
Sign up for consultation
Procedures for Notification of Personal Data Protection Violations plays a pivotal role in the mechanism to ensure information security and privacy rights of data subjects. In the context of complex cybersecurity incidents, compliance with this process not only helps organizations avoid administrative penalties but also demonstrates the highest responsibility towards customer privacy. In the following article, Long Phan Consulting Company will analyze this procedure in detail according to legal regulations.

Not every cybersecurity incident needs to be reported. Identifying the correct violation threshold is the first and most important step for effective legal compliance. According to Article 23 of the Personal Data Protection Law 2025, the notification obligation only arises when the enterprise discovers a violation with a risk of causing serious consequences.
Specifically, enterprises must evaluate based on the following factors:
>>>See more: List of Sensitive Personal Data Effective from January 1, 2026
According to Article 28 of Decree 356/2025/ND-CP, the content of the notification includes:

Immediately upon detecting a violation, enterprises need to respond to the incident and carry out immediate preventive measures. According to Article 23 of the Personal Data Protection Law 2025 and Article 28 of Decree 356/2025/ND-CP, the detailed process is as follows:
Step 1: The Personal Data Controller, Personal Data Controller and Processor, or Third Party must notify the specialized personal data protection agency no later than 72 hours from the detection of the violation if it:
Step 2: The Personal Data Controller/Controller and Processor must make a minutes confirming the occurrence of the violation and coordinate with the specialized agency to handle the violation.
Step 3: Agencies, organizations, and individuals notify the specialized agency in cases of discovering violations, wrong purpose processing, failure to ensure rights, or other legal cases.
Step 4: The specialized personal data protection agency receives the notification and handles the violation. Relevant parties are responsible for preventing violations, remedying consequences, and coordinating with the agency.
Step 5: The Personal Data Controller/Controller and Processor/Third Party sends the notification to the specialized agency or via the National Portal on Personal Data Protection using Form No. 08 in the Appendix of Decree 356/2025/ND-CP.
Based on Article 23 of the Personal Data Protection Law 2025 and Article 28 of Decree 356/2025/ND-CP, the notification must be sent no later than 72 hours from detection.
Submission Methods:
Note: If full notification cannot be made within 72 hours, the enterprise can notify in phases, but the initial notification must be sent on time and state the reason for the delay in providing full information.
The notification must be sent to the specialized personal data protection agency under the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention).
>>>See more: Confidentiality agreements between company and employee
The procedure for notifying about violations of personal data protection regulations at Long Phan Consulting Company is designed to help businesses respond quickly and accurately to data breaches. With our team of experienced experts, we are committed to working alongside our clients to optimize processes and minimize potential risks.
Our services include:
Long Phan Consulting Company is proud to be a pioneer in providing comprehensive support services. Let us protect your business from stringent legal risks.

Below, Long Phan Consulting Company provides some frequently asked questions related to procedures for Notification of Personal Data Protection Violations. We invite interested clients to refer to this information:
Yes. According to point c, clause 2, Article 1 of the 2025 Law on Personal Data Protection, this regulation applies to foreign agencies, organizations, and individuals participating in or related to the processing of personal data of Vietnamese citizens and people of Vietnamese origin. If a foreign enterprise processes data of Vietnamese citizens and a violation occurs, they must still comply with the notification process.
Answer: Currently, the 2025 Law on Personal Data Protection stipulates that the Cyber Security and High-Tech Crime Prevention Department (Ministry of Public Security) is the focal point for receiving violation notifications. However, depending on the field of activity, businesses may have the obligation to notify other specialized management agencies (for example, the State Bank of Vietnam for the finance and banking sector).
Yes. According to Article 23 of the 2025 Law on Personal Data Protection, in addition to notifying the Ministry of Public Security, businesses are responsible for notifying data holders about data breaches, except in cases where such actions endanger national security. Notifying customers helps them proactively take measures to protect their assets and personal information.
A risk assessment is necessary. If sending the email by mistake has the potential to harm the reputation, property, or infringe upon the rights of the data subject as defined in Article 23 of the 2025 Personal Data Protection Law (e.g., containing financial information, passwords, etc.), then the business must still follow the notification procedures to avoid future legal risks.
Based on Article 3 of the Law on Personal Data Protection 2025, the principles for protecting personal data from January 1, 2026 are as follows:
The data violation notification process requires accuracy, timeliness, and deep legal understanding. To ensure your business responds effectively to incidents and minimizes legal risks, please contact Long Phan Consulting Company via Hotline 1900636389 for professional assistance.









Note: The content of the articles published on the website of Long Phan Investment Consulting Company is for reference only regarding the application of legal policies. Depending on the time, subject, and amendments, supplements, and replacements of legal policies and legal documents, the consulting content may no longer be appropriate for the situation you are facing or need legal advice on. In case you need specific and in-depth advice according to each case or incident, please contact us through the methods below. With our enthusiasm and dedication, we believe that Long Phan will be a reliable solution provider for our clients.
Leave your email to receive the latest information from us
CONTACT: 1900.63.63.89
Copyright 2024 © Long Phan Consulting Company. All rights reserved.