{"id":15111,"date":"2026-06-12T14:30:22","date_gmt":"2026-06-12T07:30:22","guid":{"rendered":"https:\/\/cd.az9s.com\/?p=15111"},"modified":"2026-06-12T14:40:41","modified_gmt":"2026-06-12T07:40:41","slug":"personal-data-incident-response-and-handling-procedure","status":"publish","type":"post","link":"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/","title":{"rendered":"Personal Data Incident Response and Handling Procedure"},"content":{"rendered":"<p><em>Under the current legal framework governing personal data protection, it is <\/em><em>evident that compliance with the <strong>Law on Personal Data Protection No. 91\/2025\/QH15<\/strong> and <strong>Decree No. 356\/2025\/ND-CP<\/strong> is no longer merely an item on a company&#8217;s compliance roadmap. Instead, enterprises must construct internal policies and procedures, and fully comply with the requirements prescribed by law. Notably, the contingency plan, or collectively referred to as the sequence of steps for responding to data breach incidents, is no longer solely a problem for the technical department, but has become an urgent legal obligation of the enterprise. This article provides a detailed analysis of the personal data incident response and handling procedure through 9 fundamental steps. Each enterprise should design an appropriate incident response procedure based on its business operations and data flows.<\/em><\/p>\n<figure id=\"attachment_15103\" aria-describedby=\"caption-attachment-15103\" style=\"width: 711px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-15103\" src=\"http:\/\/cd.az9s.com\/wp-content\/uploads\/2026\/06\/pexels-kanhaiya-sharma-284427440-13062567-1-711x400.jpg\" alt=\"\" width=\"711\" height=\"400\" srcset=\"https:\/\/cd.az9s.com\/wp-content\/uploads\/2026\/06\/pexels-kanhaiya-sharma-284427440-13062567-1-711x400.jpg 711w, https:\/\/cd.az9s.com\/wp-content\/uploads\/2026\/06\/pexels-kanhaiya-sharma-284427440-13062567-1-1400x788.jpg 1400w, https:\/\/cd.az9s.com\/wp-content\/uploads\/2026\/06\/pexels-kanhaiya-sharma-284427440-13062567-1-768x432.jpg 768w, https:\/\/cd.az9s.com\/wp-content\/uploads\/2026\/06\/pexels-kanhaiya-sharma-284427440-13062567-1-1536x864.jpg 1536w, https:\/\/cd.az9s.com\/wp-content\/uploads\/2026\/06\/pexels-kanhaiya-sharma-284427440-13062567-1-2048x1152.jpg 2048w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\" \/><figcaption id=\"caption-attachment-15103\" class=\"wp-caption-text\">Source: pexels-kanhaiya-sharma-284427440-13062567<\/figcaption><\/figure>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of contents:<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #a32411;color:#a32411\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #a32411;color:#a32411\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#1_Step_1_Establishing_a_Response_Framework_and_Incident_Response_Preparedness\" >1. Step 1: Establishing a Response Framework and Incident Response Preparedness<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#2_Step_2_Detection_Screening_and_Incident_Identification\" >2. Step 2: Detection, Screening, and Incident Identification<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#3_Step_3_Containment_and_Damage_mitigation\" >3. Step 3: Containment and Damage mitigation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#4_Step_4_In-depth_investigation_and_Preservation_of_legal_evidence\" >4. Step 4: In-depth investigation and Preservation of legal evidence<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#5_Step_5_Assessment_of_legal_obligations_and_Notification_Requirements_and_Reporting_Obligations\" >5. Step 5: Assessment of legal obligations and Notification Requirements and Reporting Obligations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#6_Step_6_Execution_of_Notification_procedure_and_crisis_communication_management\" >6. Step 6: Execution of Notification procedure and crisis communication management \u00a0<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#7_Step_7_Complete_remediation_and_elimination_of_root_causes\" >7. Step 7: Complete remediation and elimination of root causes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#8_Step_8_Restore_and_operate_the_system\" >8. Step 8: Restore and operate the system<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/cd.az9s.com\/en\/personal-data-incident-response-and-handling-procedure\/#9_Step_9_Incident_documentation_Post-incident_review_and_DPIA_update\" >9. Step 9: Incident documentation, Post-incident review, and DPIA update<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"1_Step_1_Establishing_a_Response_Framework_and_Incident_Response_Preparedness\"><\/span>1. Step 1: Establishing a Response Framework and Incident Response Preparedness<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Enterprises should proactively develop emergency response plans before any incident occurs. Mandatory components include: establishing an Incident Response Team (IR Team) comprising relevant specialized functions (IT\/Cybersecurity, Legal, Communications, Human Resources); issuing internal incident handling regulations; developing a severity classification matrix and response activation thresholds; deploying automated monitoring systems, maintaining system logs, and conducting periodic incident response drills. This is a step that many enterprises tend to overlook. However, when a crisis occurs, the absence of predefined procedures may deprive the enterprise of the opportunity to comply with statutory emergency notification requirements imposed by regulatory authorities.