When a data confidentiality breach occurs, enterprises not only face the risk of information loss but must also handle contractual relationships with caution to avoid legal consequences. Contract termination must be grounded on lawful bases, supported by clear evidence, and conducted in accordance with proper legal procedures. The following article provides detailed legal guidance on contract termination due to data confidentiality breaches to help you assess breach conduct, implement valid termination procedures, and maximize the protection of your legitimate rights and interests.

I. Current practice of contract termination due to data confidentiality breaches

In the context of increasing digital transformation among enterprises, data confidentiality breaches have become a common cause leading to contract termination. Numerous cases involve employees or partners disclosing or unlawfully using sensitive information such as customer lists, business strategies, or financial data, thereby causing substantial damage.

Enterprises are becoming more cautious in drafting confidentiality clauses, implementing strict data control mechanisms, and are prepared to terminate contracts upon detecting breaches in order to protect their interests, reputation, and mitigate legal risks.

II. Understanding contract termination due to data confidentiality breaches

1. What types of data confidentiality breaches may lead to contract termination?

In practice, data confidentiality breaches may serve as grounds for contract termination where the breaching party’s conduct defeats the purpose of the contract, causes damage, or falls within cases where unilateral termination is permitted by law. Pursuant to Article 422 of the Civil Code 2015 regarding circumstances under which contracts are terminated, the following types of breaches may lead to termination:

  • Unauthorized disclosure of confidential information protected under the contract: The act of providing or sharing confidential data with third parties without authorization may lead to unilateral termination under Clause 4, Article 422.
  • Use of confidential data for improper purposes in violation of confidentiality commitments: Exploiting data for personal benefit or for competitors constitutes a breach of fundamental obligations, rendering the contractual purpose unattainable (related to Clauses 4 and 6, Article 422).
  • Loss, leakage, or exposure of data due to the fault of the breaching party: Conduct resulting in the compromise of confidential information and causing serious damage may justify contract cancellation or unilateral termination under Clause 4, Article 422.
  • Failure to implement contractual data protection measures: It constitutes a breach of obligations ensuring proper performance conditions; if consequences arise, the non-breaching party may terminate under Clause 4, Article 422.
  • Violation of laws on protection of trade secrets or personal data, rendering the contract unenforceable: Such violations may fall under “other cases prescribed by law” under Clause 7, Article 422.

A data confidentiality breach will only result in contract termination where the severity is sufficient to directly affect the contractual purpose or falls within legally permitted termination cases. To avoid disputes, parties should clearly define the scope of data, levels of breach, and handling mechanisms within the contract from the outset.

2. What types of information are commonly considered grounds for termination due to confidentiality breaches?

Information becomes grounds for contract termination where the breach defeats the contractual purpose or falls within cases where the contract may be cancelled or unilaterally terminated under Article 422 of the Civil Code 2015. Common categories include:

  • Trade secrets, strategic information, or proprietary data: Unauthorized disclosure or misuse infringes economic interests and constitutes a fundamental breach, leading to termination rights.
  • Personal data, identity information, and user data protected by law: Data leakage may result in compensation liability and make the contract incapable of achieving its purpose, consistent with Clauses 4 and 5, Article 422.
  • Technical information, systems, access credentials, passwords, and internal processes: Exposure leading to operational risks or system insecurity may justify unilateral termination due to failure to meet agreed security conditions.
  • Customer, partner, financial, or transaction-related information: Leakage is often considered a serious breach as it directly affects the enterprise’s reputation and interests, qualifying as a fundamental breach.
  • Information expressly defined in the contract as “strictly confidential”: Any breach involving such a category may trigger immediate termination under the agreed contractual mechanism (Clause 2, Article 422).

Information disclosure only constitutes grounds for termination when it renders the contract ineffective, impossible to continue, or falls within termination cases under Article 422. Therefore, clearly defining the scope of confidential information in the contract is essential for dispute resolution.

3. Who has the authority to decide on contract termination due to confidentiality breaches?

Under the Civil Code 2015, the right to terminate a contract arises from the right of unilateral termination in case of breach. Specifically:

  • The non-breaching party has the right to terminate the contract if the confidentiality breach makes the contractual purpose unattainable or constitutes a fundamental breach (Articles 422 and 428).
  • Termination rights may also belong to the party designated in the contract where confidentiality breaches are expressly stipulated as grounds for termination (Clause 2, Article 422).
  • In certain specific cases, termination may be mandated under specialized laws (Clause 7, Article 422).

In principle, the right to terminate primarily belongs to the non-breaching party, unless otherwise provided by contract or specialized legislation.

III. Legal regulations governing contract termination due to data confidentiality breaches

1. How does Vietnamese law regulate termination due to confidentiality breaches?

Vietnamese law does not provide a standalone provision specifically governing termination due to confidentiality breaches. However, such conduct is treated as a breach of contractual obligations, thereby invoking general provisions of the Civil Code 2015:

  • Article 351: A breaching party takes liability for failure to perform obligations as agreed, including confidentiality obligations.
  • Article 423: The non-breaching party may cancel the contract where the breach is fundamental, rendering the contractual purpose unattainable.
  • Article 428: The non-breaching party has the right to unilaterally terminate contract performance in the case of serious breach.
  • Article 422: Contracts terminate when one party exercises unilateral termination rights under legal regulations or agreements. 

