Challenges faced by financial companies in complying with personal data protection regulations

Insights
Challenges faced by financial companies in complying with personal data protection regulations
Posted on: 30/10/2024

    In the digital age, securities companies and investment funds must handle vast amounts of personal data, including sensitive information such as bank account numbers and transaction history. Decree No. 13/2023/ND-CP on personal data protection ("Decree 13") imposes strict rules on data collection, analysis, and sharing to protect users' rights.

    The processing of large data volumes presents challenges for financial companies, especially in analyzing, evaluating, and transferring data to partners. Every operation must comply with legal regulations while ensuring uninterrupted business activities, which is increasingly crucial as strategic decisions rely on customer data. Therefore, utilizing data for investor analysis becomes challenging when companies must not only comply with the law but also ensure operational procedures and services remain unaffected.

     

     

    Compliance Challenges with Decree 13

    The implementation of Decree 13 has faced numerous difficulties from the outset and has yet to be fully resolved. One of the major challenges for financial institutions, including securities companies and investment funds, is balancing compliance with personal data protection regulations while maintaining efficient business operations.

    Under Decree 13, data subjects have the right to know how their data is being processed, the right to refuse, and the right to request data deletion. However, in practice, financial companies not only collect and process data to provide services but also use this data for risk management and system safety purposes, which do not always require customer consent.

    The Decree mandates customer consent for any data processing activities. This requirement poses a major obstacle for financial institutions, as service provision typically requires data processing at multiple stages. Obtaining consent at each step not only slows down the process but also increases administrative workload, affecting business flexibility. Particularly with large-scale operations and vast data volumes, companies are compelled to adjust complex internal processes to comply with this requirement.

    In addition, to ensure compliance with Decree 13, financial institutions need to invest in revising IT systems, contracts, forms, and agreements with customers. This requires a comprehensive change not only in technology infrastructure but also in the operation and management of personal data.

    Another challenge is applying regulations on sensitive personal data, including financial information and customer rights. Financial institutions often need to share this information with partners, such as credit institutions, regulatory agencies, or credit appraisal units, to facilitate risk assessment, underwriting, and management activities. The lack of clarity regarding the responsibilities of parties involved in processing this data has led to legal complications. Financial institutions must not only flexibly adjust procedures but also seek guidance from regulatory agencies to avoid potential legal risks.

    Compliance Pressure in Information Sharing

    In addition to data collection and analysis, securities companies and investment funds must frequently transfer personal data to external partners, such as financial service providers, credit institutions, or credit appraisal units. These transfers are not only for transactional purposes but also for evaluation, underwriting, and risk management of financial products.

    However, when customers request to stop processing or withdraw consent for data sharing, companies face significant challenges in adjusting their procedures. They must not only halt data sharing but also ensure that the transferred data is not misused by partners. This requires a strict data management system and clear legal agreements with involved parties.

    Withdrawing customer consent can lead to complex legal consequences. According to current personal data processing regulations by financial service providers, if this occurs, financial companies may have to cease service provision to customers due to their inability to continue processing the necessary data.

    This situation may disrupt the relationship between the company and the customer, potentially leading to breaches of contractual obligations. A recent example is VNDIRECT, which stipulated in agreements with customers that if they withdraw consent, the company may have to stop providing services due to a lack of information to maintain product quality.[1]

    Severe Penalties and Negative Impact on Businesses

    Decree 13 and the Draft Decree on Administrative Sanctions in the Cybersecurity Sector[2] set forth stringent penalties for businesses that violate personal data protection regulations. The draft decree imposes penalties as a deterrent to ensure strict compliance by businesses in protecting consumer rights.

    Specifically, the draft decree provides that violations in personal data protection can result in fines of up to hundreds of millions of Dong. Particularly serious violations, such as exposing or losing the personal data of one million or more Vietnamese citizens, may incur a maximum fine of 1 billion dong or 5% of a company's annual revenue.

