Draft Law on Personal data protection: Legal Gaps in the protection of employee data

Insights
Draft Law on Personal data protection: Legal Gaps in the protection of employee data
Posted on: 25/06/2025

    In the context of global digital transformation, personal data has become an important resource, especially in the labor sector, where personal information of employees and candidates is regularly collected, processed, and stored. In Vietnam, the Draft Law on Personal Data Protection (Draft), especially Article 21[1], is designed to establish a legal framework for personal data protection in the recruitment and management of workers. This regulation reflects Vietnam's efforts to integrate with international standards, such as the European Union's General Data Protection Regulation (GDPR), and meet the requirements for privacy protection in the context of Vietnam.

     

     

    However, when compared with international standards and relevant current legal regulations of Vietnam, Article 21 of the Draft still reveals many unreasonable points, including the lack of specificity in data processing principles, lack of enforcement mechanisms, etc  and potential conflicts with other legal documents such as the Labor Code 2019 or the Law on Cyber Security 2018. In this article, we will analyze these incomplete points in detail and make comparisons with international practices and domestic laws to make specific recommendations with the desire to complete the Draft, ensure the feasibility of promulgation and implementation in practice.

    1. Regulations related to the protection of personal data of employees in the Draft

    Article 21 of the Draft stipulates the responsibilities of agencies, organizations and individuals in collecting, processing, storing, and deleting personal data in the recruitment and management of employees with the main contents such as:

    1. Stipulate the responsibilities of the recruitment agency, require that only data be collected for recruitment purposes, have the consent of the candidate, and delete the data if not recruited.
    2. Require the protection of employee data, including indefinite retention and deletion of data upon termination of the contract, unless otherwise required by law.
    3. Regulate the use of technology (such as audio and video recording) to collect data, requirements in accordance with the law and ensure that employees are well aware of this measure.
    4. Assign the Government to regulate the processing of data of Vietnamese workers by foreign organizations and individuals.

    Although Article 21 lays the foundation for the protection of personal data in the field of labor, this regulation lacks details, lacks an enforcement mechanism, and is not synchronized with other relevant provisions of Vietnamese law as well as not approaching international standards in this field.

    2. Points to adjust

    2.1 Lack of specificity in the principles of data collection and use

    Problem:

    • Clause 1.a requires the recruitment agency to collect information only "in accordance with the provisions of law" and use it for recruitment purposes or other purposes as agreed. However, the Draft does not clearly define what "in accordance with the provisions of the law" is, leading to the risk of inconsistent interpretation.
    • Clause 1.b requires the consent of the applicant, but does not specify the form of consent (written, electronic, or implied) or the manner in which the purpose and scope of the data will be communicated.
    • Clause 3.a allows the use of technology (audio and video recording) but only requires "employees to be aware of such measures" without specifying prior notice or the right to refuse. Or after agreeing, do you have the right to withdraw that right to refuse?

    Comparison with Vietnamese law:

    • Decree 13/2023/ND-CP (Article 3) stipulates eight principles for personal data protection, including transparency, clear purpose, and data minimization. However, Article 21 does not integrate these principles, in particular requiring detailed notification of the purpose and scope of data use.
    • The Labor Code 2019 (Article 3) emphasizes the privacy rights of employees, but there are no specific regulations on the processing of personal data in recruitment. Article 21 may fill this gap, but the lack of specificity in the form of consent and notification reduces effectiveness.

    Comparison with GDPR:

    • The GDPR[2] (Articles 6 and 7) requires consent to be explicit, specific, voluntary, and documented in writing or equivalent. Businesses must provide transparent information about the purpose, scope, and time of data processing, and the parties receiving the data before collecting it. The GDPR also provides for the right to withdraw consent at any time, something that Article 21 does not cover.
    • The GDPR (Article 5) applies the principle of "data minimization", which requires that only the data necessary for a specific purpose be collected. Article 21 does not mention this principle, leading to the risk of excessive data collection, especially when using surveillance technology.

    Adjustment proposals:

    • Adds clear provisions on the form of consent (e.g., in writing or electronically) and the content of the notification (purpose, scope, storage period, and data recipients).
    • Applying the principle of data minimization, it is required to collect only information necessary for recruitment or labor management purposes.
    • Stipulates the right to withdraw the consent of employees, in accordance with GDPR and Decree 13/2023/ND-CP.

    2.2 Data Deletion and Destruction Policy

    Problem:

    • Clause 1.c requires deletion of data of unemployed candidates, and Clause 2.c requires deletion of data upon termination of employment contracts, unless otherwise required by law. However, the Draft does not specify a specific deadline for data deletion or a mechanism to monitor implementation.
    • There is no provision for the right of the employee to request the deletion of the data or to check that the deletion has been made.

