46 provides that enterprises trading in cyberinformation security products and services must establish, retain, and protect customer information.

Under the Law on Personal Data Protection 2025, Article 29 stipulates that organizations and individuals providing social networking services and online communication services are responsible for clearly notifying the categories of personal data collected when data subjects install and use such services; refraining from unlawful data collection or collection beyond the agreed scope; publicly disclosing privacy policies and clearly explaining data collection, usage, and sharing practices; providing users with mechanisms to access, correct, delete data, and configure privacy settings; reporting security and privacy violations; protecting Vietnamese citizens’ personal data in cross-border data transfers; and establishing prompt and effective procedures for handling personal data protection violations.

These obligations require enterprises to adopt the proactive prevention approach rather than merely reacting after incidents occur.

3. How long may online transaction data be stored under the law?

Pursuant to Clause 3 Article 3 of the Law on Personal Data Protection 2025, personal data shall be stored for a period appropriate to the purpose of personal data processing, unless otherwise prescribed by law.

Storing data beyond the necessary period or without appropriate security measures may result in legal liability for enterprises.

4. How does Vietnamese law regulate data protection in online transactions?

Under Article 29 of the Law on Personal Data Protection 2025, organizations and individuals take the following responsibilities in protecting data in online transactions:

  • Clearly notifying the categories of personal data collected when data subjects install and use social networking or online communication services, and refraining from unlawful collection or collection beyond the agreed scope;
  • Not requiring the provision of images or videos containing full or partial identity documents as an account authentication factor;
  • Providing options allowing users to refuse the collection and sharing of data files (cookies);
  • Providing a “do not track” option, or only track usage activities with the user’s consent;
  • Not eavesdropping, recording calls, or reading text messages without the data subject’s consent, unless otherwise prescribed by law;
  • Publicly disclosing privacy policies, clearly explaining data collection, usage, and sharing practices, providing users with mechanisms to access, correct, and delete data and configure privacy settings, reporting security and privacy violations, protecting Vietnamese citizens’ personal data in cross-border transfers, and establishing prompt and effective procedures for handling data protection violations.

These provisions aim to establish a transparent and secure online transaction environment, enhance user trust, and protect users against increasingly complex risks.

IV. Questions regarding data protection in online transactions

1. Are enterprises required to report data breaches when online transaction data protection is compromised?

Pursuant to Clause 1 Article 23 of the Law on Personal Data Protection 2025 regarding obligations on notifying data breaches: 

  • Personal data controllers, personal data controllers and processors, and third parties that detect violations of personal data protection regulations which may cause harm to national defense, national security, social order and safety, or infringe upon the life, health, honor, dignity, or property of data subjects must notify the competent personal data protection authority within 72 hours from the time the violation is detected.
  • If a personal data processor detects a violation, it must promptly notify the personal data controller or the personal data controller and processor.

Accordingly, enterprises are obligated to make timely notifications when data protection in online transactions is compromised and to coordinate with relevant parties and competent authorities to address incidents, minimize damage to data subjects, and ensure legal compliance.

2. What international standards are applied to data protection in online transactions?

Main international standards commonly applied to data protection in online transactions include:

  • ISO/IEC 27001 – Standard for information security management systems;
  • ISO/IEC 27002 – Rules of practice for information security;
  • PCI DSS (Payment Card Industry Data Security Standard) – International security standard for payment data by card;
  • OWASP Top 10 – Framework for preventing security risks in web application development.

Applying these standards helps enterprises comply with the law, enhance customer trust, and reduce the risk of cyberattacks.

3. Does data protection in online transactions apply to payment data and credit card information?

It is one of the most sensitive categories of data and is subject to strict legal protection. Under Article 27 of the Law on Personal Data Protection 2025, organizations and individuals operating in finance, banking, and credit information activities are responsible for:

  • Fully complying with regulations on the protection of sensitive personal data and applicable security standards in financial and banking activities;
  • Not using a data subject’s credit information for credit scoring, ranking, or creditworthiness assessment without the data subject’s consent;
  • Collecting only personal data necessary for credit information activities from sources compliant with this Law and other relevant legal regulations;
  • Notifying data subjects in cases of leakage or loss of banking, financial, or credit information.

Therefore, any online transaction involving payments must apply enhanced data protection standards.

4. What technical tools can help enterprises enhance data protection in online transactions?

Enterprises may deploy various technical tools to enhance data protection in online transactions, including:

  • SSL/TLS encryption systems for websites;
  • Vulnerability assessment (VA) and penetration testing (Pentest) services;
  • Security information and event management (SIEM) systems with early incident alerts;
  • Anti-malware and anti-DDoS solutions;
  • PCI tokenization technology to replace actual card information with encrypted tokens.

These tools help minimize cyberattack risks and support enterprises in meeting legal requirements.

5. Can customers file complaints if enterprises fail to protect data in online transactions?

Pursuant to Point d Clause 1 Article 4 of the Law on Personal Data Protection 2025, the right to file complaints is one of the rights of data subjects. Accordingly, customers may file complaints directly with enterprises and request explanations regarding data collection and processing practices. In addition, complaints may be submitted to competent authorities such as the Ministry of Industry and Trade, the Ministry of Public Security, or consumer protection organizations.

V. Why seek legal advice from NPLaw for issues related to data protection in online transactions

NPLaw possesses a team of lawyers with in-depth expertise in personal data protection law, e-commerce, and cybersecurity, assisting enterprises in:

  • Assessing risks and establishing legal compliance processes;
  • Handling data incidents and liaising with competent authorities;
  • Advising on privacy policies, terms of use, and online transaction frameworks.

Through such support, enterprises can mitigate legal liabilities, enhance credibility, and ensure the security of customers’ data.

The above information is provided for reference purposes only. For detailed advice on specific cases, clients are kindly requested to contact NPLaw for prompt consultation.

NGOC PHU LAW COMPANY LIMITED
Phone Hotline 1: 0913449968 Hotline 2: 0913419996

Related services

Opening an english language center

  In the era of economic integration, increasing globalization, and the c...

Issues related to loan agreements

Currently, many Clients are interested in issues related to loan agreements. Und...

Law on bidding and things needing to be understand

  Currently, the sane competition of businesses has strongly contributed...

The regulations for the commercial arbitration award in vietnam

According to the general principle, a judgment (arbitral award or arbitration aw...

The franchising agreement according to the law in vietnam

Along with the current economic development, commercial businesses and franchisi...

Regulations for a false advertisement

An advertisement has an important role and a significant meaning for giving deve...

Fraudulent behaviors of renting at high prices in vietnam

Rent is always an essential choice and demand for almost all students coming to...

The regulations for the commercial arbitration center

When arising dispute issues, the parties will always seek and require competent...

WhatsApp WeChat Zalo hotline 0913449968 hotline
0
Bạn đang quan tâm đến

Chúng tôi sẵn sàng tư vấn miễn phí cho bạn!

Tư vấn điện thoại Zalo Tư vấn qua Zalo