The protection of personal data is currently a major concern for businesses, especially in the context of Vietnam's increasingly developing digital economy. Currently, with the issuance of Decree No. 13/2023/ND-CP, the ongoing drafting of the Law on Personal Data Protection, and the Draft Decree on Penalties for Administrative Violations of Regulations in the Field of Cybersecurity (including Regulations on Administrative Penalties in the Field of Personal Data Protection) ("Draft Decree"), legal compliance issues in the field of personal data protection are becoming more urgent than ever for Vietnamese businesses. E-commerce platforms are considered a "gateway" connecting many stakeholders in e-commerce activities; and the collection and processing of personal data by these businesses is extremely complicated in many aspects. Therefore, ensuring compliance with personal data protection regulations is a major challenge for enterprises engaged in providing e-commerce platform services.
Not completely new regulations
The protection of personal data in e-commerce is not a new issue. Previously, personal data was known as "personal information", and the Asia-Pacific Economic Cooperation (APEC) Forum had issued basic principles on the protection of consumers' personal information in e-commerce to guide member states in developing a legal framework on this issue1. Subsequently, the Vietnamese Government issued Decree No. 52/2013/ND-CP, which included a chapter regulating the protection of consumers’ personal information in e-commerce2. In 2023, the government issued Decree No. 13/2023/ND-CP on Personal Data Protection, which came into effect at the same time as Decree No. 52/2013/ND-CP. This decree does not exclude e-commerce platforms from the scope of regulation. Therefore, e-commerce platforms must comply with both the regulations on the protection of consumers' personal data in Decree No. 52/2013/ND-CP and the regulations on the protection of personal data in Decree No. 13/2023/ND-CP.
We find that the regulations in Chapter V of Decree No. 52/2013/ND-CP are quite similar to those in Decree No. 13/2023/ND-CP. Therefore, it can be said that e-commerce platforms have an advantage in adapting to the new regulations in Decree No. 13/2023/ND-CP due to their experience in implementing specialized legal regulations. However, Decree No. 13/2023/ND-CP still has certain differences from Decree No. 52/2013/ND-CP, and e-commerce platforms may still encounter common difficulties faced by other businesses in complying with Decree No. 13/2023/ND-CP, as well as challenges arising from the specific nature of the e-commerce field.
In addition to the current regulations mentioned above, Vietnam is also taking longer-term initiatives by developing a law on personal data protection and a draft decree on administrative penalties for violations of personal data protection regulations. In particular, the administrative penalties for personal data protection violations are quite severe, with fines potentially reaching up to 5% of a company's turnover. In this context, companies in general, and especially those providing e-commerce platform services, need to be more proactive in implementing measures to comply with Decree No. 13/2023/ND-CP in order to avoid penalties once these regulations are enacted and enforced.
Compliance challenges remain
For e-commerce platforms, compliance with personal data protection regulations poses significant challenges due to the complex and diverse nature of personal data processing, especially with the increasing number of users shopping and using services on these platforms. Some of the challenges that e-commerce platforms may face include
First, the processing of personal data by e-commerce platforms involves multiple parties. For example, current e-commerce platforms may work with Google or Facebook to obtain consumers' personal information that is already available on those platforms, to create accounts for transactions, or to transfer consumers' personal information to relevant parties such as shipping companies, intermediary payment providers, advertisers, and so on. This raises concerns about whether these relevant partners are handling consumers' personal data on e-commerce platforms in accordance with the law.
Second, the challenge is to meet the requirements for handling consumers' personal data. According to Decree No. 13/2023/ND-CP, when consumers (data subjects) make requests such as providing personal data, processing personal data, storing or deleting personal data, e-commerce platforms must fulfill these requests in accordance with Decree No. 13/2023/ND-CP. In some cases, e-commerce platforms must fulfill these requests within a certain time frame, for example, requests to delete consumers' personal data must be fulfilled within 72 hours from the time of the request. With the increasing number of users shopping and using services on e-commerce platforms, these regulations pose a significant challenge. In addition, violations of the timeframe for providing and deleting personal data may result in administrative penalties under the Draft Decree3. 
Third, the challenge of legal compliance arises when personal data is transferred abroad. Currently, some multinational e-commerce platforms operate by transferring consumers' personal data to servers in another country outside Vietnam to synchronize data and provide services directly in that country4. The transfer of personal data abroad is one of the activities that must comply with the provisions of Decree No. 13/2023/ND-CP. In particular, e-commerce platforms are required to undergo procedures to notify the Ministry of Public Security and conduct impact assessments on the transfer of personal data abroad, and to keep these records. They are also required to amend and supplement these records when the content of the previously submitted records changes. This regulation puts pressure on e-commerce platforms in terms of managing the transfer of personal data overseas, as well as monitoring and preparing documentation to comply with related administrative procedures. In addition, from a technical perspective, the transfer of personal data abroad carries inherent risks such as data breaches (the unauthorized exposure, disclosure, or loss of personal data) of Vietnamese citizens. Data breaches of Vietnamese citizens may result in administrative penalties under the Personal Data Protection Regulations, with fines of up to 5% of the company's revenue5. This is one of the fines that has a significant financial impact on businesses.
We believe that the above issues pose significant challenges for companies engaged in e-commerce activities. In order to ensure compliance with Decree No. 13/2023/ND-CP and to avoid being penalized under the administrative penalty provisions once the draft decree is enacted, e-commerce platforms will need to bind their partners involved in the processing of consumers' personal data to their responsibilities for the protection of personal data. They will need to establish appropriate mechanisms and allocate sufficient personnel to handle requests related to the processing of personal data, as well as comply with related administrative procedures. These tasks require significant investment and resources from e-commerce companies and are not easy to accomplish in a short period of time.
_______
[1] https://trungtamwto.vn/file/20761/apec-nhung-nguyen-tac-co-ban-ve-bao-ve-du-lieu-ca-nhan-trong-thuong-mai-dien-tu.pdf, accessed on July 24, 2024.
[2] Chapter V: Safety and Security in E-Commerce Transactions.
[3] Articles 18.1.c and 19.1.a of the Draft Decree
[4] Reference: Section V Grab's privacy notice, https://www.grab.com/vn/terms-policies/privacy-notice/, accessed on July 24, 2024.
[5] Article 26.4 of the Draft Decree.