Additionally, the Law on Cybersecurity 2018, the Law on Network Information Security 2015, and guiding regulations define data protection obligations, providing a basis for assessing breach conduct.

2. Can a party claim damages upon terminating a contract due to confidentiality breaches?

Pursuant to Article 360 of the Civil Code 2015, where a breach of confidentiality obligations causes damage, the breaching party must compensate for all losses, unless otherwise agreed or provided by law. Contract termination does not extinguish the right to claim damages, as liability arises from the breach itself, regardless of whether the contract remains in force.

3. Can a party initiate legal action for breach of confidentiality obligations after contract termination?

Termination of a contract does not extinguish confidentiality obligations where the contract or law provides that such obligations survive termination.

  • Under Article 360 of the Civil Code 2015, contractual obligations, including confidentiality obligations, remain enforceable, and damages may be claimed if breached.
  • The breaching party may be subject to legal action for protection of rights and compensation, even after contract termination, based on actual damages incurred.

Termination does not eliminate the right to initiate claims or seek compensation for breaches of confidentiality provisions.

IV. Questions regarding contract termination due to data confidentiality breaches

1. Can parties renegotiate after termination due to confidentiality breaches?

The law does not prohibit renegotiation after contract termination. Such negotiations depend entirely on the parties’ goodwill, as the original contract has ceased to be legally binding under Article 422.

Renegotiation is generally feasible where:

  • The parties still intend to cooperate;
  • The breaching party demonstrates good faith in remedying the breach;
  • There is no contractual prohibition against re-signing or renegotiation.

2. Procedure for terminating contracts due to confidentiality breaches

To ensure lawful termination and minimize disputes, enterprises should follow these steps:

  • Step 1 – Identifying the breach: Comparing the conduct with contractual confidentiality clauses and legal provisions to determine whether a breach has occurred.
  • Step 2 – Collecting and preserving evidence: Document emails, system logs, internal reports, and other materials to objectively substantiate the breach.
  • Step 3 – Issuing breach notice and requesting explanation: Sending a formal notice specifying the breach, its scope, consequences, and a deadline for explanation or remediation.
  • Step 4 – Assessing explanation and damages: Evaluating remedial capacity, severity, and actual damage to decide whether to continue or terminate the contract.
  • Step 5 – Issuing termination decision: In cases of serious breach or failure to remedy, issue a formal termination decision based on Article 422 and contractual provisions.
  • Step 6 – Performing post-termination procedures: Recovering devices, data, and access accounts; requiring destruction or handover of confidential materials; document handover processes.
  • Step 7 – Claiming damages or pursuing legal remedies: If damage occurs, claim compensation under Article 360 or initiate legal proceedings where necessary.

A standardized process supported by adequate evidence and documents helps enterprises protect their rights and mitigate legal risks.

3. Is the breaching party given an opportunity to remedy before termination?

In most cases, the breaching party is afforded an opportunity to remedy prior to termination, unless the contract stipulates immediate termination for serious breaches. Typically, the non-breaching party issues a written notice specifying the breach, requiring cessation, and providing a reasonable remedy period.

If the breach is remedied within the prescribed timeframe and damages are mitigated, the contract may continue. Otherwise, failure to remedy or repeated breaches, the non-breaching party is entitled to unilaterally terminate in accordance with law and contract.

4. What is the timeframe for remedying confidentiality breaches before termination?

The law does not prescribe a fixed timeframe but applies the principle of a “reasonable period” under Article 278 of the Civil Code 2015. In practice:

  • For minor breaches (technical errors, limited disclosure), remedy periods typically range from 03 to 07 days.
  • For serious breaches (sensitive data leakage, significant damage, customer impact), periods may range from 07 to 15 days to contain consequences and implement preventive measures.
  • Where the contract specifies a remedy period, such agreement prevails according to Article 278.

Accordingly, the remedy period is determined by contractual agreement or the non-breaching party, provided it is reasonable and clearly communicated prior to termination.

5. What should parties do to protect their interests upon termination due to confidentiality breaches?

Upon termination, parties should proactively implement measures to minimize damage and protect their legal rights:

  • Immediately controlling and preventing further damage: Revoking access, locking accounts, and blocking connections to prevent continued data leakage.
  • Collecting and preserving evidence: Recording system logs, communications, incident reports, and timelines for negotiation or dispute resolution.
  • Clarifying post-termination data obligations: Requiring return, transfer, or destruction of data in accordance with contractual and legal requirements.
  • Negotiating liability and compensation: Determining actual damages and asserting compensation claims under Article 360 where applicable.
  • Reporting to competent authorities in serious cases: Particularly where personal data breaches or legal reporting obligations arise.
  • Reviewing and strengthening confidentiality measures: Update technical safeguards, internal processes, and contractual terms to prevent recurrence.

In summary, proactive risk control, evidence preservation, and lawful data handling are fundamental to safeguarding rights when contracts are terminated due to confidentiality breaches.

V. Are you looking for a reputable legal expert to assist with contract termination due to data confidentiality breaches?

If your enterprise requires in-depth legal advisory services regarding contract termination due to confidentiality breaches, NPLaw is a trusted provider with a team of experienced lawyers. We assist in evaluating situations, applying appropriate legal provisions, protecting your rights, minimizing dispute risks, and ensuring lawful and effective contract termination.