Breach of software confidentiality clauses is a serious issue that affects the interests of organizations and individuals and may cause significant damage to business operations. Accordingly, Vietnamese law has established various regulations to govern and manage such matters. The following article by NPLaw provides an in-depth overview of the current legal framework and practical approaches to handling such violations.

I. Current situation of breaches of software confidentiality clauses

In the context of rapid digital transformation, enterprises, organizations, and individuals are increasingly dependent on software for their daily operations. It has inadvertently led to an increasing complexity of breaches of software confidentiality clauses.

Accordingly, breaches of software confidentiality clauses are occurring with greater frequency and becoming more sophisticated. Common breaches include:

  • Software providers unlawfully collecting, sharing, or leaking users’ data.
  • Users interfering with, cracking, or exploiting security vulnerabilities in software.
  • Parties failing to comply with confidentiality commitments stipulated in contracts or terms of use.

Such acts not only constitute legal violations but also cause serious damage to reputation, finances, and personal privacy. Therefore, deterrent sanctions are necessary to limit such situations. 

II. What constitutes a breach of software confidentiality clauses?

Before considering the regulations governing violations of software confidentiality clauses, relevant entities should first understand the basic concepts, typical cases, and methods of resolution when such situations arise in practice.

1. Concept of a breach of software confidentiality clauses

Current legislation does not provide a specific definition of “breach of software confidentiality clauses,” which creates certain difficulties for organizations and individuals in identifying infringing acts.

Accordingly, NPLaw proposes the following general definition: A breach of software confidentiality clauses refers to any act of non-compliance with commitments and regulations relating to confidentiality, data protection, and intellectual property rights as clearly stipulated in agreements between software providers and users.

A clear understanding of such a concept serves as the foundation for identifying acts that constitute violations.

2. Circumstances leading to breaches of software confidentiality clauses

In practice, breaches of software confidentiality clauses are becoming increasingly complex and state in various forms, causing confusion for many organizations and individuals in protecting their lawful interests.

Based on current practice, NPLaw identifies several common circumstances leading to violations, including:

  • Unauthorized disclosure of user information or system data: Intentionally or unintentionally sharing personal information, customer data, or user data with third parties without consent.
  • Unauthorized access to systems: Attempts to access into databases, servers, or software control systems.
  • Illegal copying or distribution of software: Use of pirated or cracked software, or sharing licensed software beyond permitted limits.
  • Failure to notify of incidents: Failure to fulfill the obligation to notify users or competent authorities upon discovery of data breaches.

The above are only some common forms of violations; in reality, such acts may be more diverse and complex, posing challenges to both affected parties and competent authorities in preventing and addressing violations.

3. Remedies when breaches of software confidentiality clauses occur

Given the serious consequences of breaches of software confidentiality clauses, many organizations and individuals seek guidance on how to address such situations in practice.

Although no specific regulation stipulates remedies for breaches of software confidentiality clauses, based on Decree No. 13/2023/NĐ-CP, NPLaw suggests several measures for reference:

  • Immediate cessation of the breaching acts: Upon detection of a breach, prompt measures should be taken to prevent further harm.
  • Remediation of consequences: Implementation of technical and legal measures to mitigate damages arising from the breach. 
  • Initiation of legal action or claims for compensation: Affected parties may file lawsuits or claim damages to protect their lawful interests.

These measures should be applied flexibly depending on the specific circumstances and needs of the affected organizations or individuals.

III. Legal regulations related to breaches of software confidentiality clauses

To limit breaches of software confidentiality clauses, Vietnamese law has promulgated various relevant regulations.

The following analysis by NPLaw clarifies applicable regulations, competent authorities, and potential consequences if breaches are not addressed.

1. Applicable regulations for handling breaches of software confidentiality clauses

When breaches occur, one of the primary concerns is how such issues are addressed under current law.

