In the context of strong digital technology development, incidents involving the leakage and unauthorized disclosure of consumers’ personal data are becoming increasingly common, causing significant damage to the lawful rights and interests of data subjects. This reality necessitates a clear legal framework and effective dispute resolution mechanisms to ensure adequate protection for users. Below, NPLAW provides a detailed analysis of the current situation and the relevant legal provisions governing such issues. 

I. Current situation regarding customers claiming compensation after discovering personal data breaches

In recent years, cyberattacks, data theft, and the exposure of customers’ personal data at organizations and enterprises have become increasingly prevalent. When such incidents occur, customers not only face the risk of misuse of their personal information, such as spam messages and fraudulent phone calls, but may also suffer financial and emotional losses.

Such situations have resulted in a growing number of customers claiming compensation after discovering that their personal data has been exposed in order to recover damages incurred. However, such compensation claims are often complex because it is difficult to establish a direct causal relationship between the data breach and the specific extent of damage suffered by each individual.

II. The concept of customers claiming compensation after discovering personal data breaches

1. What does it mean when customers claim compensation after discovering personal data breaches?

Customers claiming compensation after discovering personal data breaches refers to situations in which a data subject requests the organization or enterprise that controls or processes personal data to compensate for damages arising from the disclosure, loss, misappropriation, or unlawful use of their personal information.

2. How do compensation claims arising from personal data breaches differ from ordinary civil compensation claims?

The distinction between compensation claims due to personal data breaches and those arising from ordinary civil disputes includes the following aspects:

  • Compensation claims due to personal data breaches: The damages primarily concern violations of rights relating to personal data, including both material losses and emotional distress. In addition to compensation obligations, the data-processing entity may also be required to provide notifications, remedy the consequences, and implement additional protective measures in accordance with personal data protection regulations.
  • Ordinary civil compensation claims: These involve material and emotional damages arising from breaches of contractual obligations, violations of legal duties, or other unlawful acts. The focus is primarily on compensation for damages and cessation of the infringing conduct.

In general, while ordinary civil disputes mainly revolve around contractual breaches or violations of legal obligations, compensation claims relating to personal data breaches are directly connected to the protection of privacy rights and personal rights.

3. What evidence should customers prepare when claiming compensation for personal data breaches?

To successfully claim compensation, customers should prepare the following evidence:

  • Evidence of the personal data breach: It may include official notifications from enterprises, reports from media sources regarding the incident, or clear indicators that the information has been exposed, such as spam messages, fraudulent calls targeting specific personal information of the customer, or unauthorized use of accounts.
  • Evidence of material damage: Receipts, invoices, or other documents demonstrating expenses incurred to mitigate the consequences, including financial losses caused by fraud resulting from the leaked information.
  • Evidence of emotional distress: Although difficult to quantify, it may include documents demonstrating psychological impact, disruptions to personal life, or damage to reputation, honor, or dignity.

The preparation of complete documents and credible evidence constitutes a critical legal foundation that strengthens the legitimacy of compensation claims and facilitates a fair resolution for customers after discovering personal data breaches.

III. Legal provisions governing compensation claims for personal data breaches 

1. Principles of compensation following a personal data breach

The principles governing compensation after the disclosure of personal data are provided under Article 585 of the Civil Code 2015 and further guided by Article 3 of Resolution No. 02/2022/NQ-HDTP, including:

  • Damage must be compensated fully and in a timely manner. The parties may agree on the form of compensation, which may be monetary payment, provision of property, or performance of specific obligations.
  • The person liable for compensation may be granted a reduction in the amount of compensation if the damage occurs without fault or due to unintentional fault and the damage is excessively large compared with their financial capacity.
  • If the injured party is partly at fault in causing the damage, they shall not be entitled to compensation for the portion of damage attributable to their own fault.
  • The party whose rights and interests are infringed shall not be compensated if the damage arises from their failure to apply necessary and reasonable measures to prevent or mitigate the damage.

