At present, many companies fail to promptly notify customers when their data is lost. It directly affects trust and damages corporate reputation. Moreover, such conduct entails significant legal risks. Compliance with notification obligations enables enterprises to safeguard customer interests and avoid potential litigation.

I. Current situation of company’s failure to notify customers of data loss 

In the current context, numerous companies experience data loss incidents but do not provide timely notification to customers. Such behaviors not only reduce trust and corporate credibility but also creates legal exposure and litigation risks. The primary causes include the absence of robust data governance processes, insufficient awareness of statutory notification obligations, or an intention to avoid adverse impacts on corporate image. Such a situation highlights an urgent need for transparency, regulatory compliance, and enhanced protection of customer rights.

II. Understanding the issue of company’s failure to notify customers of data loss 

1. How does the failure to notify customers of data loss affect customer trust?

A company’s failure to notify customers of data loss may severely undermine customer trust. When customers discover that their personal information or critical data has been lost without timely notification, they may feel disregarded, perceive a lack of transparency, and concern the company’s data security practices.

Consequently, brand reputation may be damaged, customer confidence diminished, and the likelihood of continued engagement reduced, potentially leading to negative market feedback. Pursuant to Clause 2, Article 15 of the Law on Cyber Information Security 2015, organizations are obligated to promptly notify data subjects when incidents involving loss or leakage of personal data occur; violations may result in administrative sanctions or civil liability.

2. Why is timely notification of data loss important?

Timely notification of data loss is critically important as it helps mitigate legal risks, maintain corporate reputation, and protect customer rights. Early notification enables customers to take protective measures, such as changing passwords, monitoring financial transactions, or contacting competent authorities. Additionally, prompt disclosure demonstrates transparency and accountability, thereby strengthening trust and long-term customer relationships.

3. What are the indicators that a company has lost data but failed to notify customers?

Warning signs indicating that a company may have experienced data loss without timely notification are crucial for customers to identify potential risks.

Common indicators include:

  • Customer data appearing online: Personal or corporate data is found on forums, social media platforms, or the dark web.
  • Unusual communications: Customers receive emails, messages, or notifications relating to data they did not previously share.
  • System malfunctions: Data management systems experience incidents, yet the company fails to disclose or conceals the data loss.
  • Inconsistencies in records or reports: Discrepancies in reports, contracts, or transactions show potential data compromise.

Early identification of these indicators enables customers to proactively protect their rights and request that companies assume legal responsibility in accordance with applicable laws.

4. Does failure to notify customers of data loss increase the risk of litigation?

When companies remain silent about data loss incidents, customers may perceive their rights as being violated, particularly where personal or sensitive data is exposed. Pursuant to Clause 1, Article 23; Point d, Clause 1, Article 27; and Point d, Clause 1, Article 37 of the Personal Data Protection Law 2025, enterprises are required to notify relevant parties when data-related incidents occur. Failure to comply may result in:

  • Customers initiating lawsuits to claim damages;
  • Administrative sanctions imposed by data protection authorities, including fines or remedial measures;
  • Reputational damage and long-term business losses.

Accordingly, failure to notify customers of data loss not only constitutes a legal violation but also significantly increases the risk of litigation and adversely affects corporate interests.

III. Legal regulations relating to company’s failure to notify customers of data loss 

1. How may companies be sanctioned for failing to notify customers of data loss?

Enterprises that fail to notify customers of data loss may be subject to two primary forms of liability:

Administrative sanctions: Under Article 46 of Decree No. 98/2020/ND-CP, fines ranging from 10,000,000 VND to 20,000,000 VND may be imposed for acts such as:

  • Using customer information for improper purposes or without consent;
  • Failing to ensure the safety, accuracy, and completeness of information during collection, use, or transfer;
  • Denying customers the right to update or correct inaccurate information;
  • Transferring information to third parties without consent, except as otherwise provided by law.

Criminal liability: In serious cases, enterprises may be prosecuted under the Penal Code 2015 (as amended in 2017), including offenses such as:

  • Infringing upon the confidentiality or safety of correspondence, telephone, or telecommunication (Article 159);
  • Illegal provision or use of computer network or telecommunications information (Article 288);
  • Unauthorized access to computer networks, telecommunications networks, or electronic devices (Article 289).

Where a company causes data loss and fails to notify customers, such conduct may infringe upon the lawful rights and interests of customers. Pursuant to Article 584 of the Civil Code 2015, any person causing damage to the life, health, honor, dignity, reputation, property, or other lawful rights and interests of another must provide full compensation.

Thus, failure to notify data loss not only violates the law but also exposes enterprises to significant legal liabilities and reputational harm.

2. What legal provisions require companies to notify customers of data loss?

Under the Personal Data Protection Law 2025, enterprises are obligated to promptly notify relevant parties of data-related incidents to protect customer rights and interests. Specifically:

  • Clause 1, Article 23: Upon detecting a personal data protection breach that may cause harm to life, health, honor, property, or public order and security, data controllers and processors must notify the data protection authority within 72 hours from detection.
  • Point d, Clause 1, Article 27: In specific data processing activities (e.g., finance and banking), enterprises must immediately notify data subjects when personal data is leaked, lost, or exposed.
  • Point d, Clause 1, Article 37: Data controllers and processors must ensure data subject rights, including the right to be informed of data loss incidents and remedial measures.

