In the context of digitalization and international integration, the transfer of finance-related data has become an inevitable need for enterprises in investment, cooperation, and service provision activities. However, such transfers are subject to strict legal regulation on data protection, customer rights, and information security, requiring the parties to have a clear understanding of the applicable rules in order to minimize legal risks.

I. The current demand for the transfer of finance-related data

With strong development of digital transformation and economic integration, the demand for the transfer of finance-related data has been steadily increasing and has become an indispensable component of business operations. Financial data not only serves internal governance purposes but also constitutes a critical basis for assessing financial capacity, controlling risks, conducting due diligence for partners, and implementing investment, mergers and acquisitions, credit extension, and financial service provision transactions.

In parallel, the development of digital business models, fintech, e-commerce, and payment intermediary services has made the sharing, interconnection, and processing of financial data among stakeholders increasingly frequent. However, accompanying such demand are increasingly stringent legal requirements concerning information security, personal data protection, and the protection of customer rights.

Accordingly, the transfer of finance-related data is not merely a matter of agreement between parties, but must strictly comply with applicable laws to ensure legality, transparency, and security in the exploitation and use of data.

II. Understanding the transfer of finance-related data

To properly understand and effectively implement the transfer of finance-related data, it is first necessary to clarify the concept, the scope of transferable data, and the practical forms of implementation.

1. What is the transfer of finance-related data and why is it important in business?

The transfer of finance-related data refers to the sharing of, or granting access to, financial data among enterprises, organizations, and individuals through electronic or digital means, including transaction information, accounting records, tax data, cash flow data, and financial obligations.

In business practice, the transfer of financial data enhances transparency, supports governance and auditing, facilitates investment cooperation, and ensures legal compliance. However, because such activities are closely linked to economic interests and customer information, they must be conducted in accordance with legal requirements to avoid legal risks and potential disputes.

2. What types of data are considered finance-related data for transfer purposes?

Pursuant to the spirit of Article 3 of the Data Law 2024 on categories of data, finance-related data is understood as digital data reflecting information on financial, monetary, accounting, budgeting, transactional activities, and financial obligations of agencies, organizations, and individuals, represented in digital form such as figures, symbols, text, or combinations thereof.

In practice, financial data may fall into different categories, including proprietary data (for internal management purposes of enterprises and organizations), shared data (shared among state agencies in accordance with law), or open data where disclosure is permitted by law.

Notably, certain categories of financial data may be classified as important data or core data if they are capable of affecting macroeconomic stability, social stability, or national financial security in accordance with the list promulgated by the Prime Minister. In such cases, the transfer of finance-related data is subject not only to civil and commercial law, but also to specialized regulations on data management, security, and control under the Data Law 2024 and relevant regulations.

3. What forms may be used to transfer finance-related data?

Pursuant to Clause 3 Article 21 of the Data Law 2024 (as guided by Article 10 of Decree No. 165/2025/ND-CP), the law recognizes data transfer through data disclosure, including publication on data portals, e-portals, websites, mass media, and other disclosure methods prescribed by law.

Such provision recognizes data disclosure as a legally regulated form of data transfer applicable to categories of data eligible for disclosure in accordance with specialized regulations and not falling within restricted-access data.

In addition to the above form of public disclosure, in practice, the transfer of finance-related data may also be conducted through non-public methods in compliance with relevant laws, such as:

  • Controlled data sharing between parties on the basis of lawful contracts or agreements;
  • System connectivity and data integration among competent entities;
  • Provision of data at the request of competent state authorities;
  • Transfer of data to third parties for audit, advisory, or investment purposes, subject to full compliance with data security, information security, and data protection regulations.

The choice of the method for transferring financial data in each specific case must be based on the nature of the data, the purpose of transfer, and the applicable specialized regulations, in order to ensure legality and minimize legal risks.

4. How may the transfer of finance-related data affect customer rights?

The transfer of finance-related data may directly affect customers’ privacy and personal data protection rights. If conducted in compliance with law, customers may benefit from more convenient, transparent, and personalized financial services.

Conversely, transfers conducted without consent, without adequate security safeguards, or for improper purposes may result in the leakage of financial information, infringement of lawful rights and interests, and even financial and reputational harm to customers.

III. Legal regulations governing the transfer of finance-related data

The transfer of finance-related data must not be performed arbitrarily, but must strictly comply with legal provisions on data governance, personal data protection, information security, and relevant specialized regulations in order to safeguard customer rights and ensure the legal responsibilities of the parties involved.

