Uploaded by Cody Nguyen

13 2023 ND-CP 564343

advertisement
THE GOVERNMENT OF
VIETNAM
-------
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------
No. 13/2023/ND-CP
Hanoi, April 17, 2023
DECREE
PROTECTION OF PERSONAL DATA
Pursuant to the Law on Government Organization dated June 19, 2015; the Law on amendments to
some Articles of the Law on Government Organization and Law on Local Government Organization
dated November 22, 2019;
Pursuant to Civil Code dated November 24, 2015;
Pursuant to the Law on National Security dated December 03, 2004;
Pursuant to the Cybersecurity Law dated June 12, 2018;
At the request of the Minister of Public Security of Vietnam;
The Government promulgates a Decree on protection of personal data.
Chapter I
GENERAL PROVISIONS
Article 1. Scope and regulated entities
1. This Decree provides for personal data protection and responsibilities of relevant agencies,
organizations and individuals for protection of personal data.
2. This Decree applies to:
a) Vietnamese agencies, organizations and individuals;
b) Foreign authorities, entities and individuals in Vietnam;
c) Vietnamese agencies, organizations and individuals that operate in foreign countries;
d) Foreign agencies, organizations and individuals that directly process or are involved in
processing personal data in Vietnam.
Article 2. Definition of terms
For the purpose of this Decree, the following terms shall be construed as follows:
1. “Personal data” refers to electronic information in the form of symbols, letters, numbers, images,
sounds, or equivalences associated with an individual or used to identify an individual. The personal
data includes general personal data and sensitive personal data.
2. “Information used for identification of an individual" refers to information that results from an
individual's activities and may identify an individual when it is combined with other stored
information and data.
3. General personal data includes:
a) Last name, middle name and first name, other names (if any);
b) Date of birth; date of death or going missing;
c) Gender;
d) Place of birth, registered place of birth; place of permanent residence; place of temporary
residence; current place of residence; hometown; contact address;
dd) Nationality;
e) Personal image;
e) Phone number; ID Card number, personal identification number, passport number, driver’s
license number, license plate, taxpayer identification number, social security number and health
insurance card number;
h) Marital status;
i) Information about the individual’s family relationship (parents, children);
k) Digital account information; personal data that reflects activities and activity history
in cyberspace;
l) Information associated with an individual or used to identify an individual other than that
specified in Clause 4 of this Article.
4. “Sensitive personal data” refers to personal data in association with individual privacy which,
when being infringed, will directly affect an individual's legal rights and interests, including:
a) Political and religious opinions;
b) Health condition and personal information stated in health record, excluding information on
blood group;
c) Information about racial or ethnic origin;
d) Information about genetic data related to an individual's inherited or acquired genetic
characteristics;
dd) Information about an individual’s own biometric or biological characteristics;
e) Information about an individual’s sex life or sexual orientation.
g) Data on crimes and criminal activities collected and stored by law enforcement agencies;
h) Information on customers of credit institutions, foreign bank branches, payment service providers
and other licensed institutions, including: customer identification as prescribed by law, accounts,
deposits, deposited assets, transactions, organizations and individuals that are guarantors at credit
institutions, bank branches, and payment service providers;
i) Personal location identified via location services;
k) Other specific personal data as prescribed by law that requires special protection.
5. “Personal data protection” refers to an act of preventing, detecting and handling violations related
to personal data in accordance with the law.
6. “Data subject” refers to an individual to whom the data relates.
7. “Personal data processing” refers to one or multiple activities that impact on personal data,
including collection, recording, analysis, confirmation, storage, rectification, disclosure,
combination, access, traceability, retrieval, encryption, decryption, copying, sharing, transmission,
provision, transfer, deletion, destruction or other relevant activities.
8. “Consent” of a data subject refers to an act that the data subject permits the processing of his/her
personal data in a clear, voluntary and affirmative manner.
9. “Personal Data Controller” refers to an organization or individual that decides purposes and
means of processing personal data.
10. “Personal Data Processor” refers to an organization or individual that processes data on behalf of
the Personal Data Controller via a contract or agreement with the Personal Data Controller.
11. “Personal Data Controller-cum-Processor” refers to an organization or individual that jointly
decides purposes and means, and directly processes personal data.
12. “Third Party” refers to an organization or individual other than the data subject, Personal Data
Controller, Personal Data Processor, and Personal Data Controller-cum-Processor that is permitted
to process personal data.
13. "Automated processing of personal data” refers to a form of personal data processing performed
by electronic devices with a view to assessing, analyzing and predicting an individual’s activities,
including habits, preference, reliability, behavior, location, trends, capability and other
circumstances.
14. “Outbound transfer of personal data” refers to an act of using cyberspace, electronic devices,
equipment, or other forms to transfer personal data of a Vietnamese citizen to a location outside the
territory of the Socialist Republic of Vietnam or using a location outside the territory of the Socialist
Republic of Vietnam to process personal data of a Vietnamese citizen. To be specific:
a) An organization, enterprise or individual transfers personal data of a Vietnamese citizen to an
overseas organization, enterprise or management department in order to process the data for the
purposes agreed upon by the data subject;
b) The personal data of a Vietnamese citizen is processed by automatic systems outside the territory
of the Socialist Republic of Vietnam of the Personal Data Controller, Personal Data Controller-cumProcessor, Personal Data Processor for the purposes agreed upon by the data subject.
Article 3. Rules for protection of personal data
1. The personal data shall be processed as prescribed by law.
2. The data subject shall be entitled to receive information related to the processing of his/her
personal data, unless otherwise provided for by law.
3. The personal data shall be processed for the purposes that have been registered and declared by
the Personal Data Controller, the Personal Data Processor, the Personal Data Controller-cumProcessor and the Third Party.
4. The collected personal data shall be appropriate for the scope and purposes of processing. The
purchase or sale of personal data shall be prohibited in any form, unless otherwise provided for by
law.
5. The personal data shall be updated and added for the processing purposes.
6. The personal data shall be protected and secured throughout the processing. To be specific, the
personal data shall be protected from violations against regulations on protection of personal data
and prevention of loss, destruction or damage caused by incidents and use of technical measures.
7. The personal data shall be stored within a period of time that is appropriate for the processing
purposes, unless otherwise provided for by law.
8. The Personal Data Controller and the Personal Data Controller-cum-Processor shall comply with
the rules for data processing specified in Clauses 1 through 7 of this Article and prove their
compliance.
Article 4. Handling violations against regulations on protection of personal data
Agencies, organizations and individuals that commit violations against regulations on protection of
personal data, depending on the severity of their violations, may be disciplined, or face
administrative penalties or criminal prosecution according to regulations.
