Data, Technology & Compliance

Employee Data Processing in Companies

Employee Data Processing in Companies

Employees are the largest block of personal data most companies hold: candidate files, labour contracts, payroll, social insurance information, attendance data, surveillance cameras and even health information in periodic health check files. From 01/01/2026, Personal Data Protection Law 2025 (No. 91/2025/QH15) dedicates Article 25 to regulating employee data processing, with rules considerably stricter than the Decree 13/2023/ND-CP era.

The difficulty of this area is the inherently asymmetric employment relationship: employees can hardly refuse employer requests without fearing job impacts. The law therefore sets specific limits, from collection, monitoring and storage to deletion upon contract termination.

Quick summary

Main legal basesArticle 25 Law 91/2025/QH15; Decree 356/2025/ND-CP; Labour Code 2019
Notable new pointsDelete/destroy data upon contract termination; monitoring technology only when employees clearly know and consent
Target audienceHR departments, in-house legal, FDI companies with large workforces

Dedicated legal framework: Article 25 of Law 91/2025/QH15

Article 25 of the Personal Data Protection Law 2025 is the dedicated provision regulating employee data processing. The lawmakers’ approach is clear: employment relations have specifics that cannot mechanically apply general customer data rules, so dedicated limits on collection, monitoring, storage and deletion are needed.

Three pillars of Article 25 HR departments must master: employee data may be retained only within periods prescribed by law or lawful agreements between the two parties; data must be deleted/destroyed upon contract termination, except as agreed or otherwise prescribed by law; and monitoring technologies and techniques may only be applied when employees clearly know and consent, with collected data not used for other purposes without consent.

Employee data across the employment lifecycle

The employee data lifecycle begins at recruitment: CVs, applications, interview results, reference information. Many companies habitually keep unsuccessful candidates’ files “for future rounds” without permission — a practice needing correction, as retention must have a clear legal basis. At contract signing, companies collect ID cards, degrees, payroll bank accounts and dependent information for tax settlement.

During employment, data arises continuously: attendance, performance evaluations, labour discipline, periodic health checks, data from cameras and monitoring tools. The general principle: collect only data necessary for each specific purpose.

Consent in employment relations: the real “voluntariness” issue

The law requires consent to be clear, voluntary and expressed affirmatively; silence or pre-ticked boxes do not constitute consent. In employment relations, “voluntariness” is the hardest point: when employers present documents for signing, employees can hardly refuse. Companies should not assume that employee signatures on every consent document are automatically valid.

Good practice is separating consent contents by specific purpose, rather than bundling into one clause in labour contracts or regulations. For example: consenting to provide information for social insurance is one thing; consenting to use images in internal communication publications is another; consenting to collect biometric data for attendance is yet another. (See data subject consent management).

Employee monitoring: cameras, GPS, attendance software

Clause 3 Article 25 of Law 91/2025/QH15 provides that companies may only apply technologies and techniques like GPS, cameras and attendance software when employees clearly know and consent; collected data must not be used for other purposes without consent. This directly affects widespread current practices.

“Clearly knows” should be understood as employees being informed about the technology types used, monitoring scope and purposes, and data retention periods. For highly intrusive monitoring like GPS tracking of sales staff or screen recording, companies should have separate notification and consent confirmation documents. Security camera data must also not be used to evaluate work performance, as that is purpose misuse (see cameras, biometric data and compliance risks).

Personnel file retention periods: how long is enough?

Article 25 provides that employee data may be retained only within periods prescribed by law or lawful agreements between the two parties. In practice, many file types have retention periods set by sectoral laws: tax documents, accounting files and social insurance files all have minimum retention periods.

The problem lies with data lacking statutory periods: internal evaluations, meeting minutes, work emails, detailed attendance data. For this group, companies need to build their own data retention and deletion schedules, with each data type assigned a period tied to specific purposes. For example: detailed attendance data only needs 1–2 years for settlement and complaint resolution, not permanent retention.

Deleting data upon labour contract termination

Point c Clause 2 Article 25 is clear: employees’ personal data must be deleted/destroyed upon contract termination, except as agreed with employees or otherwise prescribed by law. This is one of the new regulations with the greatest operational impact.

