The announcement on its website by Nova Group Joint Stock Company (NovaGroup) on the list of individuals who are "not re-employed" has quickly become a topic of public interest[1]. Notably, the published list is not the entire identifying information of individuals. Part of the citizen ID number and phone number have been concealed. This gives rise to a fairly common argument that the data has been "anonymized" or "de-identified", and therefore no longer falls under the scope of personal data protection legislation.

It is undeniable that businesses have a legitimate need to manage recruitment risks.
In addition to the debate on how to manage human resources, the case also raises a notable legal question in the context that the Law on Personal Data Protection 2025 has been enforced: to what extent can businesses disclose personal data for internal governance purposes?
The right to manage human resources is not an absolute right
It is undeniable that businesses have a legitimate need to manage recruitment risks. For large-scale corporations, it is common to store data on candidates, recruitment results, work history, or internal violations. Many businesses also build databases to warn of risks for cases that have caused damage or serious violations of internal regulations.
From a management perspective, this is a real need and is generally not prohibited by law. However, the Law on Personal Data Protection 2025 has established an important principle: all personal data processing activities must have an appropriate legal basis, limited to the scope of the defined purpose, and ensure the rights of data subjects.
This means that businesses may have the right to collect, store or use data for a limited time for human resource management, but it is not certain that they have the right to publicize that data on the internet. It is this point that creates the boundary between human resource management and personal data protection.
It's not a matter of how many characters to cover
When discussing the NovaGroup case, many people focused on the fact that the business partially concealed its citizen ID number and phone number. However, this is not the most important legal question.
The question that needs to be asked is whether the rest of the information allows for the identification of a particular individual. If the answer is yes, that data is still essentially personal data.
This is an important difference between the conventional understanding and the legal approach to personal data protection.
In fact, many businesses still think that just replacing a few characters with an asterisk (*) or covering part of the identification information is enough data to be fully protected. However, individual recognition is not evaluated on the basis of individual data fields, but must be evaluated across the entire data set. When a list still shows the individual's full name, along with the title at the company, covering a few digits of the citizen's ID may not significantly alter identification. Even in the age of social media and digital data, just a full name combined with some other public information can be enough to determine exactly who the data subject is.
Data de-identification and data pseudo-pseudonymization are two different concepts
An important new point of Decree 356/2025/ND-CP is the deeper access to technical measures to protect personal data, including the de-identification of personal data. However, in international practice as well as in data science, a clear distinction should be made between data de-identification and data pseudo-pseudonymization.
Data pseudonymization is the replacement or obscuration of some identifying information but the ability to identify the data subject through the rest of the information or through the combination with other data sources. On the contrary, data de-identification in the true sense must be aimed at eliminating or inactivating the data subject[2].
In other words, pseudo-pseudonymization is a technical method, while de-identification is a requirement for results to be achieved. This is a difference that many businesses are not fully aware of.
In the case of NovaGroup's list, when personal names and positions are still public, it may raise the question of whether the data has actually been de-identified or has only been partially falsified through the masking of some identifying information. Moreover, when combining the disclosed information, many people can identify who the person being mentioned in NovaGroup's list is.

If an individual can still be reasonably identified from the published dataset, the goal of de-identification has not been in fact achieved.
Re-identification risks in the digital data age
One of the reasons why modern law is increasingly cautious about data disclosure activities is the risk of re-identification. The ability to identify an individual today no longer depends on a single data field such as a citizen ID number or phone number.
Search engines, social media platforms, occupational databases, and public data on the internet can be combined to reconstruct an individual's identity profile. This is also why data regulators in many countries do not assess de-identification based on how much of the data has been obscured, but on the level of identification risk that exists.
If an individual can still be reasonably identified from the published dataset, the goal of de-identification has not been in fact achieved. Viewed from this perspective, the NovaGroup case is not only a story about recruitment but also a practical example of the challenges in assessing data re-identification risks.
New data subject rights
The Personal Data Protection Law 2025 marks a significant shift in the approach to the rights of individuals. Employees or candidates are no longer just the object of providing information to the business.
They are also data subjects with a series of rights protected by law such as the right to know, the right to access data, the right to rectify data, the right to request data deletion, the right to restrict data processing and the right to object to data processing in statutory cases.
This poses new requirements for businesses in designing recruitment processes and human resource management. It is not only necessary to consider the efficiency of governance, but also to assess the impact of data processing activities on the legitimate rights and interests of data subjects.
Lessons for businesses
From a compliance perspective, the NovaGroup incident offers at least four important lessons.
First, businesses need to clearly distinguish between data that has been de-identified and data that has only been partially masked or falsified.
Second, it is necessary to evaluate the ability to identify data subjects across the entire data set instead of just looking at each individual information field.
Third, it is necessary to distinguish between the use of data within the internal scope and the disclosure of data in the internet environment.
Fourth, it is necessary to develop a process for assessing the impact of personal data protection on high-risk data processing activities, especially in the field of recruitment and labor.
Looking at it more broadly, the debate around NovaGroup's "no re-hire" list reflects the first challenges that the Vietnamese business community is facing as it enters the era of law enforcement to protect personal data. The core problem does not lie in how many characters the business has hidden in the citizen ID number or phone number. What is more important is whether the data also allows the identification of a specific individual and whether the processing of that data is in accordance with the principles of the law on the protection of personal data.
In the future, disputes over personal data may no longer revolve around whether businesses collect data or not, but will focus more on the question of how and how businesses have used the data. That is also the new boundary between corporate governance and the right to protect personal data in the digital economy.
Lawyer Nguyen Van Phuc
HM&P Law Firm
Read more: Ranh giới giữa quản trị nhân sự và bảo vệ dữ liệu cá nhân: Nhìn từ vụ NovaGroup
[1] https://tuoitre.vn/danh-sach-khong-tai-tuyen-dung-cua-novagroup-quyen-cua-doanh-nghiep-den-dau-khi-sang-loc-nhan-su-20260612161005216.htm, accessed on 2026/06/16.
[2] Clause 11, Article 12 of the Law on Environmental Protection 2025.
