VIETNAM Law and Practice Contributed by: Ngoc Luong Trinh, Tung Nguyen, Hanh Vo, Esko Cate, Nguyen Dang, Khanh Le, Hoang Nguyen and Truc Ta, VILAF
data subjects. In practical terms, this means that if a foreign company targets Vietnamese users, process - es employee or customer data relating to Vietnam, transfers Vietnam-related data offshore or provides data processing services in Vietnam, it may need to carefully assess the applicability of Vietnamese law, as outlined in examples below. • The Law on Data applies to foreign agencies organisations and individuals that directly par - ticipate in or are otherwise involved in, activities concerning digital data in Vietnam, to the same regulatory expectations as domestic entities. A key practical implication lies in the distinction between different categories of data, which affects the appli - cable cross-border compliance requirements and drives the level of regulatory scrutiny. While cross- border transfers of “important data” can generally proceed without prior approval, transfers of more sensitive “core data” require pre-approval. In prac - tice, this creates a tiered compliance burden and may introduce timing and regulatory uncertainty for transactions involving higher-risk data sets. • The Law on PDP adopts a similar scope, extending to foreign agencies organisations and individuals directly engaged in or involved in, data processing activities concerning (i) Vietnamese citizens and (ii) persons of Vietnamese origin residing in Vietnam whose nationality has not been determined and who have been issued identity cards. Accordingly, offshore entities falling within this scope must comply with substantially the same obligations as organisations and individuals in Vietnam. The Law on PDP also requires that a cross-border transfer impact assessment be submitted to the com - petent authority within 60 days of the first transfer. This approach operates as a post-transfer compliance mechanism, allowing data flows to proceed without prior regulatory approval. However, the regime relies largely on self-assessment by businesses and does not provide standards for evaluating the adequacy of protection in recipient jurisdictions. That said, the Ministry of Public Security may review the dossier and has its own discretion in issuing a result on whether it meets regulatory requirements. As a result, while the level of regulation is less restrictive compared to the EU GDPR framework, which permits cross-border
transfers only on the basis of an adequacy decision or recognised safeguards such as Standard Contractual Clauses or Binding Corporate Rules, it would be more accurate to say that Vietnam adopts its own adminis - trative assessment-based approach to cross-border transfers rather than a clearly less restrictive system. Further, both laws include mechanisms to address potential overlap in impact assessment requirements. Compliance with impact assessment obligations for “core data” and/or “important data” under the Law on Data may exempt subjects from corresponding requirements under the Law on PDP. Conversely, compliance with personal data processing or cross- border transfer impact assessments under the Law on PDP may remove the need to conduct parallel assess - ments under the Law on Data. However, this does not remove the need for organisations to map their data flows carefully and identify which legal basis or filing route applies to a particular activity. 8.3 Role and Authority of the Data Protection Agency The Law on Data as well as the Law on PDP allo - cate responsibilities to competent authorities for the administration and enforcement of data protection regulations, as outlined below. Ministry of Public Security (“MPS”) • Under the Law on Data, the MPS plays a central role in administering and enforcing data-related regulations. It is responsible for overseeing and coordinating the implementation of the data gov - ernance framework, including the management, protection, processing and use of data, as well as ensuring data security and preventing data-related violations. • Under the Law on PDP, the MPS is the primary authority responsible for state management of personal data protection. Its key responsibilities include ensuring unified state management, lead - ing the development and implementation of the legal framework and supervising compliance with data protection requirements. For the purpose of handling administrative procedures relating to personal data protection (eg, receiving data assessment report, cross-border transfer assess -
1186 CHAMBERS.COM
Powered by FlippingBook