Implementing this requires companies to build data offboarding procedures: when employees leave, HR coordinates with IT to review systems storing their data, classifying data for immediate deletion, data retained further under law (tax, insurance, accounting), and data retained under agreements with employees. Deletion should cover all copies within technical capability.

Employees’ sensitive data: health, biometrics

Personnel files contain considerable sensitive data: periodic health check results, maternity information, biometric data used for fingerprint or face attendance. Under Decree 356/2025/ND-CP, biometric data, health status and personal location via positioning services are all in the sensitive data catalogue, subject to enhanced protection measures.

For sensitive data, companies need separate consent for each type, limit access to fewer people, apply encryption, and consider less intrusive alternatives like offering employees a choice between biometric attendance and key cards (see sensitive personal data processing).

Transferring employee data within groups and abroad

For FDI companies, employee data is often synced to centralised group HR management systems hosted abroad. This is cross-border personal data transfer. Notably, the law exempts cross-border transfer impact assessments for cases where agencies and organisations store their employees’ personal data on cloud computing services.

However, this exemption is narrow: it applies to storage on cloud computing, not a general “exemption card” for all employee data transfers abroad. Companies must still have binding agreements with foreign data recipients and ensure employees’ rights. (See cross-border personal data transfers).

Employees’ rights over their data

Employees as data subjects have full rights under the Law: rights to be informed, to view, correct, receive data copies, withdraw consent, request deletion, restrict processing, object to processing and complain. Decree 356/2025/ND-CP sets specific timelines: respond to requests within 02 working days, implement corrections or data provision within 10 days, cease processing within 15 days, delete data within 20 days.

In HR practice, common requests are employees requesting file copies when leaving, requesting corrections of inaccurate information, or requesting deletion after departure. Companies need procedures to receive and handle these requests on time, with clear focal points.

Common risks and prevention in employee data governance

The most common risk is over-collection right at recruitment: application forms asking for family information, religion and detailed marital status when the position does not need them. The second risk is purpose misuse, e.g. using employees’ emergency contact information for marketing. The third is lax security: salary files sent via personal email, departed employees’ system accounts not revoked promptly.

Companies should have personal data protection personnel participate from the design of new forms and procedures, periodically check system access rights and drill data deletion procedures during offboarding.

How FLAT LAW FIRM supports companies

FLAT LAW FIRM supports comprehensive review of employee data processing: assessing recruitment forms, labour contracts, regulations and offboarding procedures; building consent document systems; designing retention schedules and data deletion procedures; building employee request handling procedures within deadlines.

With strengths in labour law advisory, we ensure data solutions harmonise with Labour Code 2019. We work in Vietnamese, Chinese and English. See also labour contracts in Vietnam and the data and technology compliance checklist.

Frequently asked questions

Can companies keep departed employees’ files?

Data must be deleted/destroyed upon contract termination under point c Clause 2 Article 25 of Law 91/2025/QH15, except as agreed with employees or otherwise prescribed by law (such as retention periods for tax, accounting and social insurance files).

Do workplace cameras need employee consent?

Under Clause 3 Article 25, companies may only use cameras and other monitoring technologies when employees clearly know and consent, and must not use data for other purposes without consent.

What are the risks of fingerprint or face attendance?

Biometric data is sensitive data, requiring separate consent and enhanced protection measures. Companies should offer employees less intrusive alternatives like key cards.

Do employees have the right to view their files?

Yes. Companies must respond to requests within 02 working days and implement viewing and data provision requests within 10 days under Decree 356/2025/ND-CP.

Does syncing employee data to group systems abroad require permission?

This is cross-border data transfer, requiring binding agreements with recipients and ensuring employees’ rights. Storage on cloud computing services may be exempt from cross-border transfer impact assessment.

Talk to FLAT LAW FIRM

If your company needs to review employee data processing or build compliance procedures under Article 25 of Law 91/2025/QH15, FLAT LAW FIRM is ready to support in Vietnamese, Chinese and English.