You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 6, 2018

Vietnam Issues Decree on Disclosure of Customer Financial Information

Informed Counsel

With Vietnam’s controversial new Law on Cybersecurity set to take effect on January 1, 2019, the protection of personal information has become a very hot topic for Vietnamese and foreign companies and organizations. In the banking sector, where customer information is particularly sensitive, confidentiality has always been a matter of crucial importance.   

In September, the government of Vietnam issued Decree No. 117/2018/ND-CP on confidentiality and  dis- closure of customer information of credit institutions and branches of foreign banks (Decree 117). Decree 117 took effect on November 1, 2018, replacing Decree No. 70/2000/ND-CP of 2000 on confidentiality, storage, and disclosure of information related to customer deposits (Decree 70). Below are some notable points of Decree 117.

Governing Scope    .

Decree 117 applies broadly to the confidentiality and disclosure of customer information of credit institutions and branches of foreign banks in Vietnam. However, some information is excluded from its purview, including customer information that is (i) classified as state secrets, (ii) provided to the State Bank of Vietnam, or (iii) used for anti-money laundering or anti-terrorism purposes.

Definition of Customer Information   

This is the first time that customer information of a credit institution or a branch of a foreign bank has been formally defined under Vietnamese legislation. Under Article 3 of Decree 117, such customer information is defined as information that is provided by the customer, or arises in the course of a customer requesting or a credit institution/bank providing banking products and services, comprising:

(1)    Personally identifiable information that contributes to identifying customers, whether individuals or organizations.

  • For individuals: Full name; specimen signature; electronic signature; date of birth; nationality; occupation; permanent residence, current residence, or place of residence abroad (for foreigners); telephone number; email address; ID card or passport number, date of issuance, and place of issuance; and other relevant information.
  • For organizations: Full name; abbreviated name; establishment license or decision; enterprise registration certificate or equivalent document; address of head office; telephone number; fax number; email address; personally identifiable information (as described above) of the legal representative of the organization; and other relevant information.

As in other Vietnamese data privacy regulations, “personally identifiable information” is defined very broadly, and the phrase “other relevant information” is problematic in that it seems to allow almost any information about the customer to be considered “personally identifiable information.”

(2)    Information on accounts, deposits, deposited assets, transactions, securing parties, and other relevant information. (Most of these terms are further defined/clarified in the same article.)

Requests from State Authorities

Competent state authorities—which have been expanded under Decree 117 to include state audit agencies, customs authorities, and tax authorities, among others— can request the disclosure of customer information from credit institutions and branches of foreign banks in order to perform their assigned functions and tasks, provided they comply with the following conditions:

  • Their request for customer information is in line with the purposes, contents, scope, and jurisdiction stipulated by law or as agreed by the customer, and they must bear responsibility for their requests.
  • They have supporting documents to prove the reasons for and objectives of such request, issued by the appropriate-level authority, and in conformity with relevant law, unless such request relates to a criminal proceeding or national security.
  • After obtaining the customer information, they must keep it confidential, use it in line with the purpose stated when requesting the information, and not disclose it to any third party without consent of the customer, except where permitted by law.

Although Decree 117 requires the authorities to maintain the confidentiality of the customer information they receive, enforcement will be a challenge in practice. By expanding the range of state authorities having the right to request customer information, without any corresponding requirements to improve oversight or secrecy, there is a greater risk of customer information being disclosed, intentionally or unintentionally.

Requests from Non-State Entities   

Under Article 11, credit institutions and branches of foreign banks may only disclose customer information to other non-state organizations or individuals in one of the following circumstances:

(1)    At the request of an entity specifically authorized to make such request in accordance with codes, laws, and resolutions issued by the National Assembly; or

(2)    Upon receiving the customer’s consent in writing or in another form as agreed with the customer.

In a notable change from Decree 70, Decree 117 does not allow credit institutions, without the prior consent of their customers, to share customer information with each other. Although this is in line with Vietnam’s general rules on data privacy, it may cause difficulties for credit institutions, as the exchange of customer information within the banking system is vital for evaluating and mitigating insolvency risks.

Other Provisions   

Decree 117 specifies the form for requesting disclosure of customer information, which applies to requests made by both state authorities and non-state entities, as well as the procedure and deadlines for financial institutions to carry out the information disclosure (10 working days for simple and readily available information, or 25 working days for complicated and not readily available information), except as otherwise regulated by the relevant laws.   

The new decree does not address whether financial institutions may provide access to, disclose, or transfer customer information to third parties located outside of Vietnam. These issues are covered by other legislation, such as the Law on Cybersecurity.

Outlook

Decree 117 aims to reduce the number of fraudulent transactions and mitigate the risk of outside parties appropriating the personal information and assets of banking customers. While these are worthy goals, the effectiveness and enforcement of Decree 117 remain to be seen.