Article 5. State management of personal data protection
The Government shall ensure uniform state management of personal data protection.
Contents of state management include:
1. Requesting competent authorities to promulgate or promulgate within its jurisdiction legal
documents, and directing and organizing the implementation of legal documents on protection of
personal data.
2. Formulating and organizing the implementation of strategies, policies, schemes, projects,
programs and plans for protection of personal data.
3. Providing guidance on measures, procedures and standards of protection of personal data for
agencies, organizations and individuals in accordance with law.
4. Disseminating and educating the law on protection of personal data; communicating and
disseminating skills and knowledge about protection of personal data.
5. Developing and providing training and refresher training for officials, public employees and
persons assigned to protect personal data.
6. Inspecting the observance of law on protection of personal data; handling complaints,
denunciations and violations against regulations on protection of personal data as prescribed by law.
7. Compiling statistics, and giving information and reports on protection of personal data and the
observance of law on personal data protection to competent authorities.
8. Encouraging international cooperation in protection of personal data.
Article 6. Application of Decree on protection of personal data, relevant laws and international
treaties
The personal data protection shall comply with regulations of international treaties to which the
Socialist Republic of Vietnam is a signatory, relevant laws and this Decree.
Article 7. International cooperation in protection of personal data.
1. Developing mechanisms for international cooperation in order to facilitate the effective
enforcement of laws on protection of personal data.
2. Engaging in judicial assistance in protecting personal data by other countries, including
notification, complaints, assistance in investigating and exchanging information, and appropriate
measures for protecting personal data.
3. Organizing conferences and seminars, conducting scientific research and promoting international
cooperation in enforcement of the law on protection of personal data.
4. Organizing bilateral and multilateral meetings to exchange experience in drafting legislation and
having the practice of protection of personal data.
5. Transferring technology serving protection of personal data.
Article 8. Prohibited acts
1. Processing personal data in contravention of regulations of law on protection of personal data.
2. Processing personal data in order to provide information and data against regulations of the
Socialist Republic of Vietnam
3. Processing personal data in order to provide information and data that affect national security,
social order and safety, and legitimate rights and interests of other organizations and individuals.
4. Obstructing protection of personal data by competent authorities.
5. Taking advantage of protection of personal data to commit violations of law.
Chapter II
PERSONAL DATA PROTECTION
Section 1. RIGHTS AND OBLIGATIONS OF DATA SUBJECT
Article 9. Data subject’s rights
1. Right to be informed
The data subject has the right to be informed of his/her personal data processing, unless otherwise
provided for by law.
2. Right to give consent
The data subject has the right to give consent to the processing of his/her personal data, other than
cases specified in Article 17 of this Decree.
3. Right to access personal data
The data subject has the right to access his/her personal data in order to look at, rectify or request
rectification of his/her personal data, unless otherwise provided for by law.
4. Right to withdraw consent
The data subject has the right to withdraw his/her consent, unless otherwise provided for by law.
5. Right to delete personal data
The data subject has the right to delete or request deletion of his/her personal data, unless otherwise
provided for by law.
6. Right to obtain restriction on processing
a) The data subject has the right to obtain restriction on the processing of his/her personal data,
unless otherwise provided for by law.
b) The restriction on the processing of personal data shall be implemented within 72 hours after
receiving request of the data subject, and all personal data that the data subject requests the
restriction, unless otherwise provided for by law.
7. Right to obtain personal data
The data subject has the right to request the Personal Data Controller and the Personal Data
Controller-cum-Processor to provide him/her with his/her personal data, unless otherwise provided
for by law.
8. Right to object to processing
a) The data subject has the right to object to the Personal Data Controller and the Personal Data
Controller-cum-Processor processing his/her personal data in order to prevent or restrict the
disclosure of personal data or the use of personal data for advertising and marketing purposes,
unless otherwise provided for by law.
b) The Personal Data Controller and the Personal Data Controller-cum-Processor shall comply with
the data subject’s request within 72 hours after receiving the request, unless otherwise provided for
by law.
9. Right to file complaints, denunciations and lawsuits
The data subject has the right to file complaints, denunciations and lawsuits as prescribed by law.
10. Right to claim damage
The data subject has the right to claim damage as prescribed by law when there are violations
against regulations on protection of his/her personal data, unless otherwise agreed by parties or
unless otherwise prescribed by law.
11. Right to self-protection
The data subject has the right to self-protection according to regulations in the Civil Code, other
relevant laws and this Decree, or request competent agencies and organizations to implement civil
right protection methods according to regulations in Article 11 of the Civil Code.
Article 10. Data subject’s obligations
1. Protect his/her own personal data; request relevant organizations and individuals to protect his/her
personal data.
2. Respect and protect others’ personal data.
3. Fully and accurately provide his/her personal data when he/she consents to the processing.
4. Participate in dissemination of personal data protection skills.
5. Comply with regulations of law on protection of personal data and prevent violations against
regulations on protection of personal data.
Section 2. PERSONAL DATA PROTECTION THROUGHOUT THE PROCESS OF
PROCESSING
Article 11. Consent of a data subject
1. The consent of the data subject shall be granted to all activities in the processing of his/her
personal data, unless otherwise provided for by law.
2. The consent is only valid when the data subject voluntarily consents and clearly knows the
following contents:
a) Type of personal data;
b) Purposes;
c) Organization or individual permitted to process personal data;
d) Rights and obligations of the data subject.
3. The consent of the data subject shall be expressed in a clear and specific manner in writing, by
voice, by ticking the consent box, by consent syntax via message, by selecting consent settings or by
other forms.
4. The consent must be bound to the same purpose. In case of multiple purposes, the Personal Data
Controller and the Personal Data Controller-cum-Processor shall list these purposes so that the data
subject consents to one or several purposes that have been set out.
5. The consent of the data subject shall be expressed in a format that can be printed and reproduced
in writing, including in electronic or verifiable format.
6. Silence or non-response is not considered as consent.
7. The data subject may give partial or conditional consent.
8. In case of the processing of sensitive personal data, the data subject shall receive notification of
thereof.
9. The consent of the data subject is valid until the data subject has other decisions or the competent
authority makes written request.
10. In case of a dispute, the Personal Data Controller and the Personal Data Controller-cumProcessor shall prove consent of the data subject.
11. Via the authorization in accordance with regulations of the Civil Code, an organization or
individual may act on behalf of the data subject to carry out procedures related to the processing of
his/her personal data with the Personal Data Controller and the Personal Data Controller-cumProcessor in case the data subject knows and consents as prescribed in Clause 3 of this Article,
unless otherwise provided for by law.
Article 12. Consent withdrawal
1. The withdrawal of consent shall not affect the lawfulness of the processing to which consent was
given before it is withdrawn.
