{"id":1158,"date":"2021-03-22T12:03:07","date_gmt":"2021-03-22T05:03:07","guid":{"rendered":"http:\/\/blogs.duanemorris.com\/vietnam\/?p=1158"},"modified":"2021-03-22T17:58:28","modified_gmt":"2021-03-22T10:58:28","slug":"new-draft-decree-on-personal-data-protection-and-cross-border-provision-of-data-the-basic-and-guidance-on-practical-handling","status":"publish","type":"post","link":"https:\/\/blogs.duanemorris.com\/vietnam\/2021\/03\/22\/new-draft-decree-on-personal-data-protection-and-cross-border-provision-of-data-the-basic-and-guidance-on-practical-handling\/","title":{"rendered":"NEW DRAFT DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE BASICS AND GUIDANCE ON PRACTICAL HANDLING"},"content":{"rendered":"<p>The issue of personal data processing is getting hotter than ever in this digital age with increasing cases where large conglomerate or even national governments being accused of utilizing citizen\u2019s personal data without consent. This trend makes no exception in Vietnam.<\/p>\n<p>So far, the Ministry of Public Security (the &#8220;MPS&#8221;) has finally prepared a Draft Decree on personal data protection (\u201cDraft Decree\u201d). The Draft Decree was shared on 9 February 2021 for public comments.  We outline below some key terms and foundation of the Draft Decree:<\/p>\n<p><strong>I.          The Basic: New Draft Decree on Personal Data Protection and Cross-Border Provision of Data<\/strong><\/p>\n<p><strong>1.         Definition<\/strong><\/p>\n<p>Personal data means data about an individual, or relating to the identification or possible identification of a particular individual. Personal data is comprised of two tranches: (i) Basic personal data includes name, date of birth, blood type, marriage status and most notably, data that reflects activity or history of activity of an individual on cyberspace; and (ii) Sensitive personal data concerning political opinion, health, financial details (credit history, income level\u2026), social relationships and data considered by laws as specific and require necessary security measures.<\/p>\n<p>Personal data processing is broadly defined as one or more acts having an impact on personal data, including collection, record, analysis, storage, change, disclosure, access right, extraction, withdrawal, encryption, decryption, delivery, deletion, cancelation and other related acts.<br \/>\n<strong><br \/>\n2.         Consent and Exception<\/strong><\/p>\n<p>Generally, the Draft Decree strictly regulates that a data owner must give his\/ her consent prior to any processing and disclosing such data, except for the following limited cases:<br \/>\n\u2022\tAs provided by the applicable law;<br \/>\n\u2022\tFor the sake of national security, social order and safety;<br \/>\n\u2022\tIn case of an emergency, a threat to life or seriously affecting the health of that data owner or public health as provided by applicable law; and<br \/>\n\u2022\tIn accordance with the Law on Press and not resulting in economic, honorable, spiritual or material damage to the data owner;<br \/>\n\u2022\tFor investigation and handling an act in violation of laws;<br \/>\n\u2022\tAs allowed by the regulations in international agreements or treaties to which Vietnam is a member; or<br \/>\n\u2022\tScientific research or statistics in encrypted form that is to be de-identified and replaced with a code.<br \/>\nHowever, Article 6.3 of the Draft Decree restricts that it is not permitted to disclose personal data that are of sensitive nature.<\/p>\n<p>When requesting to process personal data, the data owner\u2019s silence or unresponsiveness does not constitute approval. The data owner can agree only to a part of the request or approve the request with attached conditions. The data owner\u2019s consent must be displayed in a format that is printable and copy-able in writing.<\/p>\n<p>With regard to sensitive personal data, the data owner must be fully informed of the nature of the data to be processed. In case of dispute, the burden of proof lies on the data processor.<\/p>\n<p><strong>3.         Prior to any processing activity regarding sensitive personal data, the processing party must register this activity with the Personal Data Protection Committee,which is an independent body to be established under the government of Vietnam,except when:<\/strong><br \/>\n\u2022\tPersonal data is processed to serve the prevention, detection, investigation and handling of violations of the law;<br \/>\n\u2022\tTo carry out health care functions of health facilities and social security of state agencies;<br \/>\n\u2022\tServing judicial functions of the Court;<br \/>\n\u2022\tFor research, archival or statistical purposes of state agencies or scientific research organizations<\/p>\n<p><strong>4.         Personal data processors have an obligation to notify the data owner prior to their processing, except for the following:<\/strong><br \/>\n\u2022\tThe data owner has fully agreed with the contents and activities of processing personal data;<br \/>\n\u2022\tThe processing of personal data is regulated by laws, international agreements, international treaties;<br \/>\n\u2022\tThe processing does not affect the rights and interests of the data owner and it is not possible to notify the data owner;<br \/>\n\u2022\tFor scientific research and statistics collection.<\/p>\n<p><strong>5.         Cross-border transfer of personal data of Vietnamese citizens must satisfy all following four conditions:<\/strong><br \/>\n\u2022\tThe data owner consented the transfer;<br \/>\n\u2022\tOriginal data is stored in Vietnam;<br \/>\n\u2022\tRegulations on personal data protection at the receiving country are of equal or higher level compared to Vietnam\u2019s regulations;<br \/>\n\u2022\tThere is a written approval from the Personal Data Protection Committee.<\/p>\n<p><strong>6.         Penalties for violation of personal data protection rules:<\/strong><br \/>\n\u2022\tMonetary fines range from VND 50 million to VND 100 million;<br \/>\n\u2022\tAdditional penalties: Suspend the processing of personal data up to 3 months, deprive the right to use written consent issued by the Personal Data Protection Committee to process sensitive personal data and cross-border transfer of data, forcible payment of money gained from committing acts of violation.<br \/>\nMultiple violations of personal data protection regulations by a personal data processor in Vietnam can result in a maximum penalty of 5% of total revenue of the data processor in addition to the aforementioned penalties.<\/p>\n<p><strong>II.        Preliminary Guidance on Practical Handling<\/strong><\/p>\n<p>Because the Draft Decree would be amended, thus our analysis and comments hereof is preliminarily made in nature (i.e., subject to change according to the final adopted Decree).<\/p>\n<p>As a rule of thumb, the Draft Decree provides several obligations of the party processing and disclosing personal data, thus it is critical for employers\/ enterprises (the \u201cEmployer\u201d or \u201cEnterprise\u201d) to consider and adopt all those obligations into its internal rules and contracts\/ agreements with third parties. <\/p>\n<p><strong>1.         Internal Labor Rules and Labor Contracts<\/strong><\/p>\n<p>It is required for the Employer to adapt all relevant obligations in relation to personal data over its employees, staff, directors, etc. as well as those in relation to the Employer\u2019s customers, members and their staff into the Employer\u2019s internal labor rules\/ codes and collective labor agreement (if any).  This is to ensure that its employees and staff shall comply with those personal data related obligations. <\/p>\n<p>Otherwise, there is a very high risk that the Employer shall be fully responsible for the unpermitted processing and disclosing made by its employees without necessary tools to address such violations.  In addition, it is advisable to state clearly in the labor contracts with the employees that they must comply with requirements on personal data protection promulgated by the Employer and the applicable law.<\/p>\n<p>In addition, it is advisable to negotiate and agree with the employees in the relevant labor contracts about the possible data processing made by the Employer again such employees\u2019 personal data for the purpose of employment such as tax information, CVs, health information, etc. This would very likely prevent the future claims from the Employer\u2019s employees over unpermitted processing of employees\u2019 personal data. We will advise in detail if desired subject to the final Decree.   <\/p>\n<p><strong>2.         Contract\/ Agreement with Customers\/ Members<\/strong><\/p>\n<p>It is advisable for the Enterprise and Employer to consider, renegotiate and update all current and future contracts\/ agreements between the Enterprise and its customers\/ members that the Enterprise and Employer is entitled to disclose\/ process a specific list of personal data and the customers\/ members agree to give consents for such disclosure\/ processing.  The Enterprise should, with our support if desired, build a clear list and procedure for collecting, storing, disclosing and otherwise processing personal data of customers\/ members. <\/p>\n<p>***<\/p>\n<p>Please do not hesitate to contact the author Dr. Oliver Massmann under omassmann@duanemorris.com. Dr. Oliver Massmann is the General Director of Duane Morris Vietnam LLC, Member to the Supervisory Board of PetroVietnam Insurance JSC and the only foreign lawyer presenting in Vietnamese language to members of the NATIONAL ASSEMBLY OF VIETNAM.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The issue of personal data processing is getting hotter than ever in this digital age with increasing cases where large conglomerate or even national governments being accused of utilizing citizen\u2019s personal data without consent. This trend makes no exception in Vietnam. So far, the Ministry of Public Security (the &#8220;MPS&#8221;) has finally prepared a Draft &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.duanemorris.com\/vietnam\/2021\/03\/22\/new-draft-decree-on-personal-data-protection-and-cross-border-provision-of-data-the-basic-and-guidance-on-practical-handling\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NEW DRAFT DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE BASICS AND GUIDANCE ON PRACTICAL HANDLING&#8221;<\/span><\/a><\/p>\n","protected":false},"author":24,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[1025,1024],"ppma_author":[1007],"class_list":["post-1158","post","type-post","status-publish","format-standard","hentry","category-vietnam-general","tag-cross-border-provision-of-data","tag-personal-data-protection"],"authors":[{"term_id":1007,"user_id":24,"is_guest":0,"slug":"omassmann","display_name":"Dr. Oliver Massmann","avatar_url":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-content\/uploads\/sites\/19\/2014\/08\/massmannoliver-125x150.jpg","0":null,"1":"","2":"","3":"","4":"","5":"","6":"","7":"","8":""}],"_links":{"self":[{"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/posts\/1158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/comments?post=1158"}],"version-history":[{"count":0,"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/posts\/1158\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/media?parent=1158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/categories?post=1158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/tags?post=1158"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/vietnam\/wp-json\/wp\/v2\/ppma_author?post=1158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}