The data destruction policy is one of the key policies that agencies and organizations pay close attention to in the process of collecting information and processing customer data. The article below outlines the legal regulations governing data destruction policies and addresses certain related questions, thereby assisting individuals and organizations in protecting their lawful rights and interests.

I. Common legal risks related to data destruction policies

Pursuant to Clause 1 Article 15 of Decree No. 165/2025/ND-CP, common legal risks related to data destruction policies include the following:

  • Privacy risks arising from non-compliance with legal regulations on the privacy rights of data subjects during data processing and data transfer activities.
  • Cybersecurity risks arising from the failure to apply necessary measures to protect non-public data from unauthorized access by external parties or from data leakage.
  • Identification and access management risks arising from the failure to adequately safeguard non-public data against unauthorized access.
  • Other risks in data processing include data sharing risks, which occur when there is an inability to maintain control over shared data; and data management risks arising from inadequate data quality.
  • In addition, agencies and organizations may be subject to administrative penalties for violations in data processing due to non-compliance with regulations on data protection, processing, and destruction.

Accordingly, agencies and organizations may be exposed to the above-mentioned common legal risks in relation to data destruction policies.

II. Overview of data destruction policies

To better understand data destruction policies and the necessity of such policies, NPLaw invites readers to review the following content.

1. What is a data destruction policy?

Pursuant to Clause 6 Article 3 of the 2023 Law on Electronic Transactions, data refers to symbols, letters, numbers, images, sounds, or other similar forms. Furthermore, Point a Clause 1 Article 13 of Decree No. 165/2025/ND-CP defines data destruction as the activity of removing data from the structure or environment in which it is stored and ensuring the elimination of recoverability through overwriting methods or physical destruction.

A data destruction policy is a set of rules and guidelines governing the secure, permanent, and irreversible deletion or destruction of data stored on storage devices. Its purpose is to prevent information security risks and protect data from unauthorized access or use after devices reach the end of their lifecycle, when the data is no longer necessary, or upon request of the data subject.

2. Why is a clear data destruction policy necessary?

The development and implementation of a clear and effective data destruction policy not only helps enterprises save storage space and reduce costs but also ensures legal compliance and the protection of sensitive information. Specifically:

  • Enhancing storage efficiency: Paper documents, records, and unnecessary electronic data can quickly occupy large amounts of space, leading to increased storage costs. By clearly defining document retention and destruction periods, enterprises can reduce clutter, free up valuable space, and significantly cut storage expenses.
  • Ensuring legal compliance: A clear document destruction policy helps enterprises comply with relevant legal regulations and avoid unnecessary legal risks. Many industries are subject to specific legal requirements regarding document retention and destruction. For example, in the healthcare sector, medical records must be retained for a prescribed period before destruction. Failure to comply may result in legal penalties and damage to the enterprise’s reputation.
  • Protecting sensitive information: Sensitive information such as personal data of customers, employees, partners, business secrets, and financial information, if obtained by malicious actors, may cause serious harm to enterprises. Excessive data retention or the absence of a secure destruction process increases the risk of data breaches.
  • Improving operational efficiency: When documents are systematically managed and destroyed, employees can more easily search for and access necessary information.

Accordingly, it is essential for each enterprise, agency, and organization to establish a clear data destruction policy for the above reasons.

3. Is there a difference between a data destruction policy and a data security policy?

Pursuant to Clause 6 Article 3 of the 2023 Law on Electronic Transactions, data refers to symbols, letters, numbers, images, sounds, or other similar forms. Data security refers to the process of protecting digital information from unauthorized access, use, modification, damage, or theft.

A data destruction policy consists of rules and guidelines governing the secure, permanent, and irreversible deletion or destruction of data stored on storage devices.

There are certain differences between data destruction policies and data security policies, specifically:

- Regarding primary objectives:

  • Data destruction policy: To securely and permanently erase data from storage systems, ensuring that such data cannot be recovered after deletion.
  • Data security policy: To prevent unauthorized access, modification, or destruction of data, ensuring the confidentiality, integrity, and availability of information.

- Regarding scope of application:

  • Data destruction policy: Applies when data is no longer necessary, has reached the legally prescribed retention period, or upon request of the data subject.
  • Data security policy: Applies throughout the entire data lifecycle, from collection, storage, and processing to use and sharing.

Accordingly, the differences between data destruction policies and data security policies are as described above.

III. Legal regulations related to data destruction policies

Understanding legal regulations on data destruction policies is a common need among various stakeholders. Acknowledging this, NPLaw sets out the latest applicable legal provisions on data destruction policies as follows.

