In the context of the 2025 Personal Data Protection Law (“PDP Law”) and Decree 13 imposing stricter requirements on data processing activities, reviewing international case studies is essential for businesses to identify risks and strengthen their compliance frameworks. Incidents involving British Airways, the Academy of Medicine Singapore, Shein, and TikTok demonstrate that even a single gap in security measures, internal procedures, or consent-management mechanisms can result in large-scale data breaches and significant regulatory penalties. This article consolidates and analyses these cases in comparison with the corresponding provisions of the PDPL and Decree 13, with the aim of providing Vietnamese businesses with practical lessons to improve their technical safeguards, privacy policies, and data-governance processes.
Cross-border data transfer and processing is increasingly common in the context of intense digitalization. In order to ensure data security and comply with legal regulations, Decree 165/2025/ND-CP has issued an impact assessment procedure before data is transferred abroad.
The breach of the General Data Protection Regulations (GDPR) at the H&M Service Center in Nuremberg, Germany is an important legal "case study" on the privacy of workers at enterprises. Perhaps this will be an issue that causes controversy and even frequent disputes in the near future in Vietnam, when the Law on Personal Data Protection 2025 will take effect from January 1, 2026.
The protection of children's personal data has become a global concern amid the rapid development of the Internet and social platforms. In the EU, the General Data Protection Regulation (GDPR) has special provisions aimed at protecting children online. Similarly, the U.S. applies the COPPA Child Privacy Protection Act.
The legal framework governing the operation of Data Centers (DC) in Vietnam is built on the basis of basic laws on technology and telecommunications. Initially, the general rules on information technology application and development activities were established in the Law on Information Technology 2006. This law provides general principles, including the right to apply information technology in commerce and regulations on specialized inspections. In parallel, the Telecommunications Law 2023 sets out a framework for the management of telecommunications networks and services, including encouraging infrastructure development.
Businesses that use personal data to serve the goal of promoting products and services may face many obstacles in the near future. They can be sued for ad spam and it is difficult to avoid legal litigation.
Individual customer image data is becoming a valuable resource for businesses. From the use of surveillance cameras in retail stores, facial recognition in payment systems, to image analysis for marketing purposes, businesses are leveraging this type of data to enhance customer experience and optimize business operations. However, in the context that Vietnam is requiring strict protection of personal data, the way businesses collect and process customer image data will have many changes.
For many businesses, in the coming time, marketing activities must be reviewed and shaped new strategies to comply with the new legal framework on personal data protection that Vietnam has issued in 2025. Many new, complex and far-reaching requirements will place many responsibilities on the shoulders of businesses that are not very easy.
Targeted advertising campaigns have become the main tool of businesses in reaching consumers today. From searching for a car, buying a book, or simply stopping for a few seconds in front of a video on social media, the hidden data system then silently records, analyzes, and "personalizes" the next ad that appears on your screen. That's the power of data, but it's also the source of new legal risks, security risks, and personal privacy risks.
Cyberspace has become an integral part of children's lives. From online learning and social media entertainment, to gaming and accessing digital health services, children are generating and sharing vast amounts of personal data. However, children often lack awareness of the risks associated with collecting, using, and sharing this data, leading to problems such as misuse of information, targeted advertising, or even cybersecurity threats. Therefore, the protection of children's personal data in cyberspace has become a top priority in international legal frameworks.
In today's era of strong digitalization, personal data has become a valuable asset but also full of risks for organizations and businesses. With the rise of data breaches and stricter legal regulations, protecting personal information is no longer an option but a mandatory obligation. One of the most important tools for achieving this compliance is Data Mapping – also known as data mapping. Data Mapping not only helps organizations understand their "data panorama" but also serves as a foundation for the implementation of legal requirements for personal data protection globally, especially those from regulatory agencies.
Technology and digitalization are rapidly changing professional professions and legal fields that are not out of that spiral. Artificial Intelligence (AI) has become a powerful tool, helping lawyers and legal professionals improve their work efficiency, from document research to contract analysis. However, this convenience comes with challenges in terms of professional ethics, information security, and liability.