Pursuant to Article 9 of Decree No. 13/2023/NĐ-CP, data subjects have the following rights:

  • The right to delete or request deletion of their personal data, unless otherwise prescribed by law.
  • The right to request restriction of the processing of their personal data, unless otherwise prescribed by law.
  • The right to file complaints, denunciations, or initiate lawsuits in accordance with law.
  • The right to claim compensation for damages in accordance with law when breaches of personal data protection regulations occur, unless otherwise agreed by the parties or prescribed by law.
  • The right to self-protection or to request competent authorities or organizations to apply civil protection measures in accordance with Article 11 of the Civil Code 2015.

Accordingly, upon discovering breaches of software confidentiality clauses, organizations and individuals may apply the above measures to protect their interests.

2. Competent authorities for handling breaches of software confidentiality clauses

Based on Article 9 and Clause 1 Article 23 of Decree No. 13/2023/NĐ-CP, competence for addressing breaches of software confidentiality clauses may include:

  • Settlement by the parties through negotiation or mediation.
  • The Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention).
  • Courts or commercial arbitration (Clause 9 Article 9 of the Decree).

Depending on the chosen method of dispute resolution, competence will vary accordingly.

3. Consequences if breaches of software confidentiality clauses are not resolved

Breaches of software confidentiality clauses are serious matters; failure to address them promptly may adversely affect both enterprises and users.

Potential consequences include:

  • For users: Risks of property loss, identity theft, or misuse of stolen data for fraudulent purposes.
  • For enterprises: Exposure to legal liabilities, including administrative or criminal liability, as well as compensation claims from users.

In addition, failure to timely address such breaches may result in reputational damage, public concern, and adverse impacts on social stability, particularly in a context where personal data is increasingly regarded as a valuable asset.

IV. Questions regarding breaches of software confidentiality clauses

Below are common questions and answers provided by NPLaw concerning breaches of software confidentiality clauses.

1. How do breaches of software confidentiality clauses affect users’ data protection rights?

Pursuant to Article 9 of Decree No. 13/2023/NĐ-CP, such breaches affect users’ data protection rights in the following respects:

  • The right to restrict data processing: Users may be unable to restrict the processing of their personal data once a breach has occurred.
  • The right to object to personal data processing: Data subjects have the right to object to the processing of their personal data to prevent or limit disclosure or use for advertising and marketing purposes (Point a Clause 8 Article 9 of the Decree). However, breaches compromise the confidentiality of such data.

In summary, breaches of software confidentiality clauses undermine users’ rights to restrict and object to personal data processing.

2. Can the breaching party be required to fully remedy leaked data?

In principle, where a party violates software confidentiality clauses, the affected party may require remediation of consequences according to Article 351 of the Civil Code 2015. Accordingly, the breaching party may be required to remedy all leaked data to mitigate harm.

3. Is it necessary to stipulate emergency handling clauses upon detection of breaches of software confidentiality clauses?

Stipulating emergency handling clauses provides a legal basis for:

  • Clearly defining procedures and timelines for notifying relevant parties of breaches.
  • Clearly allocating responsibilities for handling violations.

Given these advantages, such clauses are necessary.

4. Is suspension of services mandatory upon detection of breaches of software confidentiality clauses?

Currently, there is no regulation mandating suspension of services upon detection of such breaches. However, service suspension may be required upon request of competent authorities or where breaches seriously affect users.

5. Can breaches of software confidentiality clauses render software service contracts invalid?

Pursuant to Clause 1 Article 401 of the Civil Code 2015, there is no provision rendering contracts invalid solely due to breaches of software confidentiality clauses. Therefore, such breaches do not invalidate software service contracts.

However, to protect their interests, affected parties may unilaterally terminate contracts in accordance with Clause 1 Article 428 of the Civil Code 2015.

V. Are you looking for a reputable lawyer to handle issues related to breaches of software confidentiality clauses?

Handling issues related to breaches of software confidentiality clauses requires in-depth knowledge of information technology law, cybersecurity law, personal data protection law, and digital technologies. Accordingly, many organizations and individuals seek legal counsel for accurate legal advice.

With a team of experienced lawyers and many years of practice, NPLaw is a reliable partner for clients seeking assistance with matters related to violations of software confidentiality clauses.

Through the above analysis, NPLaw has provided an overview of breaches of software confidentiality clauses. Understanding these regulations not only helps protect lawful interests but also minimizes potential legal risks.