Building a law on personal data protection in Vietnam, lessons from the hacker attack on VNDirect

Insights
Building a law on personal data protection in Vietnam, lessons from the hacker attack on VNDirect
Posted on: 27/05/2025

    Personal data is becoming the target of increasingly sophisticated cyberattacks. The hacker attack on VNDirect Securities Joint Stock Company in March 2024 is a warning bell about vulnerabilities in personal data protection in Vietnam. This incident not only disrupts business activities but also exposes the limitations of the current legal framework, and sets an urgent requirement to build a more comprehensive and effective legal system for personal data protection. This article will analyze the VNDirect case, thereby proposing solutions to build and improve personal data protection laws in Vietnam.

     

    Chairman of the National Assembly's Committee on National Defence, Security and External Relations, Mr. Le Tan Toi, delivered the appraisal report on the Draft Law on Personal Data Protection.

    Source: National Assembly.

     

    Case development

    On March 24, 2024, VNDirect announced that the company's online trading system was hacked, making it impossible for investors to access accounts or make transactions. According to cybersecurity experts, the attack showed signs of using ransomware, which encrypts all data on the company's virtualization system. The hacker is believed to belong to a professional international organization, exploiting a zero-day vulnerability to break in[1].

    In the next three days, VNDirect's system has not been fully restored, causing serious disruption in the stock market. The State Securities Commission has asked the company to make a detailed report before April 1, 2024, and at the same time coordinate with the Ministry of Public Security (Department of Cyber Security and High-tech Crime Prevention - A05) to investigate. Although VNDirect insists that customers' personal information is securely stored in the cloud system and has not recorded property damage, the incident has raised concerns about the risk of personal data leakage, including name, ID number, and financial information. bank accounts, securities account information, account balances, securities codes owned by customers and many other information.

    VNDirect's case has raised many different issues such as ensuring the interests of customers when the securities company's system is paralyzed, compensating for damages suffered by customers when they cannot trade securities, transfering money out of their securities accounts for a long time. But the most prominent is the legal issue of protecting customers' private personal data, including sensitive data such as bank accounts, account balances, and customer asset balances at securities companies. Specifically, legal issues that can be noticed in this case such as:

    Risk of privacy violations. If personal data is leaked, customers may face forms of fraud or misuse of data from not only domestic fraudulent organizations but also international fraudulent organizations. The issue has been very hot recently.

    Legal liability of the enterprise. According to the Government's Decree 13/2023/ND-CP dated April 17, 2023 on personal data protection (Decree 13), VNDirect must be responsible for ensuring the security of personal data and promptly notifying the authorities when an incident occurs. The incident has shown that the data is very likely to be exposed and leaked out in this case, where and how is the responsibility of the business to customers, who are directly affected.

    Deficiencies in the legal framework. The incident shows that current regulations are not enough deterrent as well as there are no specific options to support businesses to respond to complex cyber attacks. At the same time, it is necessary to legally protect the rights and especially property rights of people and customers in similar cases that may occur in the near future.

    We believe that the case of VNDirect and similar cases in recent years has probably motivated regulators and experts to discuss and be more serious in developing a separate Law on Personal Data Protection, instead of just relying on Decree 13 or regulations scattered in many different documents to handle contemporary and complex issues such as protecting the data of individuals.

    The current legal framework for data protection in our country

    In Vietnam, the protection of personal data is governed by a number of documents, the most prominent of which is the Government's Decree No. 13, which took effect on July 1, 2023.

    In addition, the provisions in the Law on Cybersecurity (2018) and the Civil Code (2015) also mention the right to privacy and responsibility to protect information. However, these regulations are general, lacking specific guidelines on handling violations or responding to the recent pressing and pressing issues of people and businesses is the protection of personal data, a right of privacy stipulated in Vietnam.

    The VNDirect case has clearly revealed some limitations in the current legal framework on this issue, which, if applied to VNDirect's specific case, may reveal many serious "holes".

    Firstly, administrative sanctions cannot be applied

    Currently, almost Vietnamese law does not have a specific and corresponding sanction for violations under Decree 13. The proposed draft administrative sanctions in the field of personal data protection have not yet been approved, which has created a gap in the handling of personal data protection violations in practice. Many violations in this field cannot be handled or are handled, they are "steered" by the management agency through other regulations to handle.

    Second, lack of coordination mechanism

    The current law in Vietnam does not have a clear process for businesses to coordinate with the authorities in responding to incidents, leading to delays in handling. According to the provisions of Decree 13, in case of detecting a violation of regulations on personal data protection, the Personal Data Controller and the Personal Data Controller and the Personal Data Controller shall notify the Ministry of Public Security, specifically the Department of Cyber Security and High-tech Crime Prevention and Control, within 72 hours after the violation occurs. However, this regulation only applies to cases where enterprises and organizations violate but have not yet applied specific cases not due to direct violations of enterprises or organizations but due to acts of attacking the system from the outside, leading to the disclosure and leakage of personal data. In addition, the regulation of reporting within 72 hours after the violation occurs when applied to some practical cases, specifically the case of VNDirect when the report takes place within 72, 48, or even 24 hours can be a delayed reporting act and cause a lot of damage not only to businesses but especially to harm to data subjects who are individuals.

