Implementing procedures for handling data breaches in enterprises not only helps minimize damage and protect the rights and interests of customers and partners, but is also a mandatory legal obligation under the current legal framework.
I. Current situation regarding procedures for handling data breaches in enterprises
In recent years, with the strong development of the digital economy, the number of data breaches in enterprises has significantly increased in both frequency and severity. However, most Vietnamese enterprises have not yet established comprehensive procedures for handling data breaches, resulting in a negative response when incidents occur.
- First, many enterprises lack effective mechanisms for monitoring and timely detecting data breaches. A number of enterprises, particularly small and medium-sized enterprises, have not made sufficient investments in security systems, access logs, or automated alert mechanisms. When unauthorized access occurs, enterprises often detect it too late, making it difficult to isolate and mitigate damage.
- Second, incident response capacity for data breaches are insufficiently standardized. Many enterprises only have general internal regulations without developing specific procedures consisting of steps such as verification, impact assessment, incident containment, remediation, reporting, and notification to data subjects. It leads to confusion, especially when enterprises are required to fulfill their reporting obligations to competent state authorities in accordance with the law.
- Third, employees’ awareness of data security remains limited. Surveys by various security organizations indicate that user’s errors (misconfiguration, accidental sharing, opening malicious links, etc.) account for a large proportion of data breaches. Nevertheless, training activities and internal controls in many enterprises are still not adequately emphasized, leaving latent risks of data breaches.
- Fourth, investment in data protection technologies is not appropriate with the risks. Most enterprises remain at a basic level of security and have not yet implemented advanced measures such as encryption, granular access control, Data Loss Prevention (DLP), or tools for detecting abnormal access.

As a result, when a data breach occurs, enterprises may not only suffer reputational and financial losses but also face administrative sanctions for failing to comply with legally prescribed procedures.
II. Concept of procedures for handling data breaches in enterprises
In the context where data protection laws are becoming increasingly stringent and regulatory compliance requirements are rising, a proper understanding of procedures for handling data breaches is essential for enterprises to establish effective response mechanisms. Such a concept is not merely technical in nature but also reflects enterprises’ risk management capacity and legal responsibility.
1. What are procedures for handling data breaches in enterprises?
Procedures for handling data breaches in enterprises are a set of pre-established steps, measures, and coordination mechanisms designed to detect, assess, prevent, remediate, and report incidents involving leakage, loss, or unauthorized access to personal data.
These procedures typically include basic stages such as detection, verification, containment, handling, notification, and recording.
2. Common types of data breaches in enterprises
Enterprises may take various types of data breaches, most commonly including:
- Data leakage to external parties: Resulting from cyberattacks, compromised passwords, or intentional unauthorized copying by employees.
- Unauthorized data access: Including access beyond authorized privileges or access by unauthorized third parties.
- Data loss or destruction: Due to system failures, malware, or operational errors during processing.
- Misuse of data for improper purposes: Collecting data for agreed purposes but using it for another without the data subject’s consent.
- Disclosure of data to unauthorized third parties: Through accidental sharing or contracts lacking appropriate confidentiality clauses.
These types of breaches may occur at any time if enterprises lack appropriate security and monitoring measures.
3. Elements of an effective handling procedure for data breaches
A data breach handling procedure is considered effective when it meets the following criteria:
- Clear and well-structured: Handling steps must be specifically described to avoid confusion when incidents occur.
- Transparent allocation of responsibilities: Clearly identifying who detects, reports, or handles technical issues, and who is responsible for notifications.
- Rapid response capability: Verification, containment, and remediation must be implemented promptly to minimize damage.
- Legal compliance: The procedure must comply with the requirements of Article 23 of the Law on Personal Data Protection 2025, including notification and reporting obligations within 72 hours.
- Continuity and regular updates: Enterprises must periodically review and improve procedures to address emerging risks and technological changes.
- Accompanying staff training: Employees’ understanding of the procedures is essential for their practical and effective implementation.
A procedure is truly effective only when it is both legally comprehensive and practically feasible in enterprise operations.
