Data transfer in the context of leadership changes has become an increasingly common issue in corporate governance. A change in the head of an enterprise not only entails a transfer of authority but also directly involves internal data and personal data. If not conducted in compliance with applicable regulations, the enterprise may face legal risks and information security incidents. The following article provides a comprehensive analysis of current practices, relevant legal provisions, and main considerations when transferring data in the context of leadership changes.
I. Current practice of data transfer in the context of leadership changes
In practice, changes in corporate leadership are often accompanied by handover processes involving work responsibilities, documents, and data systems. However, data transfer activities are not always implemented in a structured and legally compliant manner. Many enterprises still regard data handover as a purely internal matter, lacking control procedures and failing to clearly allocate responsibilities between outgoing and incoming leaders.

In addition, critical data may be stored across multiple systems, personal devices, or private accounts of the outgoing leader, thereby increasing the risk of loss, leakage, or misuse. Such situations necessitate a serious reassessment of data transfer practices in the context of leadership changes to ensure information security and mitigate legal risks for the enterprise.
II. Concept of data transfer in the context of leadership changes
To properly identify the scope and legal responsibilities arising, it is essential to clarify the concept of data transfer in this context. Such a process extends beyond the mere handover of files and documents and directly concerns the management, exploitation, and protection of enterprise data.
1. What is data transfer in the context of leadership changes?
Data transfer in the context of leadership changes refers to the process of handing over, receiving, and transferring management authority over the entire body of enterprise data from the outgoing leader to the incoming leader upon a change in managerial or executive position. It includes internal data, business data, customer data, employees’ personal data, and other categories of data directly managed, accessed, or controlled by the outgoing leader.
Such transfer is not merely administrative in nature; it must ensure completeness, accuracy, and continuity in data management while complying with legal regulations on data protection and corporate confidentiality.
2. Why does a change in leadership create the need for data transfer within an enterprise?
A leadership change leads to the need for data transfer because the incoming leader must receive comprehensive information, documents, and data necessary for corporate management and operation. In practice, significant data are often associated with access rights, accounts, systems, and decisions of the outgoing leader. Therefore, upon such change, the enterprise must implement the transfer to ensure operational continuity.
Furthermore, data transfer helps clearly define data management responsibilities, preventing the outgoing leader from continuing to retain or use data after leaving office, thereby minimizing risks of information leakage and legal disputes.
3. What risks may arise during data transfer in the event of leadership changes?
Without clear procedures and strict controls, leadership changes may lead to multiple risks during data transfer. First, data may be handed over incompletely or inaccurately, especially where data is dispersed across different systems, devices, or personal accounts of the outgoing leader.
Additionally, data leakage, loss, or misuse may occur if access rights are not promptly revoked. Non-compliant data transfer may also expose the enterprise to violations of personal data protection laws, adversely affecting its reputation and legal liability.
III. Legal provisions governing data transfer in the context of leadership changes
Data transfer in this context is not solely an internal governance matter but is subject to various legal regulations aimed at ensuring data management accountability, information security, and the lawful rights and interests of relevant parties.
1. What are the current legal requirements regarding data management and transfer upon leadership changes?
Although current legislation does not provide a specific mechanism exclusively applicable to leadership changes, enterprises must comply with general regulations on personal data protection and data transfer.
Pursuant to Article 17 of the Law on Personal Data Protection 2025 (as guided by Article 7 of Decree No. 356/2025/ND-CP), personal data within an enterprise may only be transferred in legally permitted circumstances, including: With the consent of the data subject; sharing between departments within the same organization for the established processing purpose; transfer for continued processing in cases of division, separation, merger, consolidation, or reorganization; transfer to a data processor or third party in accordance with the law; or at the request of competent state authorities. Such transfer, whether free of charge or for consideration, does not constitute the sale or purchase of personal data.

