Guide · June 17, 2026
Ex-employee takes customer data: PDPL response and prevention
PDPL guide when ex-employees take customer data: 72h response, evidence, A05 notice, and prevention for SME/dev.
Quick answer
What should a company do immediately when discovering a departing employee took customer data?
Prioritize containing risk, preserving evidence, and assessing notification duties. Avoid wiping traces on your own; work procedurally so the evidence is usable before A05 and in civil/labor claims.
Isolate access:
Lock/reset passwords for email, CRM, and cloud storage; revoke API tokens, lock SSO; suspend suspicious accounts (do not delete).
Freeze devices/data:
Retrieve company laptops/phones; enable litigation hold on email/Drive; stop automatic log deletion.
Collect digital evidence:
Export CRM audit logs (CSV export, report export), email logs (MTA), DLP alerts, VPN access history; take timestamped screenshots, hash log files with SHA256 to preserve integrity.
Classify the data taken:
Types of data (name, phone number, email, transaction history…), volume, format (CSV, photos, USB, Zalo forwarding), whether it includes sensitive data.
Assess impact and obligations:
Determine risks to data subjects (likelihood of fraud, spam, financial harm); consider the 72-hour notification obligation under the PDPL.
Remedial actions:
Recover/seize copies, request deletion/return in writing; rotate API keys, reset app tokens, update DLP rules; notify affected internal teams.
Coordinate legal/HR:
Make a written record, invite the employee to a meeting; rely on the contract and internal rules to discipline/seek compensation as provided; consider reporting to A05 when needed.
Real-world example: a Sales employee downloads “Potential customers.xlsx” from the CRM to a USB drive before their last day. CRM logs show an export of 5,000 records at 18:42 from the company IP; at the same time, the file was sent to a personal email. This is commonly deemed a personal data security violation under the regulations.
In which cases must you notify within 72 hours under the PDPL?
According to the PDPL, businesses must notify the competent authority (A05) of personal data breaches within 72 hours of discovery. Notification to data subjects and its contents should follow the regulations; we recommend seeking legal advice.
Common situations to consider notifying:
- Personal data is accessed without authorization, appropriated, or disclosed outside the company.
- Large volume or includes sensitive data (e.g., identity, financial).
- High risk of harm to data subjects (fraud, exposure of transaction history, reputational impact).
The notification should cover: incident description, time, systems involved, types of data, estimated quantity, anticipated impact, measures taken/underway, and a point of contact. Keep a copy and the submission timestamp to demonstrate compliance.
How can businesses prevent a repeat?
Effective prevention combines technical + organizational + legal measures, designed from system architecture and HR processes.
| Measure group | Implementation examples | Tips for SME/dev | |
|---|---|---|---|
| Technical | RBAC/ABAC, MFA, limit CRM export, watermark exports, DLP (email/endpoint), disk encryption, encryption for shared files, centralized logging (SIEM) | Enable “read-only, no export” for Sales; block sending .csv files outside the domain; enable MDM so you can wipe devices when someone leaves | |
| Organizational | Offboarding process, periodic access inventory, PDPL awareness training, assign a DPO/PDPL contact | 24–48h checklist: disable SSO, reclaim badges, collect devices; quarterly access review | |
| Legal | NDA, clause that data belongs to the company, information rules, disciplinary measures | Update employment contract/addendum: ban taking data outside, obligations after termination |
Design least privilege:
Map roles to permissions; block export by default; whitelist only lead accounts.
Limit exfiltration channels:
Block sync of sensitive folders; enable DLP for Gmail/Outlook; log clipboard/USB in line with law and internal rules.
Protect APIs and integrations:
Rotate keys, bind to IPs; log query details (who, when, how many records).
Anonymize/minimize data:
Only display phone numbers as 09xx… for roles that do not need the full value; tokenize sensitive fields.
Gapless offboarding:
Scheduled timeline: T-1 notify IT/HR; T0 revoke SSO, MDM wipe, collect devices; T+1 review abnormal logs.
Controlled mobile/BYOD:
Apply MDM/containers for email and CRM; prohibit storing customer files locally on personal devices.
Which contracts and internal rules should bind employees under the PDPL?
You need clear, enforceable documents:
- Employment contract addendum/NDA: define customer personal data; commit to use only for work purposes; prohibit copying/sharing; obligations after leaving.
- IT/Information security rules: password management, devices, personal email, personal cloud, use of Zalo/Chat apps for customer information.
- PDPL policy: purposes of processing, legal bases, data subject rights (DSAR), 72-hour breach procedure.
- Agreements with processors (SaaS partners, forensics services): confidentiality terms, purpose, scope, safeguards, logs, deletion after completion.
What evidence and technical support should be retained for A05 to accept?
Focus on “who, when, what, where” and the chain of custody.
- System audit logs: CRM export/download, logins, permission changes; operating system/endpoint; proxy/email.
- Snapshots of configuration at the time of the incident: DLP rules, permissions on shared folders, SSO/IdP configuration.
- Legal documents: internal rules, previously signed NDAs; minutes of working with the employee; requests to return/delete data.
- Chain of custody: hash log files, record custodians, seal retrieved devices.
- 72-hour notification dossier (if any): content, submission time, responses; remediation plan.
A cookie/consent banner and a system that records proof of consent help you demonstrate the legal basis for processing and respond to DSARs. You can use consent.vn to standardize these steps in practice.
Source: the Personal Data Protection Law (Law 91/2025/QH15) (effective 01/01/2026): https://thuvienphapluat.vn/van-ban/cong-nghe-thong-tin/Luat-Bao-ve-du-lieu-ca-nhan-2024-576276.aspx; Decree 13/2023/ND-CP: https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Nghi-dinh-13-2023-ND-CP-bao-ve-du-lieu-ca-nhan-565692.aspx; A05: https://bocongan.gov.vn
Get started — set up in 5 minutes.
Need help with PDPL compliance?