III. Legal regulations related to procedures for handling data breaches in enterprises
In the context of increasingly stringent protection of personal data under Vietnamese law, enterprises are required not only to implement security measures but also to ensure compliance with legally prescribed procedures for handling data breaches.
1. Acts considered data breaches under the law
Acts considered data breaches in enterprises mainly include:
- Engaging in prohibited acts related to personal data protection under Article 7 of the Law on Personal Data Protection 2025, such as using another person’s personal data or allowing others to use one’s personal data for unlawful purposes, trading in personal data unless otherwise provided by law, misappropriating, intentionally disclosing, or losing personal data, and other prohibited acts.
- Processing personal data without the data subject’s consent in cases requiring consent under Article 9 of the Law on Personal Data Protection 2025.
- Violating obligations to notify data breaches under Article 23 of the Law on Personal Data Protection 2025.
- Failure by personal data controllers, personal data processors, or entities acting as both controllers and processors to properly fulfill their responsibilities under Article 36 of the Law on Personal Data Protection 2025.

Accordingly, acts infringing upon the confidentiality, integrity, and consent of personal data subjects may all be deemed violations of the law.
2. Responsibilities of enterprises when a data breach occurs
Pursuant to Article 23 of the Law on Personal Data Protection 2025, when a data breach occurs, enterprises take the following notification responsibilities:
- Personal data controllers, controllers and processors, and third parties that detect violations of personal data protection regulations which may harm national defense, national security, social order and safety, or infringe upon the life, health, honor, dignity, or property of personal data subjects must notify the specialized authority for personal data protection within no later than 72 hours from the time the violation is detected. Where a personal data processor detects a violation, it must promptly notify the personal data controller or the controller and processor.
- Personal data controllers and controllers and processors must prepare written records confirming the occurrence of personal data protection violations and cooperate with the specialized authority for personal data protection in handling such violations.
- Agencies, organizations, and individuals must notify the specialized authority for personal data protection in cases such as discovering violations of personal data protection regulations; processing personal data for improper purposes or contrary to agreements with data subjects; failing to ensure or properly implement data subjects’ rights; and other cases as prescribed by law.
- The specialized authority for personal data protection is responsible for receiving notifications and handling violations. Personal data controllers, controllers and processors, third parties, and relevant agencies, organizations, and individuals are responsible for preventing violations, remedying consequences, and cooperating with the specialized authority in handling violations.
Thus, Vietnamese law imposes stringent responsibilities on enterprises when data breaches occur, requiring timely notification, documentation of incidents, and proactive cooperation with competent authorities to comprehensively prevent and remedy consequences.
3. Sanctions applicable to enterprises failing to comply with data breach handling procedures
Enterprises that fail to comply with data breach handling procedures may be subject to various sanctions depending on the nature and severity of the violation:
- Administrative sanctions: Under Article 8 of the 2025 Law on Personal Data Protection:
+ The maximum administrative fine for trading in personal data is up to ten times the illegal revenue obtained from the violation; where there is no such revenue or the calculated fine is lower than the maximum prescribed under Clause 5 of the same Article, the fine prescribed therein shall apply.
+ The maximum administrative fine for violations related to cross-border transfer of personal data is up to 5% of the enterprise’s turnover in the preceding year; where there is no turnover or the calculated fine is lower than the maximum prescribed, the fine prescribed by law shall apply.
+ The maximum administrative fine for other violations in personal data protection is 3 billion VND. - Criminal liability: If data breaches result in serious consequences, criminal liability may arise under the Penal Code 2015, as amended in 2017, such as:
+ Infringement of the confidentiality or safety of correspondence, telephone, telegraph, or other forms of private communications (Article 159);
+ Illegal provision or use of information on computer or telecommunications networks (Article 288);
+ Illegal access into computer networks, telecommunications networks, or electronic means of others (Article 289). - Civil liability: Where violations cause serious consequences such as damage to property or reputation, enterprises may be required to compensate for damages in accordance with Articles 584 and 585 of the Civil Code 2015.
4. Basic steps in the handling procedure for data breaches of an enterprise
Pursuant to Article 23 of the Law on Personal Data Protection 2025 and data security practices, the handling procedure generally includes the following steps:
- Detection and recording of the incident.
