You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 6, 2018

Vietnam Issues Decree on Disclosure of Customer Financial Information

Informed Counsel

With Vietnam’s controversial new Law on Cybersecurity set to take effect on January 1, 2019, the protection of personal information has become a very hot topic for Vietnamese and foreign companies and organizations. In the banking sector, where customer information is particularly sensitive, confidentiality has always been a matter of crucial importance.   

In September, the government of Vietnam issued Decree No. 117/2018/ND-CP on confidentiality and  dis- closure of customer information of credit institutions and branches of foreign banks (Decree 117). Decree 117 took effect on November 1, 2018, replacing Decree No. 70/2000/ND-CP of 2000 on confidentiality, storage, and disclosure of information related to customer deposits (Decree 70). Below are some notable points of Decree 117.

Governing Scope    .

Decree 117 applies broadly to the confidentiality and disclosure of customer information of credit institutions and branches of foreign banks in Vietnam. However, some information is excluded from its purview, including customer information that is (i) classified as state secrets, (ii) provided to the State Bank of Vietnam, or (iii) used for anti-money laundering or anti-terrorism purposes.

Definition of Customer Information   

This is the first time that customer information of a credit institution or a branch of a foreign bank has been formally defined under Vietnamese legislation. Under Article 3 of Decree 117, such customer information is defined as information that is provided by the customer, or arises in the course of a customer requesting or a credit institution/bank providing banking products and services, comprising:

(1)    Personally identifiable information that contributes to identifying customers, whether individuals or organizations.

  • For individuals: Full name; specimen signature; electronic signature; date of birth; nationality; occupation; permanent residence, current residence, or place of residence abroad (for foreigners); telephone number; email address; ID card or passport number, date of issuance, and place of issuance; and other relevant information.
  • For organizations: Full name; abbreviated name; establishment license or decision; enterprise registration certificate or equivalent document; address of head office; telephone number; fax number; email address; personally identifiable information (as described above) of the legal representative of the organization; and other relevant information.

As in other Vietnamese data privacy regulations, “personally identifiable information” is defined very broadly, and the phrase “other relevant information” is problematic in that it seems to allow almost any information about the customer to be considered “personally identifiable information.”

(2)    Information on accounts, deposits, deposited assets, transactions, securing parties, and other relevant information. (Most of these terms are further defined/clarified in the same article.)

Requests from State Authorities

Competent state authorities—which have been expanded under Decree 117 to include state audit agencies, customs authorities, and tax authorities, among others— can request the disclosure of customer information from credit institutions and branches of foreign banks in order to perform their assigned functions and tasks, provided they comply with the following conditions:

  • Their request for customer information is in line with the purposes, contents, scope, and jurisdiction stipulated by law or as agreed by the customer, and they must bear responsibility for their requests.
  • They have supporting documents to prove the reasons for and objectives of such request, issued by the appropriate-level authority, and in conformity with relevant law, unless such request relates to a criminal proceeding or national security.
  • After obtaining the customer information, they must keep it confidential, use it in line with the purpose stated when requesting the information, and not disclose it to any third party without consent of the customer, except where permitted by law.

Although Decree 117 requires the authorities to maintain the confidentiality of the customer information they receive, enforcement will be a challenge in practice. By expanding the range of state authorities having the right to request customer information, without any corresponding requirements to improve oversight or secrecy, there is a greater risk of customer information being disclosed, intentionally or unintentionally.

Requests from Non-State Entities   

Under Article 11, credit institutions and branches of foreign banks may only disclose customer information to other non-state organizations or individuals in one of the following circumstances:

(1)    At the request of an entity specifically authorized to make such request in accordance with codes, laws, and resolutions issued by the National Assembly; or

(2)    Upon receiving the customer’s consent in writing or in another form as agreed with the customer.

In a notable change from Decree 70, Decree 117 does not allow credit institutions, without the prior consent of their customers, to share customer information with each other. Although this is in line with Vietnam’s general rules on data privacy, it may cause difficulties for credit institutions, as the exchange of customer information within the banking system is vital for evaluating and mitigating insolvency risks.

Other Provisions   

Decree 117 specifies the form for requesting disclosure of customer information, which applies to requests made by both state authorities and non-state entities, as well as the procedure and deadlines for financial institutions to carry out the information disclosure (10 working days for simple and readily available information, or 25 working days for complicated and not readily available information), except as otherwise regulated by the relevant laws.   

The new decree does not address whether financial institutions may provide access to, disclose, or transfer customer information to third parties located outside of Vietnam. These issues are covered by other legislation, such as the Law on Cybersecurity.

Outlook

Decree 117 aims to reduce the number of fraudulent transactions and mitigate the risk of outside parties appropriating the personal information and assets of banking customers. While these are worthy goals, the effectiveness and enforcement of Decree 117 remain to be seen.

