Personal data processing refers to one or more activities that affect personal data. The processing of personal data must comply with legal regulations to protect the rights and personal information of users. In the article below, NPLaw provides readers with some clarifications on personal data processing under current laws.
I. Understanding personal data processing
Based on the Constitution 2013, Vietnamese citizens have the inviolable right and the right to confidentiality of their personal data. Accordingly, personal data is protected by law, and any acts of infringement on personal data are strictly handled in accordance with legal provisions. All relevant parties must ensure compliance with regulations during the collection, use, and protection of personal data. These regulations aim to ensure that personal data is tightly safeguarded, preventing risks of misuse or loss that could result in negative consequences for data subjects.
II. Legal regulations on personal data processing
1. What is personal data processing?
Pursuant to Clause 7, Article 2 of Decree 13/2023/NĐ-CP, personal data processing refers to one or more activities that affect personal data, such as: collecting, recording, analyzing, verifying, storing, modifying, publicizing, combining, accessing, retrieving, revoking, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting, destroying personal data, or other related actions.
Thus, personal data processing can be briefly understood as one or more activities that affect personal data.

2. Conditions for processing personal data
Based on Clause 3, Article 3 of Decree 13/2023/NĐ-CP, personal data may only be processed for the purposes registered or declared by the Personal Data Controller, the Personal Data Processor, the Personal Data Controller and Processor, or a Third Party.
Thus, personal data may only be processed for the purposes that have been registered or declared regarding personal data processing.
3. Is it mandatory to obtain consent from data subjects when processing personal data?
Pursuant to Article 17 of Decree 13/2023/ND-CP, personal data can be processed without the consent of data subjects in the following cases:
- In emergencies where it is necessary to process relevant personal data to protect the life or health of the data subject or others. The Personal Data Controller, Personal Data Processor, Personal Data Controller and Processor, or Third Party is responsible for proving this case.
- When personal data is made public in accordance with the law.
- When data is processed by competent state authorities in cases of emergencies related to national defense, national security, public order, major disasters, or dangerous epidemics; when there is a threat to national security or defense but it isn’t necessary to declare a state of emergency; or for the prevention and control of riots, terrorism, and crimes, and legal violations as prescribed by law.
- Fulfilling contractual obligations of the data subject with relevant agencies, organizations, or individuals as stipulated by law.
- Serving operations of state agencies as specified by specialized laws.
Thus, if personal data processing falls under any of the above cases, the consent of the data subject is not required.
4. When is the consent of the data subject valid in personal data processing?
Pursuant to Clause 2, Article 11 of Decree 13/2023/ND-CP, the data subject's consent is regulated as follows:
The consent of the data subject is only valid when the data subject voluntarily agrees and is fully informed of the following:
a) The type of personal data being processed;
b) The purposes of processing personal data;
c) The organizations or individuals authorized to process personal data;
d) The rights and obligations of the data subject.
Thus, the consent of the data subject in personal data processing is only valid when the data subject voluntarily agrees and is fully aware of the four elements outlined above.

III. Common questions about personal data processing
1. How can the consent of the data subject be expressed?
Pursuant to Article 11 of Decree 13/2023/NĐ-CP, the consent of the data subject is defined as follows:
- The consent of the data subject must be clearly and specifically expressed in writing, verbal, mark in a consent box, use of a consent syntax via message, selection of technical settings to indicate consent, or through another action that demonstrates such consent.
- The consent must be presented in a format that can be printed or copied in writing, including electronic or verifiable formats.
- Silence or non-response from the data subject is not considered consent.
Thus, the consent of the data subject must be explicitly and specifically expressed through writing, voice, tick in a consent box, consent syntax via message, selection of technical consent settings, or through another demonstrative action.
2. What are the responsibilities of personal data Processors?
Pursuant to Article 39 of Decree 13/2023/NĐ-CP, the responsibilities of personal data processors are as follows:
- Only receiving personal data after having a contract or agreement on data processing with the Personal Data Controller.
- Processing personal data in accordance with the contract or agreement signed with the Personal Data Controller.
- Fully implementing personal data protection measures as stipulated in this Decree and other relevant legal documents.
- The Personal Data Processor is responsible to the data subject for any damages caused during the data processing.
- Deleting or returning all personal data to the Personal Data Controller after the data processing is completed.
- Cooperating with the Ministry of Public Security and competent state authorities in protecting personal data and providing information to support investigations and handle violations of personal data protection laws.
Thus, the personal data processor must comply with the six responsibilities outlined above.
3. Is parents’ consent required when processing their child's personal data?
Based on Clause 2, Article 20 of Decree 13/2023/NĐ-CP, the processing of child's personal data is regulated as follows: The processing of child's personal data requires the child's consent if the child is 7 years old or older, along with the consent of the child's parents or legal guardians, except in cases specified in Article 17 of this Decree. The Personal Data Controller, Personal Data Processor, Personal Data Controller and Processor, or Third Party must verify the child's age before processing their personal data.
Thus, the processing of children's personal data requires their consent, as well as the consent of the parents or legal guardians if they are 7 years old or older, in accordance with the above regulations.
4. Is it mandatory for personal data processing impact assessment records to be available at the enterprise?
Pursuant to Clause 4, Article 24 of Decree 13/2023/ND-CP on personal data processing impact assessments: Personal data processing impact assessment records must always be available to facilitate inspections and evaluations by the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention). One original copy must be submitted to the Ministry of Public Security using Form No. 04 in the Appendix of this Decree within 60 days from the date personal data processing begins.
Thus, personal data processing impact assessment records must always be readily available to serve inspections and evaluations by the Ministry of Public Security, as stipulated by law.
5. What information must be included in the personal data processing notification?
Pursuant to Clause 2, Article 13 of Decree 13/2023/ND-CP, the notification to the data subject regarding personal data processing must include the following contents:
- The purposes of processing;
- The type of personal data used related to the processing purposes as stipulated in Point a, Clause 2 of this Article;
- The methods of processing;
- Information about other organizations or individuals involved in the processing purposes as stipulated in Point a, Clause 2 of this Article;
- Potential unintended consequences or damages;
- The start and end time of data processing.
Thus, a personal data processing notification must include the six elements listed above.
6. What must enterprises do when processing personal data?
Pursuant to Clauses 1 and 2, Article 24 of Decree 13/2023/ND-CP:
- The Personal Data Controller, and the Personal Data Controller and Processor must prepare and retain personal data processing impact assessment records from the moment data processing begins.
- The Personal Data Processor must prepare and retain personal data processing impact assessment records when executing a contract with the Personal Data Controller.
Therefore, when processing personal data, enterprises are required to conduct a personal data processing impact assessment.
IV. Legal consulting services related to personal data processing
The above article from NPLaw analyzes several regulations concerning personal data processing. With a team of experienced lawyers and legal professionals, NPLaw provides reputable, professional legal services to ensure the protection of the legal rights and interests of our clients.