Data, Privacy & Cybersecurity

Data, Privacy & Cybersecurity
Data Protection Day 2026: A reminder of the importance of data protection in the digital era

Data Protection Day 2026: A reminder of the importance of data protection in the digital era

In the era of deepening digitalization, personal data has become a valuable but also vulnerable asset. January 28 is chosen annually to celebrate Data Protection Day, a global event aimed at raising awareness of privacy and protecting personal information. In 2026, with the theme of emphasizing "Own Your Privacy", the issue of protecting and mastering each individual's data has become more urgent than ever, especially when AI and cloud technology are developing strongly. The article will provide some information about the origin and meaning of this day in contemporary history, and at the same time set in the context of modern Vietnam – a country that is transforming strongly in the digital economy but is also facing many challenges in protecting the privacy of each individual.
Use of biometric data in medical examination and treatment - Need the highest level of security

Use of biometric data in medical examination and treatment - Need the highest level of security

Vietnam's health sector has implemented digitalization in the management and operation of electronic medical records, online health insurance payments, patient identification with chip-based citizen identification cards, and even the application of AI in diagnosing and monitoring patient health. This leads to medical examination and treatment facilities ("hospitals") collecting and processing more and more personal data of patients. However, compliance with data security and privacy in this field in Vietnam has not been given proper attention.
Don

Don't play with user biometric data

Unlike passwords or bank card numbers that can be changed, biometric data is permanently tied to the human body. Once illegally collected, used, or leaked, individuals have almost no ability to "recall" or "reset" their biological characteristics. Therefore, many legal systems around the world have considered biometric data as sensitive personal data and set strict protection requirements.
Hospitals face significant challenges in protecting patient data

Hospitals face significant challenges in protecting patient data

Vietnam's health sector, especially hospitals, will face many difficulties in complying with the new provisions of the Law on Personal Data Protection 2025 (the Law on PDP) which takes effect from January 1, 2026. This confusion stems not only from the shift from traditional management systems to digitalized models, where data is easily exposed, leaked, or abused, but also from the important nature of the type of data that hospitals are collecting and holding.
Where does responding to a personal data incident start?

Where does responding to a personal data incident start?

In the digital economy, it can be said that personal data is and will become the operational pillar of businesses. From financial transactions, customer care, recruitment, marketing to consumer behavior analysis, every activity relies on this data stream.
Guidance on procedures for issuance of the Certificate of eligibility to trade in data intermediary products and services

Guidance on procedures for issuance of the Certificate of eligibility to trade in data intermediary products and services

Data intermediary is a type of business of products and services that help connect data subjects, data owners and users, through commercial agreements. This is a potential type of business because data is considered a high-value asset in the digital era and agencies, organizations and individuals currently have a high demand for connecting, sharing, exchanging and accessing data. However, opportunity comes with responsibility. Enterprises providing data intermediary products and services between service users and state agencies must be registered, managed and licensed.
Draft sanctioning of administrative violations in the field of data that have a great impact on business activities

Draft sanctioning of administrative violations in the field of data that have a great impact on business activities

Vietnam is entering a critical phase in data management, with new regulations set in place to shape the future of data-related activities. In November 2024, the Data Law was approved by the 15th National Assembly and officially took effect on July 1, 2025 ("Data Law 2024"). This is the first time that Vietnam has enacted an in-depth law, laying the legal foundation for the management, security, processing and use of digital data .
 What should enterprises do to manage risks arising from employees’ use of AI?

What should enterprises do to manage risks arising from employees’ use of AI?

The digital era that forces businesses to accelerate innovation to maintain a competitive advantage is creating a major polarization within organizations. On the one hand, sales and product development teams are under pressure to apply AI to optimize performance; The other side is the risk management teams (technical and legal teams) that strive to prevent incidents that cause loss of trust or ensure compliance with the law. This interference leads to a common but dangerous phenomenon: "Shadow AI" – the arbitrary use of AI tools by employees without the approval or supervision of the IT department .
Personal Data Protection – How is the market survey industry responding?

Personal Data Protection – How is the market survey industry responding?

Market survey businesses not only collect identifying information such as name, age, occupation, but also collect data on consumer behavior, interests, personal opinions, product reviews, even sensitive information such as health status, etc. financial behavior or social issues. The scope of data collection and use is wide, so businesses in this segment are forced to make many adjustments to adapt to the new legal system on PDP.
The era of “trading benefits for data” is over!

The era of “trading benefits for data” is over!

Many businesses have been choosing the model of collecting and exploiting personal data based on the principle of exchanging benefits for the right to use data - the data giver and the data recipient are happy. However, behind that seemingly reasonable exchange mechanism is a significant legal risk for businesses.
CNIL sanctioned e-commerce platform SHEIN 150 million euros for violating its cookie policy

CNIL sanctioned e-commerce platform SHEIN 150 million euros for violating its cookie policy

On September 1, 2025, the Restriction Committee of the French National Commission for Informatics and Freedoms (CNIL) issued the Deliberation Judgment No SAN-2025-005 , which is an important legal event confirming France's tough stance on compliance with cookie regulations . The ruling sanctioned INFINITE STYLES SERVICES CO. LIMITED (ISSCL), a subsidiary of the SHEIN group, with a record administrative fine of €150,000,000.
2026 – predicting 3 common types of personal data disputes in Vietnam

2026 – predicting 3 common types of personal data disputes in Vietnam

Early identification of potential disputes over customers' personal data helps businesses proactively assess risks, improve internal processes, invest in technology, and build transparency mechanisms for users. But to think that we have to obey the new law because it is the LAW is not very thorough. Because businesses around the globe are increasingly sympathetic and trusting to partners who respect privacy and protect personal data. Business opportunities start there.