In the context of the 2025 Personal Data Protection Law (“PDP Law”) and Decree 13 imposing stricter requirements on data processing activities, reviewing international case studies is essential for businesses to identify risks and strengthen their compliance frameworks. Incidents involving British Airways, the Academy of Medicine Singapore, Shein, and TikTok demonstrate that even a single gap in security measures, internal procedures, or consent-management mechanisms can result in large-scale data breaches and significant regulatory penalties. This article consolidates and analyses these cases in comparison with the corresponding provisions of the PDPL and Decree 13, with the aim of providing Vietnamese businesses with practical lessons to improve their technical safeguards, privacy policies, and data-governance processes.
1. British Airways data leak (2018)[1]
1.1. Background of the incident
In 2018, British Airways (BA) systems were cyberattacked, resulting in about 430,000 customers having their personal information exposed, including payment card data (name, address, payment card number, and security code (CVV)). BA did not detect the attack on its own on the day of the incident, but was only alerted by a third party more than two months after the incident. This incident is one of the largest data breaches in the European aviation industry.

In October 2020, the UK's Information Commissioner's Office (ICO) concluded that BA had failed to adequately implement the technical and organisational measures necessary to protect personal data as required by the European Union's General Data Protection Regulation (GDPR). As a result, BA was fined £20 million – one of the largest fines at the time.
In the sanctioning decision, the ICO outlined measures that BA can apply to minimize or prevent the risk of hackers accessing the internal network, including:
- Limit access to applications, data, and tools, only to the extent necessary for employees to properly perform their job functions;
- Perform rigorous security testing, such as cyber-attack simulation to assess the system's defenses;
- Protect employee and third-party accounts with multi-factor authentication.
1.2. Lessons for Vietnamese businesses
From the British Airways case, businesses in Vietnam can learn important lessons to comply with the Law on Personal Data Protection (“PDP”) and Decree 13 related to the application of necessary security measures to protect personal data, notification of violations of regulations on PDP:
|
Legal Risks |
Legal basis |
Lessons learned for businesses |
|
Failure to apply proper protection
|
Article 37.1(c) of the Law provides for the responsibilities of the data controller. |
Enterprises must establish access control systems, data encryption, multi-factor authentication, and continuous security monitoring. |
|
Failure to notify violations of regulations on PDP
|
Article 23 of the Law on PDP stipulates the notification of violations of regulations on PDP. |
Enterprises need to develop a response process when a personal data incident occurs, assign a focal point to notify the specialized agency in charge of PDP within 72 hours from the detection of the violation. |
|
Failing to make and archive records of impact assessment of personal data processing |
Article 21 of the Law on PDP stipulates the assessment of impacts on personal data treatment |
Enterprises need to carry out an impact assessment on the processing of personal data in accordance with the law on PDP. Information recorded by the enterprise in the impact assessment dossier (information on the parties in the personal data processing activities, description of the personal data processing activities will be one of the bases for the competent authority to consider responsibility when an incident of violation of personal data handling occurs). |
2. Academy of Medicine Singapore Breaches PDP Obligations (2023)[2]
2.1. Background of the incident
The Academy of Medicine Singapore (the "Academy") is an institution that offers postgraduate and specialist medical training in Singapore. In July 2023, the Academy had a data leak incident due to the Academy's server being infected with ransomware. As a result, the personal data (full name, address, phone number, email, photo ID, bank account number, credit card number – with both CVV and expiration date) of 6,574 people who are employees and participants in events and exams organized by the Academy was stolen and posted for sale on the darkweb. The PDP Commission of Singapore (PDPC) after receiving the notice of infringement conducted an investigation and issued a decision to sanction the Academy for failing to take reasonable measures to prevent unauthorized access, collection, use, disclosure or modification of personal data in accordance with Article 24 of the Singapore PDP Act 2012 (PDPA). The main violations pointed out by the Commission are as follows:
- Lack of software update process, resulting in an outdated firewall and operating system (the organization has been using outdated servers for more than 3 years).
- There are no reasonable safeguards for sensitive financial data (credit card information stored in clear text, not encrypted).
- Confidentiality responsibilities are not clearly stipulated in contracts with contractors providing information technology services to the Academy.
In addition to being fined S$9,000, the Academy was required to apply additional penalties:
- Evaluate and configure the firewall appropriately;
- Review the network architecture, separate the data processing and storage area;
- Enhance the security of servers and endpoints;
- Delete or encrypt sensitive data, comply with PCI DSS (Payment Card Industry Data Security Standard);
- Do not store CVV after the transaction is completed;
- Conduct annual security checks;
- Report on the completion of the remedy to the Commission within 60 days.
