For many years, when it comes to legal compliance in businesses, people often think of issues such as taxation, labor, fire protection, production safety, or internal controls. However, in the context of strong digital transformation, personal data has become a type of "special asset" of businesses and at the same time an object of increasingly tight protection by law.

Partner Nguyen Ngoc Tra My in a PDP training for nearly 100 businesses organized by The Saigon Times in collaboration with the Department of Industry and Trade of Ho Chi Minh City
In Vietnam, along with the emergence of Decree 13/2023/ND-CP, the Data Law 2024 and especially the Personal Data Protection Law 2025 which came into effect on January 1, 2026, the obligation to protect personal data is no longer an ethical choice or brand image. which has become a mandatory legal compliance requirement for businesses.
In that context, many businesses focus on investing in technology systems, security software or hiring legal consultants to develop data protection policies. However, an important but often overlooked element is: legal training on personal data protection for workers.
In fact, in many data leaks, the cause does not come from sophisticated hackers or complex technology vulnerabilities, but stems from the behavior of internal personnel: sending the wrong email, sharing the wrong access, using customer data for the wrong purpose, etc insecure data storage or lack of awareness of confidentiality obligations.
In other words, if data is an "asset," then the workers are the ones who directly hold the keys to that asset.
Personal data risks increasingly come from the human factor
In practice, many businesses are still looking at personal data protection mainly from a technical and technological perspective. When a data incident occurs, the first reaction is usually to upgrade the IT system, buy more firewalls, encrypt data, or strengthen network security.
However, international experience shows that the human factor is one of the most common causes of personal data breaches.
An HR employee accidentally sends the company-wide payroll file to the wrong recipient. A salesperson uses old customer data to serve personal work after quitting his job. A marketer voluntarily shares a customer list with a third party to run ads. A manager downloads data internally to a personal computer but does not apply appropriate security measures.
These acts may not come from bad intentions, but they are still enough to make businesses face the risk of violating the law on personal data protection.
It is worth noting that in the modern corporate environment, nearly every department has access to personal data to varying degrees. The human resources department processes labor records; accountants with bank account information; marketing customer data management; IT operates data systems; business of storing partner information; Customer care receives feedback and transaction history.
This means that the risk of personal data breaches is no longer a problem of the IT department or the legal department, but a problem for the entire business.
In many cases, the enterprise may have fully developed internal processes but the employee does not understand or is not aware of the seriousness of the violation. At that time, it is the gap in awareness and training that will become the biggest weakness in the compliance system.
The current law not only requires businesses to "have policies", but also to organize enforcement
A common practice in many businesses is to develop quite complete documents such as personal data protection policies, internal regulations, information security commitments or data processing clauses in employment contracts. However, these documents sometimes exist only on paper or are issued formally to "sufficient records".
Meanwhile, current legal trends are increasingly emphasizing the essence of compliance activities.
According to the requirements of the Law on Personal Data Protection 2025, enterprises not only need to issue regulations but also apply appropriate management measures to ensure that personal data is processed for the right purpose, in the right scope, for the right subjects and safely during the data processing process.
In fact, it is difficult for businesses to prove that they have taken "necessary and appropriate measures" if workers, especially those who directly process the data, are completely untrained or do not understand the legal obligations involved.
In many international legal systems such as the European Union's GDPR, personnel training is seen as an important part of the personal data compliance program. When assessing a business's level of compliance, the regulator not only considers whether the business has a policy, but also whether personnel receive periodic training, whether there is an internal breach handling process, and whether the business has actually built a culture of data protection.
This trend is also becoming more and more evident in Vietnam.
In the event of a personal data incident, the fact that businesses have a well-organized training program, training records, personnel guidance processes and appropriate internal control mechanisms can become an important factor to prove goodwill to comply as well as minimize legal risks.
Moreover, the current personal data protection law requires enterprises to develop a plan and implement periodic training and refresher training on personal data protection for the human resource system in their [1]units.

Associate Pham Thanh Huy in a PDP training for clients
Training helps businesses reduce legal risks and compensation liabilities
One of the biggest consequences of a personal data breach is the risk of business liability, including administrative sanctions, civil damages, or even criminal liability in some serious cases.
Notably, in many situations, even if the violation is committed by an individual employee, the enterprise can still be considered the main responsible entity because it is the one that manages and controls the data processing activities.
For example, if employees arbitrarily use customer data for the wrong purpose but the business does not have an appropriate decentralization mechanism, does not provide internal training, or does not supervise data processing, the business may have difficulty demonstrating that it has fully fulfilled its management obligations.
In addition to direct liability, data incidents can also lead to many indirect consequences such as loss of brand reputation, risk of disputes with partners; affect internal operations,...
For businesses that operate across borders or work with foreign customers, the requirement for personal data training has even become a commercial condition. Many international corporations now require partners in Vietnam to prove that they have periodic personal data protection training programs for their employees, especially in fields such as technology, finance, e-commerce, education, and healthcare,....
Therefore, personal data training is not merely a compliance cost, but is increasingly becoming a part of enterprise risk management.
Training is not just for legal or IT departments
Another common mistake is that businesses assume that only the legal or information technology department needs to understand the law on personal data.
In fact, personal data breaches often appear in "non-technical" departments more than businesses think. Many risks can occur if the recruitment department keeps the candidate's CV for too long without proper grounds; Marketing sends promotional emails without a valid consent mechanism; Customer care records calls but does not notify them adequately; or manage the use of cameras or surveillance equipment beyond the scope of necessity,....
If workers are not trained, it is easy for them to see personal data as just "information for work", rather than perceiving that this is strictly protected by law.
Therefore, personal data training needs to be approached universally throughout the enterprise, with appropriate content for each location group.
Not all personnel need to have a deep understanding of the entire legal system. However, every employee needs to be equipped with the most basic knowledge for personal data protection.
In addition, for sensitive positions such as HR, marketing, IT, legal or middle management, businesses should have a more in-depth training program because these are teams that regularly process data with a large scope.
In the long term, the greatest value of training is not only in "avoiding penalties", but also in building a culture of data protection in the business.
Similar to a culture of compliance or occupational safety, a culture of data protection can only be formed when employees understand that personal data is not just a business resource, but also associated with privacy and human rights.
Where should businesses start?
In fact, not all businesses need to immediately implement complex or expensive training programs. It is more important to start in the right direction and in accordance with the scale of the operation.
Businesses can consider issues such as: (1) Assess which departments are processing a lot of personal data; (2) Identify common data risks in internal operations; (3) Develop regulations and guidelines for data processing that are easy to understand; (3) Organize periodic training and assessments for employees, especially in important positions; (4) Request a commitment to the confidentiality of personal data in the course of work; (5) Establish an internal data incident reporting mechanism; (6) Retraining when there is a change in laws or procedures.
In particular, businesses should not consider personal data training as a "one-time" activity, but need to maintain it regularly along with the process of updating laws and changing technology.
In many cases, just a short but focused training session can also help businesses prevent huge risks in the future.
It can be seen that if technology is a "technical barrier" that protects data, then workers' perception is a "human barrier". A strong security system can still be broken by an ignorant or careless personnel. Therefore, legal training on personal data protection for employees is no longer a formal activity, but should be considered an essential part of the risk management and sustainable development strategy of enterprises.
+84 28 7308 0839
