{"id":2552,"date":"2026-09-23T23:55:34","date_gmt":"2026-09-23T16:55:34","guid":{"rendered":"https:\/\/kmunion.vn\/en\/?p=2552"},"modified":"2026-09-23T23:55:34","modified_gmt":"2026-09-23T16:55:34","slug":"vietnam-data-breach-72-hour-notification","status":"publish","type":"post","link":"https:\/\/kmunion.vn\/en\/vietnam-data-breach-72-hour-notification.html","title":{"rendered":"Personal Data Breaches and Vietnam 72 Hour Notification Rules"},"content":{"rendered":"<p class=\"km-updated\">Updated: 23 September 2026<\/p>\n<p>The Personal Data Protection Law&#x27;s 72-hour deadline concerns breach notification in prescribed cases. It is not a period during which a business may wait before responding. As soon as signs of unauthorised access are detected, the business should contain the effects while identifying the data involved and notification obligations.<\/p>\n<h2>When the 72 hour period starts<\/h2>\n<p>Article 23 of Law No. 91\/2025\/QH15 requires controllers, controllers-cum-processors and third parties to notify breaches they detect that may harm national defence, security, public order or safety, or data subjects&#x27; life, health, honour, dignity or property. The deadline is no later than 72 hours after detecting the violation.<\/p>\n<p>It is therefore inaccurate to say that every technical alert requires notification through the same procedure. Nor should a business wait until all damage is established before starting the clock. Record the detection time, available information, impact assessment and reasons for the notification decision at that point.<\/p>\n<h2>Whom processors must notify<\/h2>\n<p>Article 23 requires processors to notify controllers promptly when a breach is detected. A provider discovering unauthorised access to customer data may not satisfy this duty by waiting for a monthly report. Contracts should establish contacts, communication channels and information-sharing arrangements compatible with the controller&#x27;s deadline.<\/p>\n<p>For example, a software provider detects an unusual customer file export by a support account. It should preserve relevant information, restrict further access and inform the controller as required. The business must still assess its own duties; the provider&#x27;s email cannot automatically be treated as notification to a state authority.<\/p>\n<h2>What the notification must contain<\/h2>\n<p>Article 28 of Decree No. 356\/2025\/ND-CP prescribes Form No. 08. Key information includes the time, location and nature of the incident; data types and volume; contact details; actual or potential consequences; and response and mitigation measures. The recipient is the prescribed specialised personal data protection authority.<\/p>\n<p>If information is incomplete, follow Article 28&#x27;s notification and supplementation procedure instead of delaying everything. Separate confirmed facts from estimates under investigation. Article 29 contains additional provisions for biometric and location data; assess overlapping duties according to the affected data.<\/p>\n<h2>Actions to take alongside notification<\/h2>\n<p>Article 23 requires recording violations and implementing response and remediation measures. A business can assign an incident coordination team with technical, data protection and decision-making representatives. Retain logs, configurations, timestamps and communications under controlled conditions to support verification.<\/p>\n<p>Do not erase all traces simply to \u201cclean the system\u201d. Isolation measures must balance containment with investigative needs. After the initial response, review the cause, access rights, contracts and impact assessment dossiers. Incident findings can improve governance, without guaranteeing that recurrence is impossible.<\/p>\n<h2>One incident may trigger several notification duties<\/h2>\n<p>Article 23(3) also requires notification when violations, processing for incorrect purposes, non-compliance with agreements or failures to safeguard data subjects&#x27; rights are detected. Do not assess only the harm threshold in paragraph 1 and conclude that low risk means no reporting. Read both paragraphs separately with the implementing rules; the 72-hour deadline must not be automatically applied to every other notification duty.<\/p>\n<p>If an incident involves information systems or AI, also review cybersecurity law, security level rules and Article 12 of the Artificial Intelligence Law. Notification to the data protection authority, sector-specific reporting and contractual customer notices may have different recipients, contents and deadlines. An email to a provider does not fulfil all these obligations.<\/p>\n<h2>Documents to review after technical remediation<\/h2>\n<p>If excessive subcontractor access caused the incident, configuration fixes should be accompanied by reviews of contracts, permissions and impact assessments. If a copy used for AI was exposed, reassess the purpose and storage scope. Retain the timeline, grounds for notification decisions and remediation results to demonstrate accountability.<\/p>\n<p>An incident often raises the next question: who can access the data, and why? The cloud and security level dossier articles help examine both issues before another incident occurs.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>Must every leak be fully disclosed to the public? That does not follow from the duty to notify the specialised authority. Separately identify duties to inform affected individuals and any applicable sector-specific duties.<\/strong><\/p>\n<p><strong>Does 72 hours mean working hours or three working days? Article 23 uses hours. Do not convert this into working days or exclude weekends.<\/strong><\/p>\n<p><strong>Does hiring an incident response firm replace notification responsibility? No. A support provider may perform assigned work, but each party&#x27;s statutory responsibilities must still be identified.<\/strong><\/p>\n<h2>Legal sources<\/h2>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=214590&amp;pageid=27160\">Personal Data Protection Law No. 91\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216387&amp;pageid=27160\">Decree No. 356\/2025\/ND-CP implementing personal data protection requirements<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216499&amp;pageid=27160\">Cybersecurity Law No. 116\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-331-2026-nd-cp-470334.htm\">Decree No. 331\/2026\/ND-CP on cybersecurity assurance by security level<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216334&amp;pageid=27160\">Artificial Intelligence Law No. 134\/2025\/QH15<\/a><\/p>\n<p><em>Sources checked through 23 September 2026.<\/em><\/p>\n<h2>Related articles<\/h2>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-business-responsibilities.html\">Article 02  Vietnam Personal Data Protection Law and Business Responsibilities in 2026<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-impact-assessment-dossier.html\">Article 04  Vietnam Personal Data Processing Impact Assessment Requirements<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-system-security-level-dossier-approval.html\">Article 12  Vietnam Information System Security Level Dossiers and Approval Authorities<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-cloud-service-notification-responsibilities.html\">Article 19  Vietnam Cloud Service Notification and Data Protection Responsibilities<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-templates.html\">Article 21  Vietnam Personal Data Protection Templates and How to Use Them<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn when Vietnam&#8217;s 72-hour personal data breach notification rule applies, who must report, the receiving authority and the records to keep.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[78],"tags":[],"_links":{"self":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2552"}],"collection":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/comments?post=2552"}],"version-history":[{"count":1,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2552\/revisions"}],"predecessor-version":[{"id":2585,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2552\/revisions\/2585"}],"wp:attachment":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/media?parent=2552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/categories?post=2552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/tags?post=2552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}