Personal data protection: it is too difficult for companies to comply with regulations

Insights
Personal data protection: it is too difficult for companies to comply with regulations
Posted on: 12/06/2024

    In this article, our Managing Partner, Nguyen Van Phuc will analyze the challenges that businesses face in complying with regulations on personal data protection and propose solutions to help businesses minimize potential risks. The article was published in The Saigon Times No. 23 - 2024, dated on June 05, 2024. Below is the English version:

    Personal data is playing an increasingly important role in the digital economy. Considering the importance of personal data as well as the risks in case of illegal collection and processing of personal data, the government issued Decree 13/2023/ND-CP on the Protection of Personal Data ("Decree 13") in April 2023. This Decree came into effect shortly thereafter, but it is undeniable that the provisions of this Decree are still quite new and vague for many businesses. Recently, the Ministry of Public Security is also in the final stages of drafting a Decree on Sanctioning Administrative Violations in the Area of Cybersecurity ("Draft Decree"), which includes violations of personal data protection regulations. This Draft Decree is expected to take effect in June 2024 and will certainly put great pressure on companies to comply with personal data protection regulations.

    Many points are unclear

    The Draft Decree was enacted based on the need to have a law that sanctions administrative violations in cybersecurity, especially in the context that the issue of personal data protection is attracting a lot of attention from businesses and people. However, as Decree 13 is still new to many companies, even government administrative agencies, some provisions in the draft decree are not clear.

    (Source: The Saigon Times)

    This is evidenced by the inconsistency between the provisions of Decree 13 and the Draft Decree. For example, Article 14(e)(1) of the Draft Decree requires the controller of personal data and the controller and processor of personal data to delete personal data within 48 hours upon the request of the data subject. However, according to the provisions of Clause 5, Article 16 of Decree 13/2023/NĐ-CP, the time limit for fulfilling this obligation may be extended up to 72 hours. This inconsistency not only confuses the deadlines for processing applications, but also makes it difficult for the parties concerned to comply with the legal requirements. As a result, unnecessary violations may occur, leading to unnecessary disputes and complaints. In order to solve this problem, it is necessary to review and adjust the regulations in the Draft Decree to be consistent with Decree 13.

    At the same time, with respect to the requirement to delete data when the original purpose of collection is no longer necessary, clearly determining that purpose of collection is a major challenge for companies. At present, the Draft Decree does not provide specific quantitative limits for determining the purpose of data collection, which makes it difficult to comply with this obligation and exposes businesses to the risk of administrative penalties. Specifically, Point đ Clause 1 Article 14 of the Draft Decree stipulates that if personal data is not deleted upon the request of the data subject or if the original purpose of data collection is no longer necessary, this behavior will be considered a violation and subject to a fine of VND20,000,000 to VND40,000,000 (for businesses). In a context where businesses regularly process personal data of customers and employees, it is difficult to respond promptly to all data deletion requests and to accurately determine when the purpose of data collection is no longer necessary. Businesses need to keep personal information for various purposes for a long time after the relationship with a customer or employee has ended. Forcibly deleting data upon request without considering other factors creates risks for organizations, including the loss of critical evidence or data in the event of a dispute.

    In addition, another issue in the Draft Decree that also requires attention is the regulation on penalties for storing personal data without a contract or a document from a competent state authority on the functions and tasks assigned by the storage of personal data (item b, clause 1, Article 20 of the Draft Decree). According to this regulation, companies may be subject to administrative sanctions for storing personal data without a contract. It can be understood that this provision is based on the fact that companies may process personal data without the consent of data subjects (employees, customers, partners, etc.) in order to fulfill their obligations under the data subject's contract with relevant agencies, organizations and individuals according to the provisions of the law. However, according to the provisions of the Draft Decree, if a company collects and stores information about another public company (which has been disclosed and includes information about other individuals on the board of directors of that company) to serve the purposes of the company, the company is still likely to be sanctioned for not having a contract with the above public company/individual leaders. If this regulation becomes effective in practice, many companies will be at risk of violating the law, as the collection of public companies' disclosed information (including personal information) is necessary and important, and serves many business purposes without affecting public companies, such as analyzing the operational and administrative activities of public companies before investing. In our opinion, this regulation needs more careful consideration before being applied in practice.

    Business direction?

    In addition to the above, both the Draft Decree and Decree 13 still contain many vague contents and regulations, making it difficult for companies to understand and comply with them. At the same time, there are also many potential challenges for enterprises to be fined for administrative violations.

    (Source: Internet)

    At present, more and more enterprises are still confused about the regulations related to personal data protection. We believe that in order to minimize the risks that may be encountered, companies should take the necessary measures to comply with personal data protection regulations early on:

    First, companies need to review all activities related to the collection and processing of personal data. In addition, companies need to define their exact role in this relationship, whether it is a controller of personal data, a processor of personal data, or both. Correctly defining their role will help companies to fully and correctly comply with their obligations and regulations, including completing administrative procedures with the Ministry of Public Security.

    Second, companies should assess their operations with respect to personal data protection regulations. It is the responsibility of the enterprise to search and detect errors and violations of the enterprise against regulations on personal data protection, evaluate the extent of violations, encounter risks, and find appropriate solutions to resolve them.

    Third, organizations need to quickly review, adopt, or amend internal policies regarding the protection of personal information. These policies can come from many different document sources, such as collective bargaining agreements, work rules, employment contracts, etc. Therefore, organizations need to prioritize reviewing all of these documents as soon as possible. At the same time, companies should also develop special procedures and policies on personal data protection, which will serve as the basis for companies to conduct other activities, such as training and dissemination of regulations on personal data protection.

    Fourth, companies need to promote internal control. Compliance monitoring can help companies detect errors and violations early and find specific solutions quickly, thereby limiting the risks that arise.

    Finally, an activity that companies should also consider implementing soon is the training and dissemination of personal data protection policies and regulations to employees and managers in their own companies. This activity helps to raise the awareness of every employee about the importance of personal data protection and the consequences of corporate violations.

    In summary, there are still many ambiguities in the provisions of Decree 13 and the Draft Decree on Sanctioning Administrative Violations in Cybersecurity, which pose great challenges to companies in complying with these regulations. However, the protection of personal data is a key issue in the current digital economy, so companies also need to take measures to quickly adapt to legal regulations, and the scope of regulation is deep, covering almost every aspect of business operations.

     

    Read more at: Bảo vệ dữ liệu cá nhân: Quá khó để doanh nghiệp tuân thủ quy định