In an increasingly competitive business environment, customer data has become a highly valuable asset for enterprises. However, the sale, disclosure, or transfer of customer data to competitors poses significant legal risks and directly affects customers’ rights and interests, as well as the reputation of enterprises. The following article examines the legal issues surrounding the sale of customer data to competitors.
I. Current situation relating to the sale of customer data to competitors
At present, the exchange, disclosure, or sale of customer data to competitors has become increasingly common and sophisticated across various industries, including banking and finance, insurance, real estate, e-commerce, and telecommunications services. The data unlawfully exploited typically includes basic personal information, contact details, transaction histories, customer needs, and consumer behavior data.

In practice, such conduct does not always originate from corporate policy but may result from weaknesses in internal data management systems, inadequate access control mechanisms, or a lack of legal compliance awareness among certain employees. In some cases, customer data is sold to competitors for illicit profit, to gain market advantages, or to facilitate unauthorized marketing activities.
Furthermore, many enterprises have not yet established comprehensive personal data protection procedures in accordance with applicable laws. As a result, customer data may be shared beyond the purposes originally disclosed to customers or without the lawful consent of data subjects. It significantly increases the risk of disputes, complaints, and regulatory sanctions.
II. Concept of selling customer data to competitors
1. What is the sale of customer data to competitors?
The sale of customer data to competitors refers to an act of transferring or commercializing customer information, such as names, telephone numbers, email addresses, consumer behavior data, and transaction histories, to a directly competing enterprise.
Clause 4, Article 3 of Decree No. 13/2023/ND-CP on Personal Data Protection provides that personal data may not be bought or sold in any form unless otherwise prescribed by law.
The sale of customer data to competitors may only be considered lawful under very limited circumstances:
- Personal data may only be processed with the consent of the data subject. Such consent must be voluntary, explicit, specific, and verifiable, as prescribed in Clause 1, Article 9 and Clause 1, Article 11 of Decree No. 13/2023/ND-CP.
- In addition, Clause 2 Article 8 of the Law on Protection of Consumer Rights 2023 provides that business organizations and individuals may not provide consumer information to third parties without the consumer’s consent, except where otherwise provided by law.
- The transfer of personal data to competitors must not violate competition laws, particularly Clause 1, Article 45 of the Law on Competition 2018, which prohibits acts contrary to the principles of good faith and honesty that cause or may cause damage to the lawful rights and interests of other enterprises. Such activities must also not involve sensitive personal data as defined in Clause 4, Article 2 of Decree No. 13/2023/ND-CP.
2. Who may be considered a party engaging in the sale of customer data to competitors?
Parties engaging in the sale of customer data to competitors may include individuals or organizations that directly or indirectly transfer, disclose, or sell customer information to competing enterprises.
These parties may include:
- Enterprises that own or control customer data.
- Managers and legal representatives of enterprises who have the authority to approve, direct, or authorize the sale of customer data.
- Employees and internal personnel who have direct access to customer data and who extract, disclose, or sell such information to competitors independently or under instructions.
- Third-party service providers entrusted with data processing activities, including technology partners, marketing service providers, and data centers, where they exceed the scope of their authorization and transfer or sell customer data to competitors.
3. How does the sale of customer data to competitors differ from data sharing for business cooperation purposes?
The sale of customer data to competitors differs from lawful data sharing for business cooperation purposes in several main respects:
- Purpose: The sale of customer data to competitors is conducted for financial gain derived from customer information. Data sharing for business cooperation aims to facilitate legitimate business collaboration and operational support between the parties.
- Relationship between the Parties: In cases involving competitors, the recipient enterprise is a direct competitor that independently exploits the data for its own commercial benefit. In business cooperation arrangements, the recipient is typically a business partner or service provider that is not in direct competition with the data owner and does not have the right to independently exploit the data for its own purposes.
- Control over data: When customer data is sold to a competitor, the transferring enterprise generally loses control over the data and cannot effectively regulate how the purchaser uses it. In contrast, data sharing for business cooperation allows the enterprise to maintain control over the data, while the receiving party may only process the information within the scope and purposes authorized by the enterprise.
