In the digital era, data has become one of the most valuable assets of any enterprise, directly influencing operational efficiency, corporate reputation, and market competitiveness. Nevertheless, many enterprises remain negligent in implementing proper data backup processes, resulting in situations where enterprises fail to back up data appropriately, thereby exposing themselves to significant legal risks and substantial losses in the cases of data loss, corruption, or leakage. The following article analyzes the current situation, relevant concepts, legal regulations, associated risks, and frequently asked questions regarding data backup, helping enterprises better understand their responsibilities and effective preventive measures.
I. Current situation regarding enterprises failing to properly back up data
The loss of critical data due to technical failures, malware, or hardware malfunctions may disrupt business operations and adversely affect corporate credibility. In addition, enterprises may face legal risks, administrative sanctions, or claims for damages if they violate data retention requirements prescribed by law.

Common causes include insufficient awareness, the absence of standardized data management procedures, and backup systems that lack adequate security measures or geographical redundancy. It demonstrates that enterprises failing to properly back up data remains a widespread issue that requires timely remediation to minimize potential risks.
II. Concept of enterprises failing to properly back up data
1. What does it mean for an enterprise failing to properly back up data?
Data backup refers to the process of creating copies of data systems, configurations, applications, and other digital assets and storing such copies separately from the original data. Such a process enables enterprises to protect and promptly restore data in the case of information system failures, hardware damage, natural disasters, or human errors.
Accordingly, an enterprise fails to properly back up data when it does not adequately, regularly, and securely create, store, or protect backup copies of its data, thereby increasing the risk of losing, damaging, or disclosing important information.
It may include the following circumstances:
- Absence of backup copies of data.
- Failure to perform backups regularly or according to a predetermined schedule.
- Storing backup copies in the same physical location as the original data.
- Failure to encrypt or otherwise protect backup data against unauthorized access.
- Failure to periodically test and verify data restoration capabilities.
2. What actions are considered improper data backup practices in enterprises?
An enterprise may be deemed to have failed to properly back up data when it engages in any of the following practices:
- Failure to create backup copies: Important data exists only on the primary system without separate backup copies. In the cases of technical failures, cyberattacks, or natural disasters, such data may be permanently lost.
- Irregular or inadequate data backup: Outdated or infrequently updated backups may result in incomplete or obsolete data restoration.
- Storing backup data in the same location as original data: When the original data is damaged or compromised, backup copies are likely to be affected as well.
- Failure to protect or encrypt backup data: Unencrypted backup data or backup systems lacking access controls are vulnerable to unauthorized access and data breaches.
- Failure to conduct periodic testing and restoration exercises: Enterprises do not verify whether data can be successfully restored from backup copies. In actual emergencies, restoration attempts may fail, causing severe operational disruptions.
III. Legal regulations relating to enterprises failing to properly back up data
1. Common data backup methods currently used
Data backup within enterprises is generally implemented through the following methods:
- Full Backup: A complete copy of all data is created at a specific point in time, allowing rapid restoration but requiring significant storage capacity.
- Incremental Backup: Only data changes made since the most recent backup are copied, reducing storage requirements and backup duration.
- Differential Backup: Data changes made since the most recent full backup are copied, providing a balance between restoration efficiency and storage consumption.
- On-Premises Backup: Data is backed up to servers or physical storage devices directly managed by the enterprise.
- Cloud Backup: Data is backed up on systems operated by third-party service providers. Although convenient and flexible, such a method requires strict oversight regarding security measures and legal responsibilities.
2. What is the statutory data retention period?
Pursuant to Clause 1 Article 27 of Decree No. 53/2022/ND-CP: The data retention period prescribed in Article 26 of this Decree shall commence from the date on which the enterprise receives the request for data retention and continue until such request is terminated. The minimum retention period shall be 24 months.
Accordingly, under current regulations, enterprises are required to retain data in Vietnam for a minimum period of 24 months, unless otherwise prescribed by law for specific categories of data.
