Login credential data plays a critical role in the digital operations of businesses. Collecting, storing, and protecting such data in violation of applicable regulations may lead to serious legal sanctions.
I. The impact of login credential data on businesses
Login credential data serves as the first layer of protection that enables businesses to control access to their systems and internal resources. If such data is exposed, businesses may face risks of unauthorized access, data theft, or operational disruption. A breach involving login credentials may also increase the risk of violating laws on data protection and cybersecurity.

At the same time, incidents related to login credentials can undermine the trust of customers and partners in a business. Therefore, the effective management and strict protection of login credential data have become essential requirements for business operations in the digital era.
II. Understanding login credential data
Login credential data refers to a set of information used to authenticate a user's identity when accessing a business’s system, application, or service, including usernames, passwords, authentication codes, and other related security factors.
1. What is login credential data and why is it important for accessing online services?
Login credential data refers to a collection of information used to verify a user’s identity when accessing an online system, platform, or service. Common contents include usernames, passwords, PIN codes, one-time passwords (OTP), and biometric data. These credentials function as the “key” that controls access to accounts, personal data, and internal corporate resources.
If login credentials are disclosed, stolen, or used unlawfully, malicious actors may gain control over accounts, steal sensitive information, conduct fraudulent transactions, or disrupt system operations. For such reasons, login credential data plays a particularly important role in ensuring information security, protecting data, and maintaining user trust in online services.
2. What types of login credential data are commonly used by users?
Login credential data typically includes usernames, passwords, PIN codes, OTP codes, security questions, authentication tokens, or biometric identifiers such as fingerprints and facial recognition data. Among these, the most common form is the combination of a username and password, while OTP codes, tokens, or biometric authentication are often used as additional factors in multi-factor authentication systems to enhance security when accessing online services and protect accounts from unauthorized intrusion.
3. Why is protecting login credential data necessary for users?
Protecting login credential data is essential to prevent unauthorized access to personal accounts and thereby safeguard private information, assets, and the lawful rights and interests of users. If login credentials are exposed, malicious actors may seize control of an account, conduct unauthorized transactions, steal data, or misuse personal information for unlawful purposes.
In addition, protecting login credentials helps users reduce the risk of legal liability arising from fraudulent activities conducted under their accounts.
4. What regulations must be complied with when storing login credential data to ensure security?
The storage of login credential data must comply with the principles of personal data protection stipulated in Article 3 of Decree No. 13/2023/ND-CP. These principles require that appropriate security measures be applied throughout the entire data processing lifecycle, that data be retained only for the period necessary to serve the processing purpose, and that businesses be able to demonstrate compliance with these principles.
Businesses are responsible for complying with the data processing principles set out in Clauses 1 to 7, Article 3 of Decree No. 13/2023/ND-CP and must be able to prove their compliance with these requirements.
At the same time, pursuant to Clause 2 Article 26 and Clause 1 Article 27 of Decree No. 53/2022/ND-CP, domestic businesses must store within Vietnam data relating to personal information and login credentials of service users in Vietnam for a minimum period of 24 months from the time a request is made by a competent authority. Such a requirement aims to ensure data security and facilitate state management and investigation activities when necessary.
III. Legal regulations relating to login credential data
1. How does Vietnamese law regulate the protection of login credential data?
Vietnamese law currently provides relatively comprehensive regulations on the protection of users’ login credential data, treating such data as a form of personal data that must be strictly managed and protected throughout the processes of collection, storage, and processing.
First, regarding the scope of data that must be stored in Vietnam, Clause 1 Article 26 of Decree No. 53/2022/ND-CP stipulates that businesses must store within the territory of Vietnam data relating to service users in Vietnam, including personal information; user-generated data such as account names, service usage time, IP login and logout addresses, email addresses, and telephone numbers; and data concerning user relationships such as friends and interaction groups.

