For years, a bank's value has often been seen in terms of its capital size, asset quality, branch network or credit market share. But in the digital era, another asset is increasingly determining the attractiveness of M&A deals: customer data.
For investors, data on transaction behavior, credit history, financial needs, or customer engagement not only reflects the quality of the bank's operations, but also opens up opportunities for ecosystem integration, product development, and post-transaction value creation. Therefore, in many deals, data is almost seen as part of the "added value" that the buyer expects to receive along with control of the bank.

Every M&A has an intersection between business interests and compliance requirements.
However, the law does not look at the problem in the way of the market. Investors can buy control of the bank, but that does not mean that they automatically have the right to access, copy or exploit all the data of millions of customers. For banks, data is not only a commercial asset but also the subject of two parallel legal protection regimes: the law on the protection of personal data and the obligation to keep customer information confidential in banking activities. These two layers of protection make data a type of "special asset", which cannot be automatically followed by deals such as shares, tangible assets or technology systems.
That's why a seemingly simple question has become the central legal issue of many bank M&A deals today: Does M&A automatically allow the transfer of customer data?
The market wants data, the law wants to limit
Every M&A has an intersection between business interests and compliance requirements. For banks, that intersection is customer data.
Buyers always tend to want access to as much data as possible. This is completely understandable. The quality of the customer portfolio, transaction history, product utilization rate, financial behavior or risk analysis data all directly affect the bank's valuation and post-transaction mining strategy. An investor not only buys a bank today, but also buys the ability to generate revenue from the customer base for years to come.
On the other hand, the target bank is obliged to protect the data of the same customers who create the value of the deal. Sharing too much information can lead to a breach of confidentiality obligations, affect the privacy of customers, and even give rise to liability before the transaction is signed.
Meanwhile, customers - the subject of the data - often do not know that their data is being reviewed during the due diligence process, much less have the opportunity to control how the data will be used after the bank changes hands.
Therefore, the law does not choose to absolutely protect any interests. Instead, the current legal system tries to balance three goals at the same time: facilitating M&A activities, ensuring investors' business rights, and protecting customer privacy.
That's also why M&A isn't considered a "passport" for customer data to automatically follow the deal.
Buying shares doesn't mean controlling the data
One of the most common misconceptions in M&A practice is to equate control of the business with control of the data.
Suppose an investor buys 90% of the shares of a bank. After the transaction, the investor becomes the controlling shareholder. Does that mean they have the right to ask the bank to transfer all customer data to the group's system?
From an economic perspective, many people can answer yes. But from a legal perspective, these are two completely different issues.
In a share purchase transaction, the object to be transferred is the shares, not the data. The target bank continues to exist as an independent legal entity and remains the direct entity providing services to the customer. A change in the shareholder structure does not immediately change the entity that is processing the personal data.
This is a point that needs to be distinguished very clearly between business control and data processing rights.
Voting rights, the right to appoint the board of directors or the right to decide on business strategies do not automatically entail the right to remove the customer database from the bank's system and transfer it to the parent company or other companies in the group.
In other words, business ownership is not the same as a business's right to exploit data.
This is also the reason why the law on personal data protection does not operate according to the logic of the law on ownership or corporate law.
Not every M&A transaction results in a data transfer
Another cause of misunderstanding is that the concept of "M&A" in practice is much broader than the cases prescribed by law.
The Personal Data Protection Law 2025 allows data transfers in some cases of reorganization such as division, separation, consolidation, merger or conversion of ownership. However, this does not mean that every transaction called M&A in the market automatically falls under that scope.
A share purchase, an asset purchase, and a bank merger have completely different legal structures.
In the event of a merger, the merged bank ceases to exist and the rights and obligations are transferred to the merged bank. The fact that the data continues to be processed by the successor has a relatively clear legal basis. In contrast, in a share purchase transaction, the target bank still exists. In principle, no data is required to "go" to another legal entity just because the shareholder has changed.
This difference is especially important in deals with foreign elements. Foreign investors can own Vietnamese banks, but that does not mean that customer data is allowed to be transferred to the group's system abroad.
Without distinguishing between these transaction structures, it is easy to lead to the understanding that every M&A is data that is transferable, which is an understanding that the current law does not aim for.
Two layers of protection make banking data a special asset class
Unlike many other businesses, the bank's data is simultaneously governed by two legal systems.
The first layer is the law on personal data protection. The second layer is the regulation on customer information security in the Law on Credit Institutions.
This makes a huge difference. A data processing activity may meet the requirements of the law on personal data protection but is not yet eligible for the bank to provide customer information according to specialized regulations.
In other words, finding grounds for processing under one law may not necessarily mean that banks are allowed to provide data under the other law.
This is the point that makes bank M&A have a higher level of complexity than many other fields.

In many deals, investors often expect to mine the data to cross-sell insurance, securities, asset management, or other financial products in the ecosystem.
Transaction due diligence is not only legal due diligence but also data due diligence
Interestingly, data risk often does not appear after the deal is completed, but appears from the very first days. That's when investors want to see the most information to decide whether to buy the bank or not.
An investor may need to evaluate the quality of the credit portfolio, customer concentration, product utilization rate, or the effectiveness of each customer segment. But that doesn't mean the bank has to open the entire profile of each customer. In fact, this is where the principle of data minimization needs to be applied most strongly. Buyers need information for valuation. But not all information for valuation needs personally identifiable data.
An aggregated report, anonymized or pseudonymized data in many cases is still sufficient to serve the evaluation of the deal.
This also explains why data due diligence is gradually becoming an independent component of large M&A deals, rather than just being seen as a small part of legal due diligence or IT due diligence. If financial due diligence answers the question "how much is a bank worth", then data due diligence needs to answer an equally important question: After buying a bank, what is the buyer really allowed to do with the existing data? This is the question that determines the true value of the data asset.
The value of data lies not only in its quantity, but also in its ability to be used legally
In many deals, investors often expect to mine the data to cross-sell insurance, securities, asset management, or other financial products in the ecosystem. But if the data is only allowed to continue to serve the original banking purpose, the actual commercial value of the dataset may be significantly lower than expected.
This reveals an aspect that is less discussed: data risk is not only a compliance risk, but also a valuation risk. A bank with a very good balance sheet but a flawed data governance system can completely reduce the value of the deal.
On the contrary, a bank that builds a transparent data governance platform, full legal basis and good control over data processing rights will create a higher level of certainty for the buyer in exploiting value after M&A.
Non-asset data "follows" the deal
Perhaps the biggest change banks and investors need to realize is that personal data cannot be treated like other tangible assets in an M&A deal.
A building, a technology system, or a portfolio of assets can be transferred with a bank. But customer data is always tied to the purpose of collection, the basis of processing, and the rights of the data subject. Those limitations don't disappear just because the bank has changed hands.
Therefore, the most important question in bank M&A is not "whether data can be transferred or not", but "what data really needs to be transferred, to whom, for what and on what legal basis". That will be a question that must be answered from the opening of the data room, during the negotiation process and will continue to be considered when the two systems begin to integrate after the transaction.
For years, investors have seen data as part of the bank's value. That's not wrong. But in the era of personal data protection, the economic value of data is no longer determined simply by the size or quality of the data set, but also by the ability to use it legally. That's what determines whether a bank M&A deal actually creates sustainable value.