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"2_Step_2_Detection_Screening_and_Incident_Identification\"><\/span>2. Step 2: Detection, Screening, and Incident Identification<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Upon receiving warning signals from technical systems, customer complaints, employee reports, or notifications from business partners, the enterprise must immediately determine the nature of the incident: whether it is a general cybersecurity incident or a personal data breach. The enterprise must identify the categories of affected data, assess the proportion of sensitive personal data involved (including financial information, biometric data, behavioral data, etc.), and determine the scope of impacted data subjects.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"3_Step_3_Containment_and_Damage_mitigation\"><\/span>3. Step 3: Containment and Damage mitigation<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Promptly implement technical measures to sever the flow of leaked data and isolate the affected zone: Revoke access privileges of suspicious accounts; Change all administrative credentials and access credentials; Isolate servers, devices, or network segments under attack; Disconnect relevant systems while maintaining data integrity to serve investigation activities. Under the new Law, enterprises have the obligation to proactively prevent any illegal exploitation of data from their systems.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"4_Step_4_In-depth_investigation_and_Preservation_of_legal_evidence\"><\/span>4. Step 4: In-depth investigation and Preservation of legal evidence<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Conduct technical analysis to determine the root cause, time of occurrence, intrusion methods, and the destination of the stolen data. Simultaneously, the Incident Response Team must execute a strict evidence preservation procedure: Extract and freeze system logs, access logs, system storage snapshots, and relevant emails and technical reports. The preservation of intact evidence serves not only for fixing technical errors but constitutes a mandatory legal obligation to prove that the enterprise has exerted its utmost efforts when competent authorities conduct inspections or resolve civil disputes.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"5_Step_5_Assessment_of_legal_obligations_and_Notification_Requirements_and_Reporting_Obligations\"><\/span>5. Step 5: Assessment of legal obligations and Notification Requirements and Reporting Obligations<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Based on the preliminary investigation results, the Legal Department, in coordination with the Data Protection Officer (DPO), shall review notification obligations:<\/p>\n<ul>\n<li><em>To Regulatory Authorities:<\/em> Determine the reports, supporting documents, and breach notification forms to be submitted to the Cyber Security and High-Tech Crime Prevention Department (A05 &#8211; Ministry of Public Security) within the statutory timeline (must be executed immediately upon detection).<\/li>\n<li><em>To the Data Subjects:<\/em> Determine the mandatory forms of notification when their data privacy is severely threatened.<\/li>\n<li><em>To Partners:<\/em> Review Data Processing Agreements (DPA) and Service Level Agreements (SLA) to notify relevant parties in the supply chain.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"6_Step_6_Execution_of_Notification_procedure_and_crisis_communication_management\"><\/span>6. Step 6: Execution of Notification procedure and crisis communication management \u00a0<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The enterprise shall proceed to submit the personal data breach report to the Cyber Security and High-Tech Crime Prevention Department (A05) in accordance with the prescribed forms. Concurrently, send direct notifications to the affected data subjects in clear, plain, and understandable language, describing the nature of the incident and providing specific guidance on self-protection measures for their assets and personal information. Coordinate closely with outsourced data processors to synchronize information.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"7_Step_7_Complete_remediation_and_elimination_of_root_causes\"><\/span>7. Step 7: Complete remediation and elimination of root causes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>After containing the situation, the enterprise shall implement deep technical measures to completely eliminate risks: Patch system security vulnerabilities; Update software patches; Change encryption keys; Apply Multi-Factor Authentication (MFA) on an organization-wide scale; Review and minimize system access privileges to the maximum extent. If the incident originates from a vulnerability of a third party, require such party to execute the corresponding remediation procedure and require written confirmation that the remediation measures have been completed.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"8_Step_8_Restore_and_operate_the_system\"><\/span>8. Step 8: Restore and operate the system<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The system and data shall only be restored to normal operational status after being recovered from clean and secure backups. The recovery process must be executed in phases, under continuous monitoring by malware scanning tools and intensive security checks to ensure that the old vulnerabilities are not re-exploited.