You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 6, 2018

Vietnam Issues Decree on Disclosure of Customer Financial Information

Informed Counsel

With Vietnam’s controversial new Law on Cybersecurity set to take effect on January 1, 2019, the protection of personal information has become a very hot topic for Vietnamese and foreign companies and organizations. In the banking sector, where customer information is particularly sensitive, confidentiality has always been a matter of crucial importance.   

In September, the government of Vietnam issued Decree No. 117/2018/ND-CP on confidentiality and  dis- closure of customer information of credit institutions and branches of foreign banks (Decree 117). Decree 117 took effect on November 1, 2018, replacing Decree No. 70/2000/ND-CP of 2000 on confidentiality, storage, and disclosure of information related to customer deposits (Decree 70). Below are some notable points of Decree 117.

Governing Scope    .

Decree 117 applies broadly to the confidentiality and disclosure of customer information of credit institutions and branches of foreign banks in Vietnam. However, some information is excluded from its purview, including customer information that is (i) classified as state secrets, (ii) provided to the State Bank of Vietnam, or (iii) used for anti-money laundering or anti-terrorism purposes.

Definition of Customer Information   

This is the first time that customer information of a credit institution or a branch of a foreign bank has been formally defined under Vietnamese legislation. Under Article 3 of Decree 117, such customer information is defined as information that is provided by the customer, or arises in the course of a customer requesting or a credit institution/bank providing banking products and services, comprising:

(1)    Personally identifiable information that contributes to identifying customers, whether individuals or organizations.

  • For individuals: Full name; specimen signature; electronic signature; date of birth; nationality; occupation; permanent residence, current residence, or place of residence abroad (for foreigners); telephone number; email address; ID card or passport number, date of issuance, and place of issuance; and other relevant information.
  • For organizations: Full name; abbreviated name; establishment license or decision; enterprise registration certificate or equivalent document; address of head office; telephone number; fax number; email address; personally identifiable information (as described above) of the legal representative of the organization; and other relevant information.

As in other Vietnamese data privacy regulations, “personally identifiable information” is defined very broadly, and the phrase “other relevant information” is problematic in that it seems to allow almost any information about the customer to be considered “personally identifiable information.”

(2)    Information on accounts, deposits, deposited assets, transactions, securing parties, and other relevant information. (Most of these terms are further defined/clarified in the same article.)

Requests from State Authorities

Competent state authorities—which have been expanded under Decree 117 to include state audit agencies, customs authorities, and tax authorities, among others— can request the disclosure of customer information from credit institutions and branches of foreign banks in order to perform their assigned functions and tasks, provided they comply with the following conditions:

  • Their request for customer information is in line with the purposes, contents, scope, and jurisdiction stipulated by law or as agreed by the customer, and they must bear responsibility for their requests.
  • They have supporting documents to prove the reasons for and objectives of such request, issued by the appropriate-level authority, and in conformity with relevant law, unless such request relates to a criminal proceeding or national security.
  • After obtaining the customer information, they must keep it confidential, use it in line with the purpose stated when requesting the information, and not disclose it to any third party without consent of the customer, except where permitted by law.

Although Decree 117 requires the authorities to maintain the confidentiality of the customer information they receive, enforcement will be a challenge in practice. By expanding the range of state authorities having the right to request customer information, without any corresponding requirements to improve oversight or secrecy, there is a greater risk of customer information being disclosed, intentionally or unintentionally.

Requests from Non-State Entities   

Under Article 11, credit institutions and branches of foreign banks may only disclose customer information to other non-state organizations or individuals in one of the following circumstances:

(1)    At the request of an entity specifically authorized to make such request in accordance with codes, laws, and resolutions issued by the National Assembly; or

(2)    Upon receiving the customer’s consent in writing or in another form as agreed with the customer.

In a notable change from Decree 70, Decree 117 does not allow credit institutions, without the prior consent of their customers, to share customer information with each other. Although this is in line with Vietnam’s general rules on data privacy, it may cause difficulties for credit institutions, as the exchange of customer information within the banking system is vital for evaluating and mitigating insolvency risks.

Other Provisions   

Decree 117 specifies the form for requesting disclosure of customer information, which applies to requests made by both state authorities and non-state entities, as well as the procedure and deadlines for financial institutions to carry out the information disclosure (10 working days for simple and readily available information, or 25 working days for complicated and not readily available information), except as otherwise regulated by the relevant laws.   

The new decree does not address whether financial institutions may provide access to, disclose, or transfer customer information to third parties located outside of Vietnam. These issues are covered by other legislation, such as the Law on Cybersecurity.

Outlook

Decree 117 aims to reduce the number of fraudulent transactions and mitigate the risk of outside parties appropriating the personal information and assets of banking customers. While these are worthy goals, the effectiveness and enforcement of Decree 117 remain to be seen.

RELATED INSIGHTS​ 

April 28, 2025
In recent years, Vietnam has positioned itself among the leading countries in the world in terms of digital asset ownership and trading volume. This rapid adoption reflects the country’s growing digital economy and the increasing engagement of individuals and businesses in blockchain-based financial activities. Central to this growth are Resolution No. 57-NQ/TW of the Politburo dated December 22, 2024, on breakthroughs in science, technology, innovation, and national digital transformation with a vision to 2045 (“Resolution 57”) and Resolution No. 03/NQ-CP of the Government dated January 9, 2025, promulgating the Action Plan to Implement Resolution 57 (“Resolution 03”), which outline a flexible and innovative policy framework that embraces pilot programs for emerging technologies to lay the groundwork for Vietnam’s legislative framework concerning cryptocurrency and blockchain technologies. Regulatory clarity in terms of digital assets and blockchain technologies is now more critical than ever for businesses and investors. In light of this, Vietnam is currently in the process of introducing three key legal instruments, with drafts of the Law on Digital Technology Industry (“Draft DTI Law”), Resolution of the National Assembly on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Financial Center Resolution”), and Resolution of the Government on the Pilot Implementation of Crypto Asset Markets in Vietnam (“Draft Crypto Pilot Resolution”) nearing promulgation. Current Regulatory Direction and Schedule Vietnam’s regulatory framework for crypto assets and blockchain has been in a developmental stage since 2017, focusing on directions, plans, and schedules rather than established regulations. In February 2024, under Decision No. 194/QD-TTg of the Prime Minister, the Ministry of Finance (MOF) was assigned to draft a legal framework to either prohibit or regulate virtual assets and service providers by May 2025, signaling a clearer regulatory direction. In March 2025, Directive No. 05/CT-TTg of the Prime Minister directed the MOF
March 28, 2025
On October 25, 2024, the State Bank of Vietnam (SBV) issued Circular No. 49/2024/TT-NHNN (“Circular 49”) amending and supplementing certain provisions of Circular No. 11/2022/TT-NHNN dated September 30, 2022, on bank guarantees (“Circular 11”). However, shortly thereafter, the SBV replaced both Circular 11 and Circular 49 with Circular No. 61/2024/TT-NHNN (“Circular 61”) dated December 31, 2024, which incorporates most of the updates from Circular 49 while introducing further amendments to bank guarantee regulations to align with the 2024 Law on Credit Institutions and 2023 Law on Real Estate Business. Circular 61 has an effective date of April 1, 2025. Below, we highlight some new regulations on bank guarantees under Circular 61, including those that were adopted from Circular 49. Updated Definitions Circular 61 broadens the definition of “customer” in bank guarantee relationships, introducing the possibility of a fourth party. Traditionally, a customer would request a credit institution to guarantee its obligations. Under the revised framework, a customer may also request the credit institution to issue a guarantee for another party, such as a parent company requesting a guarantee for its subsidiary. This change establishes a broader scope of parties involved in a bank guarantee relationship, which now includes the customer, the guarantor, the guaranteed party, and the beneficiary. Circular 61 also updates the definitions of “bank guarantee”, “cross-guarantee”, and “guaranteed party” to align with the term “bank guarantee” as defined in the 2024 Law on Credit Institutions. This includes requirements on mandatory debt acknowledgement. Bank Guarantees for Sale of Off-Plan Housing Circular 61, in alignment with Circular 49, the Law on Credit Institutions, and the Law on Real Estate Business, allows foreign bank branches and commercial banks (the “Guarantor”) to guarantee off-plan housing with a detailed procedure. The guarantee agreement between the Guarantor and the real estate project investor
March 21, 2025
Vietnam’s Law on Securities of 2019 was one of several laws amended (“Amended Securities Law”) under the wide-ranging Law No. 56/2024/QH15 passed by the National Assembly on November 29, 2024. The amendments came into force on January 1, 2025, with certain provisions related to professional securities investors and the eligibility criteria for public companies becoming effective on January 1, 2026. Below are some of the key points of the Amended Securities Law. Changes to Professional Securities Investors Professional securities investors (PSIs) are investors who have adequate financial capacity or securities qualifications and can participate in private placements and private funds, among other investment activities. Under the Amended Securities Law, foreign investors, including individuals and organizations, are now automatically classified as PSIs, without having to meet any requirements regarding financial capacity. This loosening of requirements is expected to attract more foreign investment. However, from January 1, 2026, individual PSIs will only be able to purchase, trade, and transfer privately placed corporate bonds that: (i) have been given credit ratings and are secured by collateral, or (ii) have been given credit ratings and covered by payment guarantees from credit institutions. Meanwhile, institutional PSIs will not be bound by these restrictions relating to privately placed corporate bonds. Protecting Shareholders in Private Securities Issuance The Amended Securities Law introduces additional conditions for private issuance of shares, convertible bonds, and warrant-linked bonds by public companies, and revises the required contents in the issuance plans from “criteria and number of investors” to “number of shares, offering price, or principles for determining the offering price.” This change promotes shareholder supervision and protects minority shareholders from overly powerful boards of directors. Expanded Powers of SSC The Amended Securities Law grants the State Securities Commission (SSC) new powers to suspend and cancel private placements of securities and adds
March 19, 2025
On January 1, 2025, the Department of Business Development (DBD) in Thailand’s Ministry of Commerce implemented new stringent corporate registration screening measures in collaboration with several other government agencies to prevent entities from opening corporate mule accounts to commit criminal activities in Thailand. The DBD’s Order of the Office of Central Company and Partnership Registration No. 3/2024 stipulates a new method for registering the establishment of partnerships and limited companies for people who have been involved in underlying crimes or who are owners of bank accounts that are being used for underlying crime, as per the notification of the Anti-Online Scam Operation Center (AOC) to the Anti-Money Laundering Office (AMLO) and the collated AMLO list of such persons. The order establishes the following key requirements: Managing partners and directors of partnerships and limited companies, respectively, whose names have been listed by the AMLO as a person who is involved in an underlying offense, or as the owner of a bank account being used for the underlying offense, must appear before the registrar in person. The concerned persons cited on the AMLO list must provide valid documentation of their identity to the DBD registrar (e.g., national identification card, government official identification card, government or state enterprise employee identification card, alien identification card, passport, document used in lieu of a travel document, or other similar documents with photo identification). This collaboration between the DBD and various relevant government agencies aims to eradicate the problem of fraudsters using mule accounts set up under legally established entities to deceive the public. It also seeks to enhance checks and screening of corporate mule accounts that are used to carry out criminal activities such as money laundering or cybercrime. These actions are part of the Thai government’s broader policy to suppress economic crimes. For more