Personal Data Breaches and Vietnam 72 Hour Notification Rules

Updated: 23 September 2026

The Personal Data Protection Law's 72-hour deadline concerns breach notification in prescribed cases. It is not a period during which a business may wait before responding. As soon as signs of unauthorised access are detected, the business should contain the effects while identifying the data involved and notification obligations.

When the 72 hour period starts

Article 23 of Law No. 91/2025/QH15 requires controllers, controllers-cum-processors and third parties to notify breaches they detect that may harm national defence, security, public order or safety, or data subjects' life, health, honour, dignity or property. The deadline is no later than 72 hours after detecting the violation.

It is therefore inaccurate to say that every technical alert requires notification through the same procedure. Nor should a business wait until all damage is established before starting the clock. Record the detection time, available information, impact assessment and reasons for the notification decision at that point.

Whom processors must notify

Article 23 requires processors to notify controllers promptly when a breach is detected. A provider discovering unauthorised access to customer data may not satisfy this duty by waiting for a monthly report. Contracts should establish contacts, communication channels and information-sharing arrangements compatible with the controller's deadline.

For example, a software provider detects an unusual customer file export by a support account. It should preserve relevant information, restrict further access and inform the controller as required. The business must still assess its own duties; the provider's email cannot automatically be treated as notification to a state authority.

What the notification must contain

Article 28 of Decree No. 356/2025/ND-CP prescribes Form No. 08. Key information includes the time, location and nature of the incident; data types and volume; contact details; actual or potential consequences; and response and mitigation measures. The recipient is the prescribed specialised personal data protection authority.

If information is incomplete, follow Article 28's notification and supplementation procedure instead of delaying everything. Separate confirmed facts from estimates under investigation. Article 29 contains additional provisions for biometric and location data; assess overlapping duties according to the affected data.

Actions to take alongside notification

Article 23 requires recording violations and implementing response and remediation measures. A business can assign an incident coordination team with technical, data protection and decision-making representatives. Retain logs, configurations, timestamps and communications under controlled conditions to support verification.

Do not erase all traces simply to “clean the system”. Isolation measures must balance containment with investigative needs. After the initial response, review the cause, access rights, contracts and impact assessment dossiers. Incident findings can improve governance, without guaranteeing that recurrence is impossible.

One incident may trigger several notification duties

Article 23(3) also requires notification when violations, processing for incorrect purposes, non-compliance with agreements or failures to safeguard data subjects' rights are detected. Do not assess only the harm threshold in paragraph 1 and conclude that low risk means no reporting. Read both paragraphs separately with the implementing rules; the 72-hour deadline must not be automatically applied to every other notification duty.

If an incident involves information systems or AI, also review cybersecurity law, security level rules and Article 12 of the Artificial Intelligence Law. Notification to the data protection authority, sector-specific reporting and contractual customer notices may have different recipients, contents and deadlines. An email to a provider does not fulfil all these obligations.

Documents to review after technical remediation

If excessive subcontractor access caused the incident, configuration fixes should be accompanied by reviews of contracts, permissions and impact assessments. If a copy used for AI was exposed, reassess the purpose and storage scope. Retain the timeline, grounds for notification decisions and remediation results to demonstrate accountability.

An incident often raises the next question: who can access the data, and why? The cloud and security level dossier articles help examine both issues before another incident occurs.

Frequently asked questions

Must every leak be fully disclosed to the public? That does not follow from the duty to notify the specialised authority. Separately identify duties to inform affected individuals and any applicable sector-specific duties.

Does 72 hours mean working hours or three working days? Article 23 uses hours. Do not convert this into working days or exclude weekends.

Does hiring an incident response firm replace notification responsibility? No. A support provider may perform assigned work, but each party's statutory responsibilities must still be identified.

Legal sources

Personal Data Protection Law No. 91/2025/QH15

Decree No. 356/2025/ND-CP implementing personal data protection requirements

Cybersecurity Law No. 116/2025/QH15

Decree No. 331/2026/ND-CP on cybersecurity assurance by security level

Artificial Intelligence Law No. 134/2025/QH15

Sources checked through 23 September 2026.

Related articles

Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026

Article 04 Vietnam Personal Data Processing Impact Assessment Requirements

Article 12 Vietnam Information System Security Level Dossiers and Approval Authorities

Article 19 Vietnam Cloud Service Notification and Data Protection Responsibilities

Article 21 Vietnam Personal Data Protection Templates and How to Use Them

Similar Blog Posts

Vietnam Personal Data Protection Templates and How to Use Them

Request reference templates for Vietnam personal data protection and understand their scope and the review…

Vietnam and EU Data Protection and AI Laws Compared by Obligation

Compare Vietnam and EU data protection and AI duties, including DPIAs, 72-hour breach rules, territorial…

Vietnam Cloud Service Notification and Data Protection Responsibilities

Explore Vietnam cloud notification rules for domestic and overseas providers and the data protection responsibilities…

Vietnam Data Centre Services Registration and Licensing

Distinguish Vietnam data centre registration from telecommunications licensing, with provincial authority and processing changes under…
Designed by W.O.A.