PERSONAL DATA PROTECTION POLICY
This Personal Data Protection Policy (hereinafter referred to as the “Policy”) describes how personal data arising during the business operations and activities of Vingroup Joint Stock Company (the “Company”), located at No.7, Bang Lang 1 Street, Vinhomes Riverside Urban Area, Phuc Loi Ward, Hanoi, Vietnam, with its official website at vingroup.net, is processed. The Company processes personal data acting as a Personal Data Controller or a Personal Data Controller-cum-Processor in accordance with relevant applicable laws.
The personal data being processed belongs to you (also referred to as the “Data Subject”) when you interact with or engage in a relationship with the Company in various capacities, such as a customer, consumer, employee, job applicant, partner contact point, shareholder, or any individual whose personal data is collected and processed by the Company. For further details regarding the processing of your personal data, please review the specific content of this Policy corresponding to your role in connection with the Company.
This Policy is issued to ensure that the processing of personal data is carried out transparently, in a controlled manner, and in compliance with the law, while helping Data Subjects clearly understand their rights and the mechanisms available to protect their privacy in their relationship with the Company.
This Policy concurrently serves as the Companys Consumer Information Protection Rules, demonstrating the Companys commitment to:
- Respecting the privacy rights and personal information of Data Subjects;
- Protecting personal information from unauthorized access, use, or disclosure;
- Building a safe, transparent, and trustworthy environment for transactions, living, and experiencing products and services.
The Company mayor amend this Policy from time to time to align with legal regulations and practical operations. Updated versions will be published via the Companys official channels.
1. DEFINITIONS AND INTERPRETATION
1.1. “Customer”: includes all individual customers, representatives/contact points of institutional customers who have entered into and executed agreements with the Company, individuals exploring and considering the use of the Companys products and services, walk-in visitors or participants in the Companys product/service introduction events, participants in community activities, and users of the Companys websites, applications, and digital platforms. This definition also encompasses consumers as defined by consumer rights protection legislation.
1.2. “Personnel”: refers to individuals who currently have or previously had an employment relationship with the Company, including but not limited to: Board members, managers, employees, applicants, interns, and collaborators.
1.3. “Contact Point”: refers to individuals who are currently or were previously designated, authorized, or factually assigned by a Partner of the Company to represent such Partner in communicating, exchanging information, transacting, or coordinating work with the Company.
1.4. “Shareholder”: refers to an individual who owns at least one share of the Company.
1.5. “Insider”: refers to a person holding a key position in the corporate governance and management structure of the Company, as determined by applicable laws from time to time.
1.6. “Related Person”: refers to an individual who has a direct or indirect relationship with the Company as determined under the Law on Enterprises and the Law on Securities.
1.7. “Consumer”: refers to an individual who purchases or uses products, goods, or services for the consumption or daily needs of themselves or their family, or for internal use by an agency or organization, and not for commercial purposes.
1.8. “Partner”: refers to organizations or individuals working with the Company to cooperate, supply products, services, or support the Companys operations. Individual partners include, but are not limited to, individual contractors, consultants, and personnel supplied to the Company by third parties.
1.9. “Personal Data”: refers to digital data or information in other forms that identifies or can lead to the identification of a specific individual, comprising Basic Personal Data and Sensitive Personal Data. Personal data that has been anonymized is no longer considered Personal Data.
1.10. “Basic Personal Data”: refers to personal data reflecting common attributes and identity backgrounds that are frequently used in transactions and social relationships and falling within the list issued by the Government.
1.11. “Sensitive Personal Data”: refers to personal data closely linked to an individuals privacy, which, if violated, will directly affect the legitimate rights and interests of agencies, organizations, or individuals, and which falls within the list issued by the Government.
1.12. “Data Subject”: refers to the individual reflected by the Personal Data.
1.13. “Processing of Personal Data” or “Processing”: refers to one or multiple operations performed upon Personal Data, such as collection, analysis, synthesis, encryption, decryption, modification, deletion, destruction, anonymization, provision, disclosure, transfer Personal Data, or other actions impacting Personal Data.
1.14. “Personal Data Controller”: refers to the party that decides the purposes and means of Processing Personal Data.
1.15. “Personal Data Processor”: refers to the party that performs Personal Data Processing on behalf of the Company based on an agreement concluded with the Company.
1.16. “Applicable Law”: means the legislative documents of Vietnam (including relevant laws, decrees, circulars, and guiding documents) governing or relating to personal data protection and other related obligations.
