In the current business cooperations, many enterprises are conducting data transfers in a spontaneous manner without establishing robust legal safeguards. Such situations have led to numerous disputes, customer data breaches, and administrative sanctions imposed by competent authorities due to violations of data transfer principles between two companies without the consent of data subjects. Below, NPLAW provides a detailed legal analysis of such data transfer between two companies.
In the current business cooperations, many enterprises are conducting data transfers in a spontaneous manner without establishing robust legal safeguards. Such situations have led to numerous disputes, customer data breaches, and administrative sanctions imposed by competent authorities due to violations of data transfer principles between two companies without the consent of data subjects. Below, NPLAW provides a detailed legal analysis of such data transfer between two companies.
I. Current situation of data transfer between two companies
Data transfer between two companies has become a main factor of mergers and acquisitions, affiliate marketing cooperation, and outsourcing service provisions. E-commerce enterprises frequently share customer information with logistics providers, while banks often share user data with partner companies on insurance. Such data circulation helps optimize services but also creates significant security vulnerabilities if not properly managed.

At present, many companies haven’t established legal data transfer procedures yet. The absence of data processing agreements makes parties have difficulties when data breaches occur. Such cases require enterprises to recognize such data transfers are not merely a technical issue but a priority legal obligation.
II. What is data transfer between two companies?
1. Importance of data transfer between two companies
Data transfer between two companies is an essential activity in business cooperation, service provision, outsourcing, and modern commercial transactions. It enables parties to efficiently utilize information, optimize operational processes, and enhance the quality of products and services.
However, data such as personal data and business data is a highly valuable asset. If not strictly controlled during the transfer process, it may lead to data leakage, privacy violations, and legal disputes. Therefore, data transfer is not only a technical matter but also closely associated with legal liability and corporate reputation.
2. Main considerations in data transfer between two companies
When transferring data, companies must pay special attention to the legal basis for the transfer, the scope of data shared, and the purposes of data use. Enterprises must ensure that data transfer complies with contractual agreements and data protection regulations, particularly notification obligations and consent from data subjects where required by law. In addition, technical and organizational measures, such as encryption, access control, supervision of data recipients, and incident response mechanisms, must be clearly established to mitigate risks and potential legal liabilities.
III. Legal regulations governing data transfer between two companies
1. Relevant legal provisions on data transfer between two companies
Pursuant to Decree No. 13/2023/ND-CP on Personal Data Protection, the transfer of personal data between two companies may only be conducted on a valid legal basis and in accordance with the purposes notified to the data subject. The transferring entity must ensure that the data recipient has adequate technical and organizational measures to protect data at an equivalent level (Article 38 of this Decree). In cases involving transfer to third parties or cross-border data transfer under Article 25 of Decree No. 13/2023/ND-CP, enterprises must additionally satisfy requirements such as conducting data processing impact assessments and fulfilling statutory notification obligations.
Furthermore, Clause 2 and Article 37 of the Personal Data Protection Law 2025 require enterprises to implement appropriate security measures, access control, and risk prevention mechanisms throughout the data transfer process.
Accordingly, data transfer between two companies is only permitted when supported by a valid legal basis, aligned with notified purposes, and accompanied by proportionate security measures, particularly in cases involving third-party or cross-border transfers.
2. Violations related to data transfer between two companies
Common violations include transferring personal data without valid consent from data subjects, using data for purposes other than those notified, transferring data to entities lacking adequate security safeguards, or conducting unlawful cross-border data transfers.
Under Article 87 of Decree No. 15/2020/ND-CP (as amended by Decree No. 14/2022/ND-CP), violations of information system protection and security supervision measures may be subject to administrative fines ranging from 10 million VND to 70 million VND. Depending on the nature and severity of the violation, enterprises may face administrative sanctions or criminal liability. For example, in the banking and financial sector, transferring personal data without the data subject’s consent may constitute an offense under Article 291 of the Criminal Code 2015 concerning illegal collection, storage, exchange, trading, or disclosure of banking account information. Offenders may be fined between 20 million VND and 700 million VND, sentenced to non-custodial reform for up to three years or imprisonment for up to seven years, prohibited from holding certain positions or professions for up to five years, and subject to partial or total confiscation of assets.
In summary, any data transfer between two companies that fails to comply with legal requirements on consent, processing purpose, security, and notification obligations may be deemed a violation, resulting in sanctions and compensation liabilities in accordance with law.
IV. Questions on data transfer between two companies
1. Does data transfer between two companies fall under personal data protection law? Why?
Clause 1 Article 2 of Decree No. 13/2023/ND-CP defines personal data as information in the form of symbols, letters, numbers, images, sounds, or similar formats in an electronic environment associated with or capable of identifying a specific individual. Data transfer between two companies directly falls under personal data protection law when the transferred data includes personal information. Under Decree No. 13/2023/ND-CP, all personal data processing activities, including provision, sharing, or transfer to third parties, must comply with personal data protection principles.

