The disclosure of confidential information of software has become increasingly serious due to various causes, including security vulnerabilities during software development, weak system administration, users’ lack of cybersecurity awareness, and intentional attacks by malicious actors. Such incidents may involve leakage of source code, customer data, trade secrets, or other sensitive information, resulting in substantial damage to businesses and end users.
I. Current situation regarding the disclosure of confidential information of software
The disclosure of confidential information of software has become increasingly serious due to various causes, including security vulnerabilities during software development, weak system administration, users’ lack of cybersecurity awareness, and intentional attacks by malicious actors.

Such incidents may involve leakage of source code, customer data, trade secrets, or other sensitive information, resulting in substantial damage to businesses and end users.
II. Understanding of the disclosure of confidential information of software
To clarify what constitutes the disclosure of confidential information of software and which information must be protected, this section provides the following analysis:
1. What is the disclosure of confidential information of software?
Software refers to a compilation of programs, instructions, and data written in a programming language to enable computers to perform specific tasks.
The disclosure of confidential information of software means the unauthorized sharing or publication of sensitive and commercially valuable software-related information, such as source code, technical know-how, or user data.
2. What types of information are classified as “confidential” and must be protected?
Confidential information of software includes:
- Sensitive user data: Personal information such as name, address, phone number, email, bank account credentials, and passwords.
- Important organizational data: Information such as customer databases, research and development costs, product information, which must be protected to avoid loss, theft, or exposure that could harm both the software provider and business partners.
- Confidential information: Any information not intended for public disclosure.
- Privacy-related information: User privacy rights and personal data protected from unauthorized access.
- Source code and database structures: Core components of the software system that must be safeguarded against unauthorized alteration and theft.
III. Legal regulations governing the disclosure of confidential information of software
1. Acts considered as unauthorized disclosure of confidential information of software
The following acts are deemed violations:
- Unauthorized access and copying: Accessing, misappropriating, or copying source code, designs, algorithms, or any other confidential software data without permission.
- Buy, sale, transfer, donation, modification, or public of confidential information: Trading, transferring, donating, modifying, or publicly disclosing confidential information of software without the owner's authorization.
- Disclosure to third parties: Providing confidential information of software to third parties without consent, causing damage or gaining unfair competitive advantage.
- Unauthorized exploitation and use: Using stolen information for personal gain or unlawful purposes.
- Disclosure of trade secrets: Intentionally disclosing trade secrets, including vulnerabilities or operational mechanisms of the software, without authorization.
- Tampering with security measures: Intentionally removing, modifying, or disabling technical protection measures safeguarding confidential information.
2. Complaint and denunciation procedures for the disclosure of confidential information of software
Denunciation procedures:
- The denouncer must submit a written denunciation to the competent authority. The receiving authority is responsible for processing the complaint in accordance with Article 23 of the Law on Denunciations 2018.
- The competent authority shall issue a denunciation acceptance decision if the legal requirements under Article 29 are satisfied.
- Verification of denunciation: The competent authority conducts investigations or assigns an inspectorate or another competent agency to verify the denunciation (Article 31).
- Conclusion: Based on the denunciation, explanations, documents, and evidence, the authority issues a denunciation conclusion and sends it to relevant parties within 05 working days in accordance with Article 35.
- Implementation of conclusion: Within 05 working days after issuing handling results, the competent authority must inform the denunciation-handling authority in writing.

Complaint procedures:
- The affected party collects evidence and submits a complaint to the software provider, requesting clarification and remediation measures.
- If the provider fails to respond or the response is unsatisfactory, the complainant may file a complaint with:
+ Ministry of Information and Communications;
+ Cyber Security and High-Tech Crime Prevention Department under the Ministry of Public Security. - If the act indicates criminal elements, the complainant may report to the police or competent investigative agency.
- Alternatively, the complainant may file a lawsuit at a competent court according to Article 186 of the Civil Procedure Code 2015.
IV. Questions on the disclosure of confidential information of software
1. What should a business do upon detecting a confidential information leak?
- Containing and isolating the incident: Disconnecting compromised servers or devices, reset credentials, and temporarily suspend affected software functions.
- Collecting evidence and assessing damage: Recording system logs, back up databases, identify leaked data, affected parties, and potential risks.
- Notifying authorities and users: Providing transparent, timely information about the incident and cooperating with competent authorities as required by law.
- Reviewing and reinforcing security policies:Evaluating and enhancing internal security protocols to prevent future breaches.
2. How does the disclosure of confidential information of software affect business reputation?
- Loss of customer trust
- Substantial financial losses, including sanctions and remediation costs
- Loss of competitive advantage due to intellectual property theft
- Legal risks and potential lawsuits from clients and partners
3. How to assess damages caused by the disclosure of confidential information of software?
- Identifying types and scope of leaked information
- Determining origin and method of attack
- Evaluating associated risk levels and impact potential
- Preparing a comprehensive damage report and remediation plan
4. Internal measures to prevent confidential information leaks
- Strict access and account management
- Encryption of sensitive data
- Access control over encrypted information
- Periodic internal and external audits
- Cybersecurity awareness training
- Clear information security policies
- Incident response planning
5. Can unauthorized disclosure of confidential information of software be criminally prosecuted?
Depending on the severity and nature of the disclosed information, criminal sanctions may apply.

For example, unauthorized disclosure of banking information may constitute a criminal offense under Article 291 of the Criminal Code 2015 concerning illegal collection, storage, exchange, or public disclosure of banking information.
V. Legal consultancy services on the disclosure of confidential information of software
The above information is provided by NPLaw to address frequently raised issues related to software confidentiality breaches. With a team of experienced attorneys and legal practitioners, NPLaw offers reliable, professional legal services ensuring optimal protection of clients’ legitimate interests. For legal assistance, please contact: