Company Data is a critical asset, encompassing internal information as well as data relating to customers and business partners. Proper management, security, and legal compliance not only help enterprises avoid legal risks but also ensure sustainable development. This article provides detailed guidance on types of data, access rights, common risks, and effective protective measures.

I. Common Legal Risks Related to Company Data

Company Data, including internal information, customer data, partner data, and intellectual property, constitutes a valuable asset.

If not properly managed, enterprises may face common legal risks such as contractual breaches, leakage of sensitive information, loss of reputation, administrative sanctions, or legal disputes. Identifying these risks enables enterprises to proactively prevent violations, safeguard data, and comply with applicable laws.

II. Understanding Company Data

Company Data serves as a fundamental basis for operations, decision-making, and the maintenance of competitive advantages. A clear understanding of data types, scope of management, access rights, and data security measures allows enterprises to use data effectively while minimizing legal risks and protecting organizational interests.

1. What Is Company Data?

Company Data refers to all information relating to an enterprise’s operations, customers, partners, personnel, and assets, which is collected, stored, and used for management, operation, decision-making, and the effective support of business development.

2. What Types of Company Data Do Enterprises Commonly Manage?

Enterprises manage various types of data to ensure smooth operations and accurate decision-making. Common categories of Company Data include:

  • Customer and partner data: Contact information, contracts, transactions, and interaction history.
  • Internal data: Financial reports, business plans, processes, and strategies.
  • Human resources data: Employee records, payroll information, and training history.
  • Product and service data: Technical specifications, production processes, and warranty information.

Strict management of these data categories enables enterprises to operate efficiently, make informed decisions, and reduce legal risks.

3. Why Is Securing Company Data Essential for Sustainable Development?

Securing Company Data is not only a legal requirement but also a key factor in ensuring stable operations and long-term growth. Effective data security helps to:

  • Prevent legal risks: Avoid violations of data protection regulations and reduce the risk of sanctions or disputes.
  • Protect corporate reputation: Data breaches may undermine the trust of customers, partners, and investors.
  • Support accurate decision-making: Secure internal information enables management to formulate sound strategies.
  • Maintain competitive advantage: Protect sensitive information on products, services, and business strategies from competitors.

Accordingly, data security is a fundamental pillar for stable operations, sustainable development, and the maintenance of competitive advantages.

4. Who Has the Right to Access Company Data Within an Organization?

Access rights to Company Data must be clearly defined to ensure security and effective management. Typically, senior management has full access to data for strategic decision-making; employees are granted access only to data directly related to their assigned duties; data controllers and security officers are responsible for supervising and managing access rights; and partners or third parties are granted limited access only pursuant to clear contractual arrangements or authorizations. Proper allocation of access rights helps protect data, minimize leakage risks, and ensure safe and transparent operations.

5. How Can Company Data Be Leaked?

Company Data may be exposed if security measures are inadequately implemented, leading to legal risks and reputational damage.

  • Human error: Employees may accidentally send emails to incorrect recipients, lose storage devices, or use weak passwords, making data vulnerable.
  • Cyberattacks: Hackers may exploit system vulnerabilities to steal customer information, partner data, or business strategies.
  • Insecure devices or software: The use of inadequately protected computers, software, or networks may result in data breaches.
  • Unauthorized disclosure: Sharing data with third parties without consent or proper controls.

Identifying the causes of data leakage enables enterprises to implement appropriate security measures, protect data, mitigate risks, and preserve corporate reputation.

III. Legal Regulations Applicable to Company Data

The management and protection of Company Data are not merely internal matters but are subject to legal regulation. Enterprises must comply with regulations on security, access rights, processing, sharing, and data retention to ensure information security, avoid legal risks, and protect the legitimate interests of relevant parties.

1. Can Company Data Be Amended or Deleted, and Who Has the Authority to Do So?

Company Data may be amended or deleted in cases permitted by personal data protection laws. Pursuant to Article 16 of Decree No. 13/2023/NĐ-CP, data subjects have the right to request rectification of inaccurate data and deletion of data in legally permitted circumstances. The implementation of such requests falls under the responsibility of the Data Controller, while the Data Processor must cooperate to ensure full and accurate compliance.

Enterprises must consider statutory data retention obligations before deleting data, while ensuring the rights of data subjects, so that data remains accurate and lawfully protected.