III. Legal regulations relating to the sale of customer data to competitors
1. Is the sale of customer data to competitors considered a violation of law?
Clause 4, Article 3 of Decree No. 13/2023/ND-CP on Personal Data Protection expressly provides that personal data may not be bought or sold in any form unless otherwise prescribed by law. The sale of customer data to competitors generally exceeds the original purposes for which the data was collected and is often conducted without valid customer consent. Consequently, such conduct is considered unlawful under Clause 1, Article 11 and Clause 1, Article 17 of Decree No. 13/2023/ND-CP and Clause 2, Article 8 of the Law on Protection of Consumer Rights 2023.

Furthermore, under Clause 1, Article 45 of the Law on Competition 2018, if the sale of customer data creates an unfair competitive advantage and causes or is likely to cause damage to another enterprise, such conduct may constitute an act of unfair competition.
The sale of customer data to competitors may also infringe civil rights protected under Clause 1, Article 38 of the Civil Code 2015 concerning the protection of privacy and personal information.
2. Legal regulations on the protection of customer personal information in business activities
Under Decree No. 13/2023/ND-CP on Personal Data Protection:
- Clauses 1, 2, and 3 of Article 3 provide that personal data must be processed for lawful and clearly defined purposes consistent with those communicated to the data subject.
- Personal data must be processed in a transparent manner, ensuring security and safety and only to the extent necessary.
- Personal data processing is lawful only when the data subject has provided consent, except where otherwise permitted by law. Such consent must be voluntary, explicit, specific, and verifiable and may not be implied or bundled with other consents, as prescribed in Clause 1, Article 9 and Clause 1 Article 11.
Customer information protection in commercial activities is also governed by the Law on Protection of Consumer Rights, which directly regulates the relationship between businesses and consumers.
- Clause 1, Article 6 provides that consumers have the right to confidentiality and security of their personal information.
- Clause 2, Article 8 prohibits business organizations and individuals from providing consumer information to third parties without the consumer’s consent unless otherwise provided by law.
Importantly, the protection of personal information is recognized as a fundamental civil right under Clauses 1 and 2, Article 38 of the Civil Code 2015.
3. Which authorities have jurisdiction to handle violations relating to the sale or disclosure of customer data?
The authorities with jurisdiction to handle violations involving the sale or disclosure of customer data include:
- The Ministry of Public Security (Cybersecurity and High-Tech Crime Prevention Department). According to Clause 6, Article 23 of Decree No. 13/2023/ND-CP, this authority serves as the lead State management agency for personal data protection and has the authority to inspect, investigate, and sanction violations.
- Competition authorities, specifically the National Competition Commission under the Ministry of Industry and Trade. If the sale of customer data is intended to create an unfair competitive advantage, the competition authority may exercise its enforcement powers under Clause 1, Article 82 of the Law on Competition 2018.
- Consumer protection authorities under the Ministry of Industry and Trade and People's Committees at the commune level. These authorities may handle violations that adversely affect consumers where personal data is unlawfully bought or sold, under Clause 10, Article 75 and Clause 2, Article 77 of the Law on Protection of Consumer Rights 2023.
4. What are the applicable sanctions for organizations and individuals engaging in the unlawful sale of customer data?
Pursuant to Clause 5, Article 102 of Decree No. 15/2020/ND-CP, as amended and supplemented by Decree No. 14/2022/ND-CP, violations relating to the storage, leasing, transmission, provision, access, collection, processing, exchange, or use of information may result in administrative fines ranging from 50 million VND to 70 million VND for individuals. For organizations, the applicable fines are doubled, ranging from 100 million VND to 140 million VND, under Point a, Clause 3, Article 84 and Clause 5, Article 4 of the same Decree.
If the unlawful sale of customer data is conducted in cyberspace, the conduct may constitute the criminal offense of illegally providing or using information on computer networks or telecommunications networks under Article 288 of the Criminal Code 2015 (as amended and supplemented in 2025).
Depending on the nature and manner of the violation, offenders may also face criminal liability under Article 291 of the Criminal Code 2015 (as amended and supplemented in 2025) for the unlawful collection, storage, exchange, or trading of information relating to bank accounts, particularly if the personal data sold includes customers’ financial information or banking account details.
