VIETER
VIETNAM INDUSTRY BRIEFING

Draft Decree on Personal Data Protection Violations & Sanctions in Vietnam

The draft decree on administrative penalties for violations in personal data protection, discussed by the Vietnamese Government on 2 May 2024, encompasses a broad spectrum within cybersecurity provisions and includes sanctions covering information securit

The draft decree on administrative penalties for violations in personal data protection, discussed by the Vietnamese Government on 2 May 2024, encompasses a broad spectrum within cybersecurity provisions and includes sanctions covering information security assurance, personal data protection, cyberattack prevention, cybersecurity implementation, and measures against illegal cyberspace and information technology usage. This draft extends the scope to encompass violations previously regulated by Decree 13/2023/ND-CP on Personal Data Protection, effective since 1 July 2023, which is Vietnam’s first comprehensive legal framework for personal data protection.

This article synthesizes key aspects of the draft decree to enhance awareness among stakeholders involved in personal data processing, involving data such as names, ages, genders, health information, criminal records, etc., or collectively referred to as Data“. It also emphasizes prudent preparatory steps to mitigate risks of non-compliance and unwarranted penalties. To grasp the essence of the Draft, it is essential to understand that personal data processing encompasses a wide range of activities conducted by entities other than Data Subjects, or in short, non-data-subjects (e.g., companies, employers) with Data belonging to Data Subjects (e.g., customers, partners, employees). Processing activities include collection, reading, storage, deletion, analysis, transfer, and so forth.

Broad applicability of regulations

Parties concerned with personal data processing include Data Subjects (individuals, regardless of nationality), controllers, processors, and third parties such as companies, operating in various capacities like partners, customers, or employers. However, Article 2 of the draft extends this further by applying penalties to entities beyond Vietnamese companies, including offshore companies, representative offices, branches (of the foreign traders in Vietnam), data system operators, non-registered organizations, sole proprietorships, and even governmental entities or institutional bodies like schools and hospitals, collectively referred to as “Controllers and Processors.

This necessitates broader cross-border compliance and includes all entities without exception. In general, any entity involved in personal data processing may face penalties for violations, irrespective of scale, structure, nationality, or importance, under the provisions of the Draft.

Specific penalties and supplementary measures for remediation

A series of administrative sanctions are imposed if violations related to personal data processing occur, comprising three groups:

  • Main sanctions group includes warnings and fines;
  • Supplementary sanctions include license revocation, suspension of operations, and others; and
  • Remedial measures aim to mitigate consequences.

Regarding financial sanctions, similar to administrative penalties in other fields, fines are common for personal data processing violations and warnings are considered for minor violations. It is important to note that fines for personal data processing violations are heavier than in other fields, and occasionally, fines may be calculated as a percentage of revenue rather than a specific amount. Common fines for controllers or processors include:

  • 100 to 140 million VND for mishandling data, processing without informing Data Subjects, or improper customer information disclosure.
  • 50 to 100 million VND for processing without consent, where silence or lack of response does not constitute consent.
  • Up to 1 billion VND for data breaches affecting fewer than 5 million Vietnamese.
  • Severe fines, potentially up to 5% of the previous financial year’s revenue, for breaches involving over 5 million Vietnamese.

In addition to the primary penalties, supplementary sanctions directly affect data controllers or processors’ operations. These may involve:

  • Temporary or permanent revocation of business licenses in sectors like postal services, telecommunications, social networks, electronic games, or professional certificates.
  • Confiscation of assets or vehicles used in violations.
  • Deportation of foreign offenders from Vietnam.
  • Suspensions from 1 to 24 months or temporary suspension of personal data processing, crucial for any business operation, typically lasting from 1 to 3 months.

Additionally, in cases of consequential violations, measures are applied to prevent similar future offenses. These may include:

  • Obligatory data deletion beyond recovery.
  • Restitution or surrender of unlawfully gained benefits.
  • Public apologies to Data Subjects.

Therefore, sanctions targeting violations of personal data processing regulations not only impact the financial aspects of data controllers or processors but also tangible aspects such as license revocation and operational suspensions. Intangible factors, such as corporate reputation and potential litigation risks from Data Subjects affected by breaches, are also addressed.

