Legal risks resulting from a company’s failure to control data usage by third parties are becoming increasingly significant. Loosely drafted agreements and inadequate supervision may easily lead to data leakage and misuse.
I. Current situation regarding a company’s failure to control data usage by third parties
As many enterprises currently engage third parties to process or manage personal data, the absence of robust control mechanisms leads to considerable legal risks. If a third party unlawfully uses personal data or fails to ensure its security, the principal enterprise may still be held liable under applicable personal data protection regulations, including Decree No. 13/2023/ND-CP on Personal Data Protection. Such a situation often stems from unclear contractual arrangements, the lack of periodic monitoring requirements, and insufficient assessments of information security risks.

Thus, enterprises should establish comprehensive procedures for selecting, supervising, and legally binding third parties in order to safeguard the rights and interests of data subjects and minimize the risk of disputes. Such measures not only ensure legal compliance but also enhance the enterprise’s reputation and information security in business operations.
II. Concept of a company’s failure to control data usage by third parties
1. What does it mean for a company to fail to control data usage by third parties?
When a company provides personal data to a third party but fails to exercise adequate control over the manner in which such data is used, such a situation is referred to as a company’s failure to control data usage by third parties. Insufficient supervision, unclear contractual arrangements, or the absence of appropriate security measures may expose personal data to leakage, misuse, or unauthorized disclosure.
Accordingly, establishing effective control mechanisms, supervisory procedures, and legally binding obligations for third parties is essential to protect personal data and mitigate legal risks. It constitutes a crucial step in ensuring regulatory compliance and safeguarding the rights and interests of data subjects.
2. Why can the failure to control third parties create data security risks?
A company’s failure to effectively supervise third parties handling personal data may result in significant legal matters and cybersecurity risks. Personal data may be accessed, used for unauthorized purposes, or disclosed if the third party does not implement appropriate protective measures. Furthermore, the enterprise may still take legal responsibility for any violations, including administrative sanctions, compensation obligations, and reputational damage. The absence of effective oversight also makes it more difficult to monitor activities and determine liability in the event of disputes. Thus, contractual safeguards, periodic supervision, and compliance with security standards are indispensable measures for mitigating such risks.
3. What forms of data usage by third parties must companies control?
The forms of personal data usage by third parties that companies must monitor include the collection, storage, processing, analysis, and sharing of personal data in accordance with the agreed purposes. According to Articles 38 and 39 of Decree No. 13/2023/ND-CP, a Data Controller is required to select a suitable Data Processor, supervise the implementation of security measures, and ensure the rights of data subjects. Meanwhile, a Data Processor may only conduct processing activities as authorized under the processing agreement, is responsible for protecting personal data, and must return or delete the data upon completion of its assigned tasks.
Strict oversight of such activities helps prevent data breaches, unauthorized use of personal data, and potential legal liabilities for the company.
III. Legal regulations concerning a company’s failure to control data usage by third parties
1. What acts by third parties are considered data protection violations under Vietnamese law?
Under Decree No. 13/2023/ND-CP, a third party is deemed to violate personal data protection laws when it collects, stores, uses, transfers, or discloses personal data without the consent of the data subject or beyond the scope and purposes for which consent was granted. In addition, under Articles 38 and 39, a third party may be deemed in violation if it fails to implement adequate security measures, maintain records of data processing activities, or delete and return personal data upon termination of the processing arrangement.
Furthermore, Article 8 of Decree No. 13/2023/ND-CP sets out prohibited acts, including: unlawful processing of personal data (Clause 1); processing personal data for purposes that adversely affect national security, social order and safety, or the lawful rights and interests of organizations and individuals (Clause 3); obstructing personal data protection activities conducted by competent authorities (Clause 4); and abusing personal data protection activities to commit unlawful acts (Clause 5).
Depending on the severity of the violation, these acts may result in administrative sanctions or criminal prosecution.
2. What measures must enterprises implement to supervise data usage by third parties?
Pursuant to Article 3 of Decree No. 13/2023/ND-CP, enterprises are responsible for establishing supervisory measures to ensure that third-party processing of personal data complies with applicable laws (Clause 1), is conducted for the registered or publicly disclosed purposes (Clause 3), and remains within the necessary scope of processing (Clause 4). Accordingly, enterprises must require third parties to process personal data strictly in accordance with the agreed purposes, scope, and duration; refrain from purchasing, selling, or unlawfully using personal data; and ensure that personal data remains accurate and updated for processing purposes (Clause 5).
