In the context of digital transformation and increasingly extensive data utilization, transferring data to internal partners has become a common business activity within enterprises. However, if not strictly controlled and performed in compliance with legal regulations, such transfers may involve significant risks relating to confidentiality, legal liability, and data privacy rights. The following article clarifies the core legal issues that enterprises should pay attention to when conducting internal data transfers.

I. Current situation relating to data transfer to internal partners

In practice, many enterprises regularly transfer data to internal partners such as affiliated companies, branches, or specialized departments for management, operational, and business purposes. It helps improve interconnectivity and enhances the efficiency of data utilization.

However, many enterprises have not yet established comprehensive internal data transfer procedures, lacking approval mechanisms, access authorization systems, and appropriate security measures. Data transfers are often conducted merely for convenience rather than being linked to legal risk control, thereby creating potential risks of information leakage, violations of data protection regulations, and adverse impacts on the lawful rights and interests of the enterprise.

II. Concept of data transfer to internal partners

1. What is data transfer to internal partners?

Data transfer to internal partners refers to the act of an enterprise sharing, providing, or allowing units, departments, or organizations having an internal relationship to access to data under its management for the purpose of management, administration, production, business operations, or service provision.

Such transfer may be performed in various forms, including transferring electronic data, granting system access rights, conducting database synchronization, or exploiting shared data, provided that it aligns with the intended purpose of use, is conducted within proper authority, and complies with legal regulations on data protection.

2. Who is considered an internal partner in the process of data transfer?

In the process of transferring data to internal partners, an internal partner is generally understood as an organization, unit, or individual having a subordinate, affiliated, or lawfully authorized relationship within the same enterprise system. Specifically, it may include:

  • Parent companies, subsidiaries, and affiliated companies within the same corporate group or business group;
  • Branches, representative offices, and dependent units of the enterprise;
  • Internal departments, divisions, or functional units responsible for data exploitation and processing;
  • Individuals or units authorized in writing by the enterprise to perform specific tasks associated with the intended use of data.

3. When is data considered lawfully transferred to internal partners?

Personal data is considered lawfully transferred to internal partners when all of the following conditions under the Law on Personal Data Protection 2025 are simultaneously satisfied:

  • It falls within cases permitted by law: The sharing of personal data among departments, units, and internal partners within the same agency or organization for the continued processing of data consistent with the established processing purpose falls under Point b, Clause 1, Article 17.
  • There is a lawful basis for data processing: The transfer is conducted based on the consent of the data subject or falls under cases where data processing does not require consent under Articles 9 and 19 of this Law.
  • Compliance with personal data protection principles: The transfer activity ensures proper purpose, proper scope, safety, security, and appropriate storage duration under Article 3.
  • It does not change the rights and obligations of the data subject: Internal transfer must not restrict or deprive the personal data subject of their rights under Article 4 of this Law.

III. Legal regulations related to data transfer to internal partners

1. Scope of data permitted to be transferred to internal partners

Pursuant to the Law on Personal Data Protection 2025, the scope of personal data permitted to be transferred to internal partners must be strictly determined based on the processing purpose and personal data protection principles, specifically as follows:

  • Limited only to the necessary scope: Personal data transferred to internal partners must include only data necessary for implementing the established processing purpose and must not be arbitrarily expanded. Such a principle is provided in Clause 2, Article 3.
  • Consistent with the determined processing purpose: The scope of transferred data must align with the purpose of personal data processing that the enterprise has notified, agreed upon, or registered; data must not be used for other purposes without a valid legal basis under Clause 2, Article 3 and Article 17 of this Law.
  • No infringement of data subject rights: Determining the scope of transferred data must not infringe upon or limit the rights of personal data subjects as prescribed in Clause 1, Article 4.
  • Ensuring data safety and security: Within the scope of transferred data, enterprises must apply appropriate protective measures to prevent leakage, loss, or unauthorized access under Clause 4, Article 3.