1.17. “Personal Data Protection Policy” or “Policy”: refers to the entire content of this policy, consisting of 14 sections.
2. COMMITMENT TO PERSONAL DATA PROTECTION
The Company commits NOT to buy or sell Personal Data and to adhere to the following principles when Processing Personal Data:
- Fully complying with agreements and documents established with the Data Subject.
- Processing Personal Data for specific, clear, and lawful purposes as set forth in this Policy and in compliance with Applicable Law.
- Continuously applying and regularly updating appropriate personal data protection measures in line with Applicable Law to safeguard Personal Data against incidents, unauthorized access, destruction, loss, or damage.
- Retaining Personal Data appropriately and only to the extent necessary as permitted under Applicable Law.
3. SCOPE OF APPLICATION
This Policy applies to all Data Subjects of the Company, including:
- Customers.
- Company Personnel.
- Contact Points.
- Shareholders, Insiders, and Related Persons of the Company.
4. TYPES OF PERSONAL DATA COLLECTED AND PURPOSES OF PROCESSING
4.1. For Customers
4.1.1. Types of Personal Data Collected
4.1.1.1.Basic Personal Data
· Identity and contact information: Full name; date of birth; gender; nationality; phone number; email address; permanent address; contact address.
· Legal and identification information: Information from identity documents and identifiers such as Identity Card/Citizen Identity Card/Passport/Personal Identification Number; other identifying information as prescribed by law (if any).
· Residency information: Information regarding residency status, form, duration, and purpose of residency to comply with legal regulations, manage records, and determine the scope of product and service provision.
· Transportation and access control information: Transportation information (e.g., vehicle license plate); access card information; access control data for buildings, areas, or events.
· Information on needs and interests: Information regarding preferences and interest in products and services; registration for consultation; registration to participate in events, programs, and activities organized by the Company.
· Product, service, and usage history information: Information on the registration and usage of products and services; data relating to the process and history of using products and services.
· Digital account and usage history data: Account data on the website/applications such as login credentials; data regarding the history of using the website, applications, or service channels (e.g., views, actions, interacted content).
· Technical and system operation data: IP address, cookies, device ID, device information, browser type, system logs, and other technical data used for operation, security, and system improvement.
· Feedback and evaluation data: Feedback, complaints, recommendations, and evaluation data provided by Customers.
· Customer segmentation information: Information on Customers preferences and needs in respect of products and services.
4.1.1.2. Sensitive Personal Data
· Biometric data: Facial recognition data and other biometric data (in cases where the Customer registers or consents to use).
· Financial, credit, and transaction information: Information relating to contracts, transactions, financing, guarantees, or loans (including financial and credit information); bank account information and payment-related details (including financial transaction details).
· Identifiable audio and video recordings: Data from audio and video recording systems at buildings, urban areas, public spaces, or events, to the extent that it can be used to identify or monitor an individual.
· Online activity and behavioral data on the Companys services: Browsing journey data on websites/applications, cookie data regarding application usage behavior, user interaction data, and user profile or segmentation data.
· Images of identity cards / citizen identity cards / identification cards / passports.
4.1.1.3. Legal Bases and Purposes for Processing Personal Data
The Company processes Customers Personal Data for the following purposes, based on consent or other legal bases such as contract performance, compliance with statutory obligations, and other legal grounds as described below.
4.1.1.4. Based on the Data Subjects consent, Personal Data is processed to:
(a) Marketing and Advertising
Conduct consultation, introduction, and communication of the Companys products and services through events, programs, community activities, or other forms such as on websites, applications, and digital platforms; Personalize, based on Customer preferences, to conduct advertising and marketing on websites, applications, digital platforms, and other media.
(b) Research, Development, and Improvement of Products and Services
Conduct research, development, and improvement of products/services; Personalize the Customer experience through technological enhancements, website interfaces, social networks, and applications to ensure convenience for Customers.
(c) Data Transfer to Third Parties: Transfer Personal Data to third parties for their own purposes (e.g., research, development; product/service advertising and marketing) in accordance with the law.
4.1.1.5. To perform other purposes permitted by law to process Personal Data without the Data Subjects consent, including:
(a) Assessing the feasibility of providing products and services to specific Customers, as follows:
- Identifying and verifying information regarding the Personal Data Subject.
- Assessing, appraising, and approving the provision of products and services in accordance with application forms, proposals, and contracts of the Personal Data Subject and/or their related persons.
