Gone are the days of freely collecting and processing customer image data

Insights
Gone are the days of freely collecting and processing customer image data
Posted on: 27/10/2025

    Individual customer image data is becoming a valuable resource for businesses. From the use of surveillance cameras in retail stores, facial recognition in payment systems, to image analysis for marketing purposes, businesses are leveraging this type of data to enhance customer experience and optimize business operations. However, in the context that Vietnam is requiring strict protection of personal data, the way businesses collect and process customer image data will have many changes.

     

     

    Stricter regulations on personal image data protection

    According to Decree 13/2023/ND-CP, personal data includes information in the form of symbols, letters, digits, images, sounds, or similar forms that are associated with a specific person or help identify a specific person. Image data, especially facial images used for biometric identification, is classified as sensitive personal data, which requires a higher level of protection.

    The Law on Personal Data Protection 2025, which was approved by the National Assembly on June 26, 2025 and will take effect from January 1, 2026 (the Law on PDP), further strengthens the provisions of Decree 13, emphasizing the principles of transparency, consent and accountability. This new law applies not only to domestic enterprises but also to foreign organizations that handle personal data in Vietnam, with stricter sanctions, including administrative fines of up to 5% of revenue or criminal handling in case of serious violations.

    The core principle of image data collection is to be based on the voluntary, specific, and clearly informed consent of the data subject. According to Decree 13/2023/ND-CP, consent must be an affirmative action, which cannot be inferred from silence or non-objection. For image data, which can be related to biometrics such as fingerprints or faces, the Law on PDP 2025 stipulates that this is sensitive data, requires separate consent and is not bundled together with other provisions[1].

    According to these regulations, enterprises are obliged to: First, must ensure that consent is voluntary and clear from customers. For example, when customers register for services at the store, businesses can use the form of checking the consent box on the mobile application or voice recording confirmation. However, customers must not be forced to agree to access basic services, as this violates the principle of voluntariness. The 2025 law emphasizes that consent must be specific to each purpose, such as "using facial images to authenticate payments" and not vague purposes such as "improving services" as many businesses are doing. In addition, enterprises are not allowed to collect, trade, or share image data without consent, and must stop processing as soon as consent is withdrawn.

    Secondly, the obligation to notify is mandatory and must be fulfilled before data is processed. The notice should include: (i) the purpose of the processing, the type of data (such as facial images, surveillance video), (ii) the method and time of the processing, (iii) stakeholders such as the cloud service provider, and (iv) the potential consequences such as the risk of data leakage. For businesses using AI to analyze images, it is necessary to clearly inform the algorithm used and the possibility of bias. International practice recommends using simple, easy-to-understand language, avoiding technical terminology, and providing notifications via multiple channels such as email, apps, or on-site signage when making announcements.

    Managing risks when collecting and processing personal data

    Businesses must proactively assess the risks of processing image data, especially on a large scale or involving sensitive data. Data Protection Impact Assessment (DPIA) is a mandatory tool under Decree 13/2023/ND-CP, and the Law on PDP 2025 extends this requirement to all sensitive data processing activities. DPIA helps identify risks such as data exposure, image-based discrimination, and propose measures to mitigate the risk of data leakage and quickly handle possible incidents.

    The DPIA process includes activities such as describing the disposal, assessing necessity and proportionality, identifying risks to stakeholder interests, and remedial measures. For camera systems using AI facial recognition, enterprises must submit a DPIA to the Department of Cyber Security and High-tech Crime Prevention and Combat, Ministry of Public Security. The Law on PDP 2025 requires the DPIA to be updated periodically or when there is a major change, and to keep reports for at least 5 years.

     

    Source: The Saigon Times

     

    In addition, businesses should internalize regulations into labor contracts, customer service, with clear provisions on data scope and confidentiality obligations. For example, in the contract signed with the employee who accesses the image data, it is necessary to stipulate personal responsibility to avoid abuse. According to experience from countries such as Singapore, Europe, or even China, the implementation of DPIA not only helps with compliance but also improves reputation, as customers increasingly prioritize business transparency and compliance with personal data protection.

    To comply with customer image data protection regulations

    When using cameras to collect customer images, businesses must strictly follow them to avoid invading privacy. The current personal data protection law requires transparency by installing a clear notice board at the camera location, stating the purpose, scope and contact to exercise the right. The installation location must be legal, not directed at a private area such as a locker room or toilet, and not invade the personal life and privacy of others.

    The storage period of image data should be limited, usually not exceeding 3 months unless otherwise provided for by law. The Law on PDP 2025 adds that data from cameras must be processed only for the purpose for which it was notified, and must not be used for advertising activities without the explicit consent of the customer. Therefore, taking photos of customers using the company's products to carry out advertising campaigns or any activities that promote the development of the company's brand without the explicit consent of the customer is a violation. In fact, retail chains in Vietnam such as WinMart, Bach Hoa Xanh, have implemented quite clear signage and policies to help reduce complaints from customers. However, the number of businesses that understand the scope of image data collection and comply with these regulations is still quite limited.

    Security is key to preventing unauthorized access to image data. Businesses need to apply technical measures such as data encryption when storing and transmitting, access control based on the role of each employee participating through DPIA activities. At the same time, businesses must periodically check the backup and the possibility of problems for this type of data. Training employees in legal compliance skills and requirements is mandatory, as no business is held accountable for employee behavior and faces strict legal penalties when an incident occurs.

    It can be seen that the days when businesses could freely collect customer image data to develop their brand or even let employees reveal their customers' images to the outside when collected[2]. Now, this behavior is considered a serious violation of the law and can seriously damage the brand. In a time when data and privacy are being prioritized for protection, businesses are forced to pay attention and invest in complying with legal requirements – a key to sustainable development.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm

    Read more: Hết thời thoải mái thu thập và xử lý dữ liệu hình ảnh của khách hàng


    [1] Clause 2 (dd), Article 4 of the Draft Decree guiding the Law on PDP 2015

    [2] https://znews.vn/du-luan-day-song-ve-vu-doi-trai-gai-bi-quay-canh-nong-trong-rap-cgv-post864900.html, accessed on 10/13/2025.