In addition, enterprises must implement technical and organizational measures to protect personal data throughout the processing lifecycle, including access controls, system security measures, and safeguards against loss or data breaches as required under Clause 6, Article 3. Supervisory obligations also include limiting data retention periods (Clause 7) and demonstrating compliance with personal data protection principles by third parties, which falls within the responsibilities of the Data Controller under Clause 8, Article 3.
3. Does the law require enterprises to enter into mandatory data management agreements with third parties?
Under Decree No. 13/2023/ND-CP, there is no general legal requirement that enterprises must execute agreements with every third party receiving personal data. The obligation to enter into a written agreement applies specifically to the relationship between a Personal Data Controller and a Personal Data Processor under Clause 1, Article 39, where the recipient processes personal data on behalf of the enterprise.

With respect to third parties as defined in Clause 12, Article 2, the Decree does not contain a separate provision mandating the execution of contracts. Nevertheless, enterprises remain responsible for ensuring that any processing activities conducted by third parties comply with the personal data protection principles set out in Article 3 and for demonstrating such compliance under Clause 8, Article 3 and Clauses 1 and 4, Article 38. Thus, in practice, entering into agreements or incorporating legally binding contractual provisions with third parties remains a necessary measure for fulfilling data control and security obligations and minimizing legal risks, even though such agreements are not mandatory in all circumstances.
4. What sanctions apply to companies that fail to supervise third parties in accordance with the law?
First, a company that fails to supervise third parties or permits third parties to unlawfully use personal data may be subject to administrative sanctions and compensation obligations under Article 8 of the Law on Personal Data Protection 2025. Under Clause 1, Article 8, organizations that commit violations may be subject to administrative sanctions depending on the nature, severity, and consequences of the violation and must compensate for any resulting damages. Regarding monetary fines, Clause 5, Article 8 provides that the maximum fine for other violations in the sector of personal data protection is 3 billion VND.
If a company allows the purchase or sale of personal data, the applicable fine may reach up to ten times the revenue generated from the unlawful activity under Clause 3, Article 8. If the violation involves cross-border transfer of personal data due to inadequate control of third parties, the company may be subject to a fine of up to 5% of its preceding year’s revenue under Clause 4, Article 8. These sanctions apply to organizations under Clause 6, Article 8.
In cases the failure to supervise third parties results in a serious infringement of personal privacy or confidential information, individuals within the enterprise may also face criminal liability. Specifically, under Clause 1, Article 159 of the Criminal Code 2015 (as amended and supplemented in 2017), any person who unlawfully infringes upon another person's privacy or information security may be subject to a fine ranging from 20,000,000 VND to 50,000,000 VND, non-custodial reform for up to three years, or imprisonment for up to three years. Where the offense is committed in an organized manner, involves abuse of position or authority, or causes serious consequences, the term of imprisonment may range from one year to three years under Clause 2, Article 159.
In addition, if personal data is unlawfully posted online, traded, or otherwise misused in cyberspace, the conduct may be prosecuted under Article 288 of the Criminal Code (as amended and supplemented in 2017). The applicable fines include a fine ranging from 30,000,000 VND to 200,000,000 VND, non-custodial reform for up to three years, or imprisonment from six months to three years under Clause 1, Article 288. In aggravated circumstances, the offender may face imprisonment of up to seven years under Clause 2, Article 288.
IV. Questions regarding a company’s failure to control data usage by third parties
1. Can customers file complaints if their data is unlawfully used by a third party due to the company’s failure to exercise proper control?
Pursuant to Articles 9 and 38 of Decree No. 13/2023/ND-CP on Personal Data Protection, customers have the right to file complaints if their personal data is unlawfully used by a third party due to the company’s failure to exercise proper control. Data subjects may request the enterprise to address the violation, initiate legal proceedings, or seek compensation for damages resulting from the infringement. Enterprises remain liable to data subjects for damages arising from the processing of personal data.
