Data, Privacy & Cybersecurity

Data, Privacy & Cybersecurity

Some cases of international personal data protection violations and lessons for Vietnamese businesses

In the context of the 2025 Personal Data Protection Law (“PDP Law”) and Decree 13 imposing stricter requirements on data processing activities, reviewing international case studies is essential for businesses to identify risks and strengthen their compliance frameworks. Incidents involving British Airways, the Academy of Medicine Singapore, Shein, and TikTok demonstrate that even a single gap in security measures, internal procedures, or consent-management mechanisms can result in large-scale data breaches and significant regulatory penalties. This article consolidates and analyses these cases in comparison with the corresponding provisions of the PDPL and Decree 13, with the aim of providing Vietnamese businesses with practical lessons to improve their technical safeguards, privacy policies, and data-governance processes.

Procedure instructions assessment of impacts on cross-border data transfer and processing

Cross-border data transfer and processing is increasingly common in the context of intense digitalization. In order to ensure data security and comply with legal regulations, Decree 165/2025/ND-CP has issued an impact assessment procedure before data is transferred abroad.

Risks when businesses violate employee privacy

The breach of the General Data Protection Regulations (GDPR) at the H&M Service Center in Nuremberg, Germany is an important legal "case study" on the privacy of workers at enterprises. Perhaps this will be an issue that causes controversy and even frequent disputes in the near future in Vietnam, when the Law on Personal Data Protection 2025 will take effect from January 1, 2026.

EDPB asks to sanction TikTok for infringing on children's privacy and lessons for Vietnam

The protection of children's personal data has become a global concern amid the rapid development of the Internet and social platforms. In the EU, the General Data Protection Regulation (GDPR) has special provisions aimed at protecting children online. Similarly, the U.S. applies the COPPA Child Privacy Protection Act.

Legal framework for Data Center services business in Vietnam

The legal framework governing the operation of Data Centers (DC) in Vietnam is built on the basis of basic laws on technology and telecommunications. Initially, the general rules on information technology application and development activities were established in the Law on Information Technology 2006. This law provides general principles, including the right to apply information technology in commerce and regulations on specialized inspections. In parallel, the Telecommunications Law 2023 sets out a framework for the management of telecommunications networks and services, including encouraging infrastructure development.

How businesses should handle complaints about advertising spam

Businesses that use personal data to serve the goal of promoting products and services may face many obstacles in the near future. They can be sued for ad spam and it is difficult to avoid legal litigation.

Gone are the days of freely collecting and processing customer image data

Individual customer image data is becoming a valuable resource for businesses. From the use of surveillance cameras in retail stores, facial recognition in payment systems, to image analysis for marketing purposes, businesses are leveraging this type of data to enhance customer experience and optimize business operations. However, in the context that Vietnam is requiring strict protection of personal data, the way businesses collect and process customer image data will have many changes.

Business marketing activities must adapt their strategies to comply with personal data protection law in Vietnam

For many businesses, in the coming time, marketing activities must be reviewed and shaped new strategies to comply with the new legal framework on personal data protection that Vietnam has issued in 2025. Many new, complex and far-reaching requirements will place many responsibilities on the shoulders of businesses that are not very easy.

Targeted advertising and the problem of protecting personal data: A legal perspective

Targeted advertising campaigns have become the main tool of businesses in reaching consumers today. From searching for a car, buying a book, or simply stopping for a few seconds in front of a video on social media, the hidden data system then silently records, analyzes, and "personalizes" the next ad that appears on your screen. That's the power of data, but it's also the source of new legal risks, security risks, and personal privacy risks.

Regulations on the protection of children's data in cyberspace of countries and experiences for Vietnam

Cyberspace has become an integral part of children's lives. From online learning and social media entertainment, to gaming and accessing digital health services, children are generating and sharing vast amounts of personal data. However, children often lack awareness of the risks associated with collecting, using, and sharing this data, leading to problems such as misuse of information, targeted advertising, or even cybersecurity threats. Therefore, the protection of children's personal data in cyberspace has become a top priority in international legal frameworks.

Data Mapping – An effective solution to comply with Personal Data Protection Law

In today's era of strong digitalization, personal data has become a valuable asset but also full of risks for organizations and businesses. With the rise of data breaches and stricter legal regulations, protecting personal information is no longer an option but a mandatory obligation. One of the most important tools for achieving this compliance is Data Mapping – also known as data mapping. Data Mapping not only helps organizations understand their "data panorama" but also serves as a foundation for the implementation of legal requirements for personal data protection globally, especially those from regulatory agencies.

Using AI in law practice: Balancing efficiency and professional ethics

Technology and digitalization are rapidly changing professional professions and legal fields that are not out of that spiral. Artificial Intelligence (AI) has become a powerful tool, helping lawyers and legal professionals improve their work efficiency, from document research to contract analysis. However, this convenience comes with challenges in terms of professional ethics, information security, and liability.