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"9_Step_9_Incident_documentation_Post-incident_review_and_DPIA_update\"><\/span>9. Step 9: Incident documentation, Post-incident review, and DPIA update<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The enterprise shall complete the Incident Handling Dossier, including: Incident Report, timeline of events, records of management decisions and actions taken, and remediation results. Organize a post-incident evaluation meeting to derive lessons learned and update the internal response procedure. In particular, the enterprise must update its personal data processing impact assessment dossier (DPIA &#8211; Form No. 10) to be submitted to the Ministry of Public Security if the incident leads to changes in the technical structure or data flow of the organization. The entire incident dossier must be strictly archived to serve long-term inspection and examination activities.<\/p>\n<p>Based on CDLAF&#8217;s practical advisory experience, we have observed that the majority of enterprises focus on the question: <em>&#8220;How to prevent incidents?&#8221;<\/em>, but have not adequately prepared for the more critical question: <em>&#8220;What will the enterprise do when an incident actually occurs?&#8221;<\/em><\/p>\n<p>In the context of increasingly stringent personal data protection regulations, the capacity to respond to incidents is not merely a technological matter but also a legal compliance and governance capability of the enterprise. A well-structured incident handling procedure will assist enterprises in minimizing damages, timely fulfilling reporting obligations, and better protecting the lawful rights and interests of data subjects.<\/p>\n<p><strong><em>Time<\/em><\/strong><strong><em> of writing<\/em><\/strong><em>: June 09, 2026<\/em><\/p>\n<p><em>The article contains general information which is of reference value. In case you want to receive legal opinions on issues you need clarification on, please get in touch with our Lawyer \u00a0at\u00a0 <a href=\"https:\/\/mail.google.com\/mail\" target=\"_blank\" rel=\"noopener\"><strong>info@cd.az9s.com<\/strong><\/a><\/em><\/p>\n<div class=\"content-post-nd\">\n<div style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-5519 size-full aligncenter\" src=\"http:\/\/cd.az9s.com\/wp-content\/uploads\/2023\/05\/CHUONG-TRINH-THANG.png\" alt=\"\" width=\"1080\" height=\"600\" srcset=\"https:\/\/cd.az9s.com\/wp-content\/uploads\/2023\/05\/CHUONG-TRINH-THANG.png 1080w, https:\/\/cd.az9s.com\/wp-content\/uploads\/2023\/05\/CHUONG-TRINH-THANG-720x400.png 720w, https:\/\/cd.az9s.com\/wp-content\/uploads\/2023\/05\/CHUONG-TRINH-THANG-768x427.png 768w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/div>\n<\/div>\n<div class=\"content-post-nd\">\n<p><strong>Why choose CDLAF\u2019s service?<\/strong><\/p>\n<ul class=\"li-content\">\n<li>We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;<\/li>\n<li>We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;<\/li>\n<li>Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;<\/li>\n<li>As a Vietnamese law firm, we have a thorough understanding of Vietnam&#8217;s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;<\/li>\n<li>CDLAF&#8217;s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.<\/li>\n<li>Strict information security procedures throughout the service performance and even after the service is completed.<\/li>\n<\/ul>\n<\/div>\n<p><strong style=\"color: #a32411;\">You can refer for more information:<\/strong><\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul>\n<li><a href=\"https:\/\/cd.az9s.com\/en\/what-must-social-networks-and-online-platforms-do-to-comply-with-the-personal-data-protection-law-2025\/\">What Must Social Networks and Online Platforms Do to Comply with the Personal Data Protection Law 2025?<\/a><\/li>\n<li><a href=\"https:\/\/cd.az9s.com\/en\/personal-data-in-recruitment-and-labor-management-what-businesses-need-to-note\/\">Personal Data in Recruitment and Labor Management What Businesses Need to Note?<\/a><\/li>\n<li><a href=\"https:\/\/cd.az9s.com\/en\/personal-data-transfer-under-the-2025-personal-data-protection-law-what-businesses-need-to-know\/\">Personal Data Transfer under the 2025 Personal Data Protection Law: What Businesses Need to Know<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n<div class=\"az-fs-contact-form-7\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Under the current legal framework governing personal data protection, it is evident that compliance with the Law on Personal Data Protection No. 91\/2025\/QH15 and Decree No. 356\/2025\/ND-CP is no longer merely an item on a company&#8217;s compliance roadmap. Instead, enterprises must construct internal policies and procedures, and fully comply with the requirements prescribed by law. [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":15103,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[64],"tags":[],"class_list":["post-15111","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"acf":[],"_links":{"self":[{"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/posts\/15111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/comments?post=15111"}],"version-history":[{"count":3,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/posts\/15111\/revisions"}],"predecessor-version":[{"id":15114,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/posts\/15111\/revisions\/15114"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/media\/15103"}],"wp:attachment":[{"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/media?parent=15111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/categories?post=15111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cd.az9s.com\/en\/wp-json\/wp\/v2\/tags?post=15111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}