The protection of customer information and data is a crucial factor in safeguarding privacy and consumer interests. In the digital era, ensuring data security helps prevent risks of loss and leakage of personal information. Accordingly, legal regulations on information security are increasingly refined to build trust and promote sustainable development. In the below article, NPLaw invites readers to explore legal issues relating to information and data protection of customers.

I. Current status of information and data protection of customers 

The current state of customer information and data protection remains inadequate and concerning. Although Vietnamese law provides regulations for the protection of personal data, in practice, many enterprises fail to comply fully or lack effective information security systems.

Customer data collection is widespread, many organizations fail to clearly notify customers of the intended purpose of use, nor do they adopt adequate technical and organizational measures to ensure data security. Cases of leakage, trade, and unauthorized use of personal information are increasing, particularly in areas such as e-commerce, finance–banking, and online services. The main causes are limited corporate awareness, insufficient investment in technological infrastructure, and enforcement measures that lack deterrent effect.

II. Legal provisions relating to information and data protection of customers

1. Responsibility for information and data protection of customers

According to Article 15 of the Law on Consumer Protection 2023, enterprises are responsible for protecting customer information and data as follows:

  • Whether directly or through other organizations, when enterprises collect, store, use, modify, update, or delete personal information, they must ensure data security and strictly comply with legal requirements;
  • If enterprises authorize or hire other parties to process customer information, the transfer of data must be subject to the consumer’s consent. Such authorization or engagement must be made in writing, clearly stipulating the permitted scope of data processing, the responsibilities of each party in safeguarding consumer data, and compliance with all relevant legal regulations;
  • When consumers conduct transactions via an intermediary or a third-party platform, such a third party is equally responsible for ensuring information security in accordance with the law.

2. Establishment of information and data protection policies of customers 

When collecting, storing, and using information of customers, enterprises are required to set up information protection policies as a legal compliance measure and to safeguard consumer rights. Under Article 16 of the Law on Consumer Protection 2023, enterprises must specify the following:

  • Purpose of information collection;
  • Scope of information use;
  • Duration of information storage;
  • Measures for protecting information.

These policies must be made publicly and transparently available, either by posting at the enterprise’s office or transaction locations in easily visible places, or by publishing them on websites, mobile applications, or other electronic platforms used for consumer interaction. 

3. Essential contents of an information and data protection commitment

Currently, there is no specific statutory template for an information protection commitment between enterprises and customers. However, to ensure legal safety and demonstrate enterprise accountability in protecting personal information, a commitment should generally include the following:

  • Information of the parties;
  • Scope of protected information;
  • Purpose of collection and use;
  • Enterprise’s confidentiality obligations;
  • Duration of data storage;
  • Handling measures in case of breach, including liability for damages if any;
  • Validity of the commitment;
  • Signatures of the parties.

III. Questions on information and data protection of customers 

1. What are the sanctions for violations of customer information and data protection?

Pursuant to Article 46 of Decree No. 98/2020/NĐ-CP, violations of information and data protection of customers are subject to fines ranging from 10,000,000 VND to 20,000,000 VND for acts such as:

  • Failure to clearly notify consumers of the purpose of data collection and use;
  • Use of information for purposes other than those consented to by consumers;
  • Failure to ensure safety, accuracy, and completeness when collecting, using, or transferring data;
  • Failure to allow consumers to correct errors in their information;
  • Transfer of data to third parties without consumer consent (except as permitted by law).
  • Furthermore, if the violated information constitutes personal secrets (e.g., financial, health, or ID information), the fine is doubled, ranging from 20,000,000 VND to 40,000,000 VND.

2. What is the most important content of a data protection commitment, and why?

The most critical elements of a data protection commitment are the scope of protected information and the purpose of collection and use. These provisions define which categories of personal data are collected, processed, and protected, and clarify why the enterprise requires such information.

Clear definition of scope and purpose enables consumers to understand their rights and how their information will be used, preventing misuse or unauthorized disclosure. It also serves as the legal basis for determining enterprise liability in case of a breach.

3. Is it necessary to notify consumers when collecting their information and data?

According to Article 17 of the Law on Consumer Protection 2023, enterprises must strictly comply with the following when collecting and using customer information:

  • Prior to collection, enterprises must clearly and publicly notify consumers of the purpose, scope, and duration of information storage;
  • Enterprises must establish a clear mechanism for consumers to choose what information they agree to provide, and to explicitly indicate their consent or refusal for each item;
  • Notification and consent are not required if the information has already been publicly disclosed by the consumer (e.g., on social media), or in specific cases provided by law.

Therefore, when collecting customer data, enterprises are obligated to provide transparent and public notification regarding the relevant aspects of collection and use.

4. What regulations must enterprises comply with regarding customer information and data protection?

Under Articles 15 and 17 of the Law on Consumer Protection 2023, enterprises collecting and using customer information must comply with:

  • Ensuring security and safety of consumer information, including when authorizing or outsourcing to third parties, in strict accordance with the law;
  • Authorizing or outsourcing data processing only with consumer consent, and such authorization must be documented, defining the scope and responsibilities of the parties;
  • Establishing explicit mechanisms for consumers to choose whether to consent to the sharing of personal information;
  • Providing consumers with clear notification of the purpose, scope, use, and storage period of information prior to collection, and obtaining consent, except for special statutory exceptions;
  • Third parties involved in transactions are also responsible for protecting customer information in compliance with the law.

5. What are the legal consequences of customer data leakage? 

Customer data leakage can result in serious legal consequences for enterprises. Companies may take administrative sanctions for violating regulations on the collection, use, and protection of consumer information, as stipulated in Article 46 of Decree No. 98/2020/NĐ-CP.

If the leaked data constitutes personal secrets, sanctions may be doubled.

6. What should enterprises do when a confidential breach for customer data occurs?

When a breach of customer data protection occurs, enterprises should:

  • Enterprises promptly detect and assess: Determining the scope, severity, and type of data affected;
  • Enterprises must prevent and control: Applying technical measures to stop further leakage or intrusion and secure systems;
  • Enterprises notify promptly: Informing relevant departments, affected customers, and regulatory authorities as required by law;
  • Enterprises need to investigate and remedy: Identifying the root cause and implement corrective measures to prevent recurrence;
  • Enterprises must support customers: Providing guidance, protective services, or compensation if necessary to mitigate harm;
  • Enterprises have to review and strengthen security: Updating security policies, improve procedures, and train staff for enhanced future prevention.

IV. Legal advisory services on information and data protection of customers 

The above article is provided by NPLaw regarding information and data protection of customers. With a team of experienced lawyers and legal experts, NPLaw is always ready to accompany, advise, and support clients on legal matters concerning information and data protection. For legal support, please contact NPLaw.