1. How does Vietnamese law regulate data destruction policies?

Pursuant to Article 26 of the 2024 Law on Data, as guided by Article 13 of Decree No. 165/2025/ND-CP:

  • Data subjects have the right to request data owners and data controllers to destroy the data they have provided, unless otherwise prescribed by law. Data controllers are responsible for establishing procedures and implementing measures and methods for data destruction in accordance with the data subject’s request.
  • State agencies shall organize the regular and continuous adjustment and updating of data and decide on the storage of historical records of activities such as integration, adjustment, updating, copying, transmission, transfer, retrieval, deletion, and destruction of data under their management.
  • Data destruction must be carried out within 72 hours from receipt of the data subject’s request, and the results of data retrieval, deletion, or destruction must be notified to the data owner, unless otherwise prescribed by law. Where data destruction is not feasible, data owners and data controllers must cease data processing and use.
  • Data adjustment and updating refer to the supplementation or modification of one or more data records in a database or information system.

Accordingly, Vietnamese law regulates data destruction policies as outlined above.

2. What violations commonly occur during the implementation of data destruction policies?

Pursuant to Point a Clause 1 Article 13 of Decree No. 165/2025/ND-CP, data destruction is defined as the removal of data from the storage structure or environment and ensuring non-recoverability through overwriting or physical destruction.

Furthermore, pursuant to Clause 1 Article 16 of Decree No. 13/2023/ND-CP, data subjects have the right to request personal data controllers and personal data controllers and processors to delete or destroy their personal data in the following cases:

  • Where the data is no longer necessary for the agreed collection purpose and the data subject accepts any potential consequences arising from the deletion request;
  • Where consent is withdrawn;
  • Where the data subject objects to data processing and the personal data controller or controller and processor lacks legitimate grounds to continue processing;
  • Where personal data is processed inconsistently with the agreed purpose or in violation of the law;
  • Where personal data must be deleted pursuant to legal regulations.
  • Based on the above provisions, common violations during the implementation of data destruction policies include:
  • Violations of personal data protection regulations: Destroying data without complying with personal data protection laws, thereby infringing upon data subjects’ rights and interests.
  • Incomplete data deletion: Failure to thoroughly destroy data, leaving residual traces of sensitive data in other locations, creating opportunities for hackers to recover and access data unlawfully.
  • Destruction contrary to initial agreements: Destroying data in a manner inconsistent with agreements between data subjects and data controllers.
  • Non-compliance with destruction procedures: Inadequate or incomplete destruction procedures, or omission of critical steps, leading to data leaks, information disclosure, or destruction of incorrect data.
  • In summary, agencies and organizations frequently commit the above violations during the implementation of data destruction policies.

3. What risks can a data destruction policy help organizations avoid?

  • Agencies and organizations are required to adopt data destruction policies in the course of their business operations to ensure lawful data processing and handling of customer information. A data destruction policy helps organizations avoid the following risks:
  • Legal violations: Avoidance of severe penalties for violations of privacy and data protection regulations, and mitigation of risks of disputes or litigation.
  • Data breaches: Prevention of sensitive information (customer data, financial data, business secrets) from being stolen or accessed without authorization when storage devices are reused or sold, and reduction of cyberattack risks targeting residual data on obsolete devices.
  • Loss of reputation and customer trust: Avoidance of reputational damage and loss of customer confidence arising from data breach incidents, while demonstrating professionalism and responsibility in personal data protection.
  • Waste of resources and costs: Reduction of storage costs and space by eliminating unnecessary data.

Accordingly, a reasonable data destruction policy can help organizations avoid unnecessary risks and costly penalties.

IV. Questions related to data destruction policies

To further clarify the legal regulations on data destruction policies, below are some frequently asked questions and corresponding explanations.

1. Who is responsible for implementing the data destruction policy within a company?

Pursuant to Article 26 of the 2024 Law on Data, as guided by Article 13 of Decree No. 165/2025/ND-CP:

  • Data subjects have the right to request data owners and data controllers to destroy data they have provided, unless otherwise prescribed by law. Data controllers are responsible for establishing procedures and implementing data destruction measures at the data subject’s request.
  • State agencies shall organize the regular and continuous adjustment and updating of data and decide on the storage of historical records relating to data integration, adjustment, updating, copying, transmission, transfer, retrieval, deletion, and destruction under their management.
  • Data owners and data controllers shall conduct data integration, adjustment, updating, copying, transmission, and transfer in accordance with this Law and other relevant legal regulations.
  • In addition, Clause 10 Article 2 of Decree No. 13/2023/ND-CP defines personal data processors as organizations or individuals that process data on behalf of personal data controllers pursuant to contracts or agreements with such controllers.

Accordingly, responsibility for implementing data destruction policies within a company may rest with the data owner, data controller, or data processor, depending on contractual agreements on data processing with the data subject.

2. What steps are required to carry out data destruction in accordance with a data destruction policy?

Pursuant to Article 26 of the 2024 Law on Data, as guided by Article 13 of Decree No. 165/2025/ND-CP, the following provisions apply:

The data administrator is responsible for establishing procedures and implementing measures and methods for data destruction in accordance with the request of the data subject.

