No system is absolutely immune to data incidents — what matters is how a company reacts in the first hours. Personal Data Protection Law 91/2025/QH15 (effective 01/01/2026) dedicates Article 23 to breach notification obligations, with a strict mark: no later than 72 hours from discovery of violations that may cause serious harm. This article presents the legal framework and corporate data incident response procedures in practice.
What is a personal data breach under Law 91/2025
Article 23 regulates “violations of personal data protection regulations” — a broader concept than “data leaks” as commonly understood. Under Clause 1 Article 23, the notification obligation arises upon discovering violations that may cause harm to national defence, security, social order and safety or infringe on the life, health, honour, dignity or property of data subjects. The scope includes: cyberattacks stealing databases; employees accessing or copying without authorisation; misconfigurations exposing data; lost storage devices; or providers leaking data.
The “may cause harm” threshold is the important point: the Law does not require actual damage to have occurred before the notification obligation arises. Do not conclude on your own that “no damage yet, no need to report”. In practice, assess cautiously — if the possibility of harm cannot be ruled out, notify — and record it in internal documents.
72-hour notification obligation: who must report, to whom
Clause 1 Article 23 places the notification obligation on three subjects: personal data controllers, personal data controller-processors and third parties — upon discovering violations within the above scope, they must notify the specialised authority (the Ministry of Public Security, Article 33) no later than 72 hours from discovery. Separately, processors (e.g. cloud providers, outsourced units) discovering violations must promptly notify the controller — contracts should specify a concrete mark (e.g. 24 hours) so the controller still has time to meet the 72-hour obligation.
The 72-hour mark counts from the moment of discovery, not from when the incident occurred — an attack may have taken place weeks before being discovered. Therefore, record the discovery moment with objective evidence: system alert logs, internal incident report emails, emergency meeting minutes. This is the first thing authorities check when assessing compliance; without evidence of the discovery moment, the company can hardly defend itself against being deemed late.
Preparing confirmation minutes and coordinating with the specialised authority
Clause 2 Article 23 requires controllers and controller-processors to prepare minutes confirming the occurrence of the violation and coordinate with the specialised authority in handling. The minutes record the incident’s nature, scope of affected data, discovery moment and measures applied — the basis for authorities to cross-check and for the company to prove it met its obligations.
Clause 4 Article 23 allocates responsibilities more broadly: the specialised authority receives notifications and handles violations; controllers, controller-processors, third parties and related parties are responsible for preventing violations, remedying consequences and coordinating with the specialised authority. “Coordination” in practice includes: providing information and system logs for investigation, implementing technical requirements to contain spread, reporting remediation progress. Companies should designate a coordination focal point right in internal procedures — usually legal and IT.
Cases where data subjects and other organisations send notifications
Beyond controllers’ obligations, Clause 3 Article 23 provides that agencies, organisations and individuals notify the specialised authority when: discovering violations; data processed for wrong purposes, inconsistent with agreements with data subjects; data subjects’ rights not ensured or improperly implemented; and other cases under law. This is the channel for data subjects themselves — or anyone discovering violations — to report to the specialised authority.
The consequence: companies cannot count on “quiet internal handling” when incidents have affected data subjects, because subjects may themselves notify the authorities. In that case, having proactively notified on time, prepared minutes and actively remediated is a hugely favourable circumstance compared to being discovered through a subject’s notification while the company stayed silent.
What breach notifications should contain
Clause 5 Article 23 assigns the Government to regulate breach notification contents — details in Decree 356/2025/ND-CP. A complete notification needs: information on the notifier; description of the incident’s nature and discovery moment; affected data types and estimated number of subjects; assessment of possible harm level; measures applied; and a coordination contact.
Prepare an internal incident notification template now, instead of scrambling to draft one under 72-hour pressure when an incident occurs. The template should allow technicians to quickly fill in technical information (affected systems, attack traces, scope), legal to add legal assessment, and leadership to approve before sending. Periodically drilling this procedure is a practice large-scale data companies should adopt.
Internal incident response procedure: from detection to lessons learned
Incident response should include six stages: Stage 1 — Detection and recording: every alert from monitoring systems, employee reports or customer feedback is recorded with exact timestamps — the start of the 72-hour count; Stage 2 — Containment: isolate affected systems, prevent spread, preserve technical evidence; Stage 3 — Assessment: determine data types, number of subjects, possible harm level — deciding the notification obligation’s scope.
