How is personal data being exposed in the digital environment?
- Evelyn Carter

- 2 days ago
- 6 min read
On August 25, 2026, Vietnam Cybersecurity Magazine raised concerns about the amount of personal data individuals leave behind every day, ranging from names, phone numbers and images to health information, location and biometric data. In the digital environment, risks do not come only from cyberattacks, but also from how data is collected, shared and stored. No specific CVE is associated with this issue.
Creating an account, uploading a photo, granting an application access to location data or completing an online purchase form can all generate additional digital traces. When these activities are repeated across multiple platforms, the amount of information linked to an individual can grow significantly without the person fully realizing it.
The issue becomes more complex when these fragments of information do not remain isolated. Names, phone numbers, location data, digital accounts, transaction histories and biometric attributes can be combined to form a relatively detailed profile of an individual. For businesses, this creates a need to manage personal data throughout its entire lifecycle, from collection and storage to use, sharing and deletion.

Through which activities is personal data being exposed?
Digital traces are generated through most everyday online activities. The article by Vietnam Cybersecurity Magazine highlights that information associated with an individual can range widely, from names, phone numbers and images to health information, location and biometric data.
In practice, personal data can be generated when users:
Create accounts on websites or applications.
Provide phone numbers, email addresses and delivery addresses.
Upload photos or videos to social media.
Allow applications to access location services.
Use facial recognition or fingerprints.
Conduct transactions through banks and e-wallets.
Use health-tracking applications or wearable devices.
Allow browsers, platforms or online services to monitor digital activity.
Not every instance of data collection should be considered a “data leak.” The key distinction is whether the data is being collected, used and shared for a legitimate purpose, within an appropriate scope and with suitable protection measures.
For organizations, similar data can exist in CRM systems, human resources software, surveillance systems, customer service applications, Cloud platforms, email systems, endpoints and third-party environments. Personal data is therefore not only an end-user privacy issue but also an enterprise information governance challenge.
Which types of personal data require greater attention?
Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 was enacted on June 26, 2025 and took effect on January 1, 2026. Decree No. 356/2025/ND-CP, effective from the same date, provides more detailed provisions on basic personal data and sensitive personal data.
Under Decree No. 356/2025/ND-CP, basic personal data may include full name, date of birth, gender, place of residence, nationality, images, phone numbers, personal identification numbers, marital status and digital account information. Sensitive personal data includes information requiring stricter protection controls.
Data category | Examples in the digital environment | Key risks |
Identity information | Name, image, phone number, identification number | Impersonation, phishing, profile building |
Digital account data | Account name, email, login information | Account takeover, unauthorized access |
Health data | Health status, medical records | Privacy violations, long-term impact |
Biometric data | Facial features, fingerprints, biological characteristics | Difficult to replace once exposed |
Location data | GPS, location history | Tracking movements and behavioral patterns |
Financial data | Accounts, payment cards, transaction history | Fraud and financial losses |
Online behavior | Social media, telecommunications and online service activity | Behavioral profiling and targeted attacks |
Decree No. 356/2025/ND-CP classifies health status, biometric data, location information identified through location-based services, certain financial data and data used to monitor online service behavior as sensitive personal data. Organizations processing such information must establish restricted access controls, processing procedures and security measures.
For location data and biometric information, the law also introduces specific obligations in the event of a personal data breach, including requirements to notify affected data subjects in certain circumstances.
Businesses seeking a deeper comparison between their existing data-processing practices and the new legal requirements can refer to IPSIP’s guidance on Vietnam’s 2026 personal data protection framework:
Why Can Small Pieces of Data Create Significant Risk?
