The practice of third parties reselling customer data without notification has increasingly occurred in recent years, resulting in numerous negative consequences for data subjects and reducing public trust in the digital marketplace. Such situations highlight the urgent need for stricter supervision and effective sanctions under applicable law. The following article analyzes the current situation, clarifies relevant concepts, reviews applicable legal regulations, and examines the responsibilities of enterprises as well as the sanctions imposed for such unlawful data resale activities.

I. Current situation concerning third parties reselling customer data without notification

The practice whereby third parties (such as business partners, service providers, or advertising agencies) are initially granted access to personal data for specific purposes, but subsequently resell customer data without notifying either the data subjects or the original data providers, has become a serious and widespread concern.

As a result, customers frequently receive spam calls, unsolicited messages, and promotional emails, and in many cases may even become victims of fraud, leading to both financial and emotional harm. This practice significantly undermines trust in digital services and calls for stronger legal intervention and regulatory oversight.

II. The concept of third parties reselling customer data without notification

1. What constitutes a third party reselling customer data without notification?

Reselling customer data without notification refers to the act of transferring (including selling, exchanging, gifting, or otherwise providing) a customer’s personal data to another party without obtaining the consent of the data subject and without informing them of the new purpose of the transfer. Such conduct constitutes a serious violation of the fundamental principles governing data processing and confidentiality commitments.

Accordingly, when a third party resells customer data without notification, it constitutes an unlawful transfer of data that violates the principles of consent, transparency, and confidentiality in the processing of personal data.

2. How does the resale of customer data without notification affect customer privacy rights?

The unlawful collection, use, dissemination, or commercial exploitation of another person’s personal information is a prohibited act under Clause 5 Article 7 of the Law on Cyber Information Security 2015.

The resale of customer data without notification constitutes a serious violation of privacy rights and infringes upon personal confidentiality. Customers may consequently face risks such as spam communications, fraud schemes, psychological manipulation, misuse of personal information for unauthorized purposes, or even cyberattacks, potentially resulting in financial losses and damage to reputation.

Therefore, the act of reselling customer data without notification not only severely infringes upon customer privacy but also creates significant risks relating to property, reputation, and information security. It is a prohibited act under the law and must be subject to strict enforcement measures.

3. What motivations may lead third parties to resell customer data without notification?

The act of reselling data without notification may arise from several motivations, including:

  • Profit-driven motives: It is the primary element, as the sale of personal data constitutes an illegal yet highly profitable activity that requires minimal operational costs.
  • Exploitation of legal or contractual loopholes: Third parties may take advantage of loosely drafted contractual provisions or weaknesses in security systems to extract and sell data.
  • Lack of strict internal regulations: Employees of third parties may independently sell data in order to generate illicit income.

In summary, the resale of data without notification is often driven by economic incentives, exploitation of legal or contractual loopholes, and weaknesses in internal management systems. These factors demonstrate the urgent need to strengthen legal frameworks, contractual safeguards, and oversight mechanisms in order to effectively protect personal data.

III. Legal regulations concerning third parties reselling customer data without notification

1. Which legal instruments regulate the supervision of third parties in the use of customer data?

The supervision of third parties in the use of customer data in Vietnam is primarily governed by Decree No. 13/2023/ND-CP on Personal Data Protection. This Decree imposes strict obligations on third parties, including requirements to process data strictly for specified purposes, implement data protection and security measures, and cooperate in investigations.

It also establishes supervisory responsibilities for data controllers, requiring compliance with contractual obligations, impact assessment documentation, and legal accountability before the State. These provisions are specifically set out in Articles 38, 39, 40, and 41 of Decree No. 13/2023/ND-CP.

In addition, relevant provisions are contained in the Law on Cyber Information Security 2015, the Law on Cybersecurity 2018, and the Civil Code 2015.