2. How Does Vietnamese Law Regulate the Protection of Company Data?

The protection of Company Data is mandatory under Vietnamese law, primarily governed by Decree No. 13/2023/NĐ-CP, which aims to ensure data security, accuracy, and lawful use in business activities. Specifically:

  • Article 3: Personal data must be processed lawfully, for proper purposes, within limited scope, kept up to date, and protected throughout the processing lifecycle. The Data Controller bears responsibility for compliance and proof thereof.
  • Article 8: Prohibits unlawful data processing that affects national security, social order, or the lawful rights and interests of organizations or individuals, or obstructs competent authorities.
  • Article 10: Data subjects are obliged to protect their own personal data, provide accurate information when consenting to processing, respect others’ data, and participate in the prevention of violations.
  • Article 21: In marketing activities, personal data may only be used with customer consent, based on transparency regarding usage, and enterprises must demonstrate lawful compliance.
  • Article 26: Data protection measures must be applied from the outset and throughout processing, including managerial, technical, regulatory, and judicial measures, to ensure data is not lost, leaked, or damaged.

Enterprises must fully comply with these regulations and apply appropriate technical and managerial measures to protect Company Data, safeguard data subject rights, and avoid legal risks.

3. What Violations Commonly Occur in the Processing of Company Data?

The processing of Company Data is invariably associated with legal risks. Identifying common violations enables enterprises to take preventive measures, ensure legal compliance, and protect their lawful rights and interests.

In practice, common violations in the processing of Company Data include:

  • Unlawful data processing: Using, amending, storing, or sharing data in contravention of the provisions of Decree No. 13/2023/NĐ-CP.
  • Processing for improper purposes: Data collected for a specific purpose is used for other unauthorized purposes.
  • Data leakage or loss: Inadequate security measures resulting in data being disclosed, stolen, or damaged.
  • Failure to respect data subject rights: Failing to provide access, rectification, erasure, or refusing lawful requests of data subjects as prescribed by law.
  • Use of data for prohibited activities: Such as unlawful marketing or infringement upon the lawful rights and interests of customers or other organizations.

These violations give rise to legal risks and damage corporate reputation; therefore, enterprises must apply appropriate managerial and technical measures and ensure legal compliance to guarantee that Company Data is processed lawfully and securely.

4. Does Failure to Notify Data Subjects of the Methods of Collecting Company Data Constitute a Violation?

Failure to notify data subjects of the methods of collecting and processing Company Data constitutes a violation of law.

Pursuant to Articles 9 and 13 of Decree No. 13/2023/NĐ-CP, data subjects have the right to be informed of the processing of their personal data, and the Data Controller is obliged to notify in advance the purposes, types of data collected, and methods of processing. Failure to provide such notification infringes upon the principles of transparency and data subject control, thereby exposing enterprises to legal liability.

Accordingly, enterprises must provide clear and comprehensive notice of data collection activities to ensure legal compliance, protect individual rights, and mitigate legal risks.

IV. Frequently Asked Questions Regarding Company Data

In the course of managing Company Data, enterprises often encounter questions relating to access rights, security, risks, and legal obligations. Clarifying these issues helps enterprises prevent violations and ensure compliance with the law.

1. What Types of Company Data Are Considered Sensitive and Require Special Protection?

Certain categories of Company Data are deemed sensitive, as their infringement may directly affect the lawful rights and interests of relevant individuals or organizations.

Pursuant to Clause 4, Article 2 of Decree No. 13/2023/NĐ-CP, sensitive data include:

  • Political or religious views;
  • Health status and private life (medical records);
  • Racial or ethnic origin;
  • Genetic data and unique biometric characteristics;
  • Information on sexual life and sexual orientation;
  • Data relating to crimes and criminal conduct;
  • Customer information of credit institutions, banks, and payment service providers;
  • Personal location data;
  • Other specific data as prescribed by law.

Under Article 28 of Decree No. 13/2023/NĐ-CP, sensitive data must be subject to appropriate managerial and technical protection measures, and enterprises must clearly designate departments and personnel responsible for managing and protecting such data.

Enterprises must identify sensitive data and apply stringent protection measures, while ensuring transparency with data subjects to mitigate legal risks.

2. Under What Circumstances May a Company Be Subject to Criminal Prosecution for Data Leakage?

Where a company collects, stores, or manages customer data, including sensitive data relating to bank accounts, and unlawfully collects, stores, exchanges, trades, or discloses such information, and where the statutory constituent elements are satisfied – such as the number of accounts involved, unlawful gains, organized or professional nature, or recidivism – the company and responsible individuals may be subject to criminal liability.

Pursuant to Article 291 of the 2015 Penal Code on the Crime of Illegal Collection, Storage, Exchange, Trading, or Disclosure of Information on Bank Accounts:

  • Acts involving 20–50 accounts or unlawful gains of VND 20–50 million: a fine of VND 20–100 million or non-custodial reform for up to 3 years.
  • Acts involving 50–200 accounts, committed in an organized or professional manner, unlawful gains of VND 50–200 million, or dangerous recidivism: a fine of VND 100–200 million or imprisonment from 3 months to 2 years.
  • Acts involving 200 or more accounts or unlawful gains of VND 200 million or more: a fine of VND 200–500 million or imprisonment from 2 to 7 years, with possible additional penalties such as prohibition from holding certain positions, practicing certain professions, or confiscation of property.