IV. Questions relating to the sale of customer data to competitors
1. Can a company be exempt from legal liability if customers have given prior consent to the sale of their data to competitors?
A customer's consent does not automatically exempt a company from legal liability when selling customer data to competitors. Only under very limited circumstances may such consent serve as a lawful basis for data processing.
Pursuant to Clause 1, Article 11 and Article 17 of Decree No. 13/2023/ND-CP, the processing of personal data must be based on the data subject’s clear, specific, and separate consent. The purpose of processing, scope of use, and recipients of the data must be fully disclosed. Thus, general, ambiguous, or implied consent clauses do not satisfy the legal requirements.
Moreover, even where customer consent has been obtained, the sale of customer data to competitors remains prohibited if such conduct creates an unfair competitive advantage or restricts, distorts, or undermines fair competition in violation of Clause 1, Article 45 of the Law on Competition 2018.
2. Can customers file a lawsuit against an enterprise to claim compensation if their data is sold to competitors?
Customers are fully entitled to initiate legal proceedings against an enterprise to seek compensation where their personal data has been unlawfully sold to competitors.
The rights to privacy, personal secrets, and personal information are protected by law. The collection, retention, use, and disclosure of personal information must be conducted with the consent of the relevant individual, as prescribed in Clause 1 Article 38 of the Civil Code 2015.
Furthermore, Clause 3, Article 38 of the Civil Code 2015 provides that a person whose rights have been infringed may request the Court to order the cessation of the infringing conduct, require a public apology and rectification, and award compensation for damages.
3. Can the sale of customer data to competitors be considered a breach of service contracts with customers?
Clause 1 Article 516 of the Civil Code 2015 imposes a general obligation upon service providers to perform services in accordance with contractual agreements and to safeguard the lawful rights and interests of service users.

Within a service relationship, customers provide their data to enable the enterprise to perform contractual obligations, not for the enterprise's independent commercial exploitation. Thus, if an enterprise unlawfully sells customer data to competitors and such conduct results in unauthorized disclosure of information, exceeds the purposes of service provision, and directly infringes upon customers’ privacy rights and lawful interests, such conduct may constitute improper performance of contractual obligations and a breach of the service contract.
4. If customer data is disclosed because an employee sold the data, can the enterprise still be held legally liable?
In many circumstances, an enterprise may still take joint or direct legal liability if customer data is disclosed as a result of its employee unlawfully selling such information, even if the enterprise neither instructed nor had prior knowledge of the employee’s conduct.
Employees typically gain access to customer data in the course of performing their assigned duties. Thus, if an employee abuses his or her position to sell customer information, the enterprise may still be liable to compensate affected customers and may subsequently seek reimbursement from the employee under Article 597 of the Civil Code 2015.
In addition, Clause 1, Article 516 of the Civil Code 2015 requires service providers to protect the lawful rights and interests of service users. Allowing employees to disclose customer data demonstrates a failure by the enterprise to adequately organize, supervise, and control information security measures and may be regarded as a failure to properly perform contractual obligations.
V. Why should you seek legal consultation from NPLaw regarding the sale of customer data to competitors?
When issues arise concerning the sale of customer data to competitors, seeking legal advice from NPLaw can help clients clearly identify the nature of the violation and the rights and interests that have been infringed.
NPLaw's lawyers provide legal advice regarding the applicable legal grounds for filing complaints, initiating lawsuits, and claiming compensation. They can also represent clients in dealings with competent authorities. With extensive experience in personal data protection matters and civil disputes, NPLaw is well-positioned to assist clients in effectively safeguarding their privacy rights and lawful interests.
In summary, the unlawful sale of customer data to competitors constitutes a serious infringement of customers’ privacy rights and frequently violates personal data protection laws, competition laws, and contractual obligations arising from service agreements. Such conduct may give rise to legal liability for both individuals and organizations involved, including circumstances where the violation is committed by employees. Customers have the right to file complaints and initiate legal proceedings seeking compensation, while enterprises may face substantial legal risks and reputational damage.
The information provided above is for reference purposes only. Should you require legal advice regarding a specific matter, please contact NPLaw for prompt assistance.