You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 6, 2018

Vietnam Issues Decree on Disclosure of Customer Financial Information

Informed Counsel

With Vietnam’s controversial new Law on Cybersecurity set to take effect on January 1, 2019, the protection of personal information has become a very hot topic for Vietnamese and foreign companies and organizations. In the banking sector, where customer information is particularly sensitive, confidentiality has always been a matter of crucial importance.   

In September, the government of Vietnam issued Decree No. 117/2018/ND-CP on confidentiality and  dis- closure of customer information of credit institutions and branches of foreign banks (Decree 117). Decree 117 took effect on November 1, 2018, replacing Decree No. 70/2000/ND-CP of 2000 on confidentiality, storage, and disclosure of information related to customer deposits (Decree 70). Below are some notable points of Decree 117.

Governing Scope    .

Decree 117 applies broadly to the confidentiality and disclosure of customer information of credit institutions and branches of foreign banks in Vietnam. However, some information is excluded from its purview, including customer information that is (i) classified as state secrets, (ii) provided to the State Bank of Vietnam, or (iii) used for anti-money laundering or anti-terrorism purposes.

Definition of Customer Information   

This is the first time that customer information of a credit institution or a branch of a foreign bank has been formally defined under Vietnamese legislation. Under Article 3 of Decree 117, such customer information is defined as information that is provided by the customer, or arises in the course of a customer requesting or a credit institution/bank providing banking products and services, comprising:

(1)    Personally identifiable information that contributes to identifying customers, whether individuals or organizations.

  • For individuals: Full name; specimen signature; electronic signature; date of birth; nationality; occupation; permanent residence, current residence, or place of residence abroad (for foreigners); telephone number; email address; ID card or passport number, date of issuance, and place of issuance; and other relevant information.
  • For organizations: Full name; abbreviated name; establishment license or decision; enterprise registration certificate or equivalent document; address of head office; telephone number; fax number; email address; personally identifiable information (as described above) of the legal representative of the organization; and other relevant information.

As in other Vietnamese data privacy regulations, “personally identifiable information” is defined very broadly, and the phrase “other relevant information” is problematic in that it seems to allow almost any information about the customer to be considered “personally identifiable information.”

(2)    Information on accounts, deposits, deposited assets, transactions, securing parties, and other relevant information. (Most of these terms are further defined/clarified in the same article.)

Requests from State Authorities

Competent state authorities—which have been expanded under Decree 117 to include state audit agencies, customs authorities, and tax authorities, among others— can request the disclosure of customer information from credit institutions and branches of foreign banks in order to perform their assigned functions and tasks, provided they comply with the following conditions:

  • Their request for customer information is in line with the purposes, contents, scope, and jurisdiction stipulated by law or as agreed by the customer, and they must bear responsibility for their requests.
  • They have supporting documents to prove the reasons for and objectives of such request, issued by the appropriate-level authority, and in conformity with relevant law, unless such request relates to a criminal proceeding or national security.
  • After obtaining the customer information, they must keep it confidential, use it in line with the purpose stated when requesting the information, and not disclose it to any third party without consent of the customer, except where permitted by law.

Although Decree 117 requires the authorities to maintain the confidentiality of the customer information they receive, enforcement will be a challenge in practice. By expanding the range of state authorities having the right to request customer information, without any corresponding requirements to improve oversight or secrecy, there is a greater risk of customer information being disclosed, intentionally or unintentionally.

Requests from Non-State Entities   

Under Article 11, credit institutions and branches of foreign banks may only disclose customer information to other non-state organizations or individuals in one of the following circumstances:

(1)    At the request of an entity specifically authorized to make such request in accordance with codes, laws, and resolutions issued by the National Assembly; or

(2)    Upon receiving the customer’s consent in writing or in another form as agreed with the customer.

In a notable change from Decree 70, Decree 117 does not allow credit institutions, without the prior consent of their customers, to share customer information with each other. Although this is in line with Vietnam’s general rules on data privacy, it may cause difficulties for credit institutions, as the exchange of customer information within the banking system is vital for evaluating and mitigating insolvency risks.

Other Provisions   

Decree 117 specifies the form for requesting disclosure of customer information, which applies to requests made by both state authorities and non-state entities, as well as the procedure and deadlines for financial institutions to carry out the information disclosure (10 working days for simple and readily available information, or 25 working days for complicated and not readily available information), except as otherwise regulated by the relevant laws.   

The new decree does not address whether financial institutions may provide access to, disclose, or transfer customer information to third parties located outside of Vietnam. These issues are covered by other legislation, such as the Law on Cybersecurity.