Accordingly, enterprises may only transfer to internal partners:

  • Data directly serving declared management, operational, or restructuring purposes;
  • Data not exceeding the necessary scope for the functions and duties of the receiving unit;
  • Sensitive personal data only when stricter legal conditions are satisfied.

2. Responsibilities of the data recipient during the process of transferring data to internal partners

Pursuant to Article 37 of the Law on Personal Data Protection 2025, when receiving personal data from internal partners, the data recipient (being either a personal data processor or a personal data controller and processor) has the following principal legal responsibilities:

  • Receiving data only when there is a lawful basis: Personal data may only be received when there is an agreement or data processing contract with the data controller or the data controller and processor (Point a, Clause 2, Article 37).
  • Processing data for the proper purpose and in accordance with the agreement: The recipient must process personal data strictly in accordance with the content, scope, and purpose established in the agreement/contract and must not use the data unlawfully (Point b, Clause 2, Article 37).
  • Applying full personal data protection measures: The recipient is responsible for implementing appropriate technical and management measures to ensure the safety and security of personal data throughout the receiving and processing stages (Point c, Clause 2, Article 37).
  • Preventing and mitigating violations: Proactively preventing the unlawful collection, access, and use of personal data from systems, equipment, and services under its management (Point đ, Clause 2, Article 37).
  • Cooperating with competent authorities: Coordinating with the Ministry of Public Security and competent state authorities in personal data protection and handling legal violations (Point e, Clause 2, Article 37).
  • Taking liability for arising damages: Being liable to the data controller or the data controller and processor for damages caused during the personal data processing process and potentially incurring legal liability under Article 8 of the Law on Personal Data Protection 2025.

3. What internal approval procedures must be implemented before transferring data to internal partners?

Pursuant to the Law on Personal Data Protection 2025, before transferring personal data to internal partners, enterprises must establish and implement at least the following internal approval steps to ensure legality and safety:

  • Determining the legal basis for data transfer: Clarifying whether the transfer falls within the permitted cases under Article 17 (internal sharing, restructuring, consent of the data subject, etc.) and whether there is a lawful basis for processing under Article 9 or Article 19.
  • Reviewing the purpose and scope of transferred data: Assessing whether the proposed transferred data is consistent with the established processing purpose, limited to the necessary scope, and compliant with the principle under Clause 2, Article 3.
  • Assessing risks and data protection measures: Identifying the risk level of the data (especially sensitive data) and selecting appropriate security measures (encryption, access authorization, etc.) under Clause 4, Article 3 and Article 12.
  • Determining the role and responsibilities of the data recipient: Clearly defining whether the recipient is a data processor or a data controller and processor, along with corresponding responsibilities under Article 37.
  • Written approval and record retention: The transfer must be approved in writing internally; where required, a personal data processing impact assessment dossier must be prepared and retained under Articles 21 and 22.

4. Who within the enterprise has the right to access data when transferring it to internal partners?

Pursuant to the Law on Personal Data Protection 2025, the right to access personal data during transfer to internal partners does not apply universally, but is limited to the following entities:

  • Personal data controller: The department/individual deciding the purposes and means of data processing has the right to access data for lawful transfer purposes (Clause 7, Article 2; Point b, Clause 1, Article 37).
  • Personal data controller and processor: Where the enterprise directly both determines the purpose and processes the data, only the assigned department has access rights (Clause 9, Article 2; Clause 3, Article 37).
  • Personal data processor (internal partner): It may only access data after a data processing agreement or contract has been established and only within the assigned scope and proper processing purpose (Points a and b, Clause 2, Article 37).
  • Lawfully authorized individuals and departments: Employees or internal departments clearly assigned and authorized under internal regulations, directly serving data processing and transfer activities (Clause 4, Article 3; Article 18).

The following are not permitted to access data:

  • Individuals or departments unrelated to the data processing purpose;
  • Access exceeding the approved scope or purpose;
  • Unauthorized access without lawful authorization (Article 7).