2. The withdrawal of consent shall be expressed in a format that can be printed and reproduced in
writing, including in electronic or verifiable format.
3. When obtaining request for consent withdrawal from the data subject, the Personal Data
Controller and the Personal Data Controller-cum-Processor shall notify the data subject of potential
consequences and damage if she/he withdraws his/her consent.
4. After complying with regulations in Clause 2 of this Article, the Personal Data Controller, the
Personal Data Processor, the Personal Data Controller-cum-Processor and the Third Party shall stop
and request relevant organizations and individuals to stop processing the personal data of the data
subject who has withdrawn his/her consent.
Article 13. Notification of personal data processing
1. The notification shall be made once before the personal data is processed.
2. The following contents of the processing of personal data shall be notified to the data subject:
a) Processing purposes;
b) Type of used personal data related to the purposes specified in Point a Clause 2 of this Article;
c) Method of processing personal data;
d) Information on other organizations and individuals related to the processing purposes specified in
point a Clause 2 of this Article;
dd) Undesirable consequences and damage that may occur;
e) Starting and ending time.
3. The notification to the data subject shall be expressed in a format that can be printed and
reproduced in writing, including in electronic or verifiable format.
4. The Personal Data Controller and the Personal Data Controller-cum-Processor are not required to
comply with regulations specified in Clause 1 of this Article in the following cases:
a) The data subject knows and fully consents to the contents specified in Clauses 1 and 2 of this
Article before permitting the Personal Data Controller and the Personal Data Controller-cumProcessor to collect his/her personal data in accordance with regulations in Article 9 of this Decree;
b) The personal data is processed by the competent state agency with a view to serving operations
by such agency as prescribed by law.
Article 14. Personal data provision
1. The data subject has the right to request the Personal Data Controller or the Personal Data
Controller-cum-Processor to provide him/her with his/her personal data.
2. The Personal Data Controller or the Personal Data Controller-cum-Processor:
a) is permitted to provide personal data of the data subject for other organizations and individuals
when obtaining consent from the data subject, unless otherwise provided for by law;
b) provides the data subject’s personal data for other organizations and individuals on behalf of the
data subject if approved and authorized by the data subject, unless otherwise provided for by law;
3. b) The Personal Data Controller or the Personal Data Controller-cum-Processor shall provide the
personal data of the data subject within 72 hours after receiving his/her request, unless otherwise
provided for by law.
4. The Personal Data Controller and the Personal Data Controller-cum-Processor shall not provide
the personal data in the following cases:
a) It causes harm to the national security, social order and safety;
b) The provision of personal data may affect the safety, physical or mental health of other persons;
c) The data subject does not consent to provision of his/her personal data, and does not permit or
authorize any Third Party to receive his/her personal data.
5. Methods of requesting for provision of personal data:
a) The data subject shall directly come or authorize another person to come to the office of the
Personal Data Controller or the Personal Data Controller-cum-Processor to request for provision of
his/her personal data.
The request-receiving person shall be responsible for instructing the requesting organization or
individual to fill in a personal data request form.
If the requesting organization or individual is illiterate or disabled, and cannot write the request, the
request-receiving person shall be responsible for assisting such organization or individual in filling
in the personal data request form;
b) The request form for provision of personal data according to forms No. 01 and No. 02 specified
in the Appendix of this Decree shall be sent electronically, by post or by fax to the Personal Data
Controller, the Personal Data Controller-cum-Processor.
6. The personal data request form shall be made in Vietnamese language, including the following
main contents:
a) Full name; place of residence, address; ID Card number or passport number of the requesting
person; fax number, phone number, email address (if any);
b) Requested personal data, which specifies name of documents,
c) Methods of providing personal data;
d) Reasons and purposes for provision of personal data.
7. In case of request for provision of personal data specified in Clause 2 of this Article, a written
consent of the relevant individual or organization shall be attached.
8. Receipt of the request for provision of personal data
a) The Personal Data Controller or the Personal Data Controller-cum-Processor shall be responsible
for receiving requests for provision of personal data, and monitoring the process and the list of
personal data provided upon request;
b) The Personal Data Controller and the Personal Data Controller-cum-Processor shall notify and
instruct the requesting organization or individual to come to the competent authority or notify the
inability to provide personal data in case the requested personal data falls outside of
their jurisdiction.
9. Settlement of the request for provision of personal data
When receiving a valid request for provision of personal data, the Personal Data Controller and the
Personal Data Controller-cum-Processor that are responsible for providing personal data shall notify
the deadline, location, methods of providing personal data; actual costs for printing, copying,
photocopying and sending information by post, by fax (if any) and payment method and term; and
provide personal data according to procedures specified in this Article.
Article 15. Rectification of personal data
1. A data subject has the right to:
a) Access his/her personal data in order to view and rectify it after the Personal Data Controller and
the Personal Data Controller-cum-Processor collects the data under his/her consent, unless otherwise
provided for by law.
b) Request the Personal Data Controller and the Personal Data Controller-cum-Processor to rectify
his/her personal data in case he/she cannot directly rectify his/her personal data due to technical
reason or other reasons.
2. The Personal Data Controller and the Personal Data Controller-cum-Processor shall rectify
personal data of the data subject after obtaining his/her consent when possible or according to
regulations of specialized law. In case it is impossible to rectify personal data, the Personal Data
Controller and the Personal Data Controller-cum-Processor shall notify the data subject after 72
hours from the time of receipt of his/her request.
3. The Personal Data Processor and the Third Party may rectify the personal data of the data subject
after the Personal Data Controller and the Controller and the Personal Data Processor consent in
writing and obtain consent from the data subject.
Article 16. Storage, deletion and destruction of personal data
1. The data subject has the right to request the Personal Data Controller and the Personal Data
Controller-cum-Processor to delete his/her personal data in the following cases:
a) The data subject no longer finds the data necessary for the purposes for which it was collected
under his/her consent and he/she accepts any damage that may be caused by the deletion;
b) The data subject withdraws consent;
c) The data subject objects to the processing of his/her personal data and the Personal Data
Controller and the Personal Data Controller-cum-Processor do not have sound reasons for
continuation in the processing;
d) The personal data is processed for purposes other than those that the data subject gives the
consent or the processing of personal data is a violation against regulations of law;
dd) The personal data shall be deleted as prescribed by law.