3. Is data backup mandatory?
Vietnamese law does not contain a specific provision expressly requiring all enterprises to perform data backups. However, through legal requirements relating to information security, data protection, and data retention, enterprises are indirectly obligated to implement data backup measures to prevent data loss, damage, or leakage.

Relevant provisions include:
- Clause 6 Article 16 of Decree No. 13/2023/ND-CP: This provision establishes a general obligation concerning the storage and protection of personal data, under which data backup constitutes one of the necessary technical measures to ensure data security and recoverability in incidents.
- Clause 2 Article 11 of Decree No. 53/2020/ND-CP: This provision expressly requires critical information systems to maintain backup mechanisms and establishes standards regarding backup frequency and restoration testing.
Although the law does not explicitly use the term “mandatory data backup”, enterprises that fail to implement appropriate backup measures and thereby cause data loss may still be deemed to have violated their obligations concerning data security and protection, resulting in legal liability.
4. How are enterprises that fail to properly back up data subject to legal sanctions?
Failure to adequately back up and secure data may result in data loss, customer information breaches, infringement of consumer rights, and information security incidents in cyberspace. Depending on the nature and severity of the violation, enterprises may incur administrative, criminal, and civil liabilities.
- Administrative sanctions: Pursuant to Point c, Clause 2, Article 46 of Decree No. 98/2020/ND-CP, as amended and supplemented by Clause 5 Article 1 of Decree No. 24/2025/ND-CP, a fine ranging from 30,000,000 VND to 40,000,000 VND shall be imposed for any of the violations, such as failure to implement measures ensuring the safety and security of consumer information during the collection, storage, or use of such information, or failure to implement measures preventing violations of consumer information security as prescribed by law, except for cases specified in Point a Clause 3 Article 64 of this Decree.
- Criminal liability: Pursuant to Article 361 of the Criminal Code 2015 (as amended in 2017), intentional disclosure of work-related secrets; appropriation, trading, or destruction of confidential work-related documents shall take the following liabilities:
- Non-custodial reform for up to three years; or
- Imprisonment from six months to three years.
- If serious consequences arise, including organized conduct, damages of 100 million VND or more, or substantial adverse effects on the operations of agencies or organizations, imprisonment from two to seven years may be imposed.
In addition, under Article 362, negligent disclosure of work-related secrets; loss of confidential work-related documents are also subject for the following sanctions:
- Warning or non-custodial reform for up to three years where adverse impacts occur or damages reach 100 million VND or more.
- Imprisonment from three months to two years where damages reach 500 million VND or more or where another person exploits the circumstances to commit a serious crime.
In addition to the principal fines, offenders may also be prohibited from holding certain positions, practicing certain professions, or performing specified work for a period of one to five years.
- Civil Liability: Pursuant to Article 584 of the Civil Code 2015, enterprises must compensate for all damages arising from the loss or disclosure of data, including:
- Property damage;
- Costs of remedying the incident and restoring data;
- Damage to reputation and honor;
- Adverse impacts on the lawful rights and interests of customers, business partners, and employees.
IV. Questions regarding enterprises failing to properly back up data
1. How can it be determined whether an enterprise has properly backed up its data?
An enterprise may be deemed to have properly backed up its data when it satisfies the following fundamental requirements: Data is comprehensively and periodically backed up under a clearly established procedure; backup copies are stored separately from the original data and protected through appropriate security measures and access controls; the enterprise is capable of effectively restoring data in an incident; and the backup process complies with the intended purposes of data processing, applicable retention periods, and legal requirements relating to cybersecurity and personal data protection.
2. If a enterprise only backs up important data but loses secondary data, can it still incur legal liability?
An enterprise may still take legal liability if its failure to comprehensively back up data results in the loss of information that is required by law to be protected or retained.
Even where the lost information is considered “secondary data”, legal liability may arise if such data contains personal data, customer information, management records, accounting records, tax-related information, or any other category of data that the enterprise is legally obligated to retain. In such circumstances, the failure to properly back up the data may constitute a breach of information security and data protection obligations.
