Personal Data Incident Response and Handling Procedure

Under the current legal framework governing personal data protection, it is evident that compliance with the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP is no longer merely an item on a company’s compliance roadmap. Instead, enterprises must construct internal policies and procedures, and fully comply with the requirements prescribed by law. Notably, the contingency plan, or collectively referred to as the sequence of steps for responding to data breach incidents, is no longer solely a problem for the technical department, but has become an urgent legal obligation of the enterprise. This article provides a detailed analysis of the personal data incident response and handling procedure through 9 fundamental steps. Each enterprise should design an appropriate incident response procedure based on its business operations and data flows.

Source: pexels-kanhaiya-sharma-284427440-13062567

1. Step 1: Establishing a Response Framework and Incident Response Preparedness

Enterprises should proactively develop emergency response plans before any incident occurs. Mandatory components include: establishing an Incident Response Team (IR Team) comprising relevant specialized functions (IT/Cybersecurity, Legal, Communications, Human Resources); issuing internal incident handling regulations; developing a severity classification matrix and response activation thresholds; deploying automated monitoring systems, maintaining system logs, and conducting periodic incident response drills. This is a step that many enterprises tend to overlook. However, when a crisis occurs, the absence of predefined procedures may deprive the enterprise of the opportunity to comply with statutory emergency notification requirements imposed by regulatory authorities.

2. Step 2: Detection, Screening, and Incident Identification

Upon receiving warning signals from technical systems, customer complaints, employee reports, or notifications from business partners, the enterprise must immediately determine the nature of the incident: whether it is a general cybersecurity incident or a personal data breach. The enterprise must identify the categories of affected data, assess the proportion of sensitive personal data involved (including financial information, biometric data, behavioral data, etc.), and determine the scope of impacted data subjects.

3. Step 3: Containment and Damage mitigation

Promptly implement technical measures to sever the flow of leaked data and isolate the affected zone: Revoke access privileges of suspicious accounts; Change all administrative credentials and access credentials; Isolate servers, devices, or network segments under attack; Disconnect relevant systems while maintaining data integrity to serve investigation activities. Under the new Law, enterprises have the obligation to proactively prevent any illegal exploitation of data from their systems.

4. Step 4: In-depth investigation and Preservation of legal evidence

Conduct technical analysis to determine the root cause, time of occurrence, intrusion methods, and the destination of the stolen data. Simultaneously, the Incident Response Team must execute a strict evidence preservation procedure: Extract and freeze system logs, access logs, system storage snapshots, and relevant emails and technical reports. The preservation of intact evidence serves not only for fixing technical errors but constitutes a mandatory legal obligation to prove that the enterprise has exerted its utmost efforts when competent authorities conduct inspections or resolve civil disputes.

5. Step 5: Assessment of legal obligations and Notification Requirements and Reporting Obligations

Based on the preliminary investigation results, the Legal Department, in coordination with the Data Protection Officer (DPO), shall review notification obligations:

  • To Regulatory Authorities: Determine the reports, supporting documents, and breach notification forms to be submitted to the Cyber Security and High-Tech Crime Prevention Department (A05 – Ministry of Public Security) within the statutory timeline (must be executed immediately upon detection).
  • To the Data Subjects: Determine the mandatory forms of notification when their data privacy is severely threatened.
  • To Partners: Review Data Processing Agreements (DPA) and Service Level Agreements (SLA) to notify relevant parties in the supply chain.

6. Step 6: Execution of Notification procedure and crisis communication management  

The enterprise shall proceed to submit the personal data breach report to the Cyber Security and High-Tech Crime Prevention Department (A05) in accordance with the prescribed forms. Concurrently, send direct notifications to the affected data subjects in clear, plain, and understandable language, describing the nature of the incident and providing specific guidance on self-protection measures for their assets and personal information. Coordinate closely with outsourced data processors to synchronize information.

7. Step 7: Complete remediation and elimination of root causes

After containing the situation, the enterprise shall implement deep technical measures to completely eliminate risks: Patch system security vulnerabilities; Update software patches; Change encryption keys; Apply Multi-Factor Authentication (MFA) on an organization-wide scale; Review and minimize system access privileges to the maximum extent. If the incident originates from a vulnerability of a third party, require such party to execute the corresponding remediation procedure and require written confirmation that the remediation measures have been completed.

8. Step 8: Restore and operate the system

The system and data shall only be restored to normal operational status after being recovered from clean and secure backups. The recovery process must be executed in phases, under continuous monitoring by malware scanning tools and intensive security checks to ensure that the old vulnerabilities are not re-exploited.

9. Step 9: Incident documentation, Post-incident review, and DPIA update

The enterprise shall complete the Incident Handling Dossier, including: Incident Report, timeline of events, records of management decisions and actions taken, and remediation results. Organize a post-incident evaluation meeting to derive lessons learned and update the internal response procedure. In particular, the enterprise must update its personal data processing impact assessment dossier (DPIA – Form No. 10) to be submitted to the Ministry of Public Security if the incident leads to changes in the technical structure or data flow of the organization. The entire incident dossier must be strictly archived to serve long-term inspection and examination activities.

Based on CDLAF’s practical advisory experience, we have observed that the majority of enterprises focus on the question: “How to prevent incidents?”, but have not adequately prepared for the more critical question: “What will the enterprise do when an incident actually occurs?”

In the context of increasingly stringent personal data protection regulations, the capacity to respond to incidents is not merely a technological matter but also a legal compliance and governance capability of the enterprise. A well-structured incident handling procedure will assist enterprises in minimizing damages, timely fulfilling reporting obligations, and better protecting the lawful rights and interests of data subjects.

Time of writing: June 09, 2026

The article contains general information which is of reference value. In case you want to receive legal opinions on issues you need clarification on, please get in touch with our Lawyer  at  info@cdlaf.vn

Why choose CDLAF’s service?

  • We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
  • We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
  • Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
  • As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
  • CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
  • Strict information security procedures throughout the service performance and even after the service is completed.

You can refer for more information:

 

    SEND CONSULTATION REQUEST