2. The personal data shall not be deleted at the request of the data subject in the following cases:
a) The deletion of personal data is prohibited by law;
b) The personal data is processed by the competent state agency with a view to serving operations
by such agency as prescribed by law.
c) The personal data has been disclosed as prescribed by law.
d) The personal data is processed with a view to serving law, scientific research and statistics as
prescribed by law;
dd) The personal data shall not be deleted in the event of a state of emergency on national defense,
security, social order and safety, major disasters, or dangerous epidemics; when there is a risk of
threatening security and national defense but not to the extent of declaring a state of emergency; to
prevent and combat riots and terrorism, to prevent and combat crimes and law violations according
to regulations of law;
e) It is required to respond to emergent cases that threaten the life and health or the safety of the data
subject or other persons.
3. In case of full division, partial division, merger, consolidation or dissolution of an enterprise, the
personal data shall be transferred in accordance with law.
4. In case of full division, partial division or merger of an agency, organization or administrative
unit, and reorganization or transformation of ownership of a state-owned enterprise, the personal
data shall be transferred in accordance with law.
5. b) The deletion of personal data shall be implemented within 72 hours after receipt of the data
subject’s request, and all personal data collected by the Personal Data Controller and the Personal
Data Controller-cum-Processor, unless otherwise provided for by law.
6. The Personal Data Controller, the Personal Data Controller-cum-Processor, the Personal Data
Processor and the Third Party shall store personal data in forms in conformity with their operations
and adopt measures for protecting the personal data as prescribed by law.
7. The Personal Data Controller, the Personal Data Controller-cum-Processor, the Personal Data
Processor and the Third Party shall permanently delete personal data in the following cases:
a) The personal data is processed for unintended purposes or they have accomplished their
processing purposes under the consent of the data subject;
b) The storage of personal data is no longer necessary for their operations.
c) The Personal Data Controller, the Personal Data Controller-cum-Processor, the Personal Data
Processor and the Third Party are dissolved or no longer operate or declare bankruptcy or terminate
their business activities in accordance with the law.
Article 17. Personal data processing without the consent of data subject
1. The personal data shall be processed to protect the life and health of the data subject or others in
an emergency situation. The Personal Data Controller, the Personal Data Controller-cum-Processor,
the Personal Data Processor and the Third Party shall be responsible for proving such situation.
2. Disclosure of personal data in accordance with the law;
3. Processing of personal data by competent regulatory authorities in the event of a state of
emergency regarding national defense, security, social order and safety, major disasters, or
dangerous epidemics; when there is a threat to security and national defense but not to the extent of
declaring a state of emergency; to prevent and fight riots and terrorism, crimes and law violations
according to the provisions of law;
4. The personal data shall be processed to fulfill obligations under contracts the data subjects with
relevant agencies, organizations and individuals as prescribed by law;
5. The personal data shall be processed to serve operations by regulatory authorities as prescribed by
relevant laws.
Article 18. Processing of personal data obtained from audio and video recording activities in
public places
Competent agencies and organizations may make audio and video recording and process personal
data obtained from audio or video recording activities in public places in order to protect national
security, social order and safety, legitimate rights and interests of organizations and individuals as
prescribed by law without the consent of the data subjects. When making audio and video recording,
competent agencies and organizations shall notify the data subjects that such data subjects are being
recorded, unless otherwise provided for by law.
Article 19. Processing of personal data of individuals who are declared missing or deceased
1. The processing of personal data related to the personal data of an individual who is declared
missing or deceased is subject to the consent of his/her spouse or adult children, or his/her parents if
he/she has no spouse or child, except for cases specified in Articles 17 and 18 of this Decree.
2. In the absence of all the persons mentioned in Clause 1 of this Article, it is considered that there is
no consent.
Article 20. Processing of children's personal data
1. The children’s personal data shall be processed in the manner that the rights and the best interests
of the children are protected.
2. The processing of personal data of a child is subject to his/her consent if he/she is seven years old
or above and the consent of his/her parents or guardian(s), except for cases specified in Article 17 of
this Decree. The Personal Data Controller, Personal Data Processor, Personal Data Controller-cumProcessor and the Third Party shall verify the age of the child before processing his/her personal
data.
3. The processing of the child’s personal data shall be stopped and the personal data shall be
permanently deleted or destroyed in the following cases:
a) The personal data is processed for unintended purposes or the processing purposes have been
accomplished under the consent of the data subject, unless otherwise provided for by law;
b) The child’s parent or guardian withdraws the consent to the processing of the child’s personal
data, unless otherwise provided for by law;
c) There are sufficient grounds to prove that the processing of the child’s personal data affects
legitimate rights and interests of the child at the request of the competent authority, unless otherwise
provided for by law;
Article 21. Protection of personal data upon provision of marketing and advertising services
1. Organizations and individuals that provide marketing and advertising services may only use
personal data of customers collected through their business activities to provide marketing and
advertising services with the consent of the data subjects.
2. The processing of personal data of customers for provision of marketing and advertising services
is subject to the consent of such customers and on the basis that they know contents, methods, forms
and frequency of advertising services.
3. Organizations and individuals that provide marketing and advertising services shall prove that the
use of personal data of customers meets regulations specified in Clauses 1 and 2 of this Article.
Article 22. Illegally collecting, transferring, purchasing and selling personal data
1. Organizations and individuals related to the processing of personal data shall adopt measures for
protecting personal data in order to prevent illegal collection of personal data from their systems and
service equipment.
2. Installation of software systems, implementation of technical measures or organization of
collection, transfer, purchase or sale of personal data without the consent of the data subject is a
violation of law.
Article 23. Notification of violations against regulations on protection of personal data
1. In case of detection of a violation against regulations on protection of personal data, the Personal
Data Controller or the Personal Data Controller-cum-Processor shall notify the Ministry of Public
Security (Department of Cybersecurity and Hi-tech Crime Prevention) within 72 hours after such
violation is committed according to Form No. 03 in the Appendix to this Decree. If the notification
is given after 72 hours, the reason for the late notification shall be provided.
2. The Personal Data Processor shall notify the Personal Data Controller as quickly as possible after
detecting the violation against regulations on protection of personal data.
3. Notification contents:
a) Description of the nature of the violation, including: time, place, violation, organization,
individual, types of personal data and the amount of relevant data;
b) Contact details of the employee (s) assigned to protect the data or organizations or individuals
that are responsible for protecting personal data;
c) Description of consequences and damage that may occur;
d) Description of measures for handling and minimizing the harm caused by the violation.
4. If it is impossible to notify all the information specified in Clause 3 of this Article, the notification
may be given every time a piece of information is available.
5. The Personal Data Controller, the Personal Data Controller-cum-Processor shall make a written
confirmation of the violation against regulations on protection of personal data, and cooperate with
the Ministry of Public Security (Department of Cybersecurity and Hi-tech Crime Prevention) in
handling such violation.