RELATED INSIGHTS​ 

February 9, 2026
When unauthorized credit card transactions occur, who bears responsibility—the cardholder or the issuing bank? In Thailand, a landmark 2025 ruling by the country’s Supreme Court has clarified this question, establishing a stricter standard for banks in fraud disputes and significantly strengthening consumer protections. The case centered on disputed charges where a customer claimed their credit card had been used without authorization. The bank sued to recover the amount, and both the court of first instance and the Court of Appeal ruled in favor of the bank. However, the Supreme Court overruled their judgments and decided that the customer did not need to pay for the unauthorized transactions, placing liability squarely on the bank. This ruling was based on three key findings, which are outlined below. Finding 1: Insufficient Expert Testimony In this case, the bank bore the burden of proving matters related to the credit card system’s manufacture, design, security, and operation, as required under the Consumer Case Procedure Act B.E. 2551 (2008). To meet this requirement, the bank presented testimony from two employees in its credit card department regarding ’security measures and issuance procedures. However, the Supreme Court found these witnesses unqualified as experts, as they did not present technical or academic evidence and did not possess specialized expertise in credit card technology. As a result, their testimony failed to establish that the bank’s credit card technology was sufficiently secure against fraudulent misuse. Finding 2: Contradictory Terms and Conditions The bank’s own credit card terms and conditions included a provision acknowledging that despite the card’s EMV security standards, cardholders must still exercise caution to prevent unauthorized access. The Supreme Court interpreted this clause as an explicit admission that credit card systems remain vulnerable to hacking and fraud, even with high-level security measures in place. This acknowledgment undermined the
February 4, 2026
On November 18, 2025, Vietnam’s Ministry of Finance released for public consultation a draft decree on administrative sanctions in the field of crypto assets and crypto asset markets (the “Draft Decree”), intended to implement Resolution No. 05/2025/NQ-CP dated September 9, 2025, on the pilot crypto asset market in Vietnam (“Resolution 05”). While Resolution 05 sets out who may participate and under what conditions, the Draft Decree addresses a more practical question for market participants, i.e., what happens if those conditions are not met. In doing so, the Draft Decree offers important insight into how Vietnamese regulators intend to supervise, discipline, and ultimately shape the crypto market during the pilot phase. Regulatory Scope and Overall Sanctions Architecture The Draft Decree applies to both domestic and foreign organizations and individuals engaging in crypto-related activities in Vietnam’s market. Covered entities include: (i) crypto asset issuers; (ii) crypto asset service providers, including trading platforms and market operators; (iii) Vietnamese and foreign investors participating in the pilot market; and (iv) other organizations involved in the offering, issuance, or provision of crypto-related services in Vietnam. The breadth of this scope is deliberate. It appears to reflect a regulatory view that cross-border structures, offshore platforms, and indirect participation may not necessarily insulate market actors from compliance obligations once they operate within the pilot framework. For the crypto industry, this may mark a shift from regulatory ambiguity toward a more explicit articulation of jurisdictional reach. At first glance, the Draft Decree’s monetary penalties appear restrained. The maximum fine per administrative violation is capped at VND 200 million (approx. USD 7,700) for organizations and VND 100 million (approx. USD 3,800) for individuals. However, focusing solely on fine levels risks missing the point. The Draft Decree also places great regulatory weight on supplementary sanctions and corrective measures, including: (i)
January 23, 2026
On December 31, 2025, the State Bank of Vietnam (SBV) issued Circular No. 72/2025/TT-NHNN (Circular 72), establishing a streamlined foreign exchange framework for Vietnam’s International Financial Center (IFC). Circular 72, which took effect on the same day, implements core provisions of Decree No. 329/2025/ND-CP and marks a fundamental shift from ex ante licensing to ex post supervision for IFC member enterprises and foreign investors. These changes are designed to accelerate capital flows, reduce compliance costs, and position Vietnam as a competitive regional financial hub by granting IFC members substantially greater autonomy in currency transactions, borrowing, lending, and investment activities. Key provisions for IFC members to note are discussed below. Use of Foreign Currency and Payments within the IFC Vietnam generally requires the use of Vietnamese dong for transactions within the country, with limited exceptions. This can be burdensome for foreign investors, who may be unfamiliar with all the foreign exchange rules they must comply with. Under the new regulation, IFC member enterprises and foreign investors gain the ability to transact, list prices, and settle obligations in foreign currency when dealing with other IFC members or offshore counterparties, avoiding currency risk and conversion friction. With respect to individuals and organizations located within Vietnam who are not IFC members, the use of foreign currency must continue to comply with general restrictions on foreign exchange usage within Vietnam. Dual-Track Account System for IFC Members The new regulation introduces a two-tier account structure that differentiates transactions by purpose and counterparty. IFC member enterprises must use a designated foreign currency capital account at an IFC member bank for four specified activities: Borrowing from offshore individuals and organizations Lending to offshore entities and domestic borrowers Outbound investing from the IFC Investing elsewhere in Vietnam from the IFC All other foreign exchange transactions—including operational receipts, vendor
January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license