  • State authorities shall organize the regular and continuous adjustment and updating of data; and decide on the retention of historical records of activities involving data integration, adjustment, updating, copying, transmission, transfer, retrieval, deletion, and destruction of data under their management.
  • Data owners and data administrators shall carry out data integration, adjustment, updating, copying, transmission, and transfer in accordance with this Law and other relevant legal regulations.
  • Data deletion and destruction must be carried out within 72 hours from the receipt of the data subject’s request and the results of data retrieval, deletion, or destruction must be notified to the data owner, unless otherwise prescribed by law. Where data deletion or destruction is not feasible, the data owner and data administrator must cease the processing and use of such data.
  • Data adjustment and updating refer to the supplementation or modification of one or more data records in a database or information system.
  • Based on the above provisions, the necessary steps for carrying out data destruction include:
  • Identifying data to be destroyed: Preparing a list of documents and data that are no longer useful, no longer necessary, or have reached the prescribed retention period.
  • Establishing a Data Destruction Committee: Establishing a committee comprising members with appropriate responsibility and authority to review, examine, and approve the list of data prior to destruction, where necessary.
  • Performing data destruction: Conducting data destruction in accordance with the selected methods, ensuring safety, confidentiality, and preventing any disclosure of information.
  • Adjusting and updating data: Supplementing or modifying one or more data records in databases or information systems after data destruction has been completed.

Accordingly, the necessary steps for implementing data destruction under a data destruction policy shall be carried out in accordance with the above provisions.

3. Can a data destruction policy be applied to all types of data, or only to sensitive data?

A data destruction policy may be applied to all types of data, not only sensitive data. The law does not prescribe separate or specific data destruction policies for ordinary personal data and sensitive personal data. The purpose and level of stringency of the policy may vary depending on the type of data and must comply with the general legal regulations on data destruction. For example:

Pursuant to Article 26 of the 2024 Law on Data, as guided by Article 13 of Decree No. 165/2025/ND-CP:

  • The data administrator is responsible for establishing procedures and implementing measures and methods for data destruction at the request of the data subject.
  • Data deletion and destruction must be carried out within 72 hours from the receipt of the data subject’s request and the results of data retrieval, deletion, or destruction must be notified to the data owner, unless otherwise prescribed by law. Where data deletion or destruction is not feasible, the data owner and data administrator must cease data processing and use.

Accordingly, a data destruction policy may be applied to all types of data, and such policy shall be implemented in accordance with the regulations of the relevant authority or organization, or at the request of the data subject.

4. What actions should a company take if data is found to have been improperly destroyed?

If a company’s data is improperly destroyed, the company must prepare a written record identifying the cause and current status of the incident and notify the relevant parties. Thereafter, the company should make efforts to recover the data, contact partners to duplicate or re-confirm data, and carry out remedial actions in accordance with its internal procedures. Depending on the severity and extent of damage, the company may consider initiating legal proceedings or filing complaints in accordance with the law.

Pursuant to Article 23 of Decree No. 13/2023/ND-CP, where a violation of personal data protection regulations is detected, the Personal Data Controller or the Personal Data Controller and Processor must notify the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) no later than 72 hours after the violation occurs, using Form No. 03 in the Appendix to this Decree. In cases of notification after 72 hours, reasons for the delay must be provided.

The Personal Data Processor must notify the Personal Data Controller as soon as possible upon detecting a violation of personal data protection regulations.

The Personal Data Controller and the Personal Data Controller and Processor must prepare a written record confirming the violation of personal data protection regulations and coordinate with the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) in handling such violations.

Organizations and individuals must notify the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) upon detecting the following cases:

  • Detection of violations of the law regarding personal data;
  • Personal data being processed for improper purposes, not in accordance with the original agreement between the data subject and the Personal Data Controller or the Personal Data Controller and Processor, or in violation of legal regulations;
  • Failure to ensure or properly implement the rights of data subjects;
  • Other cases as prescribed by law.

Accordingly, where data is found to have been improperly destroyed, the company must take timely preventive measures and report to the competent authorities in accordance with the above regulations.

5. Can a data destruction policy be amended, and in which cases?

Pursuant to Article 26 of the 2024 Law on Data, as guided by Article 13 of Decree No. 165/2025/ND-CP:

  • The data administrator is responsible for establishing procedures and implementing measures and methods for data destruction at the request of the data subject.
  • Data deletion and destruction must be carried out within 72 hours from the receipt of the data subject’s request and the results of data retrieval, deletion, or destruction must be notified to the data owner, unless otherwise prescribed by law. Where data deletion or destruction is not feasible, the data owner and data administrator must cease data processing and use.

Accordingly, a data destruction policy may be amended in cases where there is a request from the data subject, where legal regulations are amended, or where the organization decides to update its internal policies. Any such amendment must comply with applicable laws and be notified to the data subject in order to ensure their lawful rights and interests.

V. Are you looking for a reputable law firm to support matters related to data destruction policies?

The above information provides responses to common questions regarding data destruction policies as shared by NPLaw with readers. With a team of experienced lawyers and legal professionals, NPLaw provides reputable and professional legal services, ensuring the best possible protection of clients’ lawful rights and interests. Should you require legal assistance, please contact NPLaw for consultation and support.

The above information is for reference purposes only. Should you require detailed advice for a specific case, please contact NPLaw for immediate consultation.