    Thirdly, there is no specific law

    The decree is only a document under the law, lacking binding and comprehensive compared to an independent law. Therefore, in the context of the development of technology, the fact that many organizations and individuals in Vietnam do not have a correct understanding of the importance of personal data protection in Vietnam, it is very necessary to develop and promulgate a law on personal data protection at this time. Especially in the current context, the collection, trading, and misuse of data in Vietnam are widespread, causing significant harm to individuals, businesses, and competent authorities alike. Moreover, similar regulations on personal data have been enacted and enforced by countries around the world and in the region for a long time such as Europe, the United States, Singapore, India, Brazil,.. it is appropriate and necessary for Vietnam to consider and promulgate an official law on personal data protection this year.

    Fourth, limitations in enforcement

    Many businesses, especially small businesses, are not fully aware of their legal responsibilities, leading to the implementation of asynchronous security measures.

    These limitations point to the need to develop a  Personal Data Protection Law with stricter regulations, inspired by international models such as the GDPR (European Union).

     

    VNDirect Securities Corporation announced the resumption of its operations starting from April 1.Source: Ho Chi Minh City Law Electronic Newspaper

     

    What experience for Vietnam from VNDirect's case

    Strengthening sanctions and accountability

    The VNDirect case shows that large businesses, even though they have invested hundreds of billions of VND in cybersecurity, can still become victims of hackers. This requires the law to provide sanctions that are sufficient deterrent, commensurate with the scale of the damage. This has also been applied by many countries.  The EU's GDPR is a good example, according to the GPDR which applies fines of up to 4% of the global revenue of violating businesses, creating a strong incentive to comply[2]. The latest draft of the Law on Personal Data Protection also stipulates a fine of 1-5% of the previous year's revenue of the violating enterprise, depending on the severity. However, in order to be able to strictly handle in some cases where the turnover level of enterprises is not high, the National Assembly and the agency submitting the draft should add a fixed rate mechanism to handle in some cases where the turnover level is insignificant. in the GDPR stipulates a fixed fine of up to 20,000,000 euros and we think that a similar regulation should be established in Vietnam's Personal Data Protection Law in the near future, the level that lawmakers can consider is from 2 to 5 billion VND.

    In addition, the competent authority needs to issue specific regulations that require businesses to be fully accountable for security measures and incident handling procedures within a reasonable time depending on the severity of the incident or the line of operation. The timeline that can be considered for inclusion in the law is 24 hours, 48 hours, and 72 hours from the time of the incident or the detection of the violation. This way of regulation will help management agencies as well as businesses flexibly meet the requirements in each specific case accordingly. At the same time, the application of administrative measures, the application of civil liability, forcing businesses to compensate customers for damage if personal data is misused is also a sanction to consider to force businesses to implement in some cases of incidents that cause serious consequences to customers.

    Establish an incident response mechanism

    The delay in restoring VNDirect's system partly stems from the lack of coordination between businesses and authorities. A new law should clearly stipulate: (1) Incident notification period: Businesses must report to the authorities (e.g., the A05 Cyber Security Department) within 24, 48 or 72 hours, depending on the case. (2) Establishment of an incident response center: The competent authority should build a specialized unit at the Ministry of Public Security or the Ministry of Information and Communications to support enterprises in handling cyber attack cases, complex and serious information leakage incidents that greatly affect enterprises,  national security, or to the data of multiple individuals. (3)  Detailed guidance on response mechanisms for enterprises:  the competent authority needs to promulgate technical regulations on data backup, encryption, and periodic security checks as well as detailed and easy-to-implement regulations for enterprises in case of serious incidents that cannot be solved by themselves or incidents that greatly affect people's data.

    Protect the rights of data subjects

    The VNDirect incident raises great concerns of many investors that their personal information may be exposed, leaked or infringed by domestic and foreign individuals and organizations. Vietnam's personal data protection laws in the coming time need to strengthen the rights of data subjects, such as (i) Right to be informed: Customers must be promptly notified of any incidents related to their data. (ii) Right to request deletion of data: Individuals can request that the business delete data when it is no longer necessary. (iii) Right to complain and sue: Establish a mechanism for individuals to complain or sue a business for infringement without going to court, such as through an independent data protection authority.

    The VNDirect hacker attack is a wake-up call to the urgency of building a comprehensive legal framework for personal data protection in Vietnam. From this incident, it is clear that there are gaps in current regulations, from low sanctions to lack of coordination in incident response. A Personal Data Protection Law with strict regulations, effective enforcement mechanisms, and independent regulators will be the foundation for protecting people's privacy, enhancing trust in the market, and enhancing Vietnam's position in the global digital environment. To achieve this, it is necessary to join hands with state agencies, businesses, and the whole community in building a safe and transparent ecosystem for personal data.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm