The Ministry of Finance has summarized the results of implementation of the Decree No. 13/2023/ND-CP, serving for the development of the Law on Personal Data Protection drafted by the Ministry of Public Security.
The 2013 Constitution affirms the inviolability of personal privacy right, expands the scope of privacy rights to include the right to protect personal secrets, including private life information, personal secrets, family secrets. The Decree No. 13/2023/ND-CP dated April 17, 2023 of the Government on personal data protection provides definitions of personal data and personal data protection, however, does not cover all areas and relationships of life, society, and regulations related to "personal information", "private information", "digital information", "personal information in cyber environment"... In addition, personal data is also closely related to human rights, civil rights, network safety and security, information security, data security, information technology and the fourth industrial revolution, e-government, digital government, digital economy. Furthermore, many organizations and businesses have been using personal data for business purposes without being subjected by any documents regulating the business conditions for such activity. Therefore, it is extremely necessary to promulgate the Law on Personal Data Protection in order to legally cover practical cases, ensure requirements on rights of personal data protection, prevent personal data infringements that affect the rights and interests of individuals and organizations, enhance responsibilities of agencies, organizations and individuals, ensuring harmony with international practices, create a fair business environment for Vietnamese and foreign enterprises... The Ministry of Public Security organizes and guides agencies and units to summarize the implementation of the Decree No. 13/2023/ND-CP to have a basis for development of the Law on Personal Data Protection.
The Ministry of Finance has summarized the results of implementing Decree No. 13/2023/ND-CP at the Ministry of Finance
Carrying out the responsibilities assigned by the Ministry of Finance on organizing and implementing the Decree No. 13/2023/ND-CP within the Ministry of Finance, the Department of Financial Informatics and Statistics has guided units under the Ministry to implement the following tasks: listing, classifying all types of personal data and legal basis for processing these types of data at the Ministry of Finance; identifying units within the Ministry to act as personal data Controllers and Processors; identifying information systems that process personal data, levels of information system security and plan to ensure thereof, researching and getting opinions on management and technical measures on personal data protection. At present, the Ministry of Finance mainly processes two types of personal data: Personal data serving for the implementation of public administrative procedures and public services according to specialized laws on taxes, customs, securities, insurance, accounting, auditing, and pricing; Personal data of officials, civil servants, public employees under management of the Ministry, according to the provisions of law on management of officials, civil servants, public employees and digital signatures certification services (related to procedures for issuance and revocation of personal digital certificates for personal digital signatures). Personal data processed at the Ministry of Finance falls into the category of "serving the activities of state agencies regulated by specialized laws", and therefore are allowed to be processed without consent of data subject, as according to the provisions of Clause 5, Article 17 of Decree 13/2023/ND-CP. For remaining personal data that does not belong to the above-said category, the data processing unit shall notify to and obtain consent of the data subject prior to processing, ensuring the data subject's rights and obligations. Personal data at the Ministry of Finance is processed on information systems of which information security levels are classified and proper information security assurance plans are implemented to ensure the safety of personal data processing process.
The Ministry of Finance has disseminated and thoroughly grasped the regulations and contents on personal data protection to each officer, civil servant, public employee through the Trade Unions of the ministry and its units, put propaganda on personal data protection into the Information and Propaganda Plan of the Ministry of Finance in 2024 according to Decision No. 45/QD-BTC dated January 9, 2024 and implement propaganda of such content on the Ministry's Portal.
The Ministry of Finance on December 20, 2023 issued the Decision No. 2813/QD-BTC promulgating Regulations on Personal Data Protection at the Ministry of Finance. Units under the Ministry such as the Department of Financial Informatics and Statistics, the State Treasury, and the State Securities Commission have proactively implemented Decree No. 13/2023/ND-CP, Regulations on personal data protection at the Ministry of Finance by dispatching official letters and notices to disseminate and organize the implementation of personal data protection within their units. The General Department of Taxation has included personal data protection content in the CIO training programs in information technology training activities in the Taxation sector, training courses to foster specialized knowledge and skills for information technology officials at taxation agencies at all levels in online form. Through propaganda activities, units and officers, civil servants, public employees of the Ministry of Finance have had a general awareness of the importance of personal data protection; the rights, obligations and responsibilities of individuals as data subjects; the responsibilities of the Personal Data Processor, Controller and Third Parties; and therefore determined to implement necessary measures to protect personal data processed at the Ministry of Finance.
However, personal data protection is still a new work. The Decree No.13/2023/ND-CP takes effect just from July 1, 2023, specific guidance documents from functional agencies for some regulations thereof have not yet available. It has shown through the summary that units under the Ministry have been confusing in fully implementing regulations on personal data protection, especially making impact assessment records of personal data processing. In the summary report sent to the Ministry of Public Security, the Ministry of Finance proposed the Ministry of Public Security, when developing the Law on Personal Data Protection, to adjust the regulations on impact assessment records of personal data processing towards limiting scope of subjects needed to prepare impact assessment records of personal data processing according to data processing scale or according to data processing purpose,... in order to increase effectiveness and efficiency; to provide regulations on content of personal data processing impact assessment records in a way easy to understand and implement; to strengthen guidance on personal data protection measures to people and businesses, whose personal data are most likely to be exposed and exploited.
(Thu Hằng)