You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 6, 2018

Vietnam Issues Decree on Disclosure of Customer Financial Information

Informed Counsel

With Vietnam’s controversial new Law on Cybersecurity set to take effect on January 1, 2019, the protection of personal information has become a very hot topic for Vietnamese and foreign companies and organizations. In the banking sector, where customer information is particularly sensitive, confidentiality has always been a matter of crucial importance.   

In September, the government of Vietnam issued Decree No. 117/2018/ND-CP on confidentiality and  dis- closure of customer information of credit institutions and branches of foreign banks (Decree 117). Decree 117 took effect on November 1, 2018, replacing Decree No. 70/2000/ND-CP of 2000 on confidentiality, storage, and disclosure of information related to customer deposits (Decree 70). Below are some notable points of Decree 117.

Governing Scope    .

Decree 117 applies broadly to the confidentiality and disclosure of customer information of credit institutions and branches of foreign banks in Vietnam. However, some information is excluded from its purview, including customer information that is (i) classified as state secrets, (ii) provided to the State Bank of Vietnam, or (iii) used for anti-money laundering or anti-terrorism purposes.

Definition of Customer Information   

This is the first time that customer information of a credit institution or a branch of a foreign bank has been formally defined under Vietnamese legislation. Under Article 3 of Decree 117, such customer information is defined as information that is provided by the customer, or arises in the course of a customer requesting or a credit institution/bank providing banking products and services, comprising:

(1)    Personally identifiable information that contributes to identifying customers, whether individuals or organizations.

  • For individuals: Full name; specimen signature; electronic signature; date of birth; nationality; occupation; permanent residence, current residence, or place of residence abroad (for foreigners); telephone number; email address; ID card or passport number, date of issuance, and place of issuance; and other relevant information.
  • For organizations: Full name; abbreviated name; establishment license or decision; enterprise registration certificate or equivalent document; address of head office; telephone number; fax number; email address; personally identifiable information (as described above) of the legal representative of the organization; and other relevant information.

As in other Vietnamese data privacy regulations, “personally identifiable information” is defined very broadly, and the phrase “other relevant information” is problematic in that it seems to allow almost any information about the customer to be considered “personally identifiable information.”

(2)    Information on accounts, deposits, deposited assets, transactions, securing parties, and other relevant information. (Most of these terms are further defined/clarified in the same article.)

Requests from State Authorities

Competent state authorities—which have been expanded under Decree 117 to include state audit agencies, customs authorities, and tax authorities, among others— can request the disclosure of customer information from credit institutions and branches of foreign banks in order to perform their assigned functions and tasks, provided they comply with the following conditions:

  • Their request for customer information is in line with the purposes, contents, scope, and jurisdiction stipulated by law or as agreed by the customer, and they must bear responsibility for their requests.
  • They have supporting documents to prove the reasons for and objectives of such request, issued by the appropriate-level authority, and in conformity with relevant law, unless such request relates to a criminal proceeding or national security.
  • After obtaining the customer information, they must keep it confidential, use it in line with the purpose stated when requesting the information, and not disclose it to any third party without consent of the customer, except where permitted by law.

Although Decree 117 requires the authorities to maintain the confidentiality of the customer information they receive, enforcement will be a challenge in practice. By expanding the range of state authorities having the right to request customer information, without any corresponding requirements to improve oversight or secrecy, there is a greater risk of customer information being disclosed, intentionally or unintentionally.

Requests from Non-State Entities   

Under Article 11, credit institutions and branches of foreign banks may only disclose customer information to other non-state organizations or individuals in one of the following circumstances:

(1)    At the request of an entity specifically authorized to make such request in accordance with codes, laws, and resolutions issued by the National Assembly; or

(2)    Upon receiving the customer’s consent in writing or in another form as agreed with the customer.

In a notable change from Decree 70, Decree 117 does not allow credit institutions, without the prior consent of their customers, to share customer information with each other. Although this is in line with Vietnam’s general rules on data privacy, it may cause difficulties for credit institutions, as the exchange of customer information within the banking system is vital for evaluating and mitigating insolvency risks.

Other Provisions   

Decree 117 specifies the form for requesting disclosure of customer information, which applies to requests made by both state authorities and non-state entities, as well as the procedure and deadlines for financial institutions to carry out the information disclosure (10 working days for simple and readily available information, or 25 working days for complicated and not readily available information), except as otherwise regulated by the relevant laws.   

The new decree does not address whether financial institutions may provide access to, disclose, or transfer customer information to third parties located outside of Vietnam. These issues are covered by other legislation, such as the Law on Cybersecurity.

Outlook

Decree 117 aims to reduce the number of fraudulent transactions and mitigate the risk of outside parties appropriating the personal information and assets of banking customers. While these are worthy goals, the effectiveness and enforcement of Decree 117 remain to be seen.

