On April 17, the Government issued Decree 13/2023/ND-CP on personal data protection; which clearly states measures and conditions to ensure personal data protection.
Vietnamese passport. Photo: Le Minh Son/Vietnam+
Measures to protect personal data
The Decree clearly states that personal data protection measures are applied from the beginning and throughout the process of processing personal data.
Measures to protect personal data include: Management measures implemented by organizations and individuals involved in processing personal data; technical measures implemented by organizations and individuals involved in processing personal data; measures implemented by competent State management agencies in accordance with the provisions of this Decree and relevant laws; investigation and prosecution measures implemented by competent State agencies; other measures as prescribed by law.
Basic personal data protection is to apply the above-mentioned personal data protection measures; develop and promulgate regulations on personal data protection, clearly stating the tasks to be performed according to the provisions of this Decree; encourage the application of personal data protection standards appropriate to the fields, professions, and activities related to personal data processing; check the network security of systems and means, equipment serving personal data processing before processing, irreversibly delete or destroy devices containing personal data.
Protecting sensitive personal data means applying the above basic personal data protection and personal data protection measures; designating a department with the function of protecting personal data, designating personnel in charge of protecting personal data, and exchanging information about the department and individuals in charge of protecting personal data with the agency specializing in protecting personal data.
In case the personal data controller, the personal data controller and processor, the data processor, or the third party is an individual, it is necessary to exchange information of the individual performing the task; notify the data subject that the sensitive personal data of the data subject is being processed, except in some prescribed cases.
Personal Data Protection Authority
According to the decree, the agency responsible for protecting personal data is the Department of Cyber Security and High-Tech Crime Prevention and Control (Ministry of Public Security), responsible for assisting the Ministry of Public Security in performing State management of personal data protection.
The national portal on personal data protection provides information on the Party's guidelines, policies, and the State's laws on personal data protection; disseminates and propagates policies and laws on personal data protection; updates information and the status of personal data protection; receives information, records, and data on personal data protection activities via cyberspace; and provides information on the results of the assessment of personal data protection work of relevant agencies, organizations, and individuals.
In addition, the National Portal on Personal Data Protection receives notifications of violations of regulations on personal data protection; warns and coordinates warnings about risks and acts of personal data infringement in accordance with the law; handles violations of personal data protection in accordance with the law; and performs other activities in accordance with the law on personal data protection.
Conditions for ensuring personal data protection activities
The Decree clearly states that the conditions for ensuring personal data protection activities include: The personal data protection force is a specialized force for protecting personal data arranged at the agency specializing in protecting personal data; the department and personnel with the function of protecting personal data are assigned in agencies, organizations and enterprises to ensure the implementation of regulations on personal data protection; organizations and individuals are mobilized to participate in protecting personal data; the Ministry of Public Security develops specific programs and plans to develop human resources for protecting personal data.
Chip-embedded citizen identification card. Source: Vietnam+
Agencies, organizations and individuals are responsible for disseminating knowledge and skills, raising awareness of personal data protection for agencies, organizations and individuals; ensuring facilities and operating conditions for agencies specialized in personal data protection.
Personal data is information in the form of symbols, letters, numbers, images, sounds or similar forms in an electronic environment that is associated with a specific person or helps to identify a specific person. Personal data includes basic personal data and sensitive personal data.
Basic personal data includes: Surname, middle name and birth name, other names (if any); date of birth; date of death or disappearance; gender; place of birth, place of birth registration, permanent residence, temporary residence, current residence, hometown, contact address; nationality; personal image; phone number, identity card number, personal identification number, passport number, driver's license number, license plate number, personal tax code number, social insurance number, health insurance card number; marital status; information about family relationships (parents, children); information about personal digital accounts; personal data reflecting activities and history of activities on cyberspace; other information associated with a specific person or helping to identify a specific person.
Sensitive personal data is personal data related to an individual's privacy that, when violated, will directly affect the individual's legitimate rights and interests, including: Political views, religious views; health status and privacy recorded in medical records, excluding information about blood type; information related to racial origin, ethnic origin; information about inherited or acquired genetic characteristics of an individual; information about physical attributes, biological characteristics of an individual; information about sexual life, sexual orientation of an individual...
Personal data protection is the activity of preventing, detecting, stopping and handling violations related to personal data according to the provisions of law.
The Decree takes effect from July 1, 2023.
According to VNA