Thus, the supervision of third parties in the use of customer data is regulated by multiple significant legal instruments, with Decree No. 13/2023/ND-CP serving as the central framework establishing compliance obligations, supervisory responsibilities, and legal accountability for relevant parties.

2. In the case of a dispute, which authorities have jurisdiction to handle cases involving third parties reselling customer data without notification?

Pursuant to Article 29 of Decree No. 13/2023/ND-CP, disputes involving third parties reselling customer data without notification may fall under the authority of the Department of Cybersecurity and High-Tech Crime Prevention under the Ministry of Public Security for investigation and enforcement.

In addition, affected parties may initiate legal proceedings before the People’s Courts or submit disputes to commercial arbitration (where an arbitration agreement exists) to resolve compensation claims and protect their lawful rights, in accordance with dispute resolution mechanisms provided under Article 317 of the Commercial Law 2005.

Enterprises are also responsible for reporting incidents and cooperating with competent authorities in handling violations, while affected individuals retain the right to initiate legal action to claim damages.

Therefore, cases involving third parties reselling customer data without notification may fall within the jurisdiction of both regulatory authorities and judicial bodies to ensure effective enforcement and protection of the lawful rights and interests of affected parties.

3. What supervisory responsibilities do enterprises have to prevent third parties from reselling customer data without notification?

To prevent third parties from reselling customer data, enterprises must establish strict contractual arrangements clearly defining the purpose and scope of data processing. Enterprises should also implement continuous supervision through periodic audits of third-party activities.

Furthermore, enterprises must require third parties to adopt robust security measures, conduct impact assessments, and comply with clearly defined contractual sanctions in case of violations. Mechanisms must also be established for the retrieval or deletion of data when necessary.

Enterprises, including data controllers and data processors, are obligated to implement appropriate organizational and technical measures, as well as security safeguards, in accordance with Decree No. 13/2023/ND-CP, particularly under Articles 38, 39, and 40.

In summary, enterprises must proactively establish comprehensive monitoring mechanisms, covering contractual, technical, and internal control measures, in order to prevent, detect, and promptly address risks associated with unlawful resale of customer data by third parties.

4. What sanctions may be imposed on third parties who resell customer data without notification?

The unlawful collection, use, dissemination, or commercial exploitation of another person’s personal information, or the exploitation of vulnerabilities within information systems to collect or extract personal data, constitutes a violation under Clause 5 Article 7 of the Law on Cyber Information Security 2015.

Depending on the nature and severity of the violation, Point c Clause 2 Article 84 of Decree No. 15/2020/ND-CP (as amended by Clause 30 Article 1 of Decree No. 14/2022/ND-CP) provides for administrative fines ranging from 40,000,000 VND to 60,000,000 VND for the unlawful collection, use, dissemination, or trading of personal information. Additional sanctions may include suspension of personal data processing activities and compulsory destruction of unlawfully collected data.

In serious cases, the sale of personal data may also lead to criminal liability. Pursuant to Article 288 of the Criminal Code 2015 (as amended in 2017), the offense of illegally providing or using information on computer networks or telecommunications networks may result in fines ranging from 30,000,000 VND to 200,000,000 VND or imprisonment from six months to three years. The maximum sanction may reach seven years of imprisonment where the offense is committed in an organized manner, causes serious consequences, generates substantial illegal profits, or constitutes a repeat offense.

In addition to administrative and criminal sanctions, the violating third party may also be liable for civil compensation under the Civil Code 2015. Under Clause 1 Article 584 and Article 585 of the Civil Code 2015 (as guided by Article 2 of Resolution No. 02/2022/NQ-HDTP), any person who infringes upon the lawful rights and interests of another and causes damage must provide full and timely compensation. The parties may agree on the compensation amount, the form of compensation (monetary payment, property transfer, or performance of specific obligations), and whether the compensation will be paid in a lump sum or installments, unless otherwise provided by law.

