During mergers, demergers, acquisitions, and other restructuring transactions, data transfer in corporate restructuring constitutes a significant legal issue that may lead to substantial risks if personal data protection regulations are not properly observed. Compliance with applicable laws enables enterprises to minimize disputes and safeguard the legitimate interests of all relevant parties.

I. Current situation relating to data transfer in corporate restructuring

In recent years, corporate restructuring activities, including mergers, consolidations, demergers, and acquisitions, have become increasingly common, resulting in a growing need for data transfer in the context of corporate restructuring.

However, many enterprises have yet to fully recognize their legal obligations when transferring data, particularly personal data relating to customers and employees. In practice, numerous data transfers have been conducted without sufficient transparency or appropriate security mechanisms, leading to disputes, complaints, or potential sanctions under personal data protection laws.

II. Concept of data transfer in corporate restructuring

1. What is data transfer in the context of corporate restructuring?

Data transfer in corporate restructuring refers to the transfer by an enterprise of all or part of the data under its management to another enterprise in the course of a merger, consolidation, division, demerger, conversion of enterprise type, or business acquisition. The transferred data may include customer data, employee data, partner information, accounting and financial data, operational data, and other digital information generated during business operations. Such transfer must comply with all applicable legal regulations.

2. Is data transfer in the context of corporate restructuring subject to personal data protection laws?

Data transfer in the context of corporate restructuring remains subject to personal data protection laws if the transferred data contains personal data of customers, employees, business partners, or other relevant individuals.

Pursuant to Clause 6 Article 2 of the Personal Data Protection Law 2025, personal data processing means one or more activities affecting personal data, including collection, recording, storage, modification, sharing, provision, transfer, deletion, and destruction of personal data. Accordingly, the transfer of data during mergers, consolidations, divisions, demergers, conversions of enterprise type, or business acquisitions constitutes personal data processing under applicable law.

Pursuant to Article 3 of the Personal Data Protection Law 2025, the transfer of personal data in the context of corporate restructuring must comply with the principles of personal data protection, including: compliance with the law; processing data within a specific and legitimate scope and purpose; ensuring accuracy and appropriate retention periods; implementing security and data protection measures; proactively preventing and handling violations; and maintaining a balance between personal data protection and the lawful rights and interests of relevant parties.

Furthermore, pursuant to Clause 1 Article 4 of the Personal Data Protection Law 2025, data subjects continue to enjoy all rights relating to their personal data, including the right to be informed, the right to consent, the right of access, the right to rectify data, and the right to request deletion of data, even where the enterprise undergoes restructuring.

3. Common disputes relating to data transfer in current corporate restructuring

During the transfer of data in corporate restructuring, the following legal disputes commonly arise:

  • Disputes concerning control rights and the scope of data use, where the data recipient exploits data beyond the agreed scope or continues using the data after completion of the restructuring transaction, potentially leading to liability under Articles 351 and 584 of the Civil Code 2015.
  • Disputes arising from the transfer of personal data without a valid legal basis, particularly where the consent of the data subject has not been obtained, in violation of Point b Clause 1 Article 4 and Article 9 of the Personal Data Protection Law 2025.
  • Disputes relating to confidentiality obligations and data breaches occurring during the transfer process, resulting in liability for damages under Article 584 of the Civil Code 2015.
  • Disputes arising from the use of data for purposes inconsistent with those originally specified following restructuring, thereby violating the personal data processing principles set out in Article 3 of the Personal Data Protection Law 2025.

III. Legal regulations relating to data transfer in corporate restructuring

1. What personal data protection principles must be observed when transferring data in corporate restructuring?

  • Compliance with Law: The transfer of personal data may only be implemented in accordance with the Constitution, the Personal Data Protection Law 2025, and other applicable legal regulations.
  • Purpose limitation and scope restriction: Personal data may only be collected, processed, and transferred to the extent necessary for a specific, clear, and lawful purpose associated with the restructuring process.
  • Accuracy and appropriate retention period: Personal data must be updated and corrected when necessary and retained only for a period appropriate to the purpose of processing, unless otherwise required by law.
  • Implementation of comprehensive protection measures: Enterprises must effectively implement organizational, technical, and personnel measures to protect personal data throughout the transfer process.
  • Proactive prevention and handling of violations: Enterprises must promptly detect, prevent, and address violations of personal data protection laws.
  • Balancing interests: The protection of personal data must be harmonized with national interests, socio-economic development objectives, and the lawful rights and interests of relevant stakeholders.