- Considering the provision or continuation of provision of any products and services of the Company to the Personal Data Subject.
(b) Performing contracts, agreements, and other instruments between the Company and the Personal Data Subject, and supporting Customers, as follows:
- Performing contractual obligations, agreements, and providing products and services to the Personal Data Subject.
- Updating and processing information of the Personal Data Subject.
- Caring for, handling, and resolving complaints and lawsuits filed by the Personal Data Subject.
- Utilizing and transferring Personal Data and relevant information to partners to identify and troubleshoot product/service technical faults, and to repair products.
- Contacting and sending notifications to the Personal Data Subject.
- Implementing promotional programs, reward redemptions, award presentations, and gift deliveries.
- Conducting other customer care and support activities, such as providing services and utilities to serve Customers.
- Providing and operating online services via websites, applications, and digital platforms.
- Organizing and managing events, programs, and community activities.
(c) Fulfilling the legal obligations of the Company
- Complying with legal regulations on tax, accounting, anti-money laundering, cybersecurity, other relevant statutory provisions, and international treaties to which Vietnam is a member.
- Complying with requests and decisions issued by competent state authorities.
(d) Protecting the legitimate rights and interests of the Data Subject and/or the Company
- Ensuring security, safety, and order at urban areas, buildings, events, and other premises of the Company; protecting the legitimate rights and interests of the Personal Data Subject, the Company, and other related parties;
- Preventing, investigating, detecting, blocking, and handling crimes and other acts that infringe upon the life, health, property, and legitimate rights and interests of the Company and Customers.
(e) Responding to emergencies.
The processing of Personal Data under this section includes transferring Personal Data to Personal Data Processors and third parties (such as subcontractors) to fulfill the aforementioned purposes.
In the course of business operations, the Company may undergo corporate reorganizations including, but not limited to, restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the right to use relevant information may be transferred and/or continue to be processed to serve the execution of the aforementioned activities, provided that it does not give rise to any new processing purposes outside of those specified in Section 4.1.1.4 and Section 4.1.1.5.
4.2. For Personnel, including job applicants
4.2.1. Types of Personal Data Collected
4.2.1.1. Personal Data of Job Applicants applying for employment positions at the Company:
(a) Basic Personal Data:
- Identity and contact information: Full name, email address, identity document number, address, phone number, date of birth, gender, marital status, and family relationships.
- Educational background and work experience: Professional qualifications, skills, employment history, and other information specified in the applicant information form.
- Other Personal Data voluntarily provided by the applicant during the recruitment process.
(b) Sensitive Personal Data:
- Images of identity cards, citizen identity cards, identification cards, and passports.
- Health information: Height, weight, medical history, and health classification conclusions.
- Ethnic origin and religion.
- Salary and income information at the most recent place of employment.
4.2.1.2. Personal Data of Employees, Interns, and Collaborators of the Company:
(a) Basic Personal Data:
- Identity and contact information: Full name, employee ID/internal identifier, date of birth, gender, nationality, residential/contact address, work email, phone number, personal photos (badge/profile photos), emergency contact details, and beneficiary information (if applicable).
- Legal and identification information: Citizen identity card/identity card/passport number; Tax Identification Number (TIN); Social insurance and health insurance numbers; residency status; work permit, visa; and information regarding foreign labor (if applicable).
- Professional and employment relationship information: Job title; position; commencement and termination dates of the employment relationship; offer letter; employment/probationary contract; and working history.
- Recruitment and competence records: Curriculum vitae (CV); application portfolio; educational and professional qualifications; degrees, certificates; and background verification information.
- HR administration information: Performance appraisals; awards and commendations; disciplinary records; working hours; overtime; annual leave, sick leave, maternity leave, and other leave entitlements.
- Financial, income, and benefits information: Insurance; benefits and other entitlements under the employment or contractual relationship.
- Family and dependent information (if applicable): Full name, date of birth, and contact information of spouses, children, and dependents; information serving tax, insurance, and benefit obligations.
- Training and development: Internal training records; certificates and training results; skill development information and career path mapping.
- Operational and internal management information: Business travel and work-related transit information; personal vehicle information (e.g., license plate); access control data, employee badges (to the extent necessary); IT system usage data, work email, work schedules; system access logs; image, video, and audio/video recording data at the workplace for security, safety, training, or internal management purposes.
(b) Sensitive Personal Data
- Salaries, wages, bonuses, and allowances; personal income tax information.
