Legal responsibilities of e-commerce platform operators in protecting consumers’ personal data

Abstract

This study examines the theoretical foundations, legal characteristics, and current Vietnamese regulations governing the responsibilities of e-commerce platform operators in collecting, notifying, and protecting consumers’ personal data. The findings indicate that Vietnamese law continues to reveal gaps and limitations in the allocation of responsibility and the governance of personal data, particularly amid the rapid development of domestic and cross-border e-commerce. Drawing on a comparative analysis of legal frameworks and regulatory practices in selected jurisdictions, the study proposes directions for improving Vietnam’s legal framework to better balance the legitimate rights and interests of platform operators and consumers while deriving lessons for international integration.
Keywords
personal data protection e-commerce platforms consumers

References

1.
Chính phủ. (2013). Nghị định số 52/2013/NĐ-CP ngày 16/5/2013 về thương mại điện tử
2.
Chính phủ. (2023). Nghị định số 13/2023/NĐ-CP ngày 17/4/2023 quy định về bảo vệ dữ liệu cá nhân
3.
Nguyễn Hoàng Khang. (2025). Tổng quan các kênh e-Commerce tại Việt Nam. Truy cập tại https://www.brandcamp.asia/blog/366-tong-quan-cac-kenh-e-commerce-tai-viet-namQuốc hội. (2025). Luật Bảo vệ dữ liệu cá nhân (Luật số: 91/2025/QH15 ngày 26/6/2025
4.
Quốc hội. (2025). Luật Thương mại điện tử (Luật số: 122/2025/QH15 ngày 10/12/2025).
5.
Quốc hội. (2023). Luật Bảo vệ quyền lợi người tiêu dùng (Luật số: 19/2023/QH15 ngày 20/6/2023).
6.
Council of Europe. (1981). Convention for the protection of individuals with regard to automatic processing of personal data (European Treaty Series No. 108). https://www.coe.int/en/web/data-protection/convention108-and-protocolNghị viện châu Âu & Hội đồng Liên minh châu Âu. (1995). Chỉ thị 95/46/EC ngày 24/10/1995 về bảo vệ dữ liệu cá nhân đối với việc xử lý dữ liệu cá nhân và việc tự do di chuyển dữ liệu.Ủy ban Thường vụ Đại hội đại biểu nhân dân toàn quốc. (2021). Luật Bảo vệ Thông tin cá nhân của Cộng hoà Nhân dân Trung Hoa (viết tắt là PIPL). Đại hội đại biểu nhân dân toàn quốc nước Cộng hòa Nhân dân Trung Hoa. http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htmTrinh, H. T. T., Nguyen, D. L., & Le, T. T. (2025). Regulatory framework for personal data protection in e-commerce: Perspective from Vietnam. Humanities and Social Sciences Communications, 12(1), Article 215. https://doi.org/10.1057/s41599-025-06100-3European Data Protection Supervisor (2021). Pseudonymous data: Processing personal data while mitigating risks. https://edps.europa.eu/press-publications/press-news/blog/pseudonymous-data-processing-personal-data-while-mitigating_en
7.
Mourby, M., Mackey, E., Elliot, J., Gowans, H., Wallace, J., Bell, J., Nicholls, H., Whitton, T., & Kaye, J. (2018). (2018). Are ‘pseudonymised’ data always personal data? Implications of the GDPR for administrative data research in the UK. Computer Law & Security Review, 34(2), 222–233. https://doi.org/10.1016/j.clsr.2018.01.002
8.
Nation Institute of Standards and Techbology (2010). Guide to protecting the confidentiability of personally identifiable information (PII) (NIST Special Publication 800-122. U.S. Department of Commerce.State of California Department of Justice. (n.d.). California Consumer Privacy Act (CCPA). Office of the Attorney General. https://oag.ca.gov/privacy/ccpaTilleke & Gibbins. (2025). Vietnam's new personal data protection law: A closer Look. https://www.tilleke.com/insights/vietnams-new-personal-data-protection-law-a-closer-look/?utm.