Many personal data leaks in Vietnam originate from employees who used to work in businesses. When the "old" becomes a new risk, the question is no longer how businesses handle the consequences, but how early they should design prevention mechanisms to limit these risks.

What these situations have in common is that data leaks do not come from "outside", but from "insiders" – people who understand the system well and know exactly where the data lies.
When data is "taken away" with personnel
A former employee of Onesms Mobile Information Technology Trading Joint Stock Company (Onesms), which provides electronic contact book services to schools across the country, took advantage of access to the system during working hours to illegally extract students' personal data. Specifically, Tung copied about 15,000 pieces of information of students and parents, including full names, phone numbers and related data from the source of the electronic contact book[1].
Notably, the act of copying data was carried out when Tung was still an employee, that is, he had legal access. However, after quitting his job, Tung was not controlled or recovered the copied data. The subject then uses social media accounts to sell data and connect with buyers, forming a systematic personal data trading activity.
According to the case file, Tung made more than 500 data trading transactions, earning illicit profits of about 700-800 million VND. The incident shows a typical vulnerability: data is "taken" from within the organization before personnel leave, and only exploited and commercialized afterwards, posing a serious risk to both businesses and data subjects. It is worth mentioning that this behavior is not caused by a sophisticated cyberattack, but by the person who has legitimate access.
This is not an isolated case. In fact, many businesses in Vietnam have faced the situation: Salespeople bring a list of customers when switching to a rival company; IT personnel back up system data before leaving work; Customer data is shared via personal email or stored on the employee's own device.
What these situations have in common is that data leaks do not come from "outside", but from "insiders" – people who understand the system well and know exactly where the data lies.
Why is it easy for businesses to "lose data" when employees quit their jobs?
The process of offboarding is still in form
Most businesses focus on handing over work, but neglect the revocation of data access. There are many cases where internal accounts have not been locked immediately. The employee has quit but the system access is still valid and the company email is still active after the employee has taken a break. This creates a dangerous "control gap".
The case we mentioned above also shows that the problem lies not only in the fact that employees copy data while working, but also in the fact that the business does not control that the data has been taken out before the time of resignation.
A rigorous offboarding process isn't just about revoking laptops, employee cards, or email keys. Businesses need to review all access rights of employees, check login history, data download history, file exports, email forwarding, and data synchronization to personal accounts or external devices. For positions with access to sensitive data such as system administration, customer care, business, engineering, or digital platform operation, control must be activated as soon as personnel show signs of quitting, not waiting for the last working day.
In this case, if the business has a warning mechanism when employees download a large amount of student and parental data; there are regulations prohibiting copying data to personal devices; have a record of confirmation of data deletion/return upon resignation; and if there is a log check before the termination of the contract, the risk may have been detected earlier.
Therefore, the lesson is not just to "lock access after quitting", but to control the entire stage before, during, and after personnel leave the business.
The data management of the business has not been systematized and the unit in charge is not clear
In fact, the majority of leaks don't take place after quitting their jobs, but start before that. If the business does not have a monitoring mechanism: personnel download data in bulk, or there are unusual accesses, then copying is almost impossible to detect.
In many businesses, customer data is still seen as "personal or partial property", rather than a business asset. This makes carrying data when quitting work "normalized", especially at securities companies and real estate companies.
In addition, businesses have not paid proper attention to systems such as access decentralization, behavior monitoring, or technical measures to prevent data loss have not been adequately invested, especially in small and medium-sized enterprises. A loose control and decentralization system is an "opportunity" for personnel to easily put data outside the company's safety and control circle.

An employment contract is one of the first legal bases to bind employees to comply with the protection of personal data at the enterprise in particular and the company's data in general.
Legal risk is no longer a "theory"
With the Law on Personal Data Protection 2025 taking effect from January 1, 2026, the Data Law 2024 and its guiding documents have placed the responsibility of businesses to protect data at a significantly higher level.
An important point that businesses should note is that the responsibility of the business does not end when an employee leaves work. If the data is exposed, the enterprise as the controller or the party that controls and processes personal data can still be sanctioned, and even have to compensate the data subject for damages. The lack of internal controls can be seen as a breach of a business's confidentiality obligations, even if the act is directly committed by an individual.
Data leakage prevention: Can't rely on "trust" alone
To limit risks from employees who have quit their jobs, businesses need to shift from a "trust" mindset to "systematic control". An effective model can be built on three layers: legal – process – technology.
Establish legal binding from the beginning
An employment contract is one of the first legal bases to bind employees to comply with the protection of personal data at the enterprise in particular and the company's data in general. In the labor contract signed with the employee, the enterprise needs to clearly stipulate: (1) the data is the property of the enterprise; (2) the obligation of confidentiality lasts after the termination of the contract; (3) sanctions for violations committed by employees.
For sensitive positions, businesses may consider signing non-compete agreements; commit not to use data after quitting your job. More importantly, when employees leave, it is necessary to confirm: they have handed over all data, do not keep copies in any form and commit not to use any data of the enterprise obtained or learned during the process of working at the enterprise.
Internal processes: control at the right time
An effective offboarding process should include: immediately locking out all access accounts; equipment recovery and data inspection; review access history before quitting work; Confirmation of completion of confidentiality obligations. At the same time, businesses should apply the principle of "minimum access" – personnel only have access to the data necessary for work. This is one of the effective measures for businesses to avoid data loss and leakage from employees who have quit their jobs at the company.
Using high-tech techniques
Technical solutions play a key role in business operations to prevent the risk of personal data/data disclosure from employees who have left their jobs. Technical solutions can be listed here such as: data loss prevention system (DLP); encryption of sensitive data; monitoring access behavior; terminal control (USB, personal device).
These tools not only help prevent leaks, but also create evidence when a dispute occurs, giving businesses the advantages of asking the individual who caused the damage to compensate and be responsible for the violation.
Prevention must begin before personnel leave
A common mistake is that businesses only tighten control when personnel have applied for leave. But at that point, the data may have been copied.
Instead, businesses must continuously monitor access behavior. At the same time, it is necessary to classify data according to the level of sensitivity and set up early warnings for unauthorized access and retrieval of data by employees while these people are still employees of the company.
Data leakage from employees who have left their jobs is no longer a rare risk, but is becoming a "system vulnerability" in many businesses. As data becomes more valuable, data lifecycle control, including the period of personnel departure, has become a must. In the context of increasingly tightening regulations, businesses cannot wait until an incident occurs to take action. Data risk prevention, after all, is not a technology story, but a risk management story in the operations of any business in the digital age.
+84 28 7308 0839
