Data breaches and cyberattacks can cause numerous consequences for an enterprise, ranging from business interruption and financial loss to arising obligations toward customers, employees, and competent state authorities. In the context of regulations on personal data protection and cybersecurity imposing increasingly specific requirements on enterprises, the prevention, detection, and response to incidents is no longer merely a technology department issue but has become a crucial element of corporate governance.
Acting as the representative of the enterprise in legal relations, the legal representative may participate in organizing risk management mechanisms, assigning responsibilities, ensuring resources, and directing incident response within their scope of authority. Concurrently, the way the enterprise prepares for and responds to incidents may also be a factor considered when assessing the performance of obligations by enterprise managers.
Thus, in the event of a data breach or cyberattack, how is the liability of the legal representative determined? What obligations must the representative fulfill in preventing and responding to such incidents?
The following article by CDLAF Law Firm analyzes the role and legal liability of the legal representative when an enterprise experiences a data breach or cyberattack, based on the provisions of the Personal Data Protection Law 2025, Decree 356/2025/ND-CP, Cybersecurity Law 2025, and Law on Enterprises 2020.

1. The role of the legal representative in data and cybersecurity risk management
According to the Law on Enterprises 2020, the legal representative is the person who, on behalf of the enterprise, exercises rights and performs obligations arising from the enterprise’s transactions and represents the enterprise in the capacity of a petitioner for civil matter resolution, plaintiff, defendant, or person with related rights and obligations before competent authorities. In the field of data protection and cybersecurity, this role is manifested in two aspects:
- External representation role: The legal representative is the entity representing the enterprise when working with specialized agencies for personal data protection, police agencies, and specialized inspectorates during the process of verifying and handling incidents.
- Internal governance role: Based on the obligations of management and administration under the Law on Enterprises 2020, the legal representative must organize and ensure that the enterprise has an appropriate governance mechanism for data and cybersecurity risks, including assigning responsibilities, allocating resources, establishing incident response procedures, and maintaining protective measures in accordance with legal requirements.
Therefore, when an incident occurs, whether the enterprise has established and implemented appropriate governance, protection, and response mechanisms is one of the factors considered when evaluating the liability of the enterprise and the legal representative.
2. Incident response obligations in the event of data breaches and cyberattacks
In cases where the enterprise acts as a personal data controller, personal data controller-processor, or personal data processor under the provisions of the Personal Data Protection Law 2025, the enterprise is responsible for fulfilling obligations related to detecting, notifying, and handling violations in accordance with relevant laws on personal data. The legal representative, within their authority, plays the role of organizing and directing the implementation of these obligations.
Accordingly, upon detecting a data breach or cyberattack, the enterprise must take the following steps:
Step 1. Activate internal incident response procedures; verify the scope, level of impact, and type of data exposed (basic data or sensitive data); and concurrently, the personal data controller and personal data controller-processor must prepare a violation confirmation record as prescribed in Clause 2, Article 23 of the Personal Data Protection Law 2025.
Step 2. In cases where the violation is likely to cause harm to national defense, national security, social order and safety, or infringe upon the life, health, honor, dignity, or property of the data subject, the enterprise must notify the specialized agency for personal data protection within a period not exceeding 72 hours from the time of detecting the violation, and notify the affected data subjects in cases involving the leakage or loss of sensitive personal data that infringes upon the material or spiritual rights and interests of the data subject (Clause 1, Article 23 of the Personal Data Protection Law 2025). The notification should clearly state: the time of discovery, the type of data affected, the level of risk, remedial measures, and the contact point responsible for data protection
Step 3. Simultaneously, if the incident originates from a cyberattack (unauthorized intrusion, malware distribution, denial-of-service attack, etc.), according to Article 41 of the Cybersecurity Law 2025, the enterprise providing services in cyberspace must immediately deploy an emergency response plan to ensure cybersecurity and report immediately to the specialized cybersecurity task force under the Ministry of Public Security (or the Ministry of National Defense for military information systems). For information system administrators in general, Article 40 of the Cybersecurity Law 2025 also stipulates the responsibility to connect the malware monitoring and prevention system to the National Cybersecurity Center and report cybersecurity incidents to the specialized agency.
Step 4. Review and remediate technical vulnerabilities, re-evaluate the entire data processing procedure, and prepare a dossier of explanation to serve the inspection and examination by competent state authorities (if any).
Delayed notification, incomplete notification, or failure to retain incident response records are direct grounds for competent authorities to consider the liability of the enterprise and the individual manager.
3. Potential Forms of Legal Liability
a. Administrative Liability of the Enterprise
When a data breach or violation of personal data protection regulations occurs, the enterprise may be subject to administrative penalties depending on the nature, severity, and consequences of the violation. Notably, for certain violations in the field of personal data protection, the monetary fine applied to the enterprise may reach up to VND 03 billion. In cases of violating regulations on cross-border transfer of personal data, the maximum monetary fine for an organization may reach up to 5% of its total revenue of the preceding year according to Article 8 of the Personal Data Protection Law 2025.
This is a sanction applied to the enterprise. The liability of the legal representative is considered separately based on their role, authority, and actions in organizing, managing, and performing the enterprise’s data protection obligations.
b. Civil Liability
A data breach or cyberattack can cause damage to the enterprise, customers, employees, or related parties. Firstly, the enterprise may bear liability to compensate for damages arising under civil law provisions, depending on the cause and basis of liability in each case.
At the internal governance level, if the enterprise’s damages arise due to the legal representative breaching their obligations during management and administration, the legal representative may bear personal liability for such damages under Article 13 of the Law on Enterprises 2020. For instance, this liability may be considered if the legal representative fails to implement governance and supervision measures within the scope of their responsibilities, and this failure leads to damages for the enterprise.
c. Criminal Liability
The legal representative does not automatically bear criminal liability merely because the enterprise experiences a data breach or is subject to a cyberattack. Criminal liability is only invoked when the individual commits an act that meets the constituent elements of a crime under the Penal Code. Depending on the specific nature and act, the legal representative may face criminal scrutiny if they directly perform or direct the performance of acts violating data or information systems, such as the Crime of obstructing or disrupting the operation of a computer network, telecommunications network, or electronic device (Article 287), the Crime of illegally providing or using information on computer networks or telecommunications networks (Article 288), or the Crime of illegally intruding into another person’s computer network, telecommunications network, or electronic device (Article 289).
Notably, the Draft Penal Code (amended) is proposing to add several crimes directly related to personal data, including the Crime of infringing on personal data, the Crime of illegally buying and selling personal data, and the Crime of obstructing personal data protection activities. However, these are currently only proposals in the law-making process and are not yet effective. The addition of these crimes indicates a trend toward strengthening criminal handling for acts infringing on personal data, whereby enterprises must proactively review and enhance data governance and protection mechanisms to meet future legal requirements.
4. Recommendations from CDLAF Law Firm
Given the context that the data protection legal framework in Vietnam has been perfected with highly deterrent sanctions, legal representatives and enterprise executive boards should note the following points:
- Proactively develop an Incident Response Plan: Enterprises must have a written procedure, clearly assigning responsibilities to each department and specifying action timelines to ensure compliance with the 72-hour milestone from the time of detecting a violation under the Personal Data Protection Law 2025.
- Appoint personnel/departments in charge of personal data protection: As required by Decree 356/2025/ND-CP, this is not only a compliance obligation but also an important basis to prove that the enterprise and the legal representative have fully exercised their duty of care when a dispute or investigation arises.
- Retain comprehensive records and evidence of compliance: Data protection policies, Data Protection Impact Assessments (DPIA), periodic cybersecurity review records, contracts with third-party data processors, etc., must be systematically stored as a basis for explanation and to minimize the risk of personal liability attribution.
- Review liability demarcation clauses internally and with technology partners: Contracts with storage and data processing service providers (cloud, outsourcing) need to clearly stipulate confidentiality responsibilities and reimbursement mechanisms when an incident arises from a third party’s fault.
- Consider Directors and Officers (D&O) Liability Insurance and cybersecurity insurance: These are supporting tools to mitigate personal financial risks for the legal representative in the event that compensation liabilities arise
Comprehensive Data Protection & Cybersecurity Compliance Advisory Services at CDLAF
CDLAF Law Firm provides comprehensive advisory solutions, assisting enterprises and legal representatives in managing legal risks related to data and cybersecurity:
1. Review current compliance status, develop personal data protection policies and incident response procedures under the Personal Data Protection Law 2025 and Decree 356/2025/ND-CP.2. Advise on demarcating internal responsibilities, draft and review contracts with data processors and technology partners to clarify the responsibilities of the parties and limit legal risks for the enterprise and managers.3. Advise on developing emergency response and cybersecurity incident handling plans, including coordination mechanisms, assignment of responsibilities, and handling steps when an incident occurs.4. Represent and provide explanations to specialized agencies for personal data protection and cybersecurity agencies when an incident occurs.
About the Author & Ecosystem: The article is legally supported by CDLAF and by the expertise of CFT Solutions – a company specializing in Finance – Tax – Accounting. We provide comprehensive management solutions that help enterprises control risks and optimize resources.
📩 BOOK A CONSULTATION WITH CDLAF’S LEGAL TEAM
Do not let procedural errors disrupt your business plans. Contact CDLAF today to receive a preliminary risk assessment from our team of Lawyers and E-commerce Legal Experts:
Hotline/Zalo: [+84 909 668 216]
Email: info@cdlaf.vn

Why choose CDLAF’s service?
- We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
- We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
- Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
- As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
- CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
- Strict information security procedures throughout the service performance and even after the service is completed.
You can refer for more information:
- Transferring Employees to Perform Other Works: Key Considerations for Enterprises
- Lawful Labor Discipline: Procedures and Key Notes for Enterprises
- Non-Compete Agreements In Employment Relationships: Are They Enforceable In Vietnam?
- Determining “Serious Damage” in Disciplinary Dismissal
- What Must Social Networks and Online Platforms Do to Comply with the Personal Data Protection Law 2025?