Outlook

Decree 117 aims to reduce the number of fraudulent transactions and mitigate the risk of outside parties appropriating the personal information and assets of banking customers. While these are worthy goals, the effectiveness and enforcement of Decree 117 remain to be seen.

RELATED INSIGHTS​ 

June 12, 2025
Thailand’s Ministry of Finance has issued a royal decree placing the business of hire purchase and leasing of cars and motorcycles under the scope of the Financial Institution Business Act B.E. 2551 (2008), effective December 2, 2025. This is to ensure appropriate regulatory oversight of these business activities, as they function similarly to credit granting and serve as a source of funding for the public with a broad impact on the overall economic system and consumers at large. The business operators that this royal decree applies to include corporate entities engaging regularly in the business of hire purchase or leasing of cars or motorcycles, currently excluding: Financial institutions and specialized financial institutions. Individuals operating such businesses (noncorporate entities). Cooperatives. Key regulatory obligations of this royal decree include the following: Business operators must disclose interest rates, service fees, and other relevant business information to the public and report to the Bank of Thailand (BOT). Business operators must display how the annual percentage rate (APR), including all annual charges covering interest and service fees, is calculated. Business operators must maintain accurate accounting records in accordance with recognized accounting standards. The BOT may issue warnings or suspend operations if business operators fail to comply with this royal decree or act unfairly in a way that may result in serious harm to customers. Directors, managers, and responsible persons of any business operator that violates this royal decree may also be subject to the prescribed penalties. Before the royal decree takes effect, business operators should conduct internal assessments and engage with counsel to prepare for regulatory implementation. The BOT is expected to issue further subordinate regulations and guidance regarding: Interest, service fees, deposits, collateral, benefits, and penalties that may be charged by business operators. Contract content, methods of benefit calculation, and format in conducting
May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.
May 5, 2025
On April 29, 2025, the government of Vietnam promulgated Decree No. 94/2025/ND-CP with regulations on a controlled “sandbox” for innovative fintech solutions in the banking sector (Decree 94). The decree aims to promote innovation, modernize banking, and enhance financial inclusion while assessing risks and benefits of fintech solutions in a controlled testing environment. Fintech Sandbox Currently, the fintech sandbox focuses on three specific areas: Credit scoring Open API data sharing Peer-to-peer (P2P) lending Eligible participants for the fintech sandbox include: Credit institutions and foreign bank branches (except for P2P lending) Fintech companies operating in Vietnam Cross-border supply by foreign providers is not included in the sandbox framework. Eligible participants are permitted to provide fintech solutions only within the scope specified in the Certificate of Sandbox Participation issued by the State Bank of Vietnam in consultation with other ministries. P2P lending companies face specific restrictions within the fintech sandbox, including prohibitions against: Providing security for customer loans Operating as a customer (i.e., P2P lender or borrower) Providing P2P lending solutions to pawn shops The maximum sandbox period is two years, with the possibility of extension as permitted by law. The outcomes of the fintech sandbox will serve as a practical basis for authorities to develop and refine future fintech regulations. It is worth noting that participation in the sandbox does not guarantee that participants will meet relevant business and investment conditions that may be stipulated in future regulations. Decree 94 will take effect on July 1, 2025, signaling that the Vietnamese government intends to take a proactive approach to fostering fintech development. Implications Parties interested in participating in the fintech sandbox should begin preparing now to be ready to apply for a Certificate of Sandbox Participation when the decree takes effect.
May 2, 2025
Attorneys from Tilleke & Gibbins have updated the latest edition of Doing Business in Thailand, a Q&A-style guide from Thomson Reuters Practical Law that offers an overview of key legal considerations for companies operating in jurisdictions worldwide. The contribution outlines the country’s legal and regulatory framework for foreign investment and business operations and reflects the latest legislative developments. The chapter addresses the following core topics: Legal system: Structure of the courts and the codified nature of Thai law. Foreign investment: Business restrictions under the Foreign Business Act, sector-specific regulations, exchange control rules, and investment incentives. Business vehicles: Overview of partnerships, private and public limited companies, and other legal entities. Employment: Labor protections, employment contracts, foreign worker requirements, and termination procedures. Tax: Corporate and personal income tax, indirect taxes, and tax obligations for residents and non-residents. Intellectual property: Registration and enforcement of patents, trademarks, designs, and copyrights. Data protection: Key provisions of the Personal Data Protection Act and related compliance obligations. Competition law: Regulatory framework under the Trade Competition Act. Anti-bribery and corruption: Relevant legislation and enforcement mechanisms. E-commerce and digital business: Legal regime for online transactions and digital platforms. Marketing and advertising: Consumer protection laws and regulations affecting advertising and marketing practices. Product regulation and liability: Safety standards, liability regimes, and roles of enforcement authorities. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.