Data Breach Notification Procedure
PART I – PURPOSE, LEGAL BASIS AND DEFINITIONS
Article 1. Purpose
1.1. This Procedure sets out the sequence, timelines, content, and notification responsibilities in the event of a personal data breach, to ensure HiTechCloud complies with its notification obligations under Vietnamese law and applicable international law, while protecting the lawful rights and interests of data subjects.
1.2. This Procedure specializes Article 14 of the Personal Data Protection Policy (PDPD) and operates in close coordination with the Information Security Incident Response Procedure (IR); it applies to every case in which HiTechCloud acts as Data Controller, as both Data Controller and Data Processor, or as Data Processor.
Article 2. Legal basis
- The Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025, Law No. 91/2025/QH15), in particular Article 23 on notification of personal data protection breaches;
- Decree 356/2025/ND-CP detailing the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), in particular Article 28 on breach notification (Form No. 08) — replacing Decree 13/2023/ND-CP from 01/01/2026;
- Cybersecurity Law 2025 (Law No. 116/2025/QH15); Data Law 2024;
- Penal Code 2015 (amended 2017); Civil Code 2015 on damages;
- GDPR (Articles 33 and 34) - applies to data subjects within scope.
Article 3. Definition of “personal data breach”
3.1. “Personal data breach” means an incident that violates personal data protection regulations, including but not limited to personal data being lost; accessed, collected, disclosed, altered, copied, or used without authorization; or destroyed, in a manner that causes or may cause harm to the lawful rights and interests of the data subject, national security, or social order and safety.
PART II - DETECTION, ASSESSMENT, AND CLASSIFICATION
Article 4. Detection and intake
4.1. A data breach may be detected through: monitoring systems (SIEM, DLP, IDS/IPS, EDR); internal reports from staff; reports from Customers or data subjects; notification from a Processor or partner; or notification from an authority or a third party.
4.2. Any suspected data breach must be reported immediately to the DPO and the Incident Response Team (CSIRT) via dpo@photuesoftware.com / report@photuesoftware.com. The 72-hour clock starts from the moment the breach is discovered.
Article 5. Assessment and severity classification
5.1. The DPO works with CSIRT to assess, as quickly as possible: (a) the type of data affected (basic/sensitive); (b) the number of data subjects affected; (c) the cause and scope; (d) the potential for harm to data subjects; (e) the mitigation measures already applied.
5.2. Severity classification:
| Level | Characteristics | Notification obligations |
|---|---|---|
| Critical | Sensitive data (location, biometric, financial, records of unlawful conduct); a large number of data subjects; high risk | Notify A05 and the data subjects within 72 hours |
| Average | Basic data; medium risk | Notify A05 within 72 hours; notify data subjects where there is a risk |
| Low | Contained, with no potential for actual damage | Record in internal files; notify as required by law |
PART III – NOTIFICATION OBLIGATIONS
Article 6. Notification to the specialist authority (A05)
6.1. On detecting a breach of personal data protection rules, the Data Controller or the Data Controller-Processor notify the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention – A05) within 72 hours at the latest from the time the breach is detected, in accordance with Article 23 of the Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025) and Article 28 of Decree 356/2025/ND-CP, using Form 08 issued together with the Decree.
6.2. Where notification is made after the 72-hour deadline, the reason for the delay or incompleteness must be stated.
Article 7. Contents of the notification
7.1. The breach notification must include, at minimum: (a) a description of the nature of the incident, including when and where it occurred; (b) the type and volume of personal data affected; (c) the (estimated) number of data subjects affected; (d) the contact information of the DPO/point of contact; (e) the potential consequences and damage, together with mitigation measures; (f) the remedial measures already taken and planned.
7.2. Where full information cannot be provided within 72 hours, HiTechCloud notifies in stages (supplementary notifications) and states the progress made.
Article 8. Notification to data subjects
8.1. For breaches involving sensitive data (particularly location, biometric, or financial data), or breaches that pose a high risk to the rights and interests of the data subject, HiTechCloud will notify the affected data subject within 72 hours of discovery, or issue a public notice and inform the data subject as soon as possible.
8.2. Notices to data subjects are written in clear, plain language and include: a description of the breach, the categories of data affected, the possible consequences, the measures HiTechCloud has taken, and recommended self-protection steps for the data subject (change passwords, monitor accounts, watch for fraud).
Article 9. Cooperation between controller and processor
9.1. When HiTechCloud acts as the Data Processor (for example, hosting the Customer's database), HiTechCloud notifies the Customer (as Data Controller) without undue delay after discovering a breach, so the Data Controller can fulfill its legal notification obligations; HiTechCloud will also cooperate by providing the necessary information and evidence.
9.2. Where HiTechCloud is the Controller, HiTechCloud is primarily responsible for notifying A05 and the data subjects.
PART IV – RECORDS, REMEDIATION AND LIABILITY
Article 10. Creating and retaining breach records
10.1. Every data breach — including low-severity breaches that do not require wide notification — must be recorded and documented, covering: the sequence of events, the assessment, the notification decision (or the reason for not notifying), the content of any notification given, and the remedial measures taken.
10.2. Violation records are retained at least 5 years from the date remediation is complete, supporting accountability and inspection by the competent authority (Article 31 of Decree No. 356/2025/NĐ-CP).
Article 11. Remediation and prevention of recurrence
11.1. In parallel with the notification, HiTechCloud applies containment and remediation measures under the Incident Response (IR) Process and updates preventive measures under the Information Security System Security Policy.
Article 12. Responsibilities and sanctions
12.1. Failing to notify, notifying late, or deliberately delaying notification may be treated as an administrative violation and dealt with under Article 8 of the Personal Data Protection Law 2025 (fines for organizations of up to VND 3 billion for other personal data protection breaches; up to 5% of the previous year's revenue for cross-border transfer breaches; and up to 10 times the proceeds for trading in data) — in addition to liability for damages and criminal liability under the applicable rules.
12.2. Responsibility for carrying out this Procedure rests with the DPO (lead), CSIRT (technical) and the Legal department (legal review), under the supervision of the Board of Management.
PART V - INTERNATIONAL JURISDICTIONS AND EFFECT
Article 13. Notification under the GDPR and other jurisdictions
13.1. For data subjects in the EU/EEA: notify the supervisory authority within 72 hours under Article 33 GDPR; notify the data subject where there is a high risk, under Article 34 GDPR.
13.2. For data subjects in other jurisdictions that impose their own notification requirements: comply with the rules of the applicable jurisdiction.
Article 14. Effective date
14.1. This procedure takes effect on 1 July 2026 and is reviewed at least every 12 months, or whenever the law changes. The Vietnamese version prevails.