RELATED INSIGHTS​ 

August 19, 2025
On August 6, 2025, Myanmar’s National Defence and Security Council (NDSC) issued Order No. 20/2025, announcing a change in the composition of the country’s Foreign Exchange Supervisory Committee (FESC). The prime minister has been appointed committee chair of the FESC, and five other individuals were appointed to the committee. The order took immediate effect. Originally established in April 2022, the FESC is responsible for approving foreign currency conversion, granting exemptions to foreign exchange restrictions, and permitting overseas transfers of foreign currency. The FESC supervises the flow of foreign currencies for domestic and foreign investment, manufacturing, exports and imports, and service businesses (including education- and health-related initiatives). The FESC is specifically responsible for considering and approving the use of foreign currency for the following: Importing machinery, vehicles, equipment, and raw materials essential for foreign investment and manufacturing projects; Importing fuel, medicine, cooking oil, fertilizer, insecticide, and construction materials not readily available on the domestic market; Covering Myanmar citizens’ needs abroad, such as medical treatment, education, or religious activities; Facilitating imports of general goods, loan repayments, interest payments to foreign lenders, service payments, and profit repatriation from investments; and Importing luxury products, including brand-name goods, jewelry, sports cars, and watches. The FESC is empowered to carry out further duties related to foreign exchange management as assigned by the NDSC Importers, exporters, investors, and business owners are encouraged to consult the most current FESC guidelines and approval lists before conducting transactions in Myanmar. For more details on these FESC composition developments, or on any aspect of financial regulations in Myanmar, please contact Tilleke & Gibbins at [email protected].
July 25, 2025
On June 17, 2025, the National Assembly of Vietnam adopted Law No. 76/2025/QH15 (Amended LOE) amending and supplementing the 2020 Law on Enterprises, which aims to reshape the legal framework to enhance transparency and alignment with international standards. The Amended LOE took effect from July 1, 2025. Below are key notes on the Amended LOE. Recognition of Beneficial Owners The beneficial owner (BO) concept was previously addressed under Vietnam’s anti-money laundering framework. However, the formal recognition of a BO in the Amended LOE marks a pivotal advancement in embedding ownership transparency into corporate governance, in line with the G7 Financial Action Task Force’s standards on anti-money laundering and counter-terrorism financing. Under the Amended LOE and Decree No. 168/2025/ND-CP of the government dated June 30, 2025, on enterprise registration (Decree 168), a BO is identified through either equity ownership or control rights. Equity ownership: Individuals holding 25% or more of a company’s charter capital or voting shares, either directly or indirectly, qualify as BOs. Indirect ownership is further defined as ownership of at least 25% of charter capital or voting shares through an intermediary organization. Control rights: Individuals with the authority to make or influence major decisions are considered BOs. The actual control over a company includes the power (i) to appoint or remove most or all members of the board of directors or the members’ council or the general director of a company; (ii) to amend the charter; or (iii) to decide other key matters specified in the company’s charter. Notably, individuals representing state ownership in state-owned enterprises are excluded from the scope of the BO concept. Companies are responsible for collecting, updating, and retaining information about BOs and cooperating with authorities when requested to identify BOs, among other obligations. Additionally, any companies registered before July 1, 2025, must
July 11, 2025
Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime. By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes: Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025. Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025. Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025. In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies. Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted. Fintech Sandbox Decree Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam: Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech
July 4, 2025
On July 3, 2025, the Trade Competition Commission of Thailand (TCCT) officially announced an invitation for stakeholders to participate in a public survey to gather feedback on the flexibility and appropriateness of credit terms across different business sectors for goods and services. The TCCT initially introduced guidelines on unfair trade practices related to credit terms applicable to small and medium-sized enterprises (SMEs) in 2021, with amendments following in 2022. The guidelines have had a wide impact, as businesses have had to adapt their payment procedures and practices, particularly those for dealing with SMEs, to comply with the guidelines. The TCCT is now seeking comprehensive feedback from businesses and other stakeholders to evaluate the effectiveness and practicality of these guidelines. The collected responses may potentially lead to future amendments aimed at enhancing fairness and efficiency in business transactions. To summarize the core principles, the guidelines aim to improve the liquidity and cash flow of SMEs, stipulating payment terms of: Within 30 days for agricultural products or primary agricultural processing involving non-complex production. Within 45 days for trade, manufacturing, and service sectors. The guidelines also identify practices deemed unfair, including: Unjustified delays in payment beyond agreed credit terms. Changes to credit terms or contractual conditions without at least 60 days’ advance notice. Other unfair conduct or credit term conditions that impose excessive burdens on an SME. Interested stakeholders are encouraged to submit their feedback through the TCCT’s online survey form available via their official public media channels. The survey is open for responses until July 20, 2025.