Conversely, if the lost data is not subject to any mandatory retention requirement, does not adversely affect the lawful rights and interests of customers or business partners, and causes no actual damage, the enterprise’s legal liability may be mitigated or may not arise at all.
Nevertheless, to minimize risks, enterprises should establish a comprehensive data backup policy rather than focusing solely on data that is subjectively regarded as “important”.
3. Should enterprises store backup data in multiple locations to reduce risks?
Enterprises should maintain backup copies of data in multiple locations to minimize the risk of data loss resulting from technical failures, cyberattacks, or disasters. However, such storage arrangements must comply with mandatory Vietnamese regulations concerning data localization.

Pursuant to Article 26 of Decree No. 53/2022/ND-CP, categories of data including personal data of users in Vietnam, user-generated data, and data concerning user relationships must be stored in Vietnam. Domestic enterprises are obligated to retain such data within Vietnam. In addition, foreign enterprises operating in sectors such as e-commerce, social networking services, data storage and sharing services, online payment services, and similar industries may also be required to store data in Vietnam and, upon request from competent cybersecurity authorities, establish branches or representative offices in Vietnam.
4. If customer data is lost due to improper data backup practices, how should the enterprise respond?
If customer data is lost as a result of inadequate backup practices, the enterprise should first identify the cause, scope, and extent of the incident. Then it should immediately implement appropriate technical measures to mitigate damage, rectify the issue, and prevent recurrence. Accordingly, the storage and processing of personal data must be conducted in a lawful and proportionate manner, limited to the purposes previously disclosed to data subjects, and accompanied by adequate protection and security measures designed to prevent unauthorized disclosure, loss, destruction, or access.
Pursuant to Article 4 of Decree No. 13/2023/ND-CP, organizations and individuals violating personal data protection regulations may be subject to administrative sanctions or criminal liability depending on the severity of the violation. Acts such as retaining personal data beyond the period necessary for the intended purpose, collecting, sharing, using, or disclosing personal data without authorization may also be subject to sanctions under Decree No. 15/2020/ND-CP. In serious cases, criminal liability may arise under Article 159 concerning the offense of infringing upon the secrecy or safety of correspondence, telephone communications, telegraphs, or other forms of private information exchange, or under Article 288 concerning the offense of illegally providing or using information on computer networks or telecommunications networks of the Criminal Code 2015 (as amended and supplemented in 2017).
5. If customer data is lost due to improper data backup practices, do customers have the right to claim compensation?
If customer data is lost or disclosed as a result of an enterprise’s failure to fulfill its obligations concerning data backup and data security, customers are entitled to seek compensation in accordance with applicable laws.
Pursuant to Clause 10 Article 9 of Decree No. 13/2023/ND-CP, data subjects have the right to claim compensation where their personal data protection rights have been infringed, unless otherwise agreed by the parties or otherwise prescribed by law.
Furthermore, under Article 584 of the Civil Code 2015, any person whose unlawful conduct infringes upon the lawful rights and interests of another person and causes damage must compensate for such damage. Accordingly, the enterprise may be liable for non-contractual damages arising from the loss or disclosure of customer data.
Compensable damages may include:
- Material damages;
- Costs incurred for remedying the incident and restoring data;
- Damage to reputation, honor, and privacy;
- Other lawful damages supported by evidence.
Where the parties are unable to reach an agreement regarding compensation, the customer has the right to initiate legal proceedings before a competent court.
V. Why should you seek legal consultation from np law regarding issues arising from improper data backup practices?
As legal regulations governing data protection, information security, and privacy rights continue to become more stringent, failing to properly back up data may expose enterprises to significant legal risks, ranging from administrative penalties and civil compensation obligations to criminal liability in certain circumstances. Accordingly, obtaining timely legal advice from experienced lawyers with in-depth expertise in this field is a crucial factor in helping enterprises effectively prevent and manage such risks.
The information provided above is for reference purposes only. Should you require detailed legal advice regarding your specific circumstances, please contact NPLaw for prompt assistance.