- Images of identity cards, citizen identity cards, identification cards, and passports.
- Bank account information for the payment of salaries, wages, bonuses, allowances, and benefits.
- Biometric data: Facial recognition data and other biometric data (in cases where the individual registers or consents to use).
- Financial, credit, and transaction information: Information relating to contracts, transactions, financing, guarantees, or loans (including financial and credit information); bank account information and payment-related details (including financial transaction details).
- Criminal record / judicial record card (if required by law or the nature of the position).
- Health information, medical status, and health classification.
- Identifiable audio and video recordings: Data from audio and video recordings within the workplace, to the extent that it can be used for identification, personnel management, work management, and compliance with relevant statutory requirements.
4.2.2. Legal Bases and Purposes for Processing Personal Data
4.2.2.1. Based on the Data Subjects consent:
- For Applicants: To conduct recruitment for employment positions at the Company (receiving applications, assessing suitability, making hiring decisions, and related activities);
- For Applicants, Employees, Interns, and Collaborators: To notify and contact regarding other future job opportunities.
- Other cases where the consent of the Data Subject is obtained.
4.2.2.2. To perform other purposes permitted by law to process Personal Data without the Data Subjects consent, including:
(a) To perform employment contracts and other agreements between the Data Subject (Employee/Intern/Collaborator) and the Company:
- Establishing, maintaining, managing, and terminating the employment, contractual, or collaborative relationship.
- Adjusting duties and working conditions.
- Disbursing salaries and wages; administering benefits, insurance, and other entitlements.
- Managing and evaluating job performance, training, and personnel development.
- Organizing and managing the workplace environment; supporting work operations and internal workflows.
(b) To fulfill the legal obligations of the Company:
- Establishing, maintaining, and retaining mandatory personnel records as prescribed by law.
- Fully complying with statutory regulations on labor, occupational health and safety, wages, working hours, taxation, social insurance, gender equality, foreign labor management, reporting obligations, and other related provisions.
- Complying with requests and decisions issued by competent authorities.
(c) To protect the legitimate rights and interests of the Data Subject and/or the Company:
- Ensuring security, safety, and order at the workplace; protecting the legitimate rights and interests of Personnel, the Company, and other related parties.
- Preventing, investigating, detecting, blocking, and handling crimes; mitigating legal risks, and resolving disputes or complaints relating to Personnel and the Company.
- Ensuring health, responding to incidents, and protecting the legitimate rights and interests of Personnel at the workplace.
(d) To respond to emergencies.
The processing of Personal Data under this section includes transferring Personal Data to Personal Data Processors and third parties (such as subcontractors) to fulfill the aforementioned purposes.
In the course of business operations, the Company may undergo corporate reorganizations including, but not limited to, restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the right to use relevant information may be transferred and/or continue to be processed to serve the execution of the aforementioned activities, provided that it does not give rise to any new processing purposes outside of those specified in this Section 4.2.2.2.
4.3. For Partner contact points and individual Partners
4.3.1. Types of Personal Data Collected
- Contact information: Full name; date of birth; identity document number (Identity Card/Citizen Identity Card) or personal identification number; job title; email address; workplace address; contact phone number.
- Professional qualifications, work experience, and practicing licenses (if applicable) in certain cases where it is necessary to verify the suitability of the Partner.
- Access and entry/exit information at the Companys premises.
- Sensitive Personal Data (if any) collected from audio and video recording activities via security cameras at the Companys premises; images of identity cards, citizen identity cards, and identification cards.
- Other Personal Data provided by the Partner during the course of communication, cooperation, and performance of contractual agreements.
4.3.2. Legal Bases and Purposes for Processing Personal Data
To perform purposes permitted by law to process Personal Data without the Data Subjects consent, including:
4.3.2.1. To perform agreements between the Company and the Partner:
- Verifying the suitability of the Partner regarding the scope of cooperation.
- Contacting, communicating, negotiating, and coordinating work between the Company and the Partner.
- Establishing, maintaining, and managing the collaborative relationship.
- Executing and managing related contracts and transactions.
4.3.2.2. To fulfill the legal obligations of the Company:
- Establishing, maintaining, and retaining mandatory records as prescribed by law.
- Complying with requests and decisions issued by competent authorities.
- Complying with statutory regulations on tax management, accounting, and other legal provisions.
4.3.2.3. To protect the legitimate rights and interests of the Data Subject and/or the Company:
- Ensuring security, safety, and order at the Company; protecting the legitimate rights and interests of the Partner, the Company, and other related parties.