Additionally, Article 4 provides that data subjects have the right to:

  • Be informed about personal data processing activities;
  • Request access, deletion, or restriction of data processing;
  • File complaints, denunciations, initiate lawsuits, or claim compensation.

Therefore, timely notification of data loss is both a fundamental legal right of customers and a mandatory obligation of enterprises.

3. Who may initiate legal action against a company for failing to notify data loss?

Under the Personal Data Protection Law 2025, companies may face legal actions from the following parties:

  • Data subjects (customers/consumers): They have the right to complain, denounce, initiate lawsuits, or claim damages if their personal data is compromised due to the company’s failure to notify (Point đ, Clause 1, Article 4).
  • State data protection authorities: These authorities may require remedial actions, impose administrative sanctions, or refer cases for criminal prosecution (Clause 4, Article 23; Point d, Clause 2, Article 37).
  • Affected third parties: Partners, suppliers, or other stakeholders suffering damage due to data breaches may also claim compensation or initiate civil proceedings.

Accordingly, failure to notify data loss exposes enterprises to legal liability from multiple parties and significantly impacts their reputation and business operations.

4. Are there any circumstances where companies may be exempt from notification liability?

In practice, enterprises may be exempt from notification obligations in certain circumstances:

  • No actual damage: Where data is leaked or lost but fully encrypted or anonymized, making it impossible to identify individuals, notification may not be required.
  • Force majeure or circumstances beyond reasonable control: Incidents caused by natural disasters or sophisticated cyberattacks, where the enterprise has fully implemented legally required safeguards.
  • Notification to authorities only: In certain cases, if the enterprise has duly reported the incident to competent authorities and no actual impact on customers is identified, direct customer notification may not be required.

Such exemptions apply only where enterprises have implemented adequate data protection measures and can demonstrate that the lack of notification does not cause harm, in compliance with legal requirements.

IV. Questions regarding company’s failure to notify customers of data loss 

1. Can failure to notify customers of data loss constitute a breach of contract?

Failure to notify customers of data loss may constitute a breach of contract if the agreement between the enterprise and the customer includes provisions on confidentiality, data protection obligations, or notification duties in the event of incidents.

Under Point đ, Clause 1, Article 4 of the Personal Data Protection Law 2025, data subjects have the right to claim compensation for damages resulting from violations of their rights. Therefore, failure to notify may lead to contractual disputes and compensation claims.

Accordingly, such conduct may simultaneously constitute a breach of contractual obligations and give rise to significant legal risks.

2. What steps should companies take to ensure timely notification of data loss?

Pursuant to Article 23 of the Personal Data Protection Law 2025, data controllers and processors must promptly notify relevant parties upon detecting data loss incidents. To ensure compliance, enterprises should implement the following steps:

  • Step 1: Detecting and recording the incident: 
  • Identifying the scope and level of impact; recording the incident within 72 hours from detection.
  • Step 2: Conducting internal notification: 
  • Data processors notify data controllers to prepare incident reports for record-keeping.
  • Step 3: Notifying competent authorities: 
  • Submitting notifications to data protection authorities for coordinated handling.
  • Step 4: Notifying customers:
  •  Providing clear and transparent information on the nature, scope, and remedial measures; guiding customers on necessary actions.
  • Step 5: Applying remedy measures and storing documents:
  •  Implementing corrective measures and maintaining records for compliance verification.

Proper implementation of these steps helps protect customer rights, minimize legal risks, and enhance corporate credibility.

3. What can customers do if they discover data loss without notification?

Customers may lodge complaints, file denunciations, initiate lawsuits, or claim damages in accordance with Point đ, Clause 1, Article 4 of the Personal Data Protection Law 2025.

They may also request competent authorities or relevant parties to take measures to protect and restore their personal data. These actions help safeguard customer rights and compel enterprises to fulfill their legal obligations.

4. What legal consequences may arise from failure to notify customers of data loss?

Failure to notify customers of data loss may result in serious legal consequences. Under Article 46 of Decree No. 98/2020/ND-CP, as amended by Clause 5, Article 1 of Decree No. 24/2025/ND-CP, violations relating to consumer information protection may result in fines ranging from 20,000,000 VND to 30,000,000 VND.

For more serious violations, such as failure to notify authorities, failure to ensure data security, or unauthorized data transfer, fines may increase to 30,000,000 VND to 40,000,000 VND. In cases involving sensitive personal data or large digital platforms, sanctions may be multiplied two to four times.

In severe cases, criminal liability may arise under Article 159 of the Penal Code 2015 (as amended in 2017), with sanctions including imprisonment from 1 to 3 years, fines ranging from 5,000,000 VND to 20,000,000 VND, and prohibition from holding certain positions for 1 to 5 years, particularly where aggravating circumstances exist.

Therefore, strict compliance with data protection regulations, transparent data governance processes, and employee training are essential to mitigate legal risks and protect corporate reputation.

V. Are you looking for a reputable lawyer to handle issues related to failure to notify data loss?

If you are experiencing difficulties or seeking to protect your rights in cases where companies fail to notify data loss, NPLaw is ready to provide in-depth legal consultation and support. Our experienced legal team can assist in assessing risks, exercising rights to complaint or litigation, and claiming compensation, while also guiding enterprises in ensuring full legal compliance. Let NPLaw accompany you in safeguarding your rights effectively and securely.

The above information is for reference purposes only. For detailed advice on specific cases, please contact NPLaw for prompt consultation.