Stage 4 — Notification: send notification to the specialised authority within 72 hours; simultaneously notify data subjects in cases prescribed by law (e.g. point d Clause 1 Article 27 for financial and banking organisations when account information is leaked or lost). Stage 5 — Remediation: patch vulnerabilities, reset access rights, support data subjects in minimising damage. Stage 6 — Lessons learned: prepare summary reports, update impact assessment dossiers under Article 22, adjust protection measures. Each stage needs clear owners — usually a cross-functional team: IT, legal, data protection personnel, communications.
Notifying data subjects: when and how
Law 91/2025 sets the obligation to notify the specialised authority (Article 23), while also setting obligations to notify data subjects in certain sector-specific cases — e.g. point d Clause 1 Article 27 for financial, banking and credit information organisations when account information is leaked or lost. Beyond legally prescribed cases, good practice is to proactively notify affected subjects when incidents may cause them actual harm — e.g. leaked login data, stolen financial information.
Notifications to data subjects should be drafted carefully: clearly describe the incident (without hiding but without speculating beyond evidence), affected data types, measures applied, and specific guidance for subjects to protect themselves (change passwords, monitor accounts, whom to contact). Crisis communication directly affects the risk of complaints and damages lawsuits (point dd Clause 1 Article 4). Honest, timely notifications with specific guidance are always better than letting customers learn from the press.
Relationship with impact assessment dossiers and preventive measures
Incident response and prevention are two sides of the same obligation. Impact assessment dossiers under Article 21 require identifying risks and mitigation measures before incidents occur; actual incidents are the test of dossier quality. If dossiers correctly identified risks and mitigation measures were implemented, actual damage is usually lower and the company has a basis to prove it met prevention obligations.
After each incident, companies need to update impact assessment dossiers under Article 22 — the incident is evidence that prior risk assessment may have been incomplete. Review technical measures: encryption (Article 12), access control, access logs, backups and recovery capability. For sensitive data — biometric, financial, health — protection must be proportionate to risk, because when infringed, harm to subjects is direct and hard to remedy. See the general obligations framework of the Law and consent management regulations.
Sanctions for violating incident response obligations
Violating notification and incident response obligations may be subject to administrative sanctions under Article 8, up to VND 3 billion for organisations (Clause 5 Article 8). In addition to fines, companies may have to compensate data subjects under point dd Clause 1 Article 4 and Clause 1 Article 8 — compensation depends on proven actual damage.
Company preparation and support from FLAT
Incident response preparation includes three groups: First, documents: issuing response procedures, recording and notification templates, data subject notification scripts. Second, people: establishing a cross-functional response team, assigning coordination focal points, periodic drills; Third, technology: intrusion monitoring and alerts, complete access logs to determine discovery moments and impact scope — without logs, 72-hour compliance cannot be proven. Privacy notices should also be reviewed to accurately reflect committed procedures. FLAT LAW FIRM supports building incident response procedures, drafting templates and advising on handling when incidents occur.
Frequently asked questions
From when is the 72-hour breach notification deadline counted?
Under Clause 1 Article 23, the 72-hour period counts from discovering the violation — not from when the incident occurred. Record the discovery moment with objective evidence (system logs, report emails, internal minutes), as this is the first thing authorities check.
What must a service provider (processor) do when discovering an incident?
Under Clause 1 Article 23, processors discovering violations must promptly notify the controller or controller-processor. The Law uses the “promptly” standard rather than fixing hours; contracts with providers should specify a concrete mark (e.g. 24 hours) so the controller still has time to meet the 72-hour obligation.
Beyond reporting to authorities, must companies notify affected customers?
Law 91/2025 directly sets the obligation to notify the specialised authority (Article 23) and obligations to notify data subjects in certain sector-specific cases — e.g. financial and banking organisations must notify when account information is leaked or lost (point d Clause 1 Article 27). Good practice is to proactively notify affected subjects when incidents may cause them actual harm, with honest content and specific self-protection guidance.
What is the fine for not notifying incidents within 72 hours?
Violating notification obligations may be subject to administrative sanctions under Article 8, up to VND 3 billion for organisations under Clause 5 Article 8 (the “other violations” group). In addition to fines, companies may have to compensate data subjects under point dd Clause 1 Article 4 and Clause 1 Article 8.
After an incident, must companies update impact assessment dossiers?
They should. Article 22 requires updating impact assessment dossiers when there are changes to sent dossier contents, and an actual incident is evidence that prior risk assessment may have been incomplete. Post-incident dossier updates — adding newly identified risks and remediation measures — both meet obligations and prove lessons learned.