Understanding these rights enables customers to better protect their privacy while encouraging enterprises to implement stricter data supervision and management measures in compliance with applicable laws.
2. If the third party is located overseas, what difficulties may arise in resolving disputes due to the company’s failure to control data usage by the third party?
If a third party is located outside Vietnam, an enterprise’s failure to control the processing of personal data may create substantial challenges in supervision, violation handling, and dispute resolution. Pursuant to Article 25 of Decree No. 13/2023/ND-CP, cross-border transfers of personal data are subject to impact assessments, notification requirements to competent authorities, and the implementation of appropriate data protection measures. Furthermore, obligations relating to record-keeping, data security, and the deletion or return of personal data under Articles 38 and 39 may be difficult to enforce if the overseas third party fails to cooperate.
In the case of a violation, coordination in investigation and enforcement under Vietnamese law may also be limited due to differences in jurisdiction among countries. Thus, enterprises should exercise caution when entering into agreements, conducting risk assessments, and supervising third parties in order to protect the rights and interests of data subjects.
3. Can customers request compensation from a company if the company fails to control data usage by a third party?
Customers are fully entitled to claim compensation from a company if their personal data is unlawfully used by a third party as a result of the company’s failure to exercise adequate control. Pursuant to Clause 10, Article 9 of Decree No. 13/2023/ND-CP, data subjects have the right to seek compensation where violations of personal data protection regulations occur. In addition, under Articles 38 and 39 of Decree No. 13/2023/ND-CP, both Personal Data Controllers and Personal Data Processors are liable to data subjects for damages arising from data processing activities.

If a company fails to supervise a third party or neglects to implement appropriate data protection measures, any disclosure, misuse, or unauthorized use of personal data may lead to compensation liability. Accordingly, rigorous supervision of third parties is not only a legal obligation but also an important measure for protecting customers’ rights and minimizing risks to the enterprise.
4. Which types of data are most vulnerable to misuse when a company fails to control data usage by third parties?
The categories of data most vulnerable to misuse when an enterprise fails to supervise third-party data usage include sensitive personal data such as health information, biometric data, religious beliefs, political opinions, private life information, and ethnic origin, as well as identification and financial information, including national identification numbers, passport numbers, bank account details, telephone numbers, addresses, and transaction histories.
Pursuant to Articles 2 and 28 of Decree No. 13/2023/ND-CP, such data must be processed using stringent security measures and may only be used for purposes to which the data subject has consented. Failure to supervise third parties may lead to privacy violations, information security breaches, and financial losses for individuals.
Accordingly, enterprises should establish robust control mechanisms and clear contractual arrangements with third parties to safeguard sensitive personal data. It is a critical step toward ensuring legal compliance and reducing potential legal liabilities.
5. Is a company required to engage an independent investigation firm when an incident arises from uncontrolled data usage by a third party?
Under Decree No. 13/2023/ND-CP, enterprises are not legally required to engage an independent investigation firm when a third party unlawfully uses personal data. As a Data Controller, the enterprise is required to maintain processing records, retain relevant information, report violations, and cooperate with competent state authorities during investigations in accordance with Articles 38 and 39.
Engaging an independent investigation firm may be considered an internal risk management measure to enhance transparency and accountability; however, it is not a mandatory legal requirement. Nevertheless, enterprises remain directly responsible for any resulting damages and must take all necessary legal measures to protect the rights and interests of data subjects. The implementation of such measures is therefore recommended as a means of strengthening governance and compliance.
V. Why should you seek legal advice from NPLaw regarding issues arising from a company’s failure to control data usage by third parties?
When legal issues arise concerning the supervision of third parties, contractual arrangements, or the processing of personal data by external service providers, seeking assistance from experienced lawyers at NPLaw is a practical solution to ensure legal compliance, minimize risks, and protect both business interests and customer rights.
NPLaw’s lawyers can assist enterprises in conducting risk assessments, reviewing contractual arrangements, drafting legally compliant agreements, and representing the enterprise in dealings with business partners or competent authorities. Such support enables enterprises to save time and costs while establishing a solid legal foundation for effective data governance and compliance.
The information provided above is for reference purposes only. Should you require detailed advice regarding a specific matter, please contact NPLaw for prompt legal assistance.