- Preventing, investigating, detecting, blocking, and handling crimes, and mitigating legal risks relating to the Partner and the Company.
- Recording, controlling entry/exit, and monitoring through security camera systems.
- Protecting people, property, as well as the legitimate rights and interests of the Partner, Contact Points, and the Company during the course of cooperation.
4.3.2.4. To respond to emergencies.
The processing of Personal Data under this section includes transferring Personal Data to Personal Data Processors and third parties (such as subcontractors) to fulfill the aforementioned purposes.
In the course of business operations, the Company may undergo corporate reorganizations including, but not limited to, restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the right to use relevant information may be transferred and/or continue to be processed to serve the execution of the aforementioned activities, provided that it does not give rise to any new processing purposes outside of those specified in this Section 4.3.2.
4.4. For Shareholders, Insiders, Related Persons
4.4.1. Types of Personal Data Collected
- Contact information: Full name; date of birth; nationality; identity document number (Citizen Identity Card/Identity Card/Passport) or personal identification number; email address; contact address; contact phone number.
- Information on shares/stock owned: Number of shares/stock; ownership percentage; time of becoming/ceasing to be a shareholder; ownership change history.
- Information on share/stock transactions: Timing of transaction registration; transaction history; transaction value; transaction reporting information of Insiders and Related Persons.
- Information on relevant rights and obligations of Shareholders: Voting rights; voting information; purchase rights, issuance rights; rights to receive dividends and profits.
- Information on titles within the Company: Job title; managerial role; scope of authority and responsibility; appointment and dismissal dates.
- Legal relationships: “Related person” relationships as defined by law; information on Insiders/Related Persons (including history).
- Tax information: Tax obligations arising from dividends, transfers of shares, and stock.
- Ownership verification information: Legal and supporting documents proving capital/share ownership.
- Information on attending the General Meeting of Shareholders and proxy/authorization: List of individuals attending the meeting; personal information of individuals authorized to attend and vote.
- Data for governance and control purposes, including data serving the detection of conflicts of interest and information related to signs of violation of disclosure or corporate governance obligations.
- Data for dispute resolution and rights protection: Legal profiles; evidentiary documents; communication information related to complaints, disputes, and legal proceedings; data serving post-transaction obligation reconciliation and rights protection.
- Sensitive Personal Data (if any): Bank account information for receiving dividends, profits, or performing transactions related to capital contributions/shares; images of identity cards, citizen identity cards, and identification cards.
- Other necessary personal information as required by law from time to time (if any) to serve corporate governance in accordance with regulations on enterprises and securities.
4.4.2. Legal Bases and Purposes for processing Personal Data
To perform purposes permitted by law to process Personal Data without the Data Subjects consent, including:
4.4.2.1.To fulfill mandatory legal obligations on corporate governance, securities (if applicable), and related regulations
- Establishing and maintaining the register of shareholders/members, and managing the history of share/capital contribution ownership.
- Disclosing information and preparing periodic/extraordinary reports as prescribed by law (on enterprises, securities, and specialized regulations, if any).
- Managing transactions, ownership changes, capital contributions, and transactions of Insiders and Related Persons.
- Fulfilling tax and financial obligations related to capital owners.
- Serving inspections, examinations, audits, and requests from competent state authorities.
- Archiving records in accordance with legal regulations.
4.4.2.2. To perform the agreements, rights, and obligations of the Data Subject in accordance with the law
- Exercising rights and obligations established under the Companys Charter, resolutions/decisions of the General Meeting of Shareholders, the Board of Directors, authorization agreements, and other lawful legal relationships.
- Managing the list of meeting attendees and authorized proxies, voting information, and decision-making procedures at meetings.
- Recording and exercising shareholders rights such as: receiving dividends/profits, transferring shares/stock, purchase rights, issuance rights, and other arising rights/benefits.
- Communicating and liaising with shareholders and Insiders (including Related Persons) to ensure the rights of shareholders and Insiders, and to serve corporate governance.
4.4.2.3. To protect the legitimate rights and interests of the Data Subject and/or the Company
- Preventing, detecting, and managing conflicts of interest in the governance and operation of the Company.
- Preventing insider trading, misuse of inside information, and related legal violations.
- Monitoring and mitigating the risks of violating governance obligations, information disclosure obligations (if applicable), and other legal obligations.