6. Organizations and individuals shall notify the Ministry of Public Security (Department of
Cybersecurity and Hi-tech Crime Prevention) when detecting the following cases:
a) Violations are detected;
b) Personal data is processed for unintended purposes or against the original agreement between the
data subject and the Personal Data Controller, the Personal Data Controller-cum-Processor or in
contravention of regulations of law;
c) The data subject's rights are not protected or not properly exercised;
d) Other cases as prescribed by law
Section 3. ASSESSMENT OF IMPACT AND OUTBOUND TRANSFER OF PERSONAL
DATA
Article 24. Assessment of impact of personal data processing
1. The Personal Data Controller and the Personal Data Controller-cum-Processor shall make and
store their dossiers on assessment of impact of personal data processing from the time of starting to
process personal data.
A dossier on assessment of impact of personal data processing includes:
a) Contact information and details of the Personal Data Controller and the Personal Data Controllercum-Processor;
b) Name and contact details of the organization or employee assigned to protect personal data of the
Personal Data Controller and the Personal Data Controller-cum-Processor;
c) Processing purposes;
d) Types of personal data to be processed;
dd) Data-receiving organization or individual, including the organization or individual that is located
or lives outside the territory of the Socialist Republic of Vietnam;
e) Cases of outbound transfer of personal data;
g) Duration of processing of personal data; estimated duration of deletion or destruction of personal
data (if any);
h) Description of measures for protecting personal data;
i) Assessment of impact of personal data processing; undesirable consequences and damage that
may occur, measures for reducing or removing such consequences and damage.
2. The Personal Data Processor shall make and store the dossier on the assessment of impact of
personal data processing in case the Personal Data Processor executes a contract with the Personal
Data Controller. A dossier on assessment of impact of personal data processing of the Personal Data
Processor includes:
a) Contact information and details of the Personal Data Processor;
b) Name and contact details of the organization or employee assigned to protect personal data of the
Personal Data Processor;
c) Description of processing of personal data and types of personal data to be processed under a
contract with the Personal Data Controller;
d) Duration of processing of personal data; estimated duration of deletion or destruction of personal
data (if any);
dd) Cases of outbound transfer of personal data;
e) General description of measures for protecting personal data;
g) Undesirable consequences and damage that may occur, measures for reducing or removing such
consequences and damage.
3. The dossier on assessment of impact of personal data processing of the Personal Data Controller,
the Personal Data Controller-cum-Processor or the Personal Data Processor specified in Clause 1
and Clause 2 of this Article shall be made in writing that is valid.
4. The dossier on assessment of impact of personal data processing shall be always available in
order to serve inspection and assessment by the Ministry of Public Security and the Ministry of
Public Security (Department of Cybersecurity and Hi-tech Crime Prevention) shall receive 01
authentic copy according to Form No. 04 in the Appendix of this Decree within 60 days from the
date of processing of personal data.
5. The Ministry of Public Security (Department of Cybersecurity and Hi-tech Crime Prevention)
shall make assessment and request the Personal Data Controller, the Personal Data Controller-cumProcessor and the Personal Data Processor to complete their dossiers on assessment in case the
assessment is not complete and accurate according to regulations.
6. The Personal Data Controller, the Personal Data Controller-cum-Processor and the Personal Data
Processor shall update and amend their dossiers on assessment of impact of personal data processing
when there is any change of contents submitted to the Ministry of Public Security (Department of
Cybersecurity and Hi-tech Crime Prevention) according to Form No. 05 in the Appendix of this
Decree.
Article 25. Outbound transfer of personal data
1. A Vietnamese citizen’s personal data shall be transferred abroad in case where the Sender makes
a dossier on assessment of impact of outbound transfer of personal data and carries out the
procedures specified in Clauses 3, 4 and 5 of this Article. The senders include the Personal Data
Controller, the Personal Data Controller-cum-Processor, the Personal Data Processor and the Third
Party.
2. A dossier on assessment of impact of outbound transfer of personal data includes:
a) Contact information and details of the Sender and the Receiver;
b) Full name and contact details of an organization or individual under the Sender involved in
sending and receiving a Vietnamese citizen’s personal data;
c) Description and explanation about objectives of the processing of a Vietnamese Citizen’s
personal data after the personal data is transferred abroad;
d) Description and clarification of type of personal data to be transferred abroad;
dd) Description and explanation about the observance of regulations on protection of personal data
in this Decree, detailed measures for protecting personal data;
e) Assessment of impact of personal data processing; undesirable consequences and damage that
may occur, measures for reducing or removing such consequences and damage.
g) Consent of the data subject according to regulations in Article 11 of this Decree when he/she is
informed of the mechanism for feedback and complaint in case of arising problems or requests;
h) Document that shows obligations and responsibilities between the Senders and the Receivers for
processing of a Vietnamese Citizen’s personal data.
3. A dossier on assessment of impact of outbound transfer of personal data shall be always available
in order to serve inspection and assessment by the Ministry of Public Security.
The Sender shall send 01 authentic copy of the assessment to the Ministry of Public Security
(Department of Cybersecurity and Hi-tech Crime Prevention) according to Form No. 06 in the
Appendix of this Decree within 60 days from the date of processing of personal data.
4. The Sender shall notify the Ministry of Public Security (Department of Cybersecurity and Hi-tech
Crime Prevention) of information about the data transfer and contact details of the organization or
individual in charge of such transfer in writing after the personal data is successfully transferred.
5. The Ministry of Public Security (Department of Cybersecurity and Hi-tech Crime Prevention)
shall make assessment and request the Sender to complete the dossier on assessment of impact of
outbound transfer of personal data in case the assessment is not complete and accurate according to
regulations.
6. The Sender shall update and amend the dossier on assessment of impact of outbound transfer of
personal data when there is any change of contents submitted to the Ministry of Public Security
(Department of Cybersecurity and Hi-tech Crime Prevention) according to Form No. 05 in the
Appendix of this Decree. The duration for completion of the dossier on assessment for the Sender is
10 days from the date of request.
7. According to specific situation, the Ministry of Public Security shall decide to inspect the
outbound transfer of personal data once a year, unless it detects violations against the law on
protection of personal data in this Decree or a Vietnamese citizen's personal data is leaked or lost.
8. The Ministry of Public Security shall decide to request the Sender to stop transferring personal
data abroad in the following cases:
a) It is detected that the transferred personal data is used for activities that violate the interests and
national security of the Socialist Republic of Vietnam.
b) The Sender does not comply with regulations in Clause 5 and Clause 6 of this Article;
c) A Vietnamese citizen's personal data is leaked or lost.
Section 4. MEASURES AND CONDITIONS FOR PROTECTION OF PERSONAL DATA
Article 26. Personal data protection measures
1. Measures for protecting personal data shall be adopted from the beginning of and throughout the
processing of personal data.
