Disputes regarding the use of transferred data are a type of dispute that commonly arises between parties during the process of data transfer. The following article sets out the legal regulations governing disputes relating to the use of transferred data and addresses several related issues in order to help individuals and organizations protect their lawful rights and interests.
I. Current situation of disputes regarding the use of transferred data
At present, disputes regarding the use of transferred data have become increasingly complex, mainly revolving around violations of privacy rights, large-scale leakage and illegal trading of personal data, infringement of information confidentiality rights, as well as the inability to determine the entity entitled to use the data after transfer.

The causes stem from various factors, such as a lack of strict data processing and security policies, contracts failing to clearly define responsibilities and rights relating to the use of transferred data, and the legal framework not appropriate with the development of digital technology. These shortcomings have resulted in serious consequences and disputes concerning the use of transferred data.
II. Understanding disputes regarding the use of transferred data
1. In what situations do disputes regarding the use of transferred data commonly arise?
Disputes relating to the use of transferred data may arise in a variety of situations. However, the following are among the most common cases:
- Use of data for improper purposes: Using data for business or marketing purposes beyond the data subject’s consent or outside the scope agreed upon in the original contract, or arbitrarily reselling such data to third parties.
- Breach of confidentiality and data leakage: Data is disclosed or unlawfully accessed due to weak security systems maintained by the data processor, resulting in losses and damages to the data subject.
- Lack of transparency and insufficient information: Enterprises fail to clearly notify users regarding the collection, transfer, processing, and use of their data.
- Cross-border data transfer: Enterprises transfer customer data overseas without complying with legal requirements, resulting in data leaks and serious impacts on customers’ privacy rights.
2. Why is it important to clearly determine the purpose of using transferred data in dispute resolution?
Clearly defining the purpose of using transferred data plays an important role in resolving disputes for the following reasons:
- It serves as the legal basis for dispute resolution: The purpose of data use is agreed upon in the contract and consented to by the data subject. In a dispute, the competent authority will consider whether the use of data falls within the scope of the agreed purpose.
- Protection of data subjects’ rights and interests: It ensures that personal data is not used for unauthorized purposes (such as advertising, resale to unauthorized third parties, or unrelated state management purposes), thereby protecting privacy rights and legitimate interests.
- Transparency and prevention of abuse: Clearly defining the purpose obliges parties to act transparently and prevents excessive collection of data for vague or improper purposes, including anti-money laundering and anti-corruption concerns.
- Minimization of disputes: If the purpose is clearly determined from the outset in the agreement, the likelihood of disputes arising later is significantly reduced.
- Proof of violations: The agreed purpose of data use upon transfer constitutes important evidence. If the recipient uses the data for other purposes, unlawful conduct can be more easily established (for example, using customer data for resale to third parties without consent).
3. What types of data commonly give rise to disputes when transferred for use?
- Personal data: Data or information in digital or other forms that identifies or helps identify a specific individual, including basic personal data and sensitive personal data. Personal data that has been anonymized is no longer considered personal data under Clause 1, Article 2 of the Law on Personal Data Protection 2025.
- Basic personal data: Personal data reflecting common identity and background information frequently used in transactions and social relationships, as classified by the Government under Clause 2, Article 2 of the Law on Personal Data Protection 2025.
- Sensitive personal data: Personal data associated with an individual’s privacy, where any infringement may directly affect the lawful rights and interests of agencies, organizations, or individuals, as classified by the Government under Clause 3, Article 2 of the Law on Personal Data Protection 2025.
- Digital data: Data concerning objects, phenomena, and events, including one or a combination of sounds, images, numbers, written characters, or symbols presented in digital form, as stipulated in Clause 1, Article 3 of the Data Law 2024.
- Important data: Data that may affect national defense, security, foreign affairs, macroeconomics, social stability, public health, and community safety, as categorized by the Prime Minister under Clause 6, Article 3 of the Data Law 2024.
4. What can parties do to prevent disputes regarding the use of transferred data?
To prevent disputes regarding the use of transferred data, parties to a contract should consider implementing the following measures:
- Data confidentiality agreements: The parties should execute non-disclosure agreements or include strict confidentiality clauses in data transfer agreements.
- Defining the purpose of data use after transfer: The contract should clearly specify the purpose of use, scope, duration, and rights of each party relating to the transferred data. It should also stipulate sanctions and remedies for violations relating to the use of transferred data.
- Allocation of authority and responsibilities: The personal data controller and the personal data controller-cum-processor may transfer personal data to a data processor or third party for processing in accordance with legal regulations or contractual agreements.
- Obtaining the consent of the personal data subject before transferring data to a third party.
III. Legal regulations relating to disputes regarding the use of transferred data
1. In disputes regarding the use of transferred data, what regulations on information confidentiality must the parties comply with?
The parties must establish an agreement regarding the transfer of personal data with the data recipient. Pursuant to Article 7 of Decree No. 356/2025/ND-CP, organizations and individuals transferring personal data under Points a, c, and d, Clause 1, Article 17 of the Law on Personal Data Protection 2025 are required to enter into a personal data transfer agreement with the data recipient, specifying the following contents:
- Purpose of the personal data transfer;
- Categories of personal data subjects and types of personal data transferred in accordance with the transfer purpose;
- Duration of personal data processing and requirements for deletion or destruction of personal data after completion of the transfer purpose;
- Legal basis for the transfer of personal data;
- Responsibilities for protecting personal data during transfer and processing;
- Responsibilities for ensuring the rights of personal data subjects;
- Responsibilities for coordination and compliance in the event of violations of personal data protection regulations.
The transfer of sensitive personal data must be accompanied by physical security measures for storage and transmission devices, encryption measures, anonymization measures, and other security measures during the transfer process.

In cases where personal data is transferred under Points a and d, Clause 1, Article 17 of the Law on Personal Data Protection 2025 for service fees or to serve the lawful interests of personal data subjects, organizations and individuals must comply with the following requirements:
- Establishing technical systems and transparent mechanisms enabling personal data subjects to provide accurate and clear consent for each transfer, based on being fully informed of the transfer purpose and the entities receiving and processing the personal data;
- Processing personal data strictly in accordance with the transfer purpose consented to by the personal data subject and compliance with the registered business sectors;
- Limiting the categories of personal data transferred to the scope necessary for the transfer purpose;
- Refraining from collection, storage, or development of personal data repositories from data transfer activities for purposes other than those consented to by the personal data subject;
- Clearly determining the roles of personal data controllers, personal data processors, and third parties in personal data transfer activities;
- Establishing agreements on the transfer and processing of personal data prior to transfer and commit to responsibilities and obligations toward personal data subjects.
2. Is it possible to initiate legal proceedings for violations of agreements relating to the use of transferred data?
Pursuant to Point đ, Clause 1, Article 4 of the Law on Personal Data Protection 2025, as guided by Article 5 of Decree No. 356/2025/ND-CP, one of the rights of personal data subjects is the right to file complaints, denunciations, initiate lawsuits, and request compensation for damages in accordance with the law.
In addition, Article 186 of the Civil Procedure Code 2015 stipulates that agencies, organizations, and individuals have the right to initiate lawsuits themselves or through lawful representatives before competent courts in order to protect their lawful rights and interests.
Accordingly, under the above provisions, individuals and organizations may initiate legal proceedings against acts violating agreements regarding the use of transferred data in order to protect their lawful rights and interests.
IV. Questions regarding disputes over the use of transferred data
1. How are disputes regarding the use of transferred data resolved?
Pursuant to Article 317 of the Commercial Law 2005, the methods for resolving commercial disputes include:
- Negotiation between the parties;
- Mediation between the parties conducted by an agency, organization, or individual agreed upon by the parties to act as mediator;
- Resolution by Arbitration or the Court.
Procedures for resolving commercial disputes by Arbitration or the Court shall be conducted in accordance with the procedural rules prescribed by law.
Pursuant to Clause 1, Article 5 of the Law on Commercial Arbitration 2010, disputes may be resolved through Arbitration if the parties have an arbitration agreement. Such arbitration agreement may be established either before or after the dispute arises. In addition, Article 186 of the Civil Procedure Code 2015 provides that agencies, organizations, and individuals have the right to initiate lawsuits themselves or through their lawful representatives (collectively referred to as plaintiffs) before competent Courts in order to protect their lawful rights and interests.