IV. Questions related to data transfer to internal partners

1. How can access to data be controlled when transferring data to internal partners?

Pursuant to Clause 4, Article 3 of the Personal Data Protection Law 2025, controlling data access when transferring data to internal partners must be conducted through the following measures:

  • Establishing an internal access authorization mechanism: The enterprise shall only allow individuals or departments whose functions and duties are relevant to the purpose of data processing to access personal data.
  • Applying managerial and technical access control measures: Implementing solutions such as system authorization, user authentication, and access scope limitations to ensure data security during the transfer process.
  • Organizing supervision and prevention of unauthorized access: Proactively preventing, detecting, and promptly stopping acts of accessing or using personal data without proper authority.

2. Can aggregated data or anonymized data be used instead of original data when transferring to internal partners?

Pursuant to Clause 1, Article 2 of the Personal Data Protection Law 2025, personal data that has been de-identified and can no longer identify or help identify a specific individual shall no longer be considered personal data.

Accordingly, when transferring data to internal partners, enterprises are permitted and encouraged to use:

  • Aggregated data; or
  • De-identified (anonymized) data

Enterprises should prioritize the use of aggregated data or anonymized data when transferring to internal partners in order to minimize risks and ensure compliance with personal data protection laws.

3. How can data security be ensured during the transfer of data to internal partners?

Pursuant to Clause 4, Article 3 of the Personal Data Protection Law 2025, ensuring data security during the transfer of data to internal partners must be implemented through the coordinated application of institutional, technical, and human measures, specifically:

  • Establishing internal regulations and procedures on data protection to strictly control the transfer and use of personal data;
  • Applying appropriate technical measures such as access control, authorization, and system security to prevent data leakage or loss;
  • Clearly defining responsibilities of relevant individuals and departments, ensuring that data is only processed for the correct purpose and within proper authority.

Ensuring data security when transferring data to internal partners is a mandatory legal obligation and must be conducted through the synchronized implementation of data protection measures under Clause 4, Article 3 of the Personal Data Protection Law 2025.

4. Can an enterprise both retain data for internal use and transfer it to internal partners?

Pursuant to Clause 2, Article 3 of the Personal Data Protection Law 2025, personal data may continue to be processed, stored, and transferred simultaneously, provided that such processing and transfer are conducted within the proper scope, for the correct purpose already established, and in compliance with legal regulations.

Accordingly, an enterprise may both retain data for internal operations and transfer such data to internal partners if:

  • The storage and transfer serve the same lawful data processing purpose;
  • The data is not used for other purposes without an appropriate legal basis.

5. Should internal confidentiality agreements be signed when transferring data to internal partners?

Pursuant to Point a, Clause 1, Article 37 of the Personal Data Protection Law 2025, the personal data controller is responsible for clearly specifying the responsibilities, rights, and obligations of the parties in agreements or contracts related to personal data processing.

Accordingly, when transferring data to internal partners, enterprises should execute internal confidentiality agreements or data processing agreements, clearly defining:

  • The scope of data that may be accessed and processed;
  • Confidentiality obligations and personal data protection responsibilities;
  • Legal liabilities in the event of violations.

V. Why should you seek legal advice from NPLaw regarding issues related to data transfer to internal partners

During the process of transferring data to internal partners, receiving timely legal advice from NPLAW’s lawyers will help enterprises:

  • Properly assess the legal grounds relating to the scope of data permitted to be transferred under regulations on personal data protection and information security.
  • Clearly determine the rights, obligations, and legal responsibilities of both the transferring party and the receiving party within the enterprise.
  • Review internal procedures, policies, confidentiality agreements, and related documents to minimize risks of legal violations.
  • Support the development of access control mechanisms, security measures, and incident-handling procedures arising during the data transfer process.
  • Minimize the risk of administrative penalties, legal disputes, and ensure that internal operations are conducted safely and effectively.

The above information is for reference purposes only. Should you require detailed advice for your specific case, please contact NPLAW Firm for prompt, accurate, and practical legal support.