2. Measures for protecting personal data include:
a) Management measure adopted by an organization or individual related to processing of personal
data;
b) Technical measure adopted by an organization or individual related to processing of personal
data;
c) Measure adopted by a competent authority according to regulations in this Decree and relevant
law;
d) Investigation and procedure measures adopted by a competent authority;
dd) Other measures as prescribed by law.
Article 27. General personal data protection
1. Adopt measures mentioned in Clause 2 Article 26 of this Decree.
2. Formulate and promulgate regulations on protection of personal data, which specify tasks to be
performed in accordance with this Decree.
3. Encourage application of standards of personal data protection in conformity with fields,
industries and activities related to the processing of personal data.
4. Inspect cybersecurity for systems, means and equipment for processing of personal data before
processing, permanent deletion or destruction of devices containing personal data.
Article 28. Sensitive personal data protection
1. Adopt measures mentioned in Clause 2 Article 26 and Article 27 of this Decree.
2. Appoint a department with the function of protecting personal data and personnel in charge of
protection of personal data, and exchange information about the department and individual in charge
of protection of personal data with the personal data protection authority. Exchange information
about the individual in charge of protection in case the Personal Data Controller, the Personal Data
Controller-cum-Processor, the Personal Data Processor or the Third Party is an individual.
3. Notify the data subject of the processing of his/her sensitive personal data, except for cases
specified in Clause 4, Article 13, Article 17 and Article 18 of this Decree.
Article 29. Personal data protection authority and National Portal on personal data
protection.
1. The personal data protection authority is the Department of Cybersecurity and Hi-tech Crime
Prevention under Ministry of Public Security that assists the Ministry of Public Security in
performing state management of personal data protection.
2. National Portal on personal data protection:
a) Provide information on guidelines and policies of the Communist Party and the State's laws on
protection of personal data;
b) Disseminate policies and laws on protection of personal data;
c) Update information and situation of protection of personal data;
d) Receive electronic information, documents and data about protection of personal data;
dd) Provide information on results of assessment of protection of personal data by relevant agencies,
organizations and individuals;
e) Receive notification of violations against regulations on protection of personal data;
g) Issue warning and cooperate in warning about risks and acts that infringe personal data as
prescribed by law.
h) Handle violations against regulations on protection of personal data as prescribed by law;
i) Perform other activities according to regulations of law on protection of personal data.
Article 30. Conditions for assurance about protection of personal data
1. Personal data protecting forces include:
a) Personal data protecting forces that are allocated in the personal data protection authority.
b) Departments and personnel in charge of protection of personal data that are appointed in
agencies, organizations and enterprise in order to comply with regulations on protection of personal
data;
c) Organizations and individuals that are encouraged to protect personal data;
d) The Ministry of Public Security shall develop specific programs and plans to develop human
resources for protection of personal data.
2. Agencies, organizations and individuals shall be responsible for disseminating knowledge and
skills in order to raise awareness of protection of personal data for agencies, organizations and
individuals.
3. Facilities and conditions for operation by the personal data protection authority shall be ensured.
Article 31. Funding for protection of personal data
1. The financial sources for protection of personal data include state budget; donation from domestic
and foreign agencies, organizations and individuals; revenue from provision of personal data
protection services; international aid and other legal sources of revenue.
2. The funding for protection of personal data of state agencies shall be provided by the state budget
and included in annual state budget estimates. Management and use of the funding from the state
budget shall comply with the law on state budget.
3. The funding for protection of personal data of organizations and enterprises shall be allocated by
such organizations and enterprises according to regulations.
Chapter III
RESPONSIBILITIES OF AGENCIES, ORGANIZATIONS AND INDIVIDUALS
Article 32. Responsibility of the Ministry of Public Security
1. Assist the Government in ensuring uniform state management of personal data protection.
2. Provide guidance on and give protection of personal data and rights of the data subject from
violations against law on protection of personal data, propose promulgation of standards of personal
data protection and production of applicable recommendations.
3. Build, manage and operate the National Portal on personal data protection.
4. Assess the results of personal data protection by relevant agencies, organizations and individuals.
5. Receive dossiers, forms and information on protection of personal data according to regulations
of this Decree.
6. Adopt measures and conduct research to innovate protection of personal data, promote
international cooperation in protection of personal data.
7. Conduct inspection, and handle complaints, denunciations and violations against regulations on
protection of personal data as prescribed by law.
Article 33. Responsibility of the Ministry of Information and Communications
1. Direct media agencies, press agencies, organizations and enterprises under its management to
protect personal data according to regulations of this Decree.
2. Develop, provide guidance and implement measures for protecting personal data, ensure
cyberinformation security for personal data in information and communication activities according
to assigned tasks and functions.
3. Cooperate with the Ministry of Public Security in inspecting and handling violations against law
on protection of personal data.
Article 34. Responsibility of the Ministry of National Defense
Manage, inspect, supervise, handle violations and apply regulations on protection of personal data to
agencies, organizations and individuals under its management according to regulations and assigned
tasks and functions.
Article 35. Responsibility of the Ministry of Science and Technology
1. Cooperate with the Ministry of Public Security in developing the personal data protection
standards and producing recommendations for application of such standards.
2. Research and discuss measures for protecting personal data to keep up with the development of
science and technology with the Ministry of Public Security
Article 36. Responsibilities of ministries, ministerial-level agencies and Government-attached
agencies
1. Perform state management of personal data protection for sectors and fields under their
management in accordance with the law on protection of personal data.
2. Develop and implement contents and tasks in protection of personal data in this Decree.
3. Amend regulations on protection of personal data in development and implementation of tasks by
ministries and central authorities.
4. Allocate funding for protection of personal data according to current state budget hierarchy.
5. Issue list of open data in accordance with regulations on protection of personal data.
Article 37. Responsibilities of the People's Committees of provinces and central-affiliated cities
(herein referred to as "the People's Committees of provinces ")
1. Perform state management of personal data protection for sectors and fields under their
management in accordance with the law on protection of personal data.
2. Impose regulations on protection of personal data in this Decree.
3. Allocate funding for protection of personal data according to current state budget hierarchy.
4. Issue list of open data in accordance with regulations on protection of personal data.
Article 38. Responsibility of Personal Data Controllers
1. Implement organizational and technical measures and appropriate safety and security measures to
prove that the personal data is processed in accordance with regulations of the law on protection of
personal data, review and update these measures when necessary.
2. Record and store log of the processing of personal data.
3. Notify violations against regulations on protection of personal data according to regulations in
Article 23 of this Decree.
4. Select an appropriate Personal Data Processor with specific tasks and only work with the Personal
Data Processor that has appropriate measures for protecting personal data.
