Article · June 17, 2026

Law firms, notary offices and the PDPL: protecting client files

Guidance for law firms and notary offices on handling sensitive client files, professional confidentiality, storage and protection under the PDPL.

consent.vn Editorial7 min read

Quick answer

Law firms and notary offices often handle sensitive personal data, from citizen ID card (CCCD), marital status to dispute files, wills, and asset transactions. Under the Personal Data Protection Law (Law 91/2025/QH15), businesses must have a lawful basis for processing, control access, store securely, and have a data breach notification process within 72 hours.

What should law firms and notary offices note about client data under the PDPL?

Treat client files as high-risk data, not just “work papers.” For law firms and notary offices, a file may contain identifying data, financials, family relationships, health, disputes, powers of attorney, and other sensitive materials. Under the rules, each act of collecting, copying, storing, sharing, or transmitting files via email or management software triggers data protection obligations.

Crucially, do not rely solely on “professional confidentiality” as a habit. The PDPL requires organizations to implement technical and organizational measures commensurate with risk: role-based access to files, access logs, file encryption, handover procedures for hard copies, and clear retention periods.

Which client files are usually sensitive data?

Short answer: most real-world files contain sensitive elements or can infer sensitive information.

Common categories include:

  • Contracts, powers of attorney, land/real estate papers, inheritance files.
  • Citizen ID card (CCCD), passports, old household registration books, contact details, biometrics if any.
  • Dispute files, divorce, adoption, guardianship, wills.
  • Payment vouchers, account numbers, assets, debts, guarantees.
  • Scans, photos, audio recordings, emails exchanged with clients.

For notary offices, receiving copies of documents and keeping registers or electronic files are data processing activities. For law firms, reviewing evidence, sending documents via internal collaboration platforms, or using chatbots/AI to summarize files can also trigger third-party control obligations and risk assessments under the rules.

Does professional confidentiality replace PDPL obligations?

No. Professional confidentiality is an important principle, but it does not replace the full set of obligations under the PDPL.

In practice, organizations should separate two layers:

  1. Professional obligations: keep information entrusted by the client confidential.
  2. Personal data compliance obligations: determine processing purposes, inform data subjects, implement safeguards, manage vendors, and handle incidents on time.

Example: a notary office stores a scanned CMND (national ID) of a client on an employee’s personal Google Drive. Even if the employee considers this “internal paperwork,” such storage can violate internal rules and increase the risk of data leakage. Files should be stored on systems controlled by the office, with access controls and the ability to revoke access when staff leave.

SituationPDPL riskRecommended approach
Storing paper files in a shared cabinetPhysical access exposureLocked cabinets, handover logbook, designated custodian
Sending scans via personal emailLoss of control, hard to revokeWork email, expiring links, encryption
Using a shared drive without access controlsIrrelevant staff can view filesPer-matter access control, access logs
Deleting files without an audit trailHard to demonstrate complianceRetention and destruction policy with defined periods

How should law firms and notary offices store files?

Storage must come with purpose, time limits, and security.

Practical principles for SMEs:

  • Only keep what is needed for business purposes and legal obligations.
  • Set specific retention periods for each type of file: contracts, notarization, complaints, accounting, HR.
  • Separate active matters from closed files; avoid “common repositories” open to everyone.
  • Have backup and recovery plans, and record who accessed or edited files.
  • When retention expires, dispose of safely: securely delete files, shred paper, and keep destruction records.

For client data—especially dispute files or wills—limit copying to personal devices. If remote work is needed, use VPN, MFA, strong passwords, and a policy prohibiting local storage outside the system.

  1. Map file flows:

    list where the office receives, enters, scans, sends, stores, and destroys client files, and who touches the data.

  2. Classify data:

    separate identifying data, financials, disputes, health, family relations, and children’s data if any.

  3. Standardize legal bases:

    state clearly the purpose of receiving files, source, recipients, and retention period.

  4. Lock down access rights:

    apply role-based and per-matter access; staff only see the parts they handle.

  5. Set up storage and destruction:

    retention schedules, backups, secure deletion/destruction, and evidence records.

  6. Prepare an incident process:

    if data is leaked, assess impact, isolate systems, and notify of the breach within 72 hours from discovery as required.

What if you use CRM, e-signature, OCR, or AI software?

These tools are not automatically “forbidden” or “allowed,” but they create obligations to manage vendors and data flows. If the software receives file uploads, performs OCR, logs data, or sends data to third parties, the office needs to know where the data goes, who can access it, how long it is stored, and how deletion works when the service ends.

With OCR and AI, the risk often lies in uploading entire files to external services without controlling the scope of use. Under the rules, review data processing terms, limit which staff may use them, and prefer in-house deployment for sensitive data. If unsure of suitability, consult a lawyer or security expert.

How should law firms and notary offices handle a data breach?

Short answer: act immediately, document thoroughly, and notify on time.

If a laptop containing files is lost, a file is sent to the wrong party, or documents are exposed via a public sharing link, the office should:

  • Contain the incident and revoke access if still possible.
  • Record the time of discovery, the data scope, and the number of affected data subjects.
  • Assess potential harm: exposure of identity, asset disputes, reputation, personal safety.
  • Notify of the data breach within 72 hours from discovery as required.
  • Cooperate with competent authorities when requested.

The enforcement authority is the Ministry of Public Security — the Department of Cybersecurity and High-Tech Crime Prevention (A05). Specific penalties will follow the Government’s guiding decree; serious violations may be subject to criminal liability.

Not in every case or solely based on consent. You must identify the correct processing basis under the rules, and still inform data subjects of the purpose, scope, and retention period.
Yes, if the drive has access controls, logging, backups, and a deletion policy. Avoid a single shared folder accessible to all staff.
This may constitute a data breach. Attempt to revoke, record the incident, and consider notifying within 72 hours from discovery as required.
Yes, but you can apply them proportionately to risk. SMEs should prioritize access controls, secure storage, vendor contracts, and incident response first.

If you are building a file storage system, consent.vn can help standardize cookie banners, store consent evidence, and DSAR flows to reduce risk from the outset.

Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement authority A05 at bocongan.gov.vn

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started