    Comparison with Vietnamese law:

    • The Labor Code 2019 (Article 48) requires the retention of employee records in some cases after the termination of the contract (for example, to resolve labor disputes or social insurance obligations, backup and send records to employees upon request). Article 21 does not clarify what "other cases prescribed by law" are, causing the risk of conflict with the Labor Code.
    • Decree 13/2023/ND-CP (Article 9) requires data deletion when it is no longer necessary, but does not stipulate a monitoring mechanism. Article 21 continues to lack this provision, reducing its practical feasibility.

    Comparison with international law (GDPR):

    • The GDPR (Article 17) provides for the "right to be forgotten", which allows individuals to request deletion of data when it is no longer needed. The organization must prove that the deletion of the data has been performed. Article 21 lacks this mechanism, reducing the ability to protect workers' rights.
    • The GDPR requires that the data retention period must be clearly defined and not exceed the necessary time. Article 21 only refers to "as prescribed by law or agreed upon in a contract" without providing specific guidance.

    Adjustment proposals:

    • Specify a specific time limit for data deletion (e.g., within 30 days of non-employment or termination of the contract).
    • Supplementing the right to request data deletion and a mechanism for employees to check that the deletion has been done.
    • Clarify exceptions to data storage (e.g., as required by the Law on Social Insurance) to avoid conflicts with the Labor Code.

     

    Overview of the seminar on the Draft law on Personal data protection. Source: Government News

     

    2.3 Use of technology in employee management

    Problem:

    • Clause 3 allows the use of technological measures (audio and video recording) but only requires "in accordance with the provisions of law" and "employees are well aware of such measures". The draft does not specify advance notice, the right to opt out, or limit the scope of supervision.

    Comparison with Vietnamese law:

    • The Labor Code 2019 (Article 6) requires that supervisory measures respect the privacy and dignity of workers. However, Article 21 does not provide for the right to refuse supervision or limit the scope, posing a risk of misuse of technology.
    • Decree 13/2023/ND-CP (Article 24) requires DPIA in some cases, but Article 21 does not integrate this requirement, leading to inconsistency.

    Comparison with international law (GDPR):

    • The GDPR (Article 22) prohibits automated decisions based on personal data (such as the use of AI to evaluate performance) unless there is explicit consent or is necessary for a contract. The GDPR also requires a data protection impact assessment (DPIA) for high-risk technology surveillance measures. Article 21 does not mention the DPIA, an important tool for risk assessment.
    • The GDPR requires detailed advance notice of the purpose, scope, and retention period of surveillance data. Article 21 only requires "employees to know" without stipulating the form or content of notification.

    Adjustment proposals:

    • DPIA requirements for high-risk surveillance technology measures, as stipulated in Decree 13/2023/ND-CP and GDPR.
    • Stipulate the right of employees to refuse supervision and require detailed advance notification of the purpose, scope, and duration of supervision.
    • Limit the scope of use of technology to ensure that only necessary data is collected, avoiding invasion of privacy.

    2.4 Data management by foreign organizations and individuals

    Problem:

    • Clause 4 assigns the Government to regulate the processing of data of Vietnamese workers by foreign organizations and individuals, but does not provide guiding principles or cross-border management mechanisms.

    Comparison with Vietnamese law:

    • The Law on Cyber Security 2018 (Article 26.3) requires foreign service providers to store data in Vietnam and set up a representative office in Vietnam. Article 21 does not integrate this requirement, leading to inconsistency.
    • Decree 13/2023/ND-CP does not specify cross-border data in the field of labor, causing Clause 4 to lack a basis for enforcement.

    Comparison with international law (GDPR):

    • The GDPR (Chapter V) details cross-border data transfers, requiring recipient countries to have an equivalent level of protection or to use additional safeguards (such as standard contracts - SCCs). Article 21 does not mention these mechanisms, making the management of cross-border data unclear.
    • The GDPR requires foreign organizations that process EU citizens' data to appoint a representative in the EU. Article 21 does not have a similar requirement, making it difficult to supervise and handle violations.

    Adjustment proposals:

    • Supplement the requirement to store data in Vietnam and appoint legal representatives for foreign organizations, in accordance with the Law on Cyber Security.
    • Apply cross-border data protection mechanisms, such as standard contracts or equivalent protection level certifications.
    • Provide specific guiding principles in Article 21 to guide the documents under the law.

     

    Article 21 of the Draft Law on Personal Data Protection is a step forward in protecting the privacy of workers in Vietnam, but there are still many points that need to be adjusted to ensure feasibility, consistency with domestic law, and conformity with international standards. Key issues include a lack of specificity in the principles of data collection and use, a lack of data erasure and technology monitoring mechanisms, a lack of cross-border data regulation, and effective enforcement monitoring mechanisms. The adjustments we propose not only help protect workers' rights but also promote Vietnam's integration into the global legal system for personal data protection, creating a clear and easy-to-implement enforcement platform for employers in practice.


     

    [1] The latest draft of the Law on Protection of Personal Data, see here  the draft of the Law on Protection of Personal Data that has been adapted for discussion at the truong.docx

     

    [2] https://gdpr-info.eu/art-7-gdpr/, accessed on 2025/06/24