1. Is customer consent required prior to the transfer of finance-related data?

As a general principle, where the transfer of finance-related data involves personal data, customer consent is required. Pursuant to Article 9 of the Law on Personal Data Protection 2025, the consent of the data subject constitutes the legal basis for personal data processing, unless otherwise provided by law.

Such consent is valid only if given voluntarily and on the basis of full information, including the types of data to be processed, the purposes of processing, the data controller, and the customer’s rights and obligations.

Consent must be clearly and specifically expressed, whether in writing or by verifiable electronic means, and must comply with principles such as purpose-specific consent, absence of coercive conditions, and the principle that silence does not constitute consent.

Accordingly, unless the law permits processing without consent, enterprises may transfer customers’ financial data only after satisfying all the above requirements for lawful consent.

2. What are the requirements on personal data security in the transfer of finance-related data?

In the transfer of finance-related data, personal data security is strictly governed by Article 8 of Decree No. 356/2025/ND-CP on personal data protection in the fields of finance, banking, and credit information. Accordingly, organizations and individuals operating in these sectors must apply technical standards and regulations on personal data protection, including de-identification and anonymization techniques, conduct annual compliance assessments, and maintain comprehensive processing logs to ensure controllability and traceability.

In addition to technical requirements, when obtaining customer consent for data transfer, the data controller must disclose mandatory information in a transparent manner, including: The purposes of data processing (including scoring, ranking, or credit assessment, if any), data sources, parties involved in data sharing, data retention periods, mechanisms for withdrawal of consent, and policies on data deletion and destruction. These constitute an important legal basis for protecting the data subject’s right of self-determination.

Furthermore, in the case of leakage or loss of sensitive data, the organization or individual directly collecting the data is obliged to notify the specialized personal data protection authority and the data subject within no more than 72 hours, with notification contents satisfying the requirements prescribed in Clause 3 Article 8 and Article 29 of Decree No. 356/2025/ND-CP. Such a requirement aims to mitigate the spread of risks and safeguard customers’ lawful rights and interests in the course of financial data transfer.

3. What sanctions apply in cases of violations in the transfer of finance-related data?

Pursuant to Article 8 of the Law on Personal Data Protection 2025, organizations and individuals that violate personal data protection regulations in the course of transferring finance-related data may be subject to administrative sanctions, criminal liability, and civil liability for damages, depending on the nature, severity, and consequences of the violation if losses are caused to data subjects.

Criminal liability may arise where acts of unlawful transfer, disclosure, or use of financial data cause serious consequences. For example, under Article 288 of the Criminal Code 2015 (as amended and supplemented in 2017) on the offense of illegally providing or using information on computer networks or telecommunications networks, any person who unlawfully posts or uses another person’s information, including personal financial data, thereby infringing lawful rights and interests, may be subject to fines or imprisonment depending on the severity of the violation.

In addition, civil liability for damages applies where violations cause actual losses to data subjects. Pursuant to Article 584 of the Civil Code 2015, any person who infringes the lawful rights and interests of another and causes damage must compensate for such damage, including property damage, loss of income, remedial costs, and moral damages (where applicable).

With respect to administrative sanctions, the law prescribes stringent measures: Acts of buying or selling personal data may be fined up to ten times the amount of unlawful proceeds; violations of regulations on cross-border transfer of personal data may be fined up to 5% of the organization’s turnover in the preceding year; other violations in the field of personal data protection may be subject to fines of up to 3 billion VND. For individuals committing the same violations, the maximum fine is one-half of that applicable to organizations.

In addition, where violations seriously infringe data subjects’ lawful rights and interests or constitute criminal offenses under criminal law, the individuals and organizations involved may be subject to criminal prosecution, resulting in long-term legal consequences for business operations and market reputation.

IV. Questions regarding the transfer of finance-related data

In the process of transferring finance-related data, many enterprises and individuals have concerns regarding legal conditions, the scope of transfer, and liabilities arising from risks. Below are common questions addressing main legal issues to be noted.

1. Can the transfer of finance-related data be restricted by international regulations? Why?

The transfer of finance-related data, particularly personal data and sensitive data, may be restricted by international regulations and commitments to which Viet Nam is a member. Pursuant to Article 30 of Decree No. 356/2025/ND-CP, international cooperation on personal data protection must be conducted through competent authorities and in compliance with Vietnamese law as well as international practices.

Accordingly, when transferring financial data abroad or to foreign partners, enterprises must not only comply with domestic regulations but also ensure compliance with data protection standards of the relevant countries and international organizations. Such aims are to prevent privacy infringement risks, ensure data security, and uphold Viet Nam’s reputation and legal obligations in international cooperation.

