Advantages and disadvantages in the process of application of Decree No. 13/2023/ND-CP on the protection of personal data from company practice

Insights
Advantages and disadvantages in the process of application of Decree No. 13/2023/ND-CP on the protection of personal data from company practice
Posted on: 10/07/2024

    The protection of personal data is a necessary requirement in the current context where the violation of personal information/data occurs and causes many negative consequences to the society. Decree No. 13/2023/ND-CP on Personal Data Protection is promulgated in April 2023, with effect from July 1, 2023 ("Decree 13") to adjust this purpose. In Vietnam, the concept of personal data protection is quite new, so the application of regulations in Decree 13 at this time remains certain advantages and disadvantages. In this discourse, the author refers to some advantages and disadvantages of Vietnam in general and especially from the perspective of enterprises in particular during the process of implementation and application of Decree 13.   

    1. Advantages in the process of applying of Decree 13 

    1.1 There are references from treaties, regulations of international law  

    With the advantage of following many developed countries in personal data protection, Vietnam can learn a lot of experience in the process of implementing and applying regulations on personal data protection. In the international treaties that Vietnam has joined, namely the WTO Accession Agreement, the Comprehensive and Progressive Agreement for Trans-Pacific Partnership ("CPTPP"), or the Vietnam-EU Free Trade Agreement ("EVFTA"), they specify the issue of personal data protection.   

    Specifically, Article 16(c)(ii) of the WTO Agreement on Trade in Services allows countries to take trade-restrictive measures when necessary to protect the privacy of individuals with respect to the processing and dissemination of personal data, and measures to protect the confidentiality of personal records and accounts, provided that such measures do not constitute arbitrary discrimination or a disguised restriction on trade. Meanwhile, Article 14.8 of the CPTPP Agreement provides that countries shall establish and maintain legal frameworks for the protection of users' personal information in e-commerce, taking into account the principles and guidelines of international institutions. In particular, countries will not discriminate in protecting e-commerce users from violations of the protection of personal information within their jurisdiction. In particular, countries must publish information on personal information protection measures for e-commerce users, including methods for individuals to exercise their rights and methods for enterprises to comply with relevant laws. In addition, countries must promote and strive for compatibility between the national laws of CPTPP countries through bilateral mechanisms or international frameworks. Finally, with respect to the EVFTA, Article 8.45 of this agreement stipulates that the parties shall adopt or maintain appropriate measures to protect personal data and privacy, including personal records and accounts. In which, regarding the financial sector, the parties will allow the transfer of information outside the territory for processing by the nature of providing financial services. Thus, it can be seen that many important international treaties in which Vietnam participates refer to the issue of personal data protection, which may put pressure on the prompt development of personal data protection regulations in the country. But this is also an advantage for Vietnam if Vietnam can build a legal framework on personal data protection in accordance with the provisions of international treaties, avoiding conflicts between international treaties and national laws. 

    Regarding the laws of countries, other regions in the world, currently many countries and major regions in the world have issued regulations on personal data protection. One of the most widely applied regulations today is the European Union's General Data Protection Regulation ("GDPR"), which came into force on May 25, 2018. Basically, the current regulations in Decree 13 have significant similarities with the GDPR. In addition, it is also important to mention the personal data protection regulations of other countries, such as the United States, France, Japan, Singapore, Thailand, ..., all of which can be valuable reference sources for Vietnam in the process of fulfilling the legal framework on personal data protection. 

    1.2 The issuance of Decree 13 during at a time of strong implementation of public administrative procedures 

    The Decree 13 imposes obligations on enterprises to carry out administrative procedures related to the processing of personal data, and the transfer of personal data abroad put a lot of pressure on enterprises, because in addition to complying with many other regulations in their operations, enterprises currently have to carry out additional administrative procedures on personal data protection. However, in addition to the fact that Vietnam is implementing a strong reform of administrative procedures, especially the digitalization of administrative procedures, the Ministry of Public Security has also recently completed the construction and launch of the National Information Portal on Personal Data Protection. In particular, enterprises can carry out administrative procedures related to Decree 13 on this information portal. Although the submission and receipt of applications via this form is still being finalized at this time, it promises to be a faster and more convenient channel for business applicants in the near future. 

    2. Difficulties in the application of Decree 13  

    1.1 People’s awareness about personal data protection is limited  

    One of the of the major challenges in protecting personal data is the awareness of people about this issue when they are the owners of the data. In Vietnam, it can be seen that the issue of personal data protection seems to have been neglected for quite a long time, which, combined with people's limited awareness, leads to a situation where personal data is publicly traded and exchanged. The habit of not recognizing the importance of personal data protection has made the process of implementing Decree 13 more or less difficult, as it is not easy to change people's habits in a short period of time. 

    1.2 The personal data protection mechanism prescribed in Decree 13 is not easy for companies to implement 

    Implementing the personal data protection mechanism under Decree 13 is not easy, even though it has been almost a year since this decree officially took effect on July 1, 2023. It can be said that the burden of responsibility for personal data protection has fallen on enterprises, as this compliance involves many responsibilities with huge amounts of data. Many companies have developed internal regulations on the protection of personal data, established and appointed personnel in charge of the protection of personal data within the company to ensure compliance with the requirements: 

    • Ensure full rights of data owners, such as the right to consent, the right to access data, the right to edit data, the right to delete data, the right to withdraw consent, ....; 

    • Develop rules for the protection of personal data protection in its company; 

    • Designate and appoint personnel responsible for the protection of personal information in the company; 

    • Notify the Ministry of Public Security (specifically A05, Department of Cyber ​​Security and High-Tech Crime Prevention) when violations of personal data protection regulations are detected; 

    • Prepare, update, and submit impact assessment dossiers on the processing of personal data according to the form to Department A05 within 60 days from the date of processing personal data; 

    • Prepare, update and send to Department A05, within 60 days from the date of personal data processing, dossiers assessing the impact of the transfer of personal data abroad, according to the form; 

    • Record and store system logs of personal data processing ; 

    • Coordinate with the Ministry of Public Security, relevant government agencies in the protection of personal data, provide information for investigation, handle violations of the Law on the Protection of Personal Data . 