A single data point may not be enough to create serious harm. However, its value can increase significantly when combined with other information.
For example, a phone number combined with a person’s name and employer can support a more convincing impersonation attempt. If attackers also obtain the person’s job title, email address, transaction history or details about a service being used, a social engineering scenario can become substantially more credible.
This is why businesses should not assess risk by looking at each data field in isolation. Organizations need to consider how information can be linked across CRM platforms, Marketing databases, employee accounts, HR systems, transaction records, system logs and third-party services.
IPSIP’s overview of Vietnam’s cybersecurity landscape in Q1 2026 recorded 165 data exposure incidents, more than 473 million leaked records and 6.9 million compromised credentials identified in cyberspace. IPSIP noted that exposed data can later be used for phishing, account takeover and further intrusion activities.
👉 Additional context on this trend is available in: Vietnam Cybersecurity Q1 2026: Data Becomes a Major Target for Cybercriminals
What should businesses do to reduce the risk of personal data exposure?
The first step is to understand what data the organization actually holds. If a business cannot identify where its data is stored, who has access to it or which third parties receive it, technical security controls are difficult to apply effectively.
Business action checklist:
Create a Data Inventory: identify customer, employee, candidate, partner and system-generated data.
Classify data: distinguish between basic data, sensitive data and assets that require stronger controls.
Map data flows: identify where information is collected, stored and transferred.
Apply data minimization: avoid collecting or retaining information that is no longer necessary for a defined purpose.
Enforce Least Privilege: users should only receive the access required for their responsibilities.
Use MFA: prioritize enterprise email, CRM, Cloud, HR platforms and administrative accounts.
Encrypt sensitive data: particularly where information is stored or transmitted across multiple environments.
Monitor logs and abnormal access: pay attention to bulk downloads and access from unusual accounts or locations.
Control third parties: review SaaS providers, Marketing agencies, Call Centers, HR vendors, logistics providers and other parties receiving data.
Build an Incident Response Plan: define responsible contacts, evidence-preservation requirements and response procedures for suspected data exposure.
If an incident has already occurred, businesses should separate containment from investigation. Deleting logs, locking accounts without proper coordination or modifying systems too early can destroy evidence needed to determine the scope and cause of the incident.
What does IPSIP Vietnam’s expert perspective show?
Dữ liệu cá nhân có thể bị truy cập hoặc phát tán qua phishing, tài khoản bị chiếm quyền, cấu hình hệ thống sai, thiết bị thất lạc, chia sẻ file sai đối tượng, ứng dụng bên thứ ba hoặc hành vi nội bộ. Không nên mặc định mọi vụ lộ dữ liệu đều bắt nguồn từ hacker.
Với doanh nghiệp, ảnh hưởng có thể vượt khỏi bản thân cơ sở dữ liệu. Dữ liệu khách hàng bị lộ có thể hỗ trợ giả mạo thương hiệu; thông tin nhân viên có thể phục vụ spear phishing; còn dữ liệu nhạy cảm có thể kéo theo yêu cầu xử lý về pháp lý, vận hành và truyền thông.
Dữ liệu cá nhân trong môi trường số không chỉ nằm trong những biểu mẫu người dùng chủ động cung cấp. Chúng được hình thành từ nhiều hoạt động khác nhau và ngày càng dễ kết nối giữa các nền tảng, thiết bị và dịch vụ.
Với cá nhân, điều cần thiết là hiểu những quyền truy cập và thông tin đang được chia sẻ. Với doanh nghiệp, ưu tiên là xác định dữ liệu mình đang sở hữu, thu thập đúng nhu cầu, giới hạn quyền truy cập và duy trì khả năng phát hiện sự cố. Bảo vệ dữ liệu vì vậy không nên bắt đầu từ câu hỏi “mua công cụ nào”, mà từ câu hỏi cơ bản hơn: tổ chức đang giữ dữ liệu gì, ở đâu và vì mục đích nào?
References
1. Vietnam Cybersecurity Magazine - “How Much Personal Data Are You Exposing Every Day?” https://tapchianninhmang.vn/ban-dang-de-lo-bao-nhieu-du-lieu-ca-nhan-moi-ngay
2. National Assembly / Government of Vietnam - Law on Personal Data Protection No. 91/2025/QH15: https://vanban.chinhphu.vn/?classid=1&docid=214590&pageid=27160&typegroup=
3. Vietnam National Legal Database - Decree No. 356/2025/ND-CP: https://vbpl.vn/bocongan/Pages/vbpq-toanvan.aspx?ItemID=187276
4. Government of Vietnam — Regulations on Protecting Personal Location and Biometric Data: https://xaydungchinhsach.chinhphu.vn/quy-dinh-bao-ve-du-lieu-ca-nhan-doi-voi-du-lieu-vi-tri-ca-nhan-du-lieu-sinh-trac-hoc-119250730155653784.htm
5. IPSIP Vietnam - Vietnam Cybersecurity Q1 2026: Data Becomes a Major Target for Cybercriminals https://www.ipsip.vn/en/post/cybersecurity-report-in-vietnam-q1-2026









Comments