If a company or data manager allows Company Data to be leaked under the above circumstances and the elements of a crime are established, competent authorities may initiate criminal proceedings and apply additional measures to address the consequences.

3. What Procedures Are Required to Detect and Remedy Company Data Leakage?

To protect Company Data, the detection and remediation of data leakage must follow a stringent process to minimize damage and ensure legal compliance.

Steps to be taken by the company:

Step 1: Detection and incident assessment

  • Identify the type of data leaked (e.g., customer information, sensitive data, internal accounts).
  • Assess the scope and severity of the incident.
  • Preserve evidence for investigation and potential legal action.

Step 2: Containment and control

  • Disconnect or secure compromised systems to prevent further leakage.
  • Implement technical measures such as changing passwords, patching software vulnerabilities, and restoring data from backups.
  • Monitor abnormal activities to prevent further unauthorized access.

Step 3: Notification and remediation

  • Promptly notify management, relevant departments, affected customers, and competent authorities as required by law.
  • Investigate root causes and remediate security vulnerabilities.
  • Provide support to affected customers where necessary, such as guidance on changing credentials, protecting accounts, or compensating damages.
  • Review and upgrade security systems and conduct employee training to prevent recurrence.

Full implementation of these steps helps enterprises mitigate damage, protect customer rights, and ensure compliance with data protection laws.

4. If Company Data Is Leaked, What Steps Must an Enterprise Take to Address the Incident?

Where Company Data is leaked, enterprises are obliged to implement response measures in accordance with Article 23 of Decree No. 13/2023/NĐ-CP to notify, coordinate handling, and mitigate damage.

Required steps:

Step 1: Notification of the violation

  • The Personal Data Controller or the Personal Data Controller and Processor must notify the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) within 72 hours from detection of the violation, stating reasons for any delay.
  • The Personal Data Processor must promptly notify the Personal Data Controller upon detecting the violation.

Step 2: Contents of notification

  • A detailed description of the incident, including time, location, conduct, type, and volume of affected data.
  • Contact details of the responsible personnel or organization for data protection.
  • Potential consequences, damages, and measures taken to remedy and mitigate harm.
  • Where information is incomplete, notification may be made in stages.

Step 3: Record and coordination

  • Prepare a written record confirming the violation.
  • Coordinate with the Ministry of Public Security and relevant authorities to address the violation and remediate consequences.

Compliance with these steps not only mitigates risks and damage arising from data leakage but also ensures adherence to personal data protection laws.

5. How Can Company Data Be Protected to Avoid Legal Disputes?

To avoid legal disputes, Company Data must be comprehensively protected through managerial and technical measures in accordance with Article 26 of Decree No. 13/2023/NĐ-CP.

  • Application from the outset and throughout processing (Clause 1, Article 26): Protective measures must be established from data collection, storage, processing, to erasure.
  • Managerial measures (Clause 2(a), Article 26): Establish internal regulations, define access rights, and train personnel on data security.
  • Technical measures (Clause 2(b), Article 26): Implement encryption, firewalls, access monitoring systems, and data backups.
  • State authority measures (Clause 2(c), Article 26): Comply with guidance, inspections, and supervision by competent authorities.
  • Investigative and judicial measures (Clause 2(d), Article 26): Cooperate with law enforcement authorities in handling data-related violations.
  • Other measures (Clause 2(dd), Article 26): Apply additional lawful measures to ensure data security and prevent legal risks.

Full implementation of the measures prescribed under Article 26 of Decree No. 13/2023/NĐ-CP enables enterprises to ensure information security, avoid legal risks, and enhance business credibility.

V. Are You Seeking a Reputable Law Firm to Support Issues Related to Company Data?

If your enterprise encounters difficulties in developing data protection policies, handling data leakage risks, or complying with personal data protection regulations, NPLaw is a trusted legal partner. With a team of lawyers experienced in data protection, cybersecurity, and compliance with Decree No. 13/2023/NĐ-CP, NPLaw can assist in drafting data processing agreements, establishing security procedures, training personnel, and representing enterprises in disputes or regulatory inspections. Contact NPLaw today to ensure safe operations, protect corporate reputation, and maintain legal compliance.

The above information is provided for reference purposes only. For detailed advice on specific cases, clients are advised to contact NPLaw for prompt consultation.