    In the practical implementation of Decree 13, the author finds that one of the difficulties enterprises face in implementing the personal data protection mechanism under Decree 13 is to ensure the full rights of personal data owners. When the provisions in this dossier are still at a macroscopic level, even if the enterprise stipulates them in its internal regulations and statutes, it is difficult to fully cover and anticipate circumstances that are likely to violate the rights of data owners. 

    In addition, recording and storing logs of personal data processing systems is also a difficult requirement for many companies, when investing in modern information technology systems and training personnel with highly specialized skills, understanding legal regulations requires a lot of time and money. Not all companies have the financial capacity and resources to meet this requirement, especially small and medium sized companies. 

    In addition, coordinating with the Ministry of Public Security and relevant government agencies to protect personal information and provide information to assist in the investigation and handling of data protection violations is not easy. Companies must ensure that the information provided is accurate and sufficient, which requires a strict and systematic management process, while most companies must rely on the assistance of third parties or even the relevant authorities. 

    1.3 Common difficulties faced by companies in complying with the personal data protection requirements of Decree 13 in practice 

    In addition to the above mechanical problems, the practical implementation of Decree 13 will also create many difficulties and challenges for enterprises. 

    Firstly, challenges in investment costs for technology and human resources training of enterprises in the process of building internal personal data processing processes. According to Decree 13, first of all, compliance with the rights of data owners under this Decree requires enterprises to establish obvious and effective procedures to handle requests for provision, adjustment, storage, deletion and destruction of personal data.  

    This requires companies to invest in advanced information technology systems to ensure the ability to access and process data quickly and accurately. Specifically, to ensure the right to access and process personal data, organizations must implement a data management system (DMS) that is highly secure and easy to use. The cost of implementing these systems can be extremely high, while training personnel with the appropriate expertise is also a difficult challenge for organizations. In order to effectively implement personal data protection processes, companies need to appoint and train experts or specialists in information security and data management. These experts must have a thorough understanding of legal regulations, security technology, and data processing processes. These factors place a significant financial burden on organizations, and these resources are typically not available in the enterprise. A lack of data security expertise can contribute to increased costs for organizations when faced with data breaches, with the average cost per breach reaching millions of dollars1. 

    Secondly, the risk of violating the personal data protection mechanism and incurring sanctions from competent authorities is a concern for companies. Currently, there are no separate sanctions for violations of Decree 13, but a Draft Decree on Administrative Sanctions in the Field of Cybersecurity is being implemented, which consolidates many administrative violations of personal data protection in Decree 13/2023/ND-CP and the corresponding penalties ("Draft Decree"). As the provisions of Decree 13 are still quite vague, the issuance of the Draft Decree simultaneously creates great pressure on companies to comply with personal data protection regulations. 

    For example, the inconsistency between Decree 13 and the Draft Decree may cause confusion in the process of promulgating internal company rules on personal data protection. According to Point e, Clause 1, Article 14 of the Draft Decree, companies must delete personal data upon request within 48 hours, while Clause 5, Article 16 of Decree 13 allows a time limit of up to 72 hours. This inconsistency makes compliance difficult and may lead to unnecessary violations, disputes and complaints.  

    In addition, the requirement to delete data when the original purpose of collection is no longer necessary is also a challenge because the current documents do not provide specific quantitative limits to determine the purpose of data collection, and there is also no relevant guidance from the competent authority. Meanwhile, the Draft Decree recognizes in Point dd, Clause 1, Article 14 that the act of not deleting data when it is no longer needed is punishable by a fine of VND20 million to VND40 million. In a context where enterprises regularly process personal data, it is not feasible to immediately adapt to every data deletion request. Forcibly deleting data without considering the purpose, retention period, or anticipation of situations that may arise may pose risks to enterprises, especially when disputes arise. 

    In general, although it has been mentioned a lot recently, personal data protection is still a new issue in Vietnam, both in terms of legal framework and practical implementation and application. With the collection of many regulations related to human and civil rights, the author believes that in the near future, Decree 13 will and must be replaced by a legal document with higher legal value. From there, the drafting of regulations will go through a more rigorous research and discussion process to ensure that each provision is appropriate and easy to implement in practice. At present, while Decree 13 is still in force, and the provisions of the draft decree on sanctioning administrative violations in the field of cybersecurity are also gradually being finalized and promised to take effect soon, companies still need to comply with these regulations to avoid risks and damages to themselves. 

    This is the abstract of Lawyer Nguyen Van Phuc at the Faculty-level workshop on "Personal Data Protection in the Digital Environment - A Comparative Study of Vietnamese and Thai Laws" 

     

    Read more at: 

    Khoa Luật Quốc tế tổ chức Hội thảo cấp Khoa chủ đề “Bảo vệ dữ liệu cá nhân trong môi trường số - Nghiên cứu so sánh pháp luật Việt Nam và Thái Lan”