2. What documentation should an enterprise prepare before transferring data in a corporate restructuring transaction?

  • Corporate restructuring documents: Resolutions, decisions, or agreements concerning mergers, consolidations, divisions, demergers, conversions of enterprise type, or business acquisitions. These documents serve as the basis for determining the scope and purpose of the data transfer.
  • Data inventory and classification records: A detailed inventory of the data intended to be transferred, clearly categorizing personal data, sensitive personal data, and non-personal data to facilitate the implementation of appropriate protection measures.
  • Documents evidencing the legal basis for personal data processing: Documents evidencing the lawful consent of data subjects or the legal grounds permitting processing without consent under Clause 3 Article 9 of the Personal Data Protection Law 2025 (as guided by Article 6 of Decree No. 356/2025/ND-CP).
  • Data processing impact assessment (DPIA) documents: If the proposed transfer falls within cases requiring a data processing impact assessment, the enterprise must prepare and retain a Data Processing Impact Assessment dossier in accordance with Article 22 of the Personal Data Protection Law 2025 (as guided by Article 20 of Decree No. 356/2025/ND-CP).
  • Data transfer and confidentiality agreements: Contracts or binding agreements between the transferring enterprise and the receiving enterprise specifying the purpose and scope of use, security measures, retention periods, and liabilities arising from violations.

3. Does data transfer in a corporate restructuring transaction alter the rights and obligations of data subjects?

Pursuant to Clauses 1 and 2 Article 4 of the Personal Data Protection Law 2025, even if personal data is transferred to a new entity as part of a restructuring transaction, data subjects continue to enjoy all statutory rights, including the right to be informed of data processing activities; the right to consent and withdraw consent; the right to access, rectify, request provision of, delete, or restrict the processing of data; the right to object to data processing; the right to file complaints, denunciations, lawsuits, and claims for damages; and the right to request the implementation of personal data protection measures.

At the same time, the obligations of data subjects remain unchanged, including the obligation to protect their own personal data, respect and protect the personal data of others, provide complete and accurate information as required by law, and comply with personal data protection regulations.

4. What mechanisms apply to disputes arising from data transfers in corporate restructuring?

Disputes arising from data transfers in the context of corporate restructuring may be resolved through the following mechanisms:

  • Resolution in accordance with contractual agreements: Pursuant to Article 385 and Point g Clause 2 Article 398 of the Civil Code 2015, parties are free to agree upon contractual terms, including rights, obligations, and dispute resolution mechanisms relating to data transfers. Accordingly, disputes should first be resolved in accordance with the provisions of the data transfer agreement or restructuring agreement.
  • Negotiation, mediation, arbitration, or court proceedings: Where no agreement can be reached, disputes may be resolved through negotiation, mediation, arbitration, or litigation before a competent court under Article 317 of the Commercial Law 2005, depending on the nature of the dispute and the parties’ choice of dispute resolution mechanism.
  • Complaints and denunciations to competent authorities: Data subjects have the right to file complaints or denunciations where their data-related rights are infringed under Point đ Clause 1 Article 4 of the Personal Data Protection Law 2025. The specialized personal data protection authority shall receive and handle such matters within its jurisdiction.
  • Administrative sanctions or criminal liability: If violations of personal data protection laws occur, the responsible organizations or individuals may be subject to administrative sanctions or criminal liability and may also be required to compensate affected parties for damages under Article 8 of the Personal Data Protection Law 2025.

IV. Questions relating to data transfer in corporate restructuring

1. If an enterprise refuses to transfer data during a corporate restructuring transaction, does such refusal constitute a violation of law?