5. Protect the rights of data subjects according to regulations in Article 9 of this Decree.
6. Be responsible to the data subject for damage caused by the processing of personal data.
7. Cooperate with the Ministry of Public Security and competent authorities in protecting personal
data and providing information serving investigation and handling of violations against the law on
protection of personal data.
Article 39. Responsibility of Personal Data Processors
1. Only receive personal data after having a contract or agreement on the processing of personal data
with the Personal Data Controller.
2. Process personal data under the contract or agreement concluded with the Personal Data
Controller.
3. Fully implement measures for protecting personal data specified in this Decree and other relevant
legal documents.
4. Be responsible to the data subject for damage caused by the processing of personal data.
5. Delete or return all personal data to the Personal Data Controller after completing the processing.
6. Cooperate with the Ministry of Public Security and competent authorities in protecting personal
data and providing information serving investigation and handling of violations against the law on
protection of personal data.
Article 40. Responsibility of Personal Data Controller-cum-Processors
Comply with all regulations on responsibilities of the Personal Data Controller and the Personal
Data Processor.
Article 41. Responsibility of the Third Party
Comply with all regulations on responsibilities for processing personal data according to regulations
in this Decree.
Article 42. Responsibilities of relevant organizations and individuals
1. Adopt measures for protecting their personal data, take responsibility for the accuracy of the
personal data provided.
2. Comply with regulations on protection of personal data in this Decree.
3. Promptly notify the Ministry of Public Security of violations related to protection of personal
data.
4. Cooperate with the Ministry of Public Security in handling violations related to protection of
personal data.
Chapter IV
IMPLEMENTATION PROVISION
Article 43. Effect
1. This Decree comes into effect from July 01, 2023.
2. Micro-enterprises, small enterprises, medium-sized enterprises, startup companies have the right
to opt for exemption from regulations on appointment of individuals and departments to protection
of personal data for the first 2 years from the date of establishment.
3. With regard to micro-enterprises, small enterprises, medium-sized enterprises, startup companies
that directly engage in the processing of personal data, regulations in Clause 2 of this Article shall
not be applied.
Article 44. Responsibility for implementation
1. The Minister of Public Security shall urge, inspect and provide guidance on the implementation of
this Decree.
2. Ministers, heads of ministerial agencies, heads of Governmental-attached agencies and the
Presidents of the People’s Committees of provinces and central-affiliated cities shall be responsible
for the implementation of this Decree./.
ON BEHALF OF THE GOVERNMENT
PP. THE PRIME MINISTER
DEPUTY PRIME MINISTER
Tran Luu Quang
APPENDIX
(Issued together with the Government’s Decree No. 13/2023/ND-CP dated April 17, 2023)
Form No.01
Personal data request form (for individuals)
Form No.02
Personal data request form (for organizations and enterprises)
Form No.03
Notification of violations against regulations on protection of personal data
Form No.04
Notification of submission of dossier on assessment of impact of personal data
processing
Form No.05
Notification of change in contents of dossier
Form No.06
Dossier on assessment of impact of outbound transfer of personal data
Form No. 01
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------
……, date….month….year….
PERSONAL DATA REQUEST FORM
(for individuals)
To: …………………………………….
1. Full name of requesting individual: ……………………………………………..……………
………………………………………………….……………………………………………………
2. Representative/Guardian 1:…………………………………………………………………….
2. ID Card/passport number …………………………………………………..
Date of issue …. /…… /….. Place of issue …………………………………………………..
4. Address 2: ……………………………………………………………………………………..
5. Phone number 3………………………….; Fax…………………; E-mail: …………………
6. Requested personal data 4: ………………………………………………………………….
7. Purposes: ………………………………………………………………………..
8. Request for personal data made for:
a) For the first time
b) Other: For the …. time
9. Number of request forms 5:
10. Methods of receiving personal data:
□ In person
□ By post (receiving address): ……………………………………………………………
□ By fax (fax number): ……………………………………………………………………………
□ By email (email address): ……………………………………………………………
□ Others: ………………………………………………………………………………..
11. Attached documents (if available): ....
REQUESTING INDIVIDUAL
(Signature and full name)
_____________________
1
Representative/Guardian 1 of the requesting individual who is a minor, has restricted capacity for
civil acts, is incapable of civil acts or is a person with limited cognition or behavior
control…according to regulations in Civil Code
2
Address of the representative/guardian.
3
Phone number/fax/email of the representative/guardian.
4
Name of the data owner and relevant information to be provided.
5
Printed, copied or photocopied request forms or data file.
Form No. 02
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
--------------….. ……, date….month….year….
PERSONAL DATA REQUEST FORM
(for organizations and enterprises)
To: …………………………………….
1. Name of organization/enterprise: ……………………………………………………………
………………………………………………………………………………………………………
2. Representative 1 …………………………………………………………………..
3. ID Card/passport number …………………………………………………..
Date of issue …. /…… /….. Place of issue …………………………………………………..
4. Address of headquarter of the organization/enterprise: …………………………………
………………………………………………………………………………………………………
5. Phone number 2………………………….; Fax…………………; E-mail: ………………….
6. Requested personal data: ……………………………………………………………….
7. Purposes: ………………………………………………………………………..
8. Request for personal data made for:
a) For the first time
b) Other: For the…time
9. Number of request forms 3: ………………………………………………………………….
10. Methods of receiving documents:
□ In person
□ By post (receiving address): ……………………………………………………………
□ By fax (fax number): ……………………………………………………………………………
□ By email (email address): ……………………………………………………………
□ Others: ………………………………………………………………………………..
11. Attached documents (if available): ....
REPRESENTATIVE 4
(Signature and full name)
__________________________
1
Representative of the organization/enterprise according to regulations in Civil Code.
2
Phone number/fax/email of the representative.
3
Printed, copied or photocopied request forms or data file.
4
Representative of the organization or enterprise (signature and full name) and seal of the
organization/enterprise.
Form No. 03
NAME OF ORGANIZATION
------No:
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
--------------…., date….month….year….
NOTIFICATION
VIOLATIONS AGAINST REGULATIONS ON PROTECTION OF PERSONAL DATA
To: the Ministry of Public Security
(Department of CyberSecurity and Hi-tech Crime Prevention, the Ministry of Public Security)
Complying with regulations on protection of personal data , ……………………… 1 submits a
dossier on assessment of impact of personal data processing to the Ministry of Public Security. To
be specific:
1. Information on an organization/enterprise
- Name of the organization/enterprise: …………………………………………………………
- Address of the headquarter:……………………………………………………………………
- Address of the transaction office:………………………………………………………………
- Establishment Decision/Enterprise Registration Certificate/Business Registration
Certificate/Investment Certificate No:….. issuing authority ........date of issue......place of issue….