- Verification and assessment of the impact on data and data subjects.
- Containment, isolation, and technical handling to prevent further spread.
- Remediation of consequences and data recovery.
- Notification to data subjects within the prescribed 72-hour timeframe.
- Reporting to competent state authorities.
- Recording and review and improvement of procedures to prevent recurrence.

The handling procedure for data breaches must comply with both technical and legal requirements, while ensuring transparency and timeliness.
IV. Questions regarding procedures for handling data breaches in enterprises
During the implementation of data breach handling procedures, many organizations and customers encounter questions related to rights, obligations, and response methods when incidents occur. Below are common issues and corresponding explanations under current legal regulations.
1. Can customers participate in or monitor enterprise data breach handling procedures?
Under Clause 1 Article 4 of the Law on Personal Data Protection 2025, personal data subjects have rights including the right to be informed of personal data processing activities; to consent or refuse consent and request withdrawal of consent; to access, rectify, or request rectification of personal data; to request provision, deletion, or restriction of processing; and to object to data processing.
Accordingly, customers (data subjects) do not directly participate in the technical and legal internal procedures for handling data breaches, but they may indirectly monitor such processes through the rights conferred by law.
2. What legal consequences may arise from failure to properly implement data breach handling procedures?
If enterprises fail to comply with data breach handling requirements, depending on the nature, severity, and consequences of the violation, they may be subject to administrative sanctions or criminal liability, and may be required to compensate for damages in accordance with Article 8 of the Law on Personal Data Protection 2025.
3. Can data breach handling procedures be applied to all types of customer data?
In principle, data breach handling procedures apply to all types of personal data, including basic data, sensitive data, financial data, and identification data. However, for sensitive personal data as defined in Clause 3 Article 2 of the Law on Personal Data Protection 2025, enterprises must apply stricter procedures, conduct higher-level risk assessments, and implement enhanced protective measures.
4. How can enterprises ensure transparency and effectiveness in data breach handling procedures?
Enterprises may ensure transparency and effectiveness by:
- Establishing written, transparent, and easily understandable procedures.
- Clearly allocating responsibilities among departments when incidents occur.
- Providing regular training to ensure personnel understand and properly implement procedures.
- Applying supporting technologies such as cybersecurity monitoring systems, DLP solutions, and access logs.
- Properly fulfilling reporting and notification obligations and safeguarding data subjects’ rights.
- Periodically reviewing and updating procedures to address emerging risks.
The combination of people, technology, and legal compliance is key to achieving transparency and effectiveness.
5. How soon must enterprises notify customers when a data breach occurs?
Under Article 23 of the Law on Personal Data Protection 2025, when a violation that may affect the rights and interests of data subjects is detected, enterprises must notify the specialized authority for personal data protection no later than 72 hours from detection. Where a personal data processor detects a violation, it must promptly notify the personal data controller or the controller and processor.
Although the law does not expressly stipulate a deadline for notifying customers, it may be understood that:
- Enterprises should notify customers as soon as possible after assessing the impact of the incident;
- Early notification is necessary to enable customers to protect themselves (e.g., changing passwords, locking accounts, being alert to fraud);
- In practice, data governance standards and international benchmarks such as the GDPR regard 72 hours as a standard reference for notification to both authorities and affected individuals.
V. Why seek legal advice from NPLaw regarding data breach handling procedures?
Handling data breaches involves complex legal regulations and requires a high level of expertise. NPLaw’s lawyers are an appropriate choice because they:
- Possess in-depth knowledge of personal data protection regulations.
- Have experience advising enterprises on building internal procedures, assessing risks, and handling real-world data breach incidents.
- Assist enterprises in drafting standardized procedures tailored to specific sectors (finance, e-commerce, education, healthcare, etc.).
- Provide direct consultation when incidents occur, helping enterprises avoid errors in reporting, notification, and remediation.
- Protect legal rights and interests while minimizing risks of penalties, complaints, and reputational damage.
The above information is provided for reference purposes only. For detailed advice on specific cases, please contact NPLaw for prompt consultation.