Data, Privacy & Cybersecurity

Data, Privacy & Cybersecurity

Aviation enterprises face complex requirements on customer personal data protection

There is a quite special feature of the aviation industry that many businesses in other fields do not encounter. Each flight transports not only passengers, but also "transports" a huge amount of personal data across borders. From the moment a passenger searches for a flight on the website, makes a booking, makes a payment, checks in online, uses facial recognition to board the plane, connects to in-flight Wi-Fi, earns reward points, requests special meals or provides medical assistance, almost the entire journey is recorded as data.

The boundary between human resource management and personal data protection: Seen from the NovaGroup case

The announcement on its website by Nova Group Joint Stock Company (NovaGroup) on the list of individuals who are "not re-employed" has quickly become a topic of public interest . Notably, the published list is not the entire identifying information of individuals. Part of the citizen ID number and phone number have been concealed. This gives rise to a fairly common argument that the data has been "anonymized" or "de-identified", and therefore no longer falls under the scope of personal data protection legislation.

Data anonymization: When technical problems become the management capacity of businesses

Artificial intelligence is turning data into a business's most important asset. The more data you can exploit, the more advantages businesses have in developing products, optimizing operations, and creating new business models. However, this process also puts businesses under increasing compliance pressure as regulations on personal data protection are continuously improved in Vietnam and around the world.

The risk of data leakage from accommodation services: lessons from the world and new governance requirements for Vietnamese businesses

In 2018, the world's hospitality industry witnessed one of the largest data breaches in history when Marriott International announced that Starwood Hotels' booking system had been illegally accessed for a long time before it was discovered . According to published information, the data of hundreds of millions of customers globally has been affected. Not only does it include names, email addresses or phone numbers, but many of the compromised information also involves passports, stay histories, and other data that can reproduce almost the entire customer's travel journey over many years.

What data is the hotel business collecting and retaining from customers?

When booking a hotel room, most customers only think that they are providing a few basic information to complete the transaction. However, from the time of searching for a room on the online platform, making a reservation, check-in, using the service to check-out, a large amount of personal data has been collected, stored, analyzed and processed by the accommodation business.

Why does Vietnam want to upgrade the regulations on electronic identification and authentication into law?

For many years, electronic identification has often been seen as a tool to support the settlement of administrative procedures in the digital environment. For the majority of people, electronic identification is associated with the VNeID application, electronic driver's license or the implementation of online public services without presenting paper documents. However, the contents proposed by the Ministry of Public Security in the dossier for the development of the Law on Electronic Identification and Authentication show that the scope and ambition of this policy are much larger.

Sanbox fintech: Is the State Bank choosing risk management over paper management?

Just over a year after Decree 94/2025/ND-CP on the sandbox testing mechanism in the banking sector was issued, the State Bank of Vietnam (SBV) has proposed to amend a series of regulations related to participation conditions, dossier composition and procedure processing process for fintech enterprises .

Establishment of a data exchange: Is Vietnam building a data market or a data management mechanism with market elements?

In Vietnam, this situation exists in many fields. National databases, specialized databases and data held by enterprises are formed more and more, but most of them still operate relatively independently. Meanwhile, technology enterprises, research organizations and artificial intelligence developers have the need to access big data sources to build new products and services but lack a transparent and legal transaction mechanism.

Why should enterprises conduct legal training on personal data protection for employees?

For many years, when it comes to legal compliance in businesses, people often think of issues such as taxation, labor, fire protection, production safety, or internal controls. However, in the context of strong digital transformation, personal data has become a type of "special asset" of businesses and at the same time an object of increasingly tight protection by law.

The paradox of personal location data

In the digital economy, a person's location data tells a lot of things, from where they are, where they live and work, who they often meet, what habits they move into, and what behavioral groups they may belong to. Location data from this perspective has the highest commercial value for businesses, and is also one of the types of data with the greatest privacy risk from a consumer perspective.

Draft Decree guiding the Law on Cybersecurity: What do cross-border business enterprises need to prepare?

The Draft Decree detailing a number of articles and measures to implement the Law on Cyber Security 2025 (the "Draft Decree") is attracting great attention from the business community, especially enterprises providing cross-border services in Vietnam. According to the content of the Draft, the drafting agency is aiming to establish a stricter and more synchronous cyber security management mechanism, including issues such as: cyber security protection measures, ensuring network information security, IP address identification management and data storage mechanism in Vietnam.

Is the personal data of the deceased protected?

Recently, social networks in Vietnam have recorded the widespread spread of information about the private life of a deceased student – from letters written to family, health status to personal circumstances before death . These contents, although shared for various purposes, from memorials to expressing emotions, quickly attracted great attention from the community. However, besides the sympathetic reactions, the case also raises a notable legal question: is the personal data of a deceased person protected?