In addition, under Article 14 of Decree No. 356/2025/ND-CP, enterprises are required to establish a dedicated unit or designate personnel responsible for personal data protection and ensure adequate human resources, facilities, and financial resources for data protection activities. In the cases of leadership changes, this responsibility must be maintained and seamlessly transferred to ensure consistent, secure, and uninterrupted data management.
Accordingly, enterprises must continue to manage and transfer data strictly in accordance with the above legal grounds and principles to minimize legal risks and ensure data security during leadership transitions.
2. What principles must enterprises comply with when transferring data to an incoming leader?
Although there is no specific regulation directly governing data transfer upon leadership changes, enterprises may comply with the following principles, by reference to the general principles on data management, connection, and sharing under Article 4 of Decree No. 278/2025/ND-CP:
- Purpose limitation and scope of authority: Data transfer must serve legitimate corporate management and operation, within the proper functions and authority, and not exceed what is necessary.
- Data security and confidentiality: The enterprise must implement technical and organizational measures to prevent data leakage, loss, or unauthorized use during the handover process.
- Controlled data sharing: Data should be transferred through appropriate internal systems and management tools to ensure traceability, control, and accountability.
- Completeness, accuracy, and currency: The transferred data must accurately reflect the enterprise’s operational status at the time of leadership change, avoiding inaccuracies or omissions that could pose governance risks.
- Non-infringement of lawful rights and interests: Particularly with respect to personal data, the transfer must comply with personal data protection and privacy laws.
- Transparency and accountability: Enterprises should prepare clear handover records, plans, or procedures to define responsibilities between outgoing and incoming leaders.
Although no specific regulation applies exclusively to enterprises, adherence to these general principles helps ensure legality, data security, and risk mitigation during leadership transitions.
3. Is there a legal requirement to verify and reconcile data before handover between two leaders?
Vietnamese law does not explicitly mandate data verification and reconciliation prior to handover between two leaders, as it is generally considered an internal corporate governance matter.
However, where enterprise data include personal or other legally protected data, the enterprise must ensure data accuracy, timeliness, and security, and comply with responsible data processing principles. Specifically, Article 3 of the Law on Personal Data Protection 2025 requires data to be accurate and updated in accordance with processing purposes. Verification and correction of inaccurate data form part of the obligation to protect data subjects’ rights.
4. What actions may an enterprise take if the outgoing leader fails to fully hand over data?
Where the outgoing leader fails to complete data handover, the enterprise has the right to maintain data control and security, and should take necessary internal governance measures, while formally requesting compliance in accordance with the law and internal procedures.
Specifically:
- The enterprise may require the outgoing leader to complete data handover in accordance with assigned duties and internal data management processes, ensuring completeness, accuracy, and security.
- The enterprise may revoke system access rights, accounts, and passwords of the outgoing leader if handover remains incomplete, to safeguard information security and prevent unauthorized use.
- If the data include personal or other critical data, the enterprise must continue to comply with data protection principles under Article 3 of the Law on Personal Data Protection 2025 and internal security standards and governance procedures.
- In cases of conflict, the enterprise may apply internal disciplinary measures or pursue legal or regulatory mechanisms if the data custodian intentionally obstructs or causes harm to the organization’s interests.
In summary, although there is no specific regulation addressing leaders’ failure to transfer data, enterprises retain the authority to implement control, recovery, and enforcement measures in accordance with internal regulations and general data protection obligations.
IV. Questions regarding data transfer in the context of leadership changes
1. Is the participation of the legal department required in the data transfer process?
The law does not mandate the involvement of a legal department in data transfer upon leadership changes. However, in practice, such participation is advisable, particularly where transferred data include personal data, critical data, or data related to the enterprise’s legal obligations.
The legal department can assist in reviewing the legal basis for transfer, determining permissible data scope, ensuring compliance with personal data protection and confidentiality requirements, and drafting handover minutes and access control procedures to mitigate legal risks.
2. Is it mandatory to delete or destroy data stored on the outgoing leader’s personal devices?
The law does not automatically require deletion or destruction of all data on the outgoing leader’s personal devices solely due to a leadership change. Deletion or destruction must comply with Point c Clause 2 Article 9 of Decree No. 356/2025/ND-CP, including cases where:
- Personal data are no longer necessary for the established purpose;
- The outgoing leader no longer has authority to process the data but continues to retain them on personal devices;
- The data subject withdraws consent or lawfully requests deletion;
- The data are processed unlawfully.
Deletion is not permitted where the law requires retention for legal obligations, inspections, audits, or dispute resolution, or where the data remain necessary for lawful management and operation.
3. Must employees or relevant departments be notified of data transfer?
Under Article 7 of Decree No. 356/2025/ND-CP, when processing personal data, including internal transfer, the data controller must notify data subjects prior to processing, specifying purpose, data categories, method, related parties, consequences, and timing.

Therefore, where data involve employees or internal departments, notification is generally required unless the data subject has already been informed and consented, or the processing falls within statutory exceptions.
4. Does the handover of accounts, passwords, and internal access rights constitute part of data transfer?
The transfer of accounts, passwords, and internal access rights forms an integral part of data transfer. It ensures lawful access for the incoming leader, protects enterprise and employee data, maintains system continuity, and reduces risks of loss, leakage, or misuse.
5. Should the enterprise prepare a data transfer plan prior to officially changing leadership?
Enterprises should prepare a comprehensive data transfer plan in advance to ensure completeness, accuracy, and compliance with confidentiality and data management principles. Such preparation prevents operational disruption, data loss, or unauthorized access and clarifies responsibilities between outgoing and incoming leaders.
V. Why seek legal advice from NPLaw on data transfer during leadership changes?
In the context of leadership changes, enterprise data transfer is a complex process involving confidentiality, personal data, and internal access rights. Engaging NPLAW enables enterprises to establish legally compliant transfer procedures, ensuring transparency, security, and minimized legal risks. NPLAW’s lawyers provide advisory services on confidentiality, access control, and responsibilities of outgoing and incoming leaders, as well as drafting agreements and handover records to ensure business continuity and protection of lawful interests.
The above information is for reference purposes only. For detailed advice tailored to specific circumstances, please contact NPLAW for prompt consultation.