Detailed sanctions for each violation

A series of violations concerning personal data protection are stipulated from Article 13 to Article 28 of the Draft, based on principles and obligations (including obligations between Controllers and Processors and Data Subjects, and between them and state authorities) set forth in Decree 13/2023/ND-CP. There are multiple behaviors considered violations of personal data protection, categorized into four groups:

  • Violations of data protection principles (including approximately 7 behaviors such as processing data contrary to legal regulations, processing data for purposes not registered for data processing, and storing data beyond the time for processing and related legal regulations).
  • Violations of data subject rights (including approximately 73 behaviors such as Data Subjects being unaware of their data being processed, collecting data not agreed upon by Data Subjects, failing to inform Data Subjects of the consequences of withdrawing consent, processing data notifications not in print or text copies, intentionally delaying data correction after agreeing to the Data Subject’s request, and providing data to other organizations or individuals with Data Subjects’ consent).
  • Violations related to processing data for business or other purposes (including about 10 behaviors such as recording or filming in public places and processing data obtained from these activities without notifying the Data Subjects, not proving the use of customer data for marketing, advertising products as per legal regulations, and illegally buying and selling personal data without reaching the level of criminal prosecution).
  • Violations of administrative and internal procedures related to data processing (including about 28 behaviors such as not notifying violations of data protection regulations, not submitting or storing data processing or/and transferring data abroad impact assessment reports, or not establishing internal regulations on personal data protection).

Organisations that fail to submit administrative reports on assessing the impact of personal data processing, transferring data abroad by the Controllers and Processors could lead to fines of up to 200 million VND. Similarly, failure to issue internal policies on sensitive personal data protection can result in fines up to 100 million VND, in addition to supplementary penalties such as revocation of business operation licenses requiring data collection, temporary suspension of data processing, and remedial measures such as public apologies in newspapers, broadcasting, television, and internet.

Compliance with personal data protection regulations requires strict adherence from Controllers and Processors, especially for companies handling large amounts of data affecting a wide range of stakeholders, necessitating uniformity in internal policies, external statements, and reporting to relevant authorities. Any errors in complying with personal data protection regulations could lead to severe consequences such as financial loss, damage to reputation, and potentially inability to operate in Vietnam.

Appropriate timeframe for enforcement

The appropriate timeframe for penalty imposition under general regulations is the period during which the competent state authority in Vietnam has jurisdiction to penalize administrative violations. Once this period elapses, the authority cannot penalize the violation. Typically, most violations are subject to a one-year timeframe, calculated from the conclusion of the violation act or, if ongoing, from the time it was detected. For instance, in cases of mishandling personal data contrary to declared purposes, the timeframe for penalizing this act can be determined in two scenarios:

  • If the controller or processor has ceased handling the data in question (e.g., data has been completely deleted), the calculation starts from the end of the processing
  • If they continue processing the data, the timeframe begins from when the non-compliant processing was discovered.

It is important to clarify that the Draft also stipulates penalties for violations occurring before its effective date but discovered or under resolution afterward. Although there is no guidance or practical demonstration yet, this suggests that violations regarding personal data processing occurring and ceased before the Draft’s effectiveness, without sanctions under any other regulation, will not be penalized. For example, if a controller or processor failed to notify the data subject about data processing, but subsequently rectified this before the Draft’s effective date, it means the violation ceased and would not incur penalties. Conversely, ongoing non-compliance after the Draft’s effective date would be subject to penalties as per the Draft’s provisions.

Conclusion

The Draft is still under discussion and revision, and the contents mentioned here may change, be supplemented, or removed upon its official version. Given the recent implementation of personal data protection regulations under Decree 13/2023/ND-CP takes effect as of 1 July 2023, we anticipate that the forthcoming Decree addressing administrative violations in the cybersecurity domain will be issued in the coming months. Consequently, regulatory authorities are likely to enhance enforcement measures, particularly in the realm of personal data protection.

Decree 13/2023/ND-CP imposes legal obligations on all parties involved in personal data processing, such as Data Subjects, controllers, processors, and third parties, entailing a series of complex legal procedures. These include formulating internal policies, obtaining consent, and submitting impact assessment reports. However, compliance with this decree remains challenging due to its new and intricate provisions, resulting in confusion among stakeholders and a lack of enforceable sanctions from competent authorities.

Our team of experts support investors in planning and implementing all the relevant processes and regulatory provisions reflecting Decree 13, ensuring internal compliance with obligations concerning personal data protection. Do not hesitate to contact us if you require more information on these important matter for organsiations in Vietnam.