In summary, compensation for damages arising from personal data breaches must be implemented on the basis of full, timely, and equitable compensation, taking into account the element of fault, the financial capacity of the liable party, and the duty of the injured party to take reasonable measures to prevent or minimize damage in accordance with civil law.

2. In which cases are customers entitled to request compensation when personal data is disclosed?

Customers are entitled to request compensation for damages in the following circumstances:

  • An enterprise or a third party unlawfully collects, stores, uses, or transfers personal data, resulting in the disclosure, loss, or misuse of the customer’s personal data.
  • An enterprise fails to implement, or inadequately implements, data protection measures as required by law, leading to cybersecurity incidents, data leaks, or unauthorized intrusions that expose customers’ personal data.
  • An enterprise or third party sells, exchanges, or provides personal data to another party without the valid consent of the customer or without providing notification as required by law.
  • The personal data breach causes actual damage to customers, such as financial loss, fraud, infringement of honor, reputation, or privacy, or costs incurred to prevent or remedy the consequences.
  • An enterprise fails to promptly notify or intentionally conceals a data breach incident, thereby enhancing the damages suffered by customers.

Customers are entitled to claim compensation when the disclosure of personal data results in actual material damages (such as financial loss or incurred expenses) or emotional damages (such as reputational harm or harassment), provided that they can establish a causal relationship between the unlawful act and the damage suffered, in accordance with Decree No. 13/2023/ND-CP and the Civil Code 2015.

3. How is the amount of compensation determined when customers claim damages for personal data breaches?

The amount of compensation when customers claim damages due to personal data breaches is determined in accordance with Articles 589 and 592 of the Civil Code 2015, as guided by Articles 5 and 9 of Resolution No. 02/2022/NQ-HDTP.

  • For material damage: It includes lost, destroyed, or damaged property; benefits associated with the use or exploitation of property that are lost or diminished; and reasonable expenses incurred to prevent, mitigate, or remedy the damage.
  • For emotional damage: Damage arising from infringement upon honor, dignity, or reputation includes reasonable costs incurred to limit or remedy the damage; actual income lost or reduced; and other damages as prescribed by law. The level of compensation for emotional distress is determined by agreement between the parties. If no agreement can be reached, the maximum compensation shall not exceed ten times the statutory base salary prescribed by the State.

Accordingly, compensation for damages caused by personal data breaches is determined based on actual losses incurred, including both material and emotional damages. Priority is given to settlement by mutual agreement between the parties; where no agreement can be reached, compensation will be determined within the statutory limits prescribed by law.

4. What is the typical procedure for customers requesting compensation?

A typical process generally involves the following steps:

  • Evidence collection: Customers must gather evidence relating to both the unlawful conduct and the damages incurred.
  • Submission of a formal request: Customers submit a written compensation request to the enterprise or data-processing entity, clearly stating the damages suffered and the compensation amount sought.
  • Negotiation and mediation: The parties conduct discussions and negotiations to reach an agreement regarding the compensation amount and settlement plan.
  • Complaint or denunciation to competent authorities: If direct negotiation fails, customers may submit complaints or denunciations to competent authorities requesting investigation and handling of the violation, such as the Department of Cybersecurity and High-Tech Crime Prevention under the Ministry of Public Security or the local police authorities.
  • Initiating a lawsuit before the Court: Customers may file a civil lawsuit concerning non-contractual damages before the competent People’s Court.

Understanding and properly following the above procedures will help ensure that customers’ rights and interests are fully protected, while also enabling compensation claims related to personal data breaches to be resolved in the most efficient and timely manner.

IV. Questions regarding compensation claims for personal data breaches

1. In which cases may a company refuse a customer’s compensation request after a personal data breach?

A company may refuse a compensation request if it can demonstrate that:

  • There is no causal relationship: The data breach incident is not the direct cause of the damage suffered by the customer.
  • The damage is entirely attributable to the customer’s fault: The damage occurs due to the customer’s own actions, such as voluntarily sharing information or violating previously communicated security guidelines.
  • Force majeure: The damage arises from force majeure or emergency circumstances where the company had implemented all necessary security measures but could not prevent the incident.