- Responding to requests, recommendations, and complaints, and resolving disputes and arising rights, including after the termination of status as a shareholder, Insider, or Related Person.
- Protecting the reputation, transparency, and compliance of the Companys operations.
4.4.2.4. Fulfilling other responsibilities of the Company (if any) in accordance with the law from time to time.
The processing of Personal Data under this section includes the transfer of Personal Data to Data Processors and Third Parties (such as subcontractors) to fulfill the aforementioned purposes.
In the course of business operations, the Company may undergo corporate reorganizations, including but not limited to restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the right to use related information may be transferred and/or continue to be processed to serve the implementation of the aforementioned activities, provided that this does not give rise to any new data processing purposes beyond those specified in this Section 4.4.2.
5. SHARING AND TRANSFER OF PERSONAL DATA
5.1. General Principles
When sharing and transferring Personal Data to a third party, the Company undertakes to:
- Only share within the necessary scope consistent with the specified processing purposes for each category of Data Subject; and
- Require the data recipient to apply appropriate data protection measures.
5.2. Data Recipients
Depending on the specific category of Data Subject, the purpose, and the processing activities, the Company shares, provides, or transfers Personal Data to the following recipients:
|
Data Recipient |
Purpose of Sharing |
|
The Companys parent company, subsidiaries, and affiliates |
Sharing and transferring Personal Data within the necessary scope, aligned with the purposes and processing activities specified in this Policy. |
|
Service providers and operational partners These service providers may include: • Public services, utilities, repairs, upgrades, and maintenance; • IT services, digital platforms, management systems (including sales, brokerage, HR, shareholders, contracts); • Payment and transaction processing services; • Payroll, tax, insurance, benefits, and other HR administration services; • Data storage, database management, and operations; • Recruitment, assessment, training, and personnel development services; • Operational support, brokerage management, and sales systems; • Contract management and communication services with partners; • Legal, financial, auditing, corporate governance advice, and other professional services. |
The Company may share and transfer Personal Data to service providers and partners to perform processing activities on behalf of the Company. These parties are only permitted to process Personal Data within the scope and purposes defined by the Company, and must comply with confidentiality and information security requirements under their agreements with the Company and legal regulations. |
|
Media and advertising partners |
To conduct communication and product promotion activities, the Company may coordinate and share Personal Data with media and advertising partners, provided that: • The sharing matches the notified processing purposes; • It complies with advertising laws; • Consent from the Data Subject is obtained where legally required. The Company does not share Customer contact information with third parties for independent marketing purposes without a proper legal basis. |
|
Relevant parties in corporate restructuring or reorganization events (such as division, separation, merger, or consolidation) |
In the event that the Company is involved in or undergoes restructuring or reorganization (e.g., division, separation, merger, consolidation), Personal Data may be disclosed or transferred as part of that transaction, provided that the recipient continues to comply with personal data protection requirements under applicable laws. |
|
Relevant parties for compliance with legal obligations and protection of non-contractual legitimate rights of the Company and Data Subjects |
The Company may provide Personal Data to competent state authorities, legal counsel, or relevant parties in necessary cases to: • Comply with legal regulations or lawful requests; • Establish, exercise, or defend the Companys legitimate rights and interests; • Prevent, detect, and handle fraudulent or non-compliant behaviors; • Protect the safety, health, and legitimate rights and interests of Data Subjects or other individuals and organizations. |
|
Entities engaged in research and development of blockchain technology, metaverse, artificial intelligence, and other automated systems |
The Company may provide, share, or transfer Personal Data for the purpose of researching and developing technological products and services, including blockchain, metaverse, artificial intelligence, and other automated systems, when fully meeting the requirements of relevant laws. |
|
Third parties upon request or consent of the Customer |
The Company may share Personal Data with third parties based on the explicit consent or direction of the Data Subject. |
6. PROCESSING OF PERSONAL DATA IN SCIENTIFIC AND TECHNOLOGICAL ACTIVITIES
6.1. Transfer of Personal Data for Scientific and Technological Development
On an appropriate legal basis and in strict compliance with Applicable Law, the Company may transfer Personal Data to its parent company, subsidiaries, affiliates, and technology partners for the purposes of scientific, technological development, and innovation, including:
- Research and development of financial technology (Fintech) products and services;
- Big Data processing;
- Building and operating blockchain technology, metaverse systems, and cloud computing;
- Cybersecurity technology;
- Technologies utilizing self-learning algorithms, artificial intelligence (AI) systems, and other automated systems.
