Template · June 17, 2026
PDPL Data Breach Incident Response Plan Template
PDPL data breach incident response plan template: roles, process, checklist, and 72-hour reporting for Vietnamese businesses.
Edit & copy
This is a reference template. Consult a legal advisor before using in production.
Quick answer
What is a data breach incident response plan template?
A data breach incident response plan template is an internal document that describes who does what when there is a leak, unauthorized access, data loss, or exposure of personal data. With the Personal Data Protection Law (Law 91/2025/QH15), businesses should prepare a ready process to respond quickly, reduce damage, and meet notification obligations under the rules, including the 72-hour deadline from discovery.
In practice, this plan is not just for tech companies. An e-commerce shop, clinic, school, fintech, or marketing agency can all encounter incidents if they store emails, phone numbers, addresses, CCCD, account logs, or customer files in the cloud.
Who needs to be involved in the incident response plan?
Businesses should define roles clearly before an incident occurs. If you wait until you are attacked to assign responsibilities, you will usually lose valuable time.
| Role | Main responsibilities | Practical notes | |
|---|---|---|---|
| Incident Lead | Coordinate response, set priorities | Usually the CTO, Head of IT, or Security Lead | |
| Legal/Compliance | Assess notification obligations, documentation, evidence | Work with legal counsel as needed | |
| DPO/Privacy Owner | Review personal data involved and notification content | If there is no DPO, designate a responsible person | |
| IT/Security | Contain, isolate systems, collect logs | Do not delete logs before backing them up | |
| CS/PR | Draft messaging for customers/partners | Communicate only after approval | |
| Management | Approve key decisions | Need a 24/7 on-call mechanism for major incidents |
What steps does the data breach incident response plan include?
You can use the six steps below as a basic framework. This version fits SMEs and is easy to turn into an SOP or internal playbook.
Detection and recording:
Record the time of discovery, the person who discovered it, anomalies, affected systems, and related data. Create a ticket or incident ID immediately.
Containment and isolation:
Cut off unauthorized access, rotate keys/API keys, disable suspect accounts, and pause sync flows if needed. The goal is to stop the spread.
Scope assessment:
Identify which types of personal data are affected, the number of data subjects, the exposure window, and whether any sensitive data is involved.
Evidence preservation:
Back up logs, screenshots, file hashes, access history, and alert emails. Do not overwrite or delete traces.
Notification and reporting:
Prepare the internal dossier for reporting as required, ensuring the 72-hour deadline from discovery. If information is still incomplete, send the initial information and update later.
Remediation and lessons learned:
Patch vulnerabilities, reset access privileges, update policies, retrain staff, and rehearse the entire process again.
How to use the PDPL data breach incident response plan template?
Below is a practical framework you can copy into Notion, Google Docs, or an internal SOP.
1) Incident information
- Incident code: IR-YYYYMMDD-001
- Date/time discovered: …
- Discoverer: …
- Systems involved: …
- Incident type: leak, lost device, unauthorized access, misdirected data, malware, exposed API key…
- Personal data involved: full name, email, phone number, address, CCCD, health records, payment data…
2) Initial recording template
“At …, the … department discovered … on the … system. There are signs that personal data of approximately … users have been affected. The related accounts/systems have been isolated, logs preserved, and the incident response process activated.”
3) First 72-hour checklist
- Confirm whether it is a real incident or a false positive.
- Isolate the affected systems.
- Assess whether personal data was accessed, exposed, altered, or lost.
- Gather logs, a timeline, and a list of related accounts.
- Determine whether you need to notify the competent authority under the rules.
- Draft a notification for data subjects if needed.
- Record all internal approval decisions.
Key point: the 72-hour clock is counted from when the business discovers the incident, not from when the incident occurred. Therefore, monitoring systems and escalation processes must be fast enough.
What should businesses prepare before an incident?
Before an incident, prepare at least five things: an emergency contact list, an incident report template, an impact assessment form, a notification template, and an evidence repository. If your business has a website/app that collects user data, separate logs, backups, and admin privileges so that evidence is not lost if an incident occurs.
A common example in Vietnam: a recruitment company sends CV files by internal email and accidentally forwards them to an external partner. At that point, the response plan should immediately guide recalling the email if possible, confirming whether the recipient has opened it, recording what data was exposed, and assessing notification obligations under the rules.
Does the incident response plan need to be tied to vendors?
Yes. If you use CRM, cloud hosting, chatbots, payment gateways, email services, or tracker/analytics tools, your contract with the vendor must clearly define responsibilities for investigation support, log provision, response time, and coordination obligations in handling incidents. Do not assume only your internal team needs to do this.
If the vendor processes data on your behalf, first check the clauses on security, incident notification, and audit rights. When legal liability is uncertain, review the contract and consult a lawyer before concluding responsibility.
FAQ about the data breach incident response plan template
- Yes. SMEs can still expose customer data, HR data, or admin accounts. The simpler the plan, the easier it is to implement—as long as it has roles, a checklist, and the 72-hour deadline.
- From the time the business discovers the incident under the rules, not from when the hacker started the attack or the file was exposed.
- You should not wait too long. Record the incident, isolate, conduct a preliminary investigation, and prepare an initial report within the 72-hour window, then update when more data is available.
- The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05).
If you wish, consent.vn can help you standardize this into an internal process, incident report templates, and a consent/DSAR evidence flow to use right away on your website or app.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP; Department of Cybersecurity and High-Tech Crime Prevention (A05) — thuvienphapluat.vn, bocongan.gov.vn
Access the full template library — no account needed.
Need more PDPL templates?