2. What are the consequences if one party fails to comply with provisions on the transfer of finance-related data?

Where a party fails to comply with provisions on the transfer of finance-related data, depending on the nature, severity, and consequences of the violation, the violating organization or individual may be subject to administrative sanctions, criminal liability, and civil liability for damages under personal data protection law.

Specifically, administrative fines may be severe: Acts of buying or selling personal data may be fined up to ten times the unlawful proceeds; violations of cross-border personal data transfer regulations may be fined up to 5% of the organization’s turnover in the preceding year; other violations may be subject to fines of up to 3 billion VND. For individuals, the maximum fine is one-half of that applicable to organizations. In addition, where violations cause actual damage to data subjects or related parties, the violator must compensate for civil damages in accordance with law.

Where the transfer of finance-related data involves unlawful intrusion into another party’s information technology systems for the purpose of collecting, copying, or appropriating data, the individuals or organizations involved may be subject to criminal prosecution under Article 289 of the Criminal Code 2015 (as amended and supplemented in 2017) on the offense of illegal intrusion into computer networks, telecommunications networks, or electronic devices of others.

3. Which authorities are competent to supervise the transfer of finance-related data?

The competent authorities for supervising, inspecting, and handling data transfer activities (including financial data) under Decree No. 356/2025/ND-CP include:

  • The specialized personal data protection authority (under the Ministry of Public Security): The focal point for state management, empowered to conduct regular inspections of personal data processing and transfer; require cross-border data transfer impact assessments; detect, prevent, and handle violations (Articles 31 and 34).
  • The Ministry of Public Security: Unified state management of personal data protection; issuance and guidance on implementation of legal instruments; protection of data subject rights; and leadership in international cooperation on personal data protection (Articles 30 and 34).
  • Ministries and ministerial-level agencies, and agencies under the Government: Supervision, international cooperation, and management of data transfer activities within their respective sectors and fields (Article 30).
  • Provincial-level People’s Committees: Management, coordinated supervision, and international cooperation on personal data protection within their localities in accordance with their competence (Article 30).

Accordingly, the transfer of financial data is directly supervised by the specialized personal data protection authority and the Ministry of Public Security, and subject to coordinated management by relevant ministries, sectors, and provincial People’s Committees depending on the sector and locality concerned.

4. What legal risks may arise when transferring finance-related data to third parties?

When transferring financial data to third parties, enterprises may face the following main legal risks:

  • Infringement of privacy and personal data protection laws: Where financial data containing personal information is shared without a proper legal basis (e.g., without data subject consent), enterprises may be subject to administrative sanctions, criminal liability, or civil compensation under data protection regulations.
  • Contractual and compliance risks due to unclear agreements: Sharing data with third parties without detailed agreements and without compliance with security standards (e.g., data processing agreements aligned with data protection principles) may lead to legal disputes, under which enterprises may remain liable for how third parties use or protect the data, even in cases of data leakage or misuse.

Such risks may result not only in financial sanctions and compensation liabilities, but also reputational damage, customer loss, and compliance burdens with international regulations where data is misused or transferred in breach of cross-border requirements.

5. What measures should be implemented to protect data during the transfer of finance-related data?

Pursuant to Clause 4 Article 2 of the Law on Personal Data Protection 2025, personal data protection refers to the use of resources, means, and measures by agencies, organizations, and individuals to prevent acts of infringement of personal data. Accordingly, when transferring finance-related data, which is high-risk data, the transferring party is obliged to implement appropriate protective measures.

Specifically, Clause 2 Article 7 of Decree No. 356/2025/ND-CP requires that the transfer of sensitive personal data be accompanied by physical security measures for storage and transmission devices, as well as the application of encryption, anonymization, and other security measures throughout the transfer process. Failure to comply with these requirements may be deemed a breach of data protection obligations and lead to corresponding legal liabilities.

V. Are you looking for a reputable legal expert to support matters relating to the transfer of finance-related data?

If you are facing legal challenges in the transfer of finance-related data, from assessing legal conditions, drafting data-sharing agreements, ensuring security compliance, to handling disputes, NPLaw is willing to support you. With a team of experienced lawyers in personal data protection, information technology law, and finance, NPLaw provides timely and in-depth legal advisory solutions to help you safeguard customer rights, mitigate legal risks, and ensure full compliance with applicable regulations.

The above information is provided for reference purposes only. For tailored advice on specific cases, please contact NPLaw for prompt consultation.