- Phone number:…………………………….. Website …………………………………………
- Personnel in charge of protection of personal data:
Full name: …………………………………………………………………………………………
Title: ……………………………………………………………………………………………….
Phone number (fixed and mobile): ……………………………………………………………
Email: ………………………………………………………………………………………………
2. Violations against regulations on protection of personal data
- Time: ………………………………………………………………………………………………
- Location: ………………………………………………………………………………………….
- Violation(s): ……………………………………………………………………………………….
- Organization, individual, types of personal data and the quantity of relevant data:
- Personnel in charge of protection of personal data: …………………………………………
Full name: ………………………………………………………………………………………….
Title: …………………………………………………………………………………………………
Phone number (fixed and mobile): ………………………………………………………………
Email: ………………………………………………………………………………………………
- Consequences: ………………………………………………………………………………….
- Measures to be taken: ………………………………………………………………………….
3. Attached documents
1. ……………………………………………………………………………………………………
2. ……………………………………………………………………………………………………
4. Commitment
(Name of agency, organization or enterprise) commits to assume legal responsibility for the
accuracy and legitimacy of provided information and attached documents.
ON BEHALF OF ORGANIZATION
OR ENTERPRISE
(Signature, full name and seal)
__________________________
1
Name of organization or enterprise
Form No. 04
NAME OF ORGANIZATION
------No:
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
--------------…., date….month….year….
NOTIFICATION
SUBMISSION OF DOSSIER ON ASSESSMENT OF IMPACT OF PERSONAL DATA
PROCESSING
To: the Ministry of Public Security
(Department of CyberSecurity and Hi-tech Crime Prevention, the Ministry of Public Security)
Complying with regulations on protection of personal data, ……………………… 1 submits a
dossier on assessment of impact of personal data processing to the Ministry of Public Security. To
be specific:
1. Information on organization or enterprise
- Name of organization or enterprise: ……………………………………………………………
- Address of the headquarter:……………………………………………………………………..
- Address of the transaction office:……………………………………………………………….
- Establishment Decision/Enterprise Registration Certificate/Business Registration
Certificate/Investment Certificate No:….. issuing authority ........date of issue......place of issue….
- Phone number:…………………………….. Website ………………………………………….
- Personnel in charge of protection of personal data: ………………………………………….
Full name: …………………………………………………………………………………………..
Title: ………………………………………………………………………………………………….
Phone number (fixed and mobile): ……………………………………………………………….
Email: …………………………………………………………………………………………………
2. Dossier on assessment of impact of personal data processing
1. ………………………………………………………………………………………………………
2. ………………………………………………………………………………………………………
3. Commitment
(Name of agency, organization or enterprise) commits to assume legal responsibility for the
accuracy and legitimacy of the dossier on assessment of impact of personal data processing and
attached documents.
ON BEHALF OF ORGANIZATION
OR ENTERPRISE
(Signature, full name and seal)
__________________________
­1
Name of organization or enterprise
Form No. 05
NAME OF ORGANIZATION
-------
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
--------------…., date….month….year….
No:
NOTIFICATION OF
CHANGE IN CONTENTS OF DOSSIER 1
To: the Ministry of Public Security
(Via Department of CyberSecurity and Hi-tech Crime Prevention)
Complying with regulations on protection of personal data, ……………………2 submits a dossier
on assessment of impact of personal data processing to the Ministry of Public Security
1. Information of organization or enterprise
- Name of organization or enterprise: ……………………………………………………………
- Address of the headquarter:……………………………………………………………………..
- Address of the transaction office:……………………………………………………………….
- Establishment Decision/Enterprise Registration Certificate/Business Registration
Certificate/Investment Certificate No:….. issuing authority ........date of issue......place of issue….
- Phone number:…………………………….. Website ……………………………………………
- Personnel in charge of protection of personal data: ……………………………………………
Full name: …………………………………………………………………………………………….
Title: ……………………………………………………………………………………………….
Phone number (fixed and mobile): ……………………………………………………………
Email: …………………………………………………………………………………………………
2. Change in contents of the dossier
- Changed contents: …………………………………………………………………………………
- Reasons: …………………………………………………………………………………….
3. Attached documents
1. ………………………………………………………………………………………………………
2. ………………………………………………………………………………………………………
4. Commitment
(Name of agency, organization or enterprise) commits to assume legal responsibility for the
accuracy and legitimacy of changed contents and attached documents.
ON BEHALF OF ORGANIZATION
OR ENTERPRISE
(Signature, full name and seal)
__________________________
1
Name of the dossier: Dossier on assessment of impact of personal data processing or assessment of
impact of outbound transfer of personal data.
2
Name of organization or enterprise.
Form No. 06
NAME OF ORGANIZATION
-------
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------
No:
…., date….month….year….
DOSSIER ON ASSESSMENT OF IMPACT OF OUTBOUND TRANSFER OF PERSONAL
DATA
To: the Ministry of Public Security
(Department of CyberSecurity and Hi-tech Crime Prevention, the Ministry of Public Security)
Complying with regulations on protection of personal data, ……………………… 1 submits a
dossier on assessment of impact of outbound transfer of personal data to the Ministry of Public
Security. To be specific:
1. Information on organization or enterprise
- Name of organization or enterprise: ………………………………………………………….
- Address of the headquarter:……………………………………………………………………
- Address of the transaction office:………………………………………………………………
- Establishment Decision/Enterprise Registration Certificate/Business Registration
Certificate/Investment Certificate No:….. issuing authority ........date of issue......place of issue….
- Phone number:………………………… Website ………………………………………………
- Personnel in charge of protection of personal data: ………………………………………….
Full name: …………………………………………………………………………………………..
Title: ……………………………………………………………………………………………….
Phone number (fixed and mobile): ……………………………………………………………
Email: ………………………………………………………………………………………………
2. Dossier on assessment of impact of outbound transfer of personal data
1. ……………………………………………………………………………………………….
2. ………………………………………………………………………………………………..
3. Commitment
(Name of agency, organization or enterprise) commits to assume legal responsibility for the
accuracy and legitimacy of the dossier on assessment of impact of outbound transfer of personal
data and attached documents.
ON BEHALF OF ORGANIZATION
OR ENTERPRISE
(Signature, full name and seal)
__________________________
1
Name of organization or enterprise
------------------------------------------------------------------------------------------------------
This translation is made by THƯ VIỆN PHÁP LUẬT, Ho Chi Minh City, Vietnam and for
reference purposes only. Its copyright is owned by THƯ VIỆN PHÁP LUẬT and protected under
Clause 2, Article 14 of the Law on Intellectual Property.Your comments are always welcomed
Download