Vietnam’s much awaited Personal Data Protection Decree: Examining Benefits and Key Challenges

Central Institute for Economic Management (CIEM), Vietnam's Dr. Thao Nguyen Minh examines the current landscape of Vietnam's personal data protection and provides a closer look at the first ever enacted personal data protection degree (Vietnam: Decree No. 13/2023/ND-CP) and its key challenges.

Read the Vietnamese version of this article.

By Dr. Thao Nguyen Minh Central Institute for Economic Management (CIEM), Vietnam

Vietnam has one of the world’s highest growth rates of internet usage and development. As of 2023, the number of Internet users in Vietnam has reached 77.93 million, accounting for 79.1% of the total population. The number of social media users also reached 70 million, equivalent to 71% of the total population. However, as technology rapidly develops, so does the need for personal data protection. Thus, there is a crucial need for the governments to protect their citizens’ personal data to deter unsanctioned use.

Prior to the promulgation of Decree No. 13/2023/ND-CP, Vietnam’s legal system did not have a unified definition of personal data. There were different definitions of personal data in various legal documents, and the provisions regarding personal data protection were fragmented. This resulted in duplication and overlap, making it challenging to implement the legal provisions effectively. According to the Ministry of Public Security (MPS), more than two-thirds of Vietnamese’s personal data is unsecured due to the proliferation of illegal data collection and exchange.

A closer look at Vietnam’s Decree No. 13/2023/ND-CP

The personal data protection decree was issued by the Vietnam government on 17 April 2023, as part of the government’s effort in implementing the National Digital Transformation Programme which aims to accelerate digital transformation to improve the country’s business efficiency and competitiveness. The decree is scheduled to take effect from 1 July 2023, with the Department of Cybersecurity and Hi-tech Crime Prevention under MPS as the key authority of the personal data protection decree.

Below are some of the notable key provisions of the decree.

Key Challenges in implementing the Personal Data Protection Decree

1. Integration of data processes into businesses – While large organisations typically have an existing system that is compliant with international data protection regulations, small and medium-sized businesses face the technical challenge of creating such a process for both data controllers and processors to meet these new regulation requirements. These businesses will need to review their entire process to meet these new data requirements and may not have the technical capabilities to evolve in such a short period of time to meet all the data requests, especially extensive impact assessment and filing requirements from stakeholders.

2. Withholding of personal data information – with the decree stipulating that the data subject has the right to “delete or request deletion of his/her personal data” or “obtain restriction on the processing of his/her personal data”, this creates a challenge for businesses (e.g. airlines and hotels) who have been collecting these personal data in their systems to make these changes quickly.

3. Government agencies to adapt to new technologies and maintain impartiality –governments will also face the challenge and pressure in pivoting to new technologies to meet the new data regulations in areas of data review, inspection and assessment, to identify data protection anomalies and data violation. Additionally, as government agencies themselves are subjects under the inspection of personal data protection, there is a need for all agencies including the governing authority of data protection, MPS, to maintain impartiality in their own internal inspection.

In conclusion, protecting personal data is essential for establishing trust in online services and encouraging participation in the digital transformation process. The issuance of Decree No 13/2013/ND-CP by the Vietnam government is a crucial step towards meeting the demands for personal data protection. However, to fulfil the promise of the personal data protection decree, it will require the MPS to provide a detailed guidance on implementing this decree, for it to properly serve as a foundation for the future development of the law on protection of personal data.

The views and recommendations expressed in this article are solely of the author/s and do not necessarily reflect the views and position of the Tech for Good Institute.

Share this insight

Discover

How is Tech for Good Institute enabling digital economy and society in Southeast Asia?

Cite this article

Thao, N. M. (2023, June 13). Vietnam’s much awaited Personal Data Protection Decree: Examining Benefits and Key Challenges. Tech For Good Institute. Retrieved from https://techforgoodinstitute.org/insights/country-spotlights/vietnams-much-awaited-personal-data-protection-decree-examining-benefits-and-key-challenges/

Keep pace with the digital pulse of Southeast Asia!

Never miss an update or event!

Mouna Aouri

Programme Fellow

Mouna Aouri is an Institute Fellow at the Tech For Good Institute. As a social entrepreneur, impact investor, and engineer, her experience spans over two decades in the MENA region, South East Asia, and Japan. She is founder of Woomentum, a Singapore-based platform dedicated to supporting women entrepreneurs in APAC through skill development and access to growth capital through strategic collaborations with corporate entities, investors and government partners.

Dr Ming Tan

Senior Fellow & Founding Executive Director

Dr Ming Tan is Senior Fellow at the Tech for Good Institute; where she served as founding Executive Director of the non-profit focused on research and policy at the intersection of technology, society and the economy in Southeast Asia. She is concurrently a Senior Fellow at and the Centre for Governance and Sustainability at the National University of Singapore and Advisor to the Founder of the COMO Group, a Singaporean portfolio of lifestyle companies operating in 15 countries worldwide. Ming was previously Managing Director of IPOS International, part of the Intellectual Property Office of Singapore. Prior to joining the public sector, she was Head of Stewardship of the COMO Group.


Ming also serves on the boards of several private companies, Singapore’s National Volunteer and Philanthropy Centre, Singapore Network Information Centre (SGNIC), and on the Digital and Technology Advisory Panel for Esplanade–Theatres on the Bay, Singapore’s national performing arts centre. Her current portfolio spans philanthropy, social impact, sustainability and innovation.