2.2. Lessons for Vietnamese businesses
From the Academy of Medicine Singapore incident, businesses in Vietnam can learn important lessons to comply with the Law on PDP and Decree 13, especially on appropriate safeguards for sensitive personal data (e.g. bank card information, e-accounts, etc ...):
|
Legal Risks |
Legal basis |
Lessons learned for businesses |
|
Lack of reasonable protection measures leads to personal data leaks; failing to assess risks and periodically review the information security system |
Article 37.1(c) of the Law provides for the responsibilities of the data controller. |
Businesses need to build a process for information technology system security, ensuring periodic updates, error corrections and data backups. At the same time, carry out risk assessments and review security systems regularly, especially for large-scale data storage or processing systems. |
|
Store sensitive DLC (especially bank card information) without encryption |
Article 27.1(a) of the Law on PDP provides for the protection of personal data in financial activities, banking, and credit information activities. Article 7.2 of the Draft Decree on personal data transfer stipulates data encryption obligations and confidentiality requirements in personal data transfer |
Businesses need to review personal data processing activities, identify collected data (basic or sensitive) to apply appropriate security measures. For sensitive personal data (such as bank card information), businesses need to encrypt data, do not save CVV, password, OTP or card information after the transaction to minimize the risk when an incident occurs. |
|
No confidentiality responsibilities are stipulated in contracts with contractors/suppliers or partners |
Article 37.1 (a) of the Law on PDP provides for the responsibilities of the data controller |
Enterprises need to include regulations on PDP in contracts with information technology and storage service providers or partners with access to personal data. In which, it clarifies the rights, obligations, and responsibilities for applying security measures of the parties. At the same time, businesses need to periodically check and assess the security capacity of suppliers or partners to ensure compliance. |
3. Shein e-commerce platform installs "Cookies"[3] without consent (2025)[4]
3.1. Background of the incident
The SHEIN Group sells clothing, footwear and accessories through its website "shein.com", which is managed by INFINITE STYLES SERVICES CO. LIMITED, BASED IN Ireland, for the European region ("SHEIN").

In August 2023, France' s National Data Protection Commission (CNIL) conducted an audit of the "shein.com" website. Based on the results of the audit, in September 2025, the CNIL issued a sanctioning decision – concluding that SHEIN had violated cookie regulations under Article 82 of the French PDP Law, and issued a fine of 150 million euros to SHEIN. The CNIL also emphasized that since 2020, the agency has continuously sanctioned and made similar decisions public, and that the sheer scale of Shein's data processing (an average of 12 million users access it in France per month) is an aggravating factor in determining the fine.
The CNIL determined that SHEIN was in breach of a number of obligations, including:
- Setting cookies without the user's valid consent;
- Failure to respect the user's choice after they refuse or withdraw consent;
- Failure to provide sufficient information about the purpose and third parties related to cookies.
Specifically, sanctioned violations include:
- Do not consult users before installing cookies: The CNIL found that some cookies – especially those for advertising purposes – were installed as soon as the user visited the "shein.com" page, before they made a choice through the cookie information banner.
- Two incomplete informative banners: The website displays two interfaces related to cookie management, but both lack information
- The first banner has three buttons, "Cookie settings", "Reject all", and "Accept" but does not specify the advertising purpose of the cookie.
- The second pop-up window only has an "Accept" button that doesn't explain the purpose of the cookie.
- Incomplete second-level information: at the second level of information (accessed via the "Cookie setting" button), there is no information about the identities of the third parties that can set cookies.
- Incomplete second-level information: At the second level of information (accessed via the "Cookie settings" button), there is no information about the identity of the third parties that can set cookies.
- The opt-out and withdrawal mechanism is ineffective: when the user clicks "Decline All" or withdraws consent, new cookies continue to be installed and old ones continue to be read.
- Ineffective opt-out and withdrawal mechanisms: When the user clicks "Decline All" or withdraws consent, new cookies continue to be set
- Ineffective mechanism of refusal and withdrawal of consent: When the user clicks "Decline All" or withdraws consent, new cookies continue to be installed and old cookies continue to be read
3.2. Lessons for Vietnamese businesses
|
Legal Risks |
Legal basis |
Lessons learned for businesses |
|
Failure to collect valid consent from users |
Article 11.1 of the Law on PDP provides for the collection, analysis and synthesis of personal data.
|
Businesses are only allowed to install or activate cookies (except for necessary technical cookies) after the user has explicitly and proactively consented. Banner cookies must represent free choice – users can opt out without hindrance or damage when accessing the service. |
|
Failing to clearly inform about the processing of collected DLC |
Article 9 of the Law on PDP stipulates the consent of the subject of personal data Article 29.3 of the Law on PDP stipulates the responsibilities of individuals and organizations in publicizing privacy policies, clearly explaining how personal data is collected, used and shared |
When collecting consent (e.g. via banner cookies), businesses must clearly explain: what cookies are for (advertising, measurement, analytics,...), who third parties can access the data, and how long it will be stored. Multiple processing purposes may not be combined in a single consent box. |
|
The right to refuse or withdraw consent from the user is not guaranteed |
Article 10 of the Law on PDP stipulates the request for withdrawal of consent, request for restriction of personal data processing Article 28.3 of the Law on PDP stipulates the responsibility of organizations and individuals in providing an option that allows users to opt out of the collection and sharing of data files (cookies) |
When the user clicks "Decline All" or "Withdraw Consent", the business must immediately stop setting or reading non-essential cookies and cease all processing of personal data accordingly. |
4. TikTok fined 345 million euros for violating children's PDP regulations (2023)[5]
4.1. Background of the incident
The Irish Data Protection Commission (DPC) has personally initiated an investigation to examine TikTok Technology Limited's ("TikTok") compliance with its obligations under the European Union's General Data Protection Regulation (GDPR) between July 31, 2020 and December 31, 2020, specifically in the handling of personal data of child users on the TikTok platform. comprise:
- Some settings on the TikTok platform, such as the default public-by-default mode and the "Family Pairing" feature.