Understanding these grounds for exemption from liability enables enterprises to review claims more carefully and ensures fairness and transparency in resolving complaints.

2. Within what timeframe must enterprises respond to customers’ compensation requests under the law?

Current legislation does not prescribe a specific mandatory timeframe for responding to compensation requests relating to personal data breaches. However, based on the general principle of good faith and cooperation in civil relations, enterprises are expected to respond within a reasonable time from the date of receiving the request.

In addition, Article 23 of Decree No. 13/2023/ND-CP requires enterprises to notify the competent authority (the Department of Cybersecurity and High-Tech Crime Prevention) within 72 hours from the occurrence of a violation of personal data protection regulations, including data leaks or data loss.

3. If enterprises and customers cannot agree on the compensation amount, which dispute resolution methods may be used?

If the parties cannot reach an agreement on compensation, they may choose among the following dispute resolution mechanisms (according to Article 317 of the Commercial Law 2005):

  • Negotiation: The parties voluntarily discuss and settle disagreements to eliminate the dispute without the involvement of a third party.
  • Mediation: A mediation process conducted with the assistance of a mediator selected by the parties, in accordance with Decree No. 22/2017/ND-CP on Commercial Mediation.
  • Arbitration: Submission of the dispute to a commercial arbitration center under the Law on Commercial Arbitration 2010, provided that an arbitration agreement exists.
  • Litigation before the Court: The customer may initiate a civil lawsuit before a competent People’s Court to claim compensation for damages.

Selecting an appropriate dispute resolution mechanism flexibly helps optimize time and costs while ensuring enforceability and legal effectiveness.

4. In cases where multiple customers are affected by the same data breach, may a company apply a general compensation mechanism or must each case be considered individually?

A company may consider applying a general compensation mechanism for damages that are difficult to quantify or for emotional distress, for example, providing a fixed amount of compensation for each affected customer or offering common remedial services such as credit monitoring or cybersecurity insurance.

However, for specific material damages, the company must still examine each case individually based on the evidence of damage provided by each customer. Such an approach must comply with the principle of full compensation for actual damages incurred.

5. Where can customers file complaints if the company refuses compensation or provides inadequate compensation?

Clause 9 Article 9 of Decree No. 13/2023/ND-CP provides that data subjects (customers) have the right to file complaints, denunciations, or initiate lawsuits in accordance with the law. Accordingly, if an enterprise refuses to compensate or provides inadequate compensation, customers may file complaints with the competent authority responsible for personal data protection, namely the Department of Cybersecurity and High-Tech Crime Prevention under the Ministry of Public Security.

In addition, customers may also initiate a lawsuit before the People’s Court to request compensation for damages arising from the enterprise’s violations.

In summary, when enterprises refuse compensation or provide inadequate compensation for damages caused by personal data breaches, customers are entitled to lodge complaints with competent authorities responsible for personal data protection or initiate legal proceedings before the Court to safeguard their lawful rights and interests in accordance with the law.

V. Why you should seek legal advice from NPLaw when facing issues related to compensation claims for personal data breaches

Legal advisory services relating to compensation arising from personal data breaches can assist clients in:

  • Identifying the legal grounds, legitimacy of compensation claims, and the level of legal risk involved.
  • Supporting the collection of necessary technical and legal evidence.
  • Representing customers or enterprises in negotiations to achieve a reasonable compensation agreement.
  • Handling disputes before courts or arbitration tribunals, preparing litigation documents, and participating in legal proceedings to protect lawful rights and interests effectively.

The above information is provided for reference purposes only. Should you have any questions regarding compensation claims following the discovery of personal data breaches, please contact NPLAW so that our team of lawyers can provide direct consultation and comprehensive assistance.