Solutions required for companies to comply with Decree 13/2023/ND-CP on the protection of personal data

Insights
Solutions required for companies to comply with Decree 13/2023/ND-CP on the protection of personal data
Posted on: 03/11/2023

    The article is made in collaboration between VCCI-HCM and HM&P Law Firm. In this article, HM&P will mention some tasks/procedures that companies need to implement in accordance with the provisions of Decree 13/2023/ND-CP on the Protection of Personal DataBelow is the English version translated by HM&P of this article:

     

    At present, personal data has gradually become a crucial resource in the digital economy. The development and use of this resource raises the issue of balancing interests with the responsibility to protect the rights and interests of individuals whose personal data has been reflected. On April 17, 2023, the Government issued Decree 13/2023/ND-CP on the Protection of Personal Data ("Decree 13"), which amends the development, management and protection of personal data. The Decree will take effect from July 1, 2023, and raises a number of requirements to be complied with by relevant organizations to ensure that personal data does not cause damage to the legitimate rights and interests of data subjects.   

    However, Decree 13 is still very new in its practical application and is almost unknown to many companies. At the same time, Decree 13 does not prescribe specific procedures for enterprises to carry out; instead, the Decree sets forth many regulations that relevant parties are required to follow. As a result, whether enterprises should strictly follow the regulations of Decree 13 or not, counterparts need to review the provisions themselves and compare them with their actual operations to plan the tasks/procedures that need to be completed.  

    In this article, we will mention some tasks/procedures that companies need to implement in accordance with the provisions of Decree 13.

    1. Determine the role of the company in processing personal data

    In addition to the data subject, who is the individual whose personal data has been reflected, Decree 13 gives a number of other subjects regarding the processing of personal data. These subjects include the personal data controller, the personal data processor and the personal data controller cum processor. In order to apply the provisions of Decree 13, companies must determine their role in the processing of personal data. In particular, at present, most companies will fall into the situation of the personal data controller cum processor, because the company must make a decision on the purpose and means of processing personal data, while it will directly further process personal data. For the sake of clarity, let us take the following example: Company A needs to collect and store the personal data of its employees for the purpose of concluding and implementing employment contracts with the company, the collection and storage are performed on the system built and developed by Company A. Company A defines the purpose of processing personal data (to serve the purpose of concluding and implementing employment contracts), at the same time, Company A decides that the processing will be applied on the system built by Company A (data processing facility). Therefore, Company A is the controller of the personal data. In addition, Company A collects and stores the personal data of its employees directly (through employees providing personal information in their employment contracts, relevant documents such as degrees, resumes, ...), accordingly, Company A is also the personal data processor. In short, Company A is the personal data controller cum processor.

    Determining the role of the company in the processing of personal data will affect its rights and obligations, and will also shape the tasks/procedures that companies need to perform.

    2. Determination of the types of personal data processed

    Decree 13 classifies personal data into basic personal data and sensitive personal data. This classification has certain implications on the obligations that companies must comply with. In particular, in the event that enterprises have sensitive personal data processing activities, they must designate a department with the function of protecting personal data, appoint personnel in charge of protecting personal data, and exchange information on the department and personnel in charge of protecting personal data with the authority in charge of protecting personal data. In order to comply with this obligation, enterprises shall establish a department with the function of protecting personal information and appoint personnel in charge of protecting personal information. At the same time, for the obligation to exchange information on the department and person in charge of personal data protection with the authorities in charge of personal data protection, enterprises will declare this content in the documents submitted to the Ministry of Public Security (Department of Cyber Security and High-Tech Crime Prevention and Control). Establishing a personal data protection department and assigning personnel to protect personal data will cost companies a lot of money. Therefore, this is also an issue that companies need to make a note of when preparing.

    In fact, many companies recruit employees based on biometric criteria, numerology, or especially medical and health criteria. These are all considered sensitive personal data. Therefore, companies need to review their operations to determine whether or not the personal information they collect and store is sensitive personal information, and then handle it appropriately.

    3. Building processes, reviewing and changing the company's document system

    This is almost a mandatory task that companies have to perform because the provisions of Regulation 13 relate to the company's employees and customers consenting to provide personal data to the company, consenting to allow the company to process their personal data, withdrawing consent, and so on. These are mostly new regulations, companies will have to change or develop more new processes, rules, forms for these activities. In particular, for employees, companies may need to amend probationary contract forms, employment contracts, collective bargaining agreements, work rules, and other internal regulations to explicitly demonstrate the employee's consent to both providing and processing personal data. At the same time, new procedures and forms must be developed for withdrawing employee consent. Meanwhile, for customers and business partners, companies need to standardize sample consent agreements for the provision and processing of personal data for customers and partners to sign. In general, the content of the policies and forms will depend on each company's operating situation, purpose, and level of use of personal data.

    In addition, the establishment of processes, review and amendment of the company's document system aims to establish regulations on the obligation to protect the personal data of the company and its employees. It is clear to say that the definition of responsibilities and sanctions, in the case of enterprises violate the protection of personal data.

    4. Implementation of technical measures to protect personal data

    According to the provisions of Decree 13, in addition to administrative measures, companies must also implement technical measures to protect personal data. Although this Decree does not explicitly prescribe these technical measures, it can be understood that they are technical protection measures that are different from the management measures mentioned above. For example, establishing a firewall system to prevent intrusions into personal data systems, using a multi-layered security system to access personal data, etc. Implementing technical measures can help companies facilitate accountability when implementing personal data processing impact assessment procedures and other related procedures.

    5. Implementation of administrative procedures

    Currently, one of the issues that many companies are concerned about is whether they need to conduct any administrative procedures with respect to Decree 13. As mentioned above, Decree 13 affects almost all operating companies, most of which will be involved in personal data processing activities. Per se, the implementation of administrative procedures can be considered mandatory for companies.

    According to the provisions, enterprises are required to implement several procedures, including assessment of the impact of processing personal data (almost the entire enterprise), assessment of the impact of transferring personal data abroad (for enterprises that transfer data abroad, usually enterprises with parent companies abroad, e-commerce enterprises, etc.), notification of violations of regulations on protection of personal data (almost the entire enterprise). On July 4, 2023, the Ministry of Public Security issued Decision No. 4660/QD-BCA-A05, thereby announcing 5 administrative procedures related to personal data processing activities. Otherwise, at present, the implementation of online administrative procedures has not been implemented because the national information portal on personal data protection has not been completed. Therefore, the implementation of these administrative procedures is still done in person or by mail.

    In general, the promulgation of Decree 13 is an appropriate addition to Vietnamese laws in the context in which the issue of information security and personal data protection is extremely urgent, so it contains many conditions and requirements that enterprises must follow. To ensure compliance with these conditions, enterprises need to be truly aware of the importance of protecting personal data, thoroughly study the legal regulations on processes and how to build protection measures on legitimate personal data; important obligations such as obtaining consent from data subjects, notification obligations, or obligations to process personal data within the permitted scope and purpose. These are fundamental issues that companies need to start focusing on establishing and building into their operations. There are quite a few requirements and conditions, as usual, compliance will face some difficulties and shortcomings. Accordingly, we believe that the core factor that this decree seems to see is to raise the awareness of personal data protection and the rigor and best efforts of enterprises in protecting personal data, especially the personal data of employees.

     

    Read the article on VCCI website at: Những hành động cần thiết của doanh nghiệp để tuân thủ Nghị định 13/2023/NĐ-CP về bảo vệ dữ liệu