- Age verification process when registering an account.
- TikTok's obligation to be transparent, especially the level of information that TikTok provides to child users about the default settings mentioned above.
In September 2023, after the conclusion of the investigation, the DCP issued a decision to sanction TikTok 345 million euros for the following violations:
- Make children's accounts public by default, making videos, comments, and personal information accessible to any user;
- Failing to verify the parent-child relationship in the "Family Pairing" feature, which allows an adult to control a child's account without proving that they are legal guardians;
- Providing unclear or confusing information to children in the privacy policy;
- The "dark patterns" interface design[6] makes it easier for children to choose less secure settings (e.g., "Public Video Sharing" is more prominent).
Legal grounds for breaches (under the European Union's General Data Protection Regulation (GDPR)):[7]
- Article 5(1)(a) & (c): Data processing shall be lawful, fair, transparent and to the minimum necessary;
- Article 25: Data protection by design and by default;
- Articles 24 & 35: Responsibilities of the data controller and the obligation to assess the impact of data protection.
4.2. Lessons for Vietnamese businesses
|
Legal Risks |
Legal basis |
Lessons learned for businesses |
|
Collect, use, or share children's personal data without the valid consent of their legal representative. |
Article 24.2 of the Law on PDP stipulates the protection of personal data of children, persons who have lost or limited their civil act capacity, and persons with difficulties in cognition and control of behavior Article 9.3 of the Law on PDP stipulates the consent of the subject of personal information
|
Businesses that provide platforms, apps, or services with users under the age of 16 must verify age and collect two layers of consent in parallel (that of the child – if 7 years of age or older, and of the parent). The system needs to save proof of consent (log, authentication code, confirmation email,...). |
|
The default design makes child's data or accounts public or vulnerable to unauthorized access |
Article 3.3 of the Law on PDP stipulates the principles of PDP |
All user accounts under the age of 16 should be set to "private" by default, and information should only be shared with parental consent. Interface design must avoid "forcing" children to disclose data or making unsafe choices in information security. |
|
Not being transparent and confusing in informing children about their privacy |
Article 4.4 Rights and obligations of personal data subjects
|
The privacy policy for children should be prepared separately, presented in easy-to-understand language, with illustrative examples, helping children and their legal representatives understand what data is collected, why and for how long to ensure the implementation of their rights and obligations. |
|
Failure to verify the identity or relationship between the guardian and the child when collecting consent |
Article 24.2 of the Law on PDP stipulates the protection of personal data of children, persons who have lost or limited their civil act capacity, and persons with difficulties in cognition and control of behavior Article 37.1(c) of the Law provides for the responsibilities of the data controller.
|
Enterprises need to establish a mechanism to verify the parent-child relationship (e.g., declaration with documents, verification via authentication code sent to parents, confirmation via registered account of guardians). |
Compliance with the law on PDP is not only a legal obligation but also a commitment to the responsibility of businesses in respecting and preserving the privacy of individuals. In the context that Vietnam's legal system on PDP is gradually improving, enterprises need to regularly monitor and update the Law on PDP, especially the Draft Decrees guiding the Law when completed in the future to promptly adjust internal processes policies and contracts accordingly.
[1] https://www.gdprregister.eu/news/british-airways-fine/, accessed on 27/11/2025.
[2]https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/commissions-decisions/gd_academy-of-medicine-singapore_10062024.pdf, accessed 27/11/2025.
[3] "Cookies" are small data files stored by a website in a user's browser to remember access information (such as login, language, browsing behavior) and serve purposes such as personalizing the experience, statistics, or advertising.
[4] https://www.cnil.fr/sites/default/files/2025-09/cnil_sanction_shein_en.pdf, accessed 27/11/2025.
[5]https://www.dataprotection.ie/en/news-media/press-releases/DPC-announces-345-million-euro-fine-of-TikTok?utm_source=chatgpt.com, last accessed on 27/11/2025
[6] "Dark patterns" are user interface designs that are deliberately orchestrated to trick or manipulate users into taking actions they don't really want, such as sharing personal data or accepting unfavorable terms.
[7] https://gdpr-info.eu/, last accessed on 14/10/2025.
