SS SiteminderStore

Compliance · Decree 13/2023/ND-CP

Vietnam Personal Data Protection

Bảo vệ dữ liệu cá nhân theo Nghị định 13/2023/NĐ-CP

Decree 13/2023/ND-CP on Personal Data Protection (Nghị định 13/2023/NĐ-CP về bảo vệ dữ liệu cá nhân) is Vietnam's first comprehensive data-protection instrument. It entered into force on 1 July 2023 and, for the first time, defines controller and processor roles, sets out the rights of data subjects, and imposes concrete procedural obligations on any entity that processes personal data of Vietnamese individuals. This page explains how SiteminderStore Vietnam Company Limited operationalises Decree 13 for the Marketplace and for every Module we distribute.

§ 01Overview of Decree 13

Decree 13 has ninety-nine articles organised in four chapters and three annexes. It defines personal data as "any information in the form of symbols, letters, numbers, images, sounds, or the equivalent, from which an individual can be identified or can be identifiable". It draws a distinction between basic personal data (name, date of birth, e-mail, phone, address, identity number, etc.) and sensitive personal data (health, biometric, financial, location, political opinion, religious belief, ethnic origin, criminal record, and any data whose disclosure would prejudice fundamental rights). It defines the roles of controller (Bên Kiểm soát dữ liệu cá nhân), processor (Bên Xử lý dữ liệu cá nhân), and controller-processor (Bên Kiểm soát và Xử lý dữ liệu cá nhân).

§ 02SiteminderStore's role

SiteminderStore acts as controller for the personal data it collects on its own account — Customer contact information, billing data, support-ticket content, marketing consent. SiteminderStore acts as processor for the personal data that flows through the Modules on behalf of the Customer — guest names, e-mails, phone numbers, reservation details. The double role is standard for a SaaS marketplace and is explicitly recognised by Decree 13.

§ 03Consent capture

Article 11 of Decree 13 lists the legal bases for processing. Consent is the principal one. Consent must be given freely, specifically, informedly, unambiguously, and in a form that can be printed, replicated, and used as evidence. On the Marketplace we capture consent through a granular banner that offers separate toggles for the strictly necessary category, for cart persistence, and for opt-in analytics. Every toggle change is written to an audit log with the timestamp, the browser fingerprint, and the version of the notice that was shown at the moment of consent. Withdrawal of consent is one click away and takes effect immediately for future processing.

Consent, under Decree 13, is not a checkbox at the bottom of a page. It is an evidenced act, freely given, that can be withdrawn as easily as it was given.

§ 04Sensitive-category data

Modules are not designed to handle sensitive personal data. Where a Customer nevertheless needs to process sensitive personal data through a Module — for example a wellness resort recording dietary preferences and health conditions of its guests — the following additional safeguards apply:

§ 05Cross-border transfer impact assessment

Article 25 of Decree 13 requires an impact assessment before any transfer of personal data of Vietnamese data subjects outside Vietnamese territory. SiteminderStore has completed such an assessment for the limited replication of aggregated, de-identified operational data to Amazon Web Services in Singapore. The assessment describes the categories of data replicated (technical counters, hashed identifiers, latency measurements), the legal basis for the transfer (the legitimate interest of the controller in operational continuity), the safeguards applied (encryption, contractual clauses, right to audit), and the assessment of the destination country's legal regime. The assessment is on file with our DPO and is refreshed every twelve months.

§ 06Data Protection Officer

Article 28 of Decree 13 requires the appointment of a Data Protection Officer for any organisation that processes personal data at scale. SiteminderStore has appointed a DPO who reports directly to the director, Nguyễn Minh Đức. The DPO is independent from the commercial and product teams, cannot be dismissed for performing the tasks required by Decree 13, and is contactable at dpo@siteminderstore.org or by post at 235 Nguyễn Văn Cừ, Phường Nguyễn Cư Trinh, Quận 1, TP. Hồ Chí Minh, marked for the attention of the Data Protection Officer. The DPO holds an annual audience with each enterprise-tier Customer on request.

§ 07Incident notification to A05

Article 43 of Decree 13 requires the controller to notify the Ministry of Public Security within seventy-two hours of becoming aware of a personal-data breach that is likely to result in a risk to the rights and freedoms of natural persons. SiteminderStore maintains a written incident-response run-book that walks through the classification of an event, the notification to the Customer as processor, the notification to A05 as controller for our own data, and the communication to affected data subjects when the risk is high. The run-book is tested twice per calendar year through a table-top exercise, and the results of the exercise are shared internally with the compliance committee.

§ 08Children's data (under 16)

Article 20 of Decree 13 applies additional protection to the personal data of children. For children under the age of seven, only the parent or legal guardian can consent; for children between seven and fifteen, the consent of both the child and the parent or legal guardian is required. Because the Marketplace targets hotel operators and not consumers, we do not collect data of minors on our own account. Where a Module handles guest data that includes minors — for example a family-friendly resort recording the age of children for kids-club allocation — the Customer is responsible for ensuring that the appropriate consents have been obtained and evidenced.

§ 09Data-subject request handling window

Request typeAcknowledgementComplete response
Access72 hours30 days (may be extended by 30 days for complex requests)
Correction72 hours15 days
Deletion72 hours30 days
Restriction72 hours15 days
Objection72 hours15 days
Portability72 hours30 days (subject to technical feasibility)
Withdrawal of consentImmediate for future processing

§ 10Recordkeeping under Article 33

Article 33 of Decree 13 requires the controller to maintain a written record of its processing activities. Our record is organised by processing purpose and describes, for each purpose, the categories of data subjects, the categories of personal data, the legal basis, the retention window, the recipients, the international transfers if any, and the security measures. The record is reviewed by the DPO every quarter and made available to A05 on request.

§ 11Audit rights

Customers on the enterprise tier may audit our compliance with Decree 13 once per calendar year, or more often after a personal-data breach that we have notified. Audits may be conducted by the Customer directly or by an independent auditor appointed by the Customer, subject to a written confidentiality undertaking. We make available our processing-activity record, our security-measures documentation, the anonymised results of our quarterly penetration tests, and the deliberations of our compliance committee in relation to any change in the Marketplace that has a material impact on personal-data protection.

§ 12Practical guidance for Customers

§ 13Sanctions

Non-compliance with Decree 13 exposes the controller and the processor to administrative fines the amount of which is set by the implementing decrees on administrative sanctions (currently up to VND 100,000,000 per infringement for private entities, with higher ceilings for repeat offenders). Serious cases may also give rise to civil liability towards the affected data subjects and, in the most severe cases, to criminal liability under the Penal Code. SiteminderStore's compliance programme is designed to keep both the Marketplace and its Customers well below the threshold at which sanctions become a live risk.

§ 14Amendments and evolution of the framework

The Ministry of Public Security has publicly indicated that Decree 13 will be complemented by a full Law on Personal Data Protection expected within the next Parliamentary term. SiteminderStore's compliance committee tracks the drafts of that Law, participates when invited in the public consultations organised by the Ministry, and updates the present page whenever an implementing text is published in the Official Gazette (Công báo).

§ 15Contact

Any question about our compliance with Decree 13/2023/ND-CP can be sent to dpo@siteminderstore.org. The Data Protection Officer replies within one Vietnamese business day. Customers on the enterprise tier can request a scheduled call with the DPO through their account manager.