6.2. Compliance Conditions for Data Transfer and Processing in Technology Environments
All transfers and processing of Personal Data within big data, AI, blockchain, metaverse, and cloud computing environments must be performed for correct purposes, limited to the necessary scope, and compliant with Applicable Law. The Company will only process Personal Data if the following requirements are met:
- Processing activities match the purposes notified to the Data Subject and possess an appropriate legal basis. If the law requires the Data Subjects consent for transfers or processing related to AI or automated systems, the Company will secure such consent.
- Implementing continuous monitoring, testing, and periodic assessments regarding cybersecurity and data confidentiality.
- Classifying AI processing activities based on risk levels; notifying Data Subjects of automated processing, explaining algorithmic principles, and providing opt-out choices.
- Binding Data Recipients via data transfer/processing agreements with strict confidentiality obligations, ensuring they process data strictly within the scope and purposes defined by the Company.
- Not using or developing systems that leverage Personal Data to harm national defense, national security, social order, or infringe upon the legitimate rights and interests of others.
7. DATA RETENTION PERIOD
7.1. The Company only retains the Personal Data of Data Subjects for the duration necessary to fulfill the processing purposes set out in this Policy or as required by relevant laws.
7.2. As soon as the purpose of processing Personal Data is accomplished or there is no longer a need to use the Personal Data for the notified purposes, the Company will delete, destroy, or anonymize the Personal Data in a timely manner, unless further retention for a specific period is permitted or required by law.
The Company may be required to retain Personal Data even after agreements between the parties have terminated to fulfill statutory obligations and/or requests from competent state authorities.
7.3. In cases where the law requires the deletion or destruction of Personal Data, the Company willthe deletion/destruction immediately in accordance with regulations, while applying necessary measures to ensure the Personal Data can no longer be accessed, recovered, or used without authorization.
7.4. The Company guarantees that the retention, deletion, and destruction of Personal Data are always performed with prudence, safety, and in compliance with law, protecting the legitimate rights and interests of both the Data Subjects and the Company.
8. PERSONAL DATA PROTECTION MEASURES
8.1. To best safeguard Customer information, the Company has been applying the following specific measures:
8.1.1. Technical measures: to prevent unauthorized access and use of Personal Data. The Company regularly coordinates with security experts tothe latest cybersecurity techniques and thereby ensure the security of Personal Data. All new software systems or major updates must undergo the appropriate information security assessments and vulnerability scanning processes, commensurate with the level of risk involved, before they go into actual operation.
8.1.2. Organizational measures: establishing internal regulations on personal data protection and third-party risk management processes; appointing dedicated personnel and compliance monitoring departments. The Company conducts scheduled and ad-hoc audits on privacy policy compliance to promptly detect and mitigate potential risks.
8.1.3. Operational measures: maintaining periodic and daily data control workflows; implementing dataand redundancy plans to ensure data is stored and processed according to committed purposes and scopes. Establishing cybersecurity incident response procedures and conducting regular security awareness training for personnel.
8.1.4. Physical measures: setting up physical barriers and strict access control systems for IT infrastructure areas, server rooms, and data storage equipment. Ensuring the physical security of data storage media and devices to prevent any unauthorized access.
8.2. Furthermore, when sharing Personal Data with third parties to serve the purposes outlined in this Policy, the Company requires the related parties to implement appropriate data protection measures to ensure that Personal Data continues to be processed securely.
However, due to the inherent nature of technology and the Internet, no security measure can guarantee absolute safety. Therefore, while the Company constantly strives to apply appropriate measures, we cannot absolutely guarantee or promise that your Personal Data will be safe in every circumstance.
9. PROTECTION OF VULNERABLE CONSUMERS RIGHTS AND INTERESTS
9.1. Where a Customer belongs to a vulnerable consumer group under Applicable Law, the processing of their Personal Data must be performed with caution, appropriateness, and enhanced protection to ensure the Customers legitimate rights and interests.
9.2. When necessary to receive and process requests from Customers, the Company may collect relevant information and documents to determine their vulnerable consumer status, on the basis of:
9.2.1. Collecting strictly within the necessary scope;
9.2.2. Utilizing the data solely for the purpose of receiving and resolving requests;
9.2.3. Applying appropriate security measures to any resulting Personal Data;
9.2.4. If a Customers rights are infringed and they request protection: The receiving officer is responsible for forwarding the Customers request to the correct level authorized to resolve Customer complaints under the Companys regulations at that time, ensuring the Customer receives support, service, and resolution as promptly as possible;
9.2.5. The Company prioritizes the direct intake and handling of requests from vulnerable consumers ahead of regular Customer requests.
