In the digital economy, it can be said that personal data is and will become the operational pillar of businesses. From financial transactions, customer care, recruitment, marketing to consumer behavior analysis, every activity relies on this data stream.
When personal data is considered a strategic "asset", every security incident, whether unintentional or stemming from a cyberattack, can immediately cause a legal and communication crisis for businesses. This article covers how businesses will respond to personal data incidents and where to start?

Source: The Saigon Times
The good news is that businesses can still make the most of the personal data collected while still ensuring that they can respond when an incident arises if they know how to build a strategy that is suitable for their characteristics from now on.
Proactive personal data management strategy based on risk assessment
An effective personal data management strategy starts from identifying the entire flow of personal data in the business. When businesses understand exactly what data they are collecting, for what purpose, who is accessed, what systems the personal data goes through, and how long it is stored, it is now possible for businesses to properly assess risks and establish appropriate preventive measures. Regular risk assessment is the foundation for businesses to shift from the mindset of "handling incidents when they arise" to thinking of "prevention from the root".
Refer to the case of HMI Institute of Health Sciences in Singapore[1]. The organization stopped operating the online training system but did not reassess the status of the personal data after the closure of the system portal, resulting in an Excel file containing the information of 761 individuals that still exists in public web directories and is indexed by search engines. It is worth mentioning that personal data files are not subject to cyber attacks but are only missed in internal processes, demonstrating the risks that arise when businesses lack a comprehensive risk assessment. HMI was subsequently fined S$10,000 and forced to restructure its data management system.
This is also a common limitation of Vietnamese businesses when personal data is no longer used but is still stored somewhere in temporary systems, personnel data is copied through many departments without controlling the level of access... are all potentially risky. Businesses don't have a periodic review strategy, so it's impossible to know where the data is and whether it's creating a legal risk. Therefore, the establishment of a department responsible for personal data protection, the implementation of impact assessments on personal data processing and the development of comprehensive policies (these are all obligations of businesses under the provisions of the Law on Personal Data Protection 2025) will help businesses proactively comply prevent personal data incidents, and will be an effective tool when businesses need to prove compliance before management agencies in arising situations.
Control the "supply chain" of personal data with suppliers and partners
In the modern business environment, personal data is rarely only in the system of an enterprise. Cloud services, marketing platforms, CRM solutions, HR software, partner applications, and even technology contractors can access personal data to a certain extent. Therefore, risks not only arise internally but also from partners in the supply chain.
One of the best examples of supply chain risk is the case of Target, a major retail conglomerate in the US[2]. The 2013 cyberattack that leaked the information of more than 40 million customers did not start with Target's systems, but from a third party (Fazio Mechanical Services), which is the contractor that manages the air conditioning system. The hackers attacked this less important account, then went on to infiltrate Target's payment system. The consequences lasted for years, including financial losses, litigation, and a decline in user confidence.
This case shows that no partner is "no or less important" when they have access to any part of the system. A small negligence on the outside can have huge consequences for a business in the data center. For Vietnamese enterprises, where the model of outsourcing technology services, human resources, and marketing cooperation through third parties is increasing sharply, this risk has become even more noticeable. To solve this problem, businesses need to build a mechanism for selecting and evaluating partners based on clear standards of security, at the same time, it requires specific legal commitments related to the scope of processing, purpose, storage period and measures to protect personal data. A regular service contract will not be enough to ensure the safety of personal data, businesses need to establish specialized provisions on personal data protection, including the responsibility to notify, the obligation to support in case of an incident, and the compensation mechanism.

However, the contract is only one part of the strategy. A more important factor is the ability to monitor and inspect regularly throughout the cooperation period, rather than the expectation that the partner will voluntarily comply if there is no corresponding control mechanism. Periodic audits, data security reports, and end-of-contract reviews are tools to help businesses ensure that personal data is not misused or exists beyond control.
Incident response strategy
In fact, personal data incidents can still occur even if businesses have built a good governance system and strictly controlled partners. When that happens, what determines the extent of the damage is not the incident itself, but how the business reacts. If businesses are slow to handle, lack transparency, or fail to meet legal obligations, the incident can quickly turn into a crisis.
Remember the Equifax data incident in 2017, one of the world's largest credit rating agencies[3] at the time suffered a data attack that leaked the information of more than 147 million people. What made Equifax heavily criticized was not only the security vulnerability, but also the but also how they react, when delays in announcing incidents, lack of transparency and giving conflicting announcements cause users to lose trust. As a result, fines and remedial costs of up to 700 million US dollars have been applied to this business.
Another example comes from Uber in 2016. When it was hacked and lost the data of 57 million users, Uber chose to pay hackers to delete the data, while deliberately hiding the problem[4]. When the case was discovered, this reaction caused Uber to suffer heavy legal damages, including fines from many countries and a sharp decline in customer and investor confidence. Uber's case shows that hiding the incident not only doesn't solve the problem, but also causes more profound damage to the business's reputation.
The above evidence reflects an important lesson for businesses, showing that immediate response, controlled transparency and compliance with legal obligations are key factors to limit damage. If businesses have a clear response process, assign responsibilities, prepare communication scenarios and reporting mechanisms to regulators, they can minimize legal and communication consequences. Not only that, the comprehensive response strategy not only focuses on the time of the incident, but also includes the recovery phase, assessing the causes, fixing vulnerabilities, and demonstrating improvement. This is the stage to help businesses demonstrate the spirit of market demand and management capacity, an important factor to restore prestige in the eyes of users.
Thus, it can be seen that the three strategies including proactive management, supply chain control and comprehensive incident response are not only measures for businesses to protect personal data but also the foundation to ensure the sustainability of businesses in the context of increasingly stringent legal regulations. Cases from Singapore or the US will be big and expensive lessons for Vietnamese businesses. As Vietnamese businesses prepare to enter the implementation phase of the Law on Personal Data Protection, serious investment in these three strategies will determine the level of legal risk, customer/partner trust, and long-term competitiveness of the business.
Lawyer Nguyen Nhat Duong
HM&P Law Firm
Read more: Ứng phó với sự cố dữ liệu cá nhân bắt đầu từ đâu?
[1] https://www.pdpc.gov.sg/all-commissions-decisions/2024/11/breach-of-the-protection-obligation-by-hmi-institute-of-health-science, last accessed on 19/11/2025.
[2]https://www.portnox.com/blog/cyber-attacks/throwback-to-the-target-hack/, last accessed on 19/11/2025.
[3] ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach?src_trk=em6755b2c96c4054.928494461458559432&utm_source=chatgpt.com, last accessed on 19/11/2025.
[4] https://vtv.vn/the-gioi/che-giau-vu-bi-tin-tac-danh-cap-thong-tin-nga-re-sai-lam-cua-uber-20171122170713375.htm?utm_source=chatgpt.com, last accessed on 19/11/2025.