An enterprise’s refusal to transfer data during a corporate restructuring transaction will only be deemed unlawful where such refusal is contrary to a legal obligation or contractual commitment. Specifically:

- Circumstances where no violation occurs

An enterprise has the right to refuse to transfer data where:

  • The proposed transfer lacks a valid legal basis or does not satisfy the conditions for personal data processing under Point b Clause 1 Article 4 of the Personal Data Protection Law 2025;
  • The transfer may infringe upon the lawful rights and interests of data subjects under Clause 1 Article 4 of the Personal Data Protection Law 2025;
  • The data subject has not consented to the transfer and the transfer does not fall within any circumstance permitting data processing without consent under Article 19 of the Personal Data Protection Law 2025.

- Circumstances where a violation may arise

A refusal to transfer data may be considered unlawful where:

  • The enterprise is contractually obligated to transfer the data but refuses to do so, thereby breaching its obligations under Article 351 of the Civil Code 2015;
  • The refusal obstructs the implementation of a corporate restructuring transaction as prescribed by law and causes damage to the other party.

2. Is data transfer during mergers and acquisitions considered a form of corporate restructuring?

Data transfer during mergers and acquisitions constitutes a component of corporate restructuring because it results in changes to the entity responsible for managing, controlling, and succeeding to the rights and obligations associated with the enterprise. Pursuant to the Enterprise Law 2020 (as amended and supplemented in 2025):

  • Article 198 - Division of enterprises: The enterprises resulting from a division or demerger succeed to the rights and obligations prescribed in the division or demerger plan, including data necessary for business operations.
  • Article 199 - Merger of enterprises: The acquiring company succeeds to all lawful rights and obligations of the merged company.
  • Article 200 - Consolidation of enterprises: The consolidated company succeeds to all rights and obligations of the consolidating companies.
  • Article 205 - Transfer of Sole Proprietorships: The transferee succeeds to all rights and obligations of the transferred sole proprietorship.

Data transfer in mergers and acquisitions is regarded as a form of corporate restructuring. Nevertheless, the recipient enterprise remains obligated to comply fully with personal data protection requirements and all other applicable legal regulations.

3. May an enterprise authorize a third party to conduct data transfers during a corporate restructuring transaction?

Pursuant to Point d Clause 1 Article 17 of the Personal Data Protection Law 2025, a personal data controller or a personal data controller and processor may transfer personal data to a personal data processor or another third party for processing activities in accordance with applicable law.

However, such delegation does not transfer legal responsibility. Pursuant to Article 37 of the Personal Data Protection Law 2025, the data controller remains responsible for ensuring the rights of data subjects and the security of personal data throughout the period during which the third party conducts the transfer and processing activities.

4. Is data encryption mandatory when transferring data during a corporate restructuring transaction?

Data encryption is not mandatory in all circumstances. Pursuant to Article 12 of the Personal Data Protection Law 2025, the obligation to encrypt data is determined as follows:

  • Clause 2 Article 12: Personal data classified as state secrets must be encrypted and decrypted in accordance with laws governing the protection of state secrets and cryptography regulations.
  • Clause 3 Article 12: For other categories of personal data, organizations and individuals may determine whether encryption and decryption measures are appropriate for their data processing activities.

V. Why should you seek legal advice from NPLaw regarding data transfers in corporate restructuring?

When implementing or addressing issues arising from data transfers in the context of corporate restructuring, obtaining timely legal advice from NPLaw’s lawyers can assist enterprises in:

  • Accurately assessing the legal framework governing data transfers under applicable personal data protection, information security, and corporate laws.
  • Clearly identifying the rights, obligations, and legal responsibilities of the transferring enterprise, the receiving enterprise, and data subjects throughout the restructuring process.
  • Reviewing merger agreements, acquisition agreements, and related documentation to identify legal risks, inappropriate provisions, or potential violations of data protection regulations.
  • Developing lawful data transfer strategies and obtaining advice regarding notification mechanisms, consent requirements, and dispute resolution involving data subjects or business partners.
  • Minimizing legal risks, avoiding administrative sanctions and legal liability, and reducing the time and costs associated with corporate restructuring.

The information provided above is for reference purposes only. Should you require detailed advice regarding a specific situation, please contact NPLaw for prompt, accurate, and practical legal assistance tailored to your business needs.