9.3. Processing Personal Data of children and individuals who lack or have limited civil capacity:
9.3.1. The Company only processes such Personal Data within the necessary scope to ensure the legitimate rights, interests, and safety of the aforementioned individuals, for example:
- Helping children or vulnerable individuals access and use services or utilities;
- Ensuring a safe, secure, appropriate, and friendly environment for product and service provision;
- Fulfilling necessary statutory obligations.
9.3.2. Where the law requires consent for the Processing of Personal Data, such consent shall be provided by the legal representative on behalf of children or individuals lacking full civil capacity, unless otherwise provided by law. For children aged 7 years and older, if data processing is intended to publish or disclose information regarding their private life or personal secrets, the Company will only proceed upon obtaining consent from both the child and their legal representative.
9.4. In case a Customers request is rejected, the Company will respond to the Customer in writing, clearly stating the legal grounds and the respects in which the Customers request is not appropriate.
10. RIGHTS AND OBLIGATIONS OF DATA SUBJECTS
10.1. Data Subjects possess rights regarding their Personal Data, including:
10.1.1. Being informed of Personal Data Processing activities.
10.1.2. Providing or withholding consent, or requesting the withdrawal of consent for Personal Data Processing.
10.1.3. Accessing, correcting, or requesting the correction of Personal Data.
10.1.4. Requesting the provision, deletion, or restriction of Personal Data Processing; submitting objections against Personal Data Processing.
10.1.5. Filing complaints, denunciations, lawsuits, or claiming damages in accordance with law.
10.1.6. Requesting the application of personal data protection measures and solutions as prescribed by law.
10.2. Data Subjects may exercise their rights by sending a request to the Personal Data Protection Department using the contact details provided in the relevant section, via direct written requests, email, or other electronic means.
10.3. Every request to exercise Data Subject rights must clearly specify at least the following details:
10.3.1. Information of the Data Subject (full name, email, or phone number).
10.3.2. The specific right the Data Subject wishes to exercise and the type of Personal Data related to the request.
10.3.3. The reasons and purpose for exercising the right (if any); and
10.3.4. Relevant information and documentation concerning the exercise of such right.
10.4. Upon receipt of a request, we will verify the identity, validity, completeness, and accuracy of the request in accordance with law, and evaluate its feasibility. We reserve the right to request additional information for verification, or decline to process the request if:
10.4.1. The Data Subject fails to provide sufficient information to verify their identity and the validity of the request; or
10.4.2. Legal regulations do not permit the Company to fulfill the Data Subjects request; or
10.4.3. There is a specific request/order from a competent state authority.
10.5. Please note that the rights listed above are not absolute and may be limited by certain legal provisions, exceptions, or other statutory requirements and principles. In specific scenarios, the Company may be entitled to refuse or restrict the fulfillment of these rights under prevailing laws.
11. AMENDMENTS AND UPDATES
11.1. This Policy may be updated, amended, supplemented, or replaced by the Company from time to time, provided that such updates, amendments, supplements, or replacements do not contradict Applicable Law and/or aim to better protect the Data Subjects information.
11.2. The updated, amended, supplemented, or replaced content of this Policy (if any) will be publicly posted by the Company in compliance with Applicable Law at that time. Data Subjects are encouraged to visit and check the website regularly to stay updated on the latest changes.
12. INFORMATION ON THE DEPARTMENT RESPONSIBLE FOR PERSONAL DATA PROTECTION
If you have any questions regarding the Companys Personal Data protection activities, please contact the Department responsible for personal data protection using the contact details below:
Company: Vingroup Joint Stock Company
Headquarters: No.7, Bang Lang 1 Street, Vinhomes Riverside Urban Area, Phuc Loi Ward, Hanoi, Vietnam
Email: [email protected]
13. NOTIFICATION
This Policy is deemed a prior notice before Personal Data is Processed by the Company. Accordingly, the Company and any involved organizations or individuals participating in the Personal Data Processing workflow are not required to issue subsequent notices prior to Processing Personal Data.
14. EFFECTIVENESS
This Personal Data Protection Policy shall take effect on 10 September 2026, replacing the Personal Data Protection Policy issued on 01 July 2023 and the Consumer Information Protection Rules dated 01 September 2025.