RELATED INSIGHTS​ 

March 19, 2025
On January 1, 2025, the Department of Business Development (DBD) in Thailand’s Ministry of Commerce implemented new stringent corporate registration screening measures in collaboration with several other government agencies to prevent entities from opening corporate mule accounts to commit criminal activities in Thailand. The DBD’s Order of the Office of Central Company and Partnership Registration No. 3/2024 stipulates a new method for registering the establishment of partnerships and limited companies for people who have been involved in underlying crimes or who are owners of bank accounts that are being used for underlying crime, as per the notification of the Anti-Online Scam Operation Center (AOC) to the Anti-Money Laundering Office (AMLO) and the collated AMLO list of such persons. The order establishes the following key requirements: Managing partners and directors of partnerships and limited companies, respectively, whose names have been listed by the AMLO as a person who is involved in an underlying offense, or as the owner of a bank account being used for the underlying offense, must appear before the registrar in person. The concerned persons cited on the AMLO list must provide valid documentation of their identity to the DBD registrar (e.g., national identification card, government official identification card, government or state enterprise employee identification card, alien identification card, passport, document used in lieu of a travel document, or other similar documents with photo identification). This collaboration between the DBD and various relevant government agencies aims to eradicate the problem of fraudsters using mule accounts set up under legally established entities to deceive the public. It also seeks to enhance checks and screening of corporate mule accounts that are used to carry out criminal activities such as money laundering or cybercrime. These actions are part of the Thai government’s broader policy to suppress economic crimes. For more
March 14, 2025
The Bank of Thailand (BOT) has published the Draft Guidelines for Digital Fraud Management, which aim to help financial service providers tackle digital fraud and ensure safety and trust in the Thai financial system. These draft guidelines, which are available for public comment until March 18, 2025, provide a comprehensive framework for financial service providers, covering prevention, detection, management, and resolution of digital fraud, as well as support for customers affected by fraud. The BOT tentatively plans to implement these draft guidelines on April 1, 2025, along with circular letters on the minimum required measures for tackling “mule accounts” (deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of any offense) and measures to strengthen Thailand’s customer due diligence and enhanced due diligence procedures. Under the draft guidelines, “financial service providers” include financial institutions and special financial institutions under the Financial Institution Business Act and payment providers under the Payment Systems Act. Commercial banks, special financial institutions, and operators of transferable e-money services must adhere to every requirement in the draft guidelines. Other financial service providers (e.g., payment providers other than operators of transferable e-money services) can implement the draft guidelines as deemed appropriate to their services, products, and service channels. Digital Fraud Management Requirements The draft guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must set and adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle, from customer onboarding to service termination, according to industry standards at a minimum and covering at least the following processes: Know your customer
February 24, 2025
On January 31, 2025, the Bank of Thailand (BOT) announced a new Notification re: Responsible Lending, replacing a similar notification from 2023. This new notification provides updated measures to assist debtors in different circumstances and clear implementation guidelines for lenders, with the aim of resolving household debt issues. Scope The service providers covered by the notification include banks and nonbanks (e.g., credit card companies, asset management companies, licensed personal loan providers, and nano finance operators) that conduct lending business. New Requirements The notification’s core focus remains loan management throughout the lifecycle of a loan—from credit product development to legal proceedings and debt transfers to other creditors—but with further clarification and detail compared to the 2023 notification. The key revisions in the new notification are summarized below. Advertising standards: The notification tightens requirements in some areas and relaxes them in others. Stricter requirements: It is now clearly stipulated that the BOT oversees taglines that may encourage excessive borrowing. More examples of noncompliant statements are also added (e.g., “Elevate your lifestyle now, pay later”; “Get approved, even with credit challenges”). In addition, advertising material that contains multiple credit products should provide clear minimum and maximum interest rates, especially when there are significant differences in the interest rates of each product. Relaxed requirements: The required information for some marketing activities is now reduced. For example, in marketing events with staff promoting loan products and offering free giveaways, service providers have the discretion to provide effective interest rate information in the manner they deem appropriate, and the advertisement material can display only the mandatory warning statements without providing interest rate details. Encouraging customer financial discipline: The notification requires service providers to implement more elaborate and extensive tools to influence customer behavior (termed “nudging” by the BOT) at every stage of the lending cycle. This
February 19, 2025
On January 3, 2025, the Bank of the Lao PDR (BOL) issued Decision No. 11/BOL on the Use of Foreign Currency in Lao PDR, taking effect on the same date. This decision sets out the rules for using foreign currency in Laos and ensures the Lao kip (LAK) remains the primary currency while allowing flexibility for international transactions. Key points in the decision are outlined below. Permissible Activities for Foreign Currency The decision provides that authorized entities can use foreign currency as a secondary currency to LAK in the setting of cost and pricing structures, announcing and advertising prices, and making or receiving payments for goods and services that are imported or have manufacturing inputs imported from other countries. Otherwise, LAK is the only permitted currency. The decision also stipulates that foreign exchange must be conducted only via authorized commercial banks or foreign exchange markets. The exchange rate for setting costs, pricing structures, announcing and advertising prices, and making and receiving payments for goods and services in foreign currency must match the exchange rate announced by commercial banks from time to time. Businesses Allowed to Use Foreign Currency The decision allows certain businesses and organizations to use foreign currency. These entities are divided into two groups: those that need approval before using foreign currency, and those that can use it immediately. Enterprises that can use foreign currency with BOL approval include: Businesses that export goods or services and entities that lease or obtain concessions from the government, generating revenue in foreign currency through commercial banks. Enterprises that provide international freight and passenger transportation services. Enterprises that provide services related to cross-border logistics and warehousing. Enterprises located at international borders and airports, such as duty-free shops and restaurants. Enterprises that have obligations to make payments in foreign currency to other