Enterprises cannot rely solely on contractual agreements to omit data subject consent and ensure data security throughout the transfer process (Article 9 of the Personal Data Protection Law 2025). Therefore, data transfer involving personal data is directly subject to personal data protection regulations, requiring full compliance with statutory principles, security obligations, and consent requirements.
2. What are the legal responsibilities of the parties in the data transfer agreement between two companies?
Pursuant to Article 37 of the Personal Data Protection Law 2025 and Articles 38, 39, and 40 of Decree No. 13/2023/ND-CP, the responsibilities of the transferring party (data controller) include:
- Ensuring data legality: Ensuring data is lawfully collected and data subjects have consented to transfer to third parties (except where otherwise provided by law);
- Notifying data subjects: Informing data subjects of the data transfer, its purposes, and the identity of the data recipient;
- Assessing recipient security capacity: Ensuring that the recipient has adequate technical and organizational measures to protect data prior to transfer;
- Conducting impact assessments: Completing personal data processing impact assessment dossiers in accordance with regulations.
Responsibilities of the receiving party (data processor or new data controller) include:
- Processing within agreed purposes: Processing data strictly in accordance with contractual terms and notified purposes, without unauthorized onward transfer;
- Implementing security measures: Applying technical (encryption, access control) and organizational (staff training, internal security policies) measures to prevent data breaches;
- Deleting or returning data: Deleting or returning data upon completion of processing purposes or termination of the contract;
- Supporting data subject rights: Coordinating with the transferring party to address data subject requests such as access, rectification, or deletion.
Clearly defining these responsibilities in the contract not only ensures strict legal compliance but also provides a solid basis for risk management, brand protection, and safeguarding data subjects’ lawful rights throughout the cooperation.
3. Can the content of the data transfer agreement between two companies be amended?
The content of the data transfer agreement may be amended upon mutual agreement of the parties. Amendments must be made in writing in the form of a contract appendix or an amendment agreement in accordance with Article 403 of the Civil Code 2015. If amendments alter the data processing purpose or scope of personal data, enterprises must re-perform notification and consent obligations under personal data protection laws.

In summary, data transfer agreements may be amended by mutual consent, but any changes affecting personal data processing purposes or scope must fully comply with renewed legal obligations regarding notification and data subject consent.
4. What risks may arise from data transfer between two companies?
Common risks include data leakage or loss, misuse of data, unauthorized onward transfer to third parties, and compensation liabilities arising from infringement of data subject rights. Enterprises may also take administrative sanctions, reputational damage, or suspension of data processing activities for non-compliance. Therefore, data transfer between two companies entails significant legal and security risks, requiring strict control mechanisms to minimize damage and liabilities.
5. Can the data transfer agreement between two companies be terminated?
A data transfer agreement may be terminated in cases stipulated in the contract or according to Article 423 of the Civil Code 2015, such as when one party materially breaches data security obligations, causes personal data leakage, or uses data for purposes contrary to the agreement. Termination does not extinguish liability for damages incurred prior to termination, and data security obligations remain effective after contract termination.
Accordingly, data transfer agreements may be terminated upon serious breaches or mutual agreement, while compensation liabilities and data security obligations continue post-termination.
V. Do you need legal expert support for data transfer between two companies?
With a team of experienced lawyers in technology and cybersecurity, NPLAW provides:
- Consultation and drafting of data transfer agreements ensuring comprehensive security clauses, joint liability provisions, and lawful protection of parties’ rights;
- Development of compliance frameworks, assistance with data processing impact assessments, and reporting procedures to competent authorities;
- Representation in handling complaints and disputes related to data breaches or violations of data transfer agreements.
The above information is for reference purposes only. Should you have any questions regarding data transfer between two companies, please contact NPLAW for direct consultation and comprehensive legal support from our lawyers.