    The recent cyberattack on VNDIRECT, which paralyzed the system, highlights the reality that businesses, especially securities companies, fund management companies, and banks, may face significant penalties if large volumes of customer information are leaked. Not only does this result in immediate financial losses but it can also erode investor and customer trust, adversely affecting the company's stock price and market reputation.

    Beyond financial risks, violations of personal data protection regulations can damage customer trust - a critical factor for securities companies and investment funds. In the financial industry, customer trust relies not only on services but also significantly on the ability to secure and protect personal information. Even a minor data security breach can severely harm a company's reputation, prompting customers to shift to competitors.

     

     

    Solutions for Financial Companies Amid Changing Legal Landscape

    Considering the recent cyberattack on VNDIRECT, financial companies face increasing demands for personal data protection under Decree 13. This is not only a legal requirement but also an opportunity to enhance reputation and strengthen customer trust. Data protection measures must be concretized and integrated into internal processes to ensure comprehensive compliance with legal regulations.

    First, companies should establish a comprehensive data management system, beginning with identifying sensitive data types, such as bank account information, of both domestic and foreign investors. Encrypting data during collection, processing, and storage is an optimal measure to prevent cyberattacks that may cause data leaks. Alongside this, clear access protocols should be established to ensure that only authorized individuals have access to critical data, with all access activities monitored and logged.

    Second, financial companies need to review and adjust data management policies to avoid overlapping legal requirements. This ensures that companies comply not only with Decree 13/2023/ND-CP on personal data protection but also with the 2019 Securities Law. Timely adjustments will help update new regulations while addressing gaps in current processes. This not only ensures the legality of data processing activities but also minimizes legal risks in case of data security incidents.

    Third, companies should actively engage with regulatory bodies, such as the State Securities Commission and the Stock Exchange, for specific guidance suited to the industry. Customer information security obligations are clearly stated in legal documents such as Circular No. 121/2020/TT-BTC, which requires securities companies to ensure the security of customers' online transaction information, preventing information leaks that could harm investors.

    Integrating compliance with Decree 13 and industry-specific regulations not only helps companies synchronize data protection processes but also avoids regulatory overlap, ensuring full and accurate legal compliance. This approach will help businesses avoid risks, maintain customer and partner trust.

    Fourth, stringent control over data storage and sharing, particularly sensitive data like bank account information, is essential. Financial companies should implement advanced encryption technologies and periodically conduct internal audits on data security. The data management system should be designed to ensure timely detection of unauthorized or abnormal access activities. Measures such as end-to-end encryption and multi-layered security solutions effectively mitigate risks from cyberattacks.

    Fifth, cybersecurity and legal training for staff is indispensable. The technical team and business staff need in-depth knowledge of personal data protection processes, as well as emergency response measures for cybersecurity incidents. Companies should conduct regular training sessions and practical scenario drills to enhance their response capabilities to attacks. Additionally, crisis notification and response procedures should be established to mitigate damage and protect investors' rights.

    In conclusion, by implementing these solutions, financial companies not only ensure compliance with Decree 13 but also lay a solid foundation for building a strong reputation and promoting sustainable growth in a challenging environment. Actively protecting investor data is a key factor in maintaining customer trust and safeguarding long-term customer interests.

    _________________

    The article was written by Lawyer Nguyen Nhat Duong and Assistant Lawyer To Kien Luong published on Tap chi Phap ly, dated 01 November 2024.

    Read more at: Tuân thủ qui định bảo vệ dữ liệu cá nhân: Giải pháp cho các công ty tài chính trong bối cảnh pháp lý thay đổi


     

    [1] Article 3 of VNDIRECT Securities Corporation's Personal Data Protection Policy, promulgated under Decision No. 599-7/2023/QD-VNDIRECT. Last accessed on October 3, 2024, at https://www.vndirect.com.vn/chinh-sach-bao-ve-du-lieu-ca-nhan-cua-vndirect/.

     

    [2] Attachment to the Submission dated April 15, 2024, from the Ministry of Public Security. See more at https://moj.gov.vn/qt/tintuc/Pages/chi-dao-dieu-hanh.aspx?ItemID=4271, last accessed October 4, 2024.