Second, regarding entities responsible for data storage, Clause 2 Article 26 of Decree No. 53/2022/ND-CP specifies that domestic businesses must store all of the above categories of data within Vietnam. In addition, foreign enterprises providing cross-border services in Vietnam may also be required to fulfill similar obligations in accordance with applicable legal provisions.
Third, regarding the minimum data retention period, Clause 1 Article 27 of Decree No. 53/2022/ND-CP stipulates that the minimum retention period is 24 months from the time the enterprise receives a data storage request from a competent authority. Meanwhile, system logs serving cybersecurity investigation purposes must be retained for at least 12 months under the Law on Cybersecurity.
Fourth, regarding compliance obligations, Clause 8 Article 26 of Decree No. 53/2022/ND-CP emphasizes that businesses failing to comply with regulations on data storage and protection may be subject to sanctions depending on the nature and severity of the violation, including administrative fines or other legal measures.
Accordingly, login credential data is not merely a technical element in digital operations but is also a category of information subject to strict legal protection. Compliance with regulations on data storage, security, and retention periods constitutes a mandatory legal obligation for enterprises in order to ensure cybersecurity and safeguard the lawful rights and interests of users.
2. Can providing login credential data to third parties result in sanctions if legal regulations are violated?
Under Vietnamese law, providing login credential data to a third party without the lawful consent of the data subject may result in serious sanctions, depending on the nature and severity of the violation.
Administrative fines:
- Unauthorized provision or sharing of data: Pursuant to Points b and c Clause 2 Article 84 of Decree No. 15/2020/ND-CP (as amended by Decree No. 14/2022/ND-CP), a business may be fined from 40,000,000 VND to 60,000,000 VND for providing, sharing, or disseminating personal information to a third party without the consent of the data subject.
- Illegal trading or exchange of data: Under Point a Clause 7 Article 102 of Decree No. 15/2020/ND-CP, the fine may reach between 50,000,000 VND and 70,000,000 VND, together with additional sanctions such as suspension of licenses, confiscation of exhibits, and disgorgement of illegal profits.
Criminal liability: If the unlawful provision of login credential data causes significant damage, generates illicit profits, or seriously affects the reputation of an organization or individual, the violator may be prosecuted under Point b Clause 1 Article 288 of the Penal Code 2015 (amended in 2017) for the offense of illegally providing or using information on computer or telecommunications networks, which carries a fine of up to 200,000,000 VND or imprisonment of up to three years.
More importantly, if such conduct causes damage to the data subject (such as financial loss, disclosure of private information, or reputational harm, etc), the violating party must compensate for damages pursuant to Article 584 of the Civil Code 2015. Under this provision, any person who unlawfully infringes upon the lawful rights and interests of another and causes damage must provide compensation. Compensable damages include actual material losses, lost or reduced lawful benefits, and, in certain circumstances, moral damages as determined by competent authorities.
Providing login credential data to third parties in violation of legal regulations not only exposes enterprises to administrative sanctions but may also lead to criminal liability. Therefore, businesses must exercise particular caution and strictly comply with personal data protection regulations.
3. How are violations relating to login credential data handled under the law?
Violations of regulations on the protection of login credential data which constitutes personal data may be subject to various forms of legal sanctions depending on the nature, severity, and consequences of the violation.
Sanctions under Decree No. 13/2023/ND-CP: Pursuant to Article 4 of Decree No. 13/2023/ND-CP, agencies, organizations, and individuals violating regulations on personal data protection may be subject to disciplinary measures, administrative sanctions, or criminal liability depending on the seriousness of the violation.
Administrative sanctions and criminal liability under the Law on Personal Data Protection 2025:
Article 8 of the Law on Personal Data Protection 2025 stipulates that organizations and individuals committing violations may be subject to administrative sanctions or criminal prosecution and must compensate for damages if losses are caused to the data subject. With respect to administrative penalties, the applicable fines are determined according to specific violations, including:
- Unauthorized trading or sale of personal data may be fined up to ten (10) times the illegal profit obtained;
- Illegal cross-border transfer of personal data may result in fines of up to 5% of the violating organization’s total revenue of the preceding year;
- Other violations relating to personal data protection may incur fines of up to 3 billion VND for organizations (for individuals committing the same violation, the maximum fine is one-half of the amount imposed on organizations).
Accordingly, depending on the specific violation involving login credential data, organizations and individuals may face sanctions ranging from administrative sanctions to criminal liability, with very strict fines under the applicable legal framework.
IV. Questions regarding login credential data
1. Can a company share customer login credential data with a third party?
Pursuant to Article 17 of the Law on Cyber Information Security 2015, businesses are not permitted to arbitrarily share customers’ login credential data with third parties. Specifically, Point a Clause 1 stipulates that the collection of personal information may only be performed after obtaining the consent of the data subject regarding the scope and purpose of the collection; Point b Clause 1 requires that such information be used strictly for the purpose previously notified, and any use for another purpose requires additional consent; and Point c Clause 1 clearly states that personal information must not be provided, shared, or disseminated to a third party except in two circumstances:
- With the consent of the data subject; or
- At the request of a competent state authority.
Accordingly, any act of sharing login credential data contrary to these conditions constitutes a violation of the law and may be subject to legal sanctions.
2. What measures must companies implement to protect login credential data?
Pursuant to Article 26 of Decree No. 13/2023/ND-CP, when processing login credential data (which constitutes personal data), businesses must simultaneously implement several groups of protective measures, including:
- Internal management measures: Businesses must establish procedures and internal regulations governing the management of login credential data, clearly define access permissions, and strictly control individuals authorized to access such data (Point a Clause 2 Article 26).
- Technical measures: Businesses must implement technical solutions such as data encryption, multi-factor authentication, system access control, and access logging in order to prevent data leakage and unauthorized access to login credential data (Point b Clause 2 Article 26).
- Coordination with competent authorities: Businesses must comply with requests and data protection measures issued by competent state authorities during supervision or inspection when necessary (Point c Clause 2 Article 26).
- Investigation and procedural measures: In the cases of violations, businesses must cooperate with competent state authorities in investigation and enforcement activities in accordance with applicable law (Point d Clause 2 Article 26).
- Other measures prescribed by law: Businesses must implement additional measures as required under specialized regulations and other relevant legal provisions to ensure the protection of login credential data (Point đ Clause 2 Article 26).
Therefore, enterprises must not only adopt internal regulations but also implement coordinated technical and management measures in order to protect both basic personal data and sensitive personal data such as login credentials throughout the entire data processing lifecycle in compliance with legal requirements.
3. If a business detects unauthorized access to login credential data, can it report the incident to competent authorities?
Pursuant to Article 23 of Decree No. 13/2023/ND-CP, when a business discovers that login credential data has been compromised or that a violation of personal data protection regulations has occurred, the business has both the right and the obligation to report the incident to competent authorities.

Specifically, the personal data controller or the entity responsible for controlling and processing personal data must notify the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) within 72 hours from the time the violation is detected, using the prescribed reporting form. If the notification is made after such a time limit, the business must provide an explanation for the delay.
Proactively reporting such incidents is not only a legal obligation but also enables businesses to cooperate with competent authorities in preventing risks, mitigating consequences, and minimizing potential legal liability.
If your business is facing difficulties related to login credential data, confidentiality obligations, data breach incidents, or potential legal sanctions, NPLaw is willing to assist with a team of experienced lawyers specializing in personal data protection and cybersecurity. Our legal professionals provide accurate advice in accordance with applicable regulations, helping businesses minimize legal risks and effectively protect their reputation.
The information above is provided for reference purposes only. For detailed legal advice regarding specific cases, please contact NPLaw Law Firm for immediate assistance.