2. If the parties cannot reach an agreement in a dispute regarding the use of transferred data, what should they do?
Pursuant to Clause 1, Article 5 of the Law on Commercial Arbitration 2010, disputes shall be resolved by Arbitration where the parties have entered into an arbitration agreement. Such agreement may be established before or after the dispute arises. At the same time, Article 186 of the Civil Procedure Code 2015 also provides that agencies, organizations, and individuals may initiate lawsuits before competent Courts to protect their lawful rights and interests.

Accordingly, data transfer agreements typically contain dispute resolution clauses. If disputes regarding the use of transferred data arise and the parties fail to reach mutual agreement on resolution, the subsequent procedures stipulated in the contract shall apply. In other words, the parties may refer the dispute to competent authorities for resolution. Where the contract contains an agreement to resolve disputes through Commercial Arbitration, the matter shall be handled by Arbitration; otherwise, the dispute shall fall under the jurisdiction of the competent Court.
3. What steps should be taken to protect rights and interests in disputes regarding the use of transferred data?
To protect their lawful rights and interests in disputes regarding the use of transferred data, individuals and organizations should take the following fundamental steps:
- Reviewing the contract: Re-examining the provisions relating to the purpose of use, scope of transfer, access rights, storage, data retention period, and confidentiality obligations. It is necessary to consider whether the transferee has used the data beyond the permitted purposes, disclosed it to third parties, or failed to implement necessary protection measures during data processing.
- Collecting evidence: Data subjects have the right to request agencies, organizations, and individuals involved in data processing to provide documents relating to the data transfer. In addition, all transactions, emails, contracts, notices, and access logs relating to the use of data should be retained.
- Negotiating and issuing notices of violation: Contact the relevant party to clarify the issue, request explanations, and propose remedial measures (such as ceasing use, compensation, or confidentiality commitments). If negotiations are unsuccessful, send an official letter or email specifying the violations, requesting resolution, and setting a deadline for compliance.
- Initiating legal proceedings before the Court or Commercial Arbitration if negotiation and mediation fail.
4. Who supervises the resolution of disputes regarding the use of transferred data?
Pursuant to Point e, Clause 1, Article 4 of the Law on Personal Data Protection 2025, data subjects have the right to request competent authorities or agencies, organizations, and individuals involved in personal data processing to implement measures and solutions to protect their personal data in accordance with the law.
Pursuant to Point i, Clause 1, Article 37 of the Law on Personal Data Protection 2025, personal data controllers are responsible for coordinating with the Ministry of Public Security and competent State authorities in protecting personal data, as well as providing information serving the investigation and handling of violations relating to personal data protection. In addition, Clause 2, Article 36 of the Law on Personal Data Protection 2025 stipulates that the Ministry of Public Security is the focal agency responsible before the Government for exercising state management over personal data protection, except for matters falling under the management authority of the Ministry of National Defense.
Judicial authorities (Courts and Arbitration): If civil or commercial disputes arise between the parties (such as breaches of data transfer agreements), such disputes shall be resolved before the Court or Commercial Arbitration under Clause 1, Article 5 of the Law on Commercial Arbitration 2010 and Article 186 of the Civil Procedure Code 2015.
Accordingly, the Ministry of Public Security is the principal authority responsible for State management of personal data protection. Meanwhile, judicial authorities (Courts and Arbitration) are the competent bodies responsible for resolving disputes regarding the use of transferred data.
V. Are you looking for a reputable and experienced lawyer to assist with disputes regarding the use of transferred data?
The above information constitutes NPLaw’s guidance regarding disputes concerning the use of transferred data. With a team of experienced lawyers and legal specialists, NPLaw provides reputable and professional legal services aimed at ensuring the best protection of our clients’ lawful rights and interests. If you require legal assistance in this area, please contact NPLaw for consultation and support.
The above information is provided for reference purposes only. Should you require detailed advice for a specific case, please contact NPLaw Firm for immediate consultation.