Accordingly, the current legal framework establishes strict sanctions ranging from administrative fines to criminal prosecution in order to deter unlawful data exploitation while affirming the State’s strong commitment to protecting privacy rights and information security for all individuals.

IV. Questions regarding third parties reselling customer data without notification

1. What should customers do if they suspect their personal data has been resold by a third party without notification?

If customers suspect or discover that their personal data has been resold without notification, they have the right to object and request that the third party or enterprise cease processing their data, according to Clauses 8 and 9 Article 9 of Decree No. 13/2023/ND-CP.

In addition, customers may also file complaints or denunciations with competent authorities or initiate legal proceedings to claim compensation for damages arising from violations of personal data protection regulations.

Thus, when customers suspect unlawful resale of their personal data, they possess full legal rights to object to data processing, demand cessation of violations, and utilize available complaint, denunciation, and litigation mechanisms to safeguard their lawful rights. 

2. Are enterprises jointly liable if they fail to detect that a third party has illegally sold customer data?

Under Article 288 of the Civil Code 2015, joint liability refers to a situation in which multiple parties are required to perform the same obligation, and the entitled party may demand performance from any of the jointly liable parties.

Although personal data protection regulations do not explicitly provide that enterprises automatically take joint liability if they fail to detect illegal data sales by third parties, according to Article 37 of the Personal Data Protection Law 2025 regarding the obligations of data controllers and data processors, enterprises may be held jointly liable with the third party if such liability has been agreed upon in the contract or if the enterprise is proven to have been negligent in appointing an inadequately qualified third party or failing to conduct periodic supervision as required.

In summary, although the law does not automatically impose joint liability, enterprises may still be held jointly liable where contractual provisions exist or where inadequate supervision of third parties constitutes contributory fault causing damage to data subjects.

3. Do customers have the right to request disclosure of the list of third parties that have accessed their data?

Under Article 9 of Decree No. 13/2023/ND-CP, data subjects have the right to access, review, modify, or request detailed information concerning the processing of their personal data, including any transfers to third parties.

Enterprises are obligated to provide information regarding third parties that have accessed such data. Accordingly, customers are entitled to request transparency concerning the third parties that have accessed their personal data in order to ensure their right to information and control over their data as prescribed by law.

4. Can customers request enterprises to provide evidence that their data has been resold by third parties?

Customers have the right to request enterprises to provide evidence relating to the resale of their data because they are entitled to access information regarding how their personal data is processed and to withdraw consent where applicable. Enterprises are also obligated to demonstrate compliance and provide transparent explanations. They must cooperate in providing information and evidence within their capacity in order to support the verification of damages and the identification of unlawful conduct.

Thus, customers have the right to request information and evidence relating to the processing and transfer of their personal data, while enterprises have a duty to provide explanations and cooperate to ensure transparency and accountability in personal data protection.

V. Why you should seek legal advice from NPLaw regarding third parties reselling customer data without notification

Legal advisory services at NPLAW relating to cases where third parties resell customer data without notification can assist clients in the following ways:

  • Determining legal liability: Analyzing contractual provisions and applicable legal regulations to identify the fault of the third party and assess potential joint liability of the enterprise (if any).
  • Supporting evidence collection: Advising on methods for preserving and collecting technical evidence and digital traces proving the unlawful transfer of data by the third party.
  • Representing clients in negotiations and crisis management: Acting on behalf of customers or enterprises in dealing with the third party to request cessation of violations, recovery of data, and negotiation of appropriate compensation.
  • Handling complaints and litigation procedures: Preparing denunciation dossiers for submission to law enforcement authorities (such as the Department of Cybersecurity) or litigation documents for filing before courts or arbitration tribunals, and participating in legal proceedings to protect clients’ privacy and lawful interests.

The above information is provided for reference purposes only. If you have any questions regarding third parties reselling customer data without notification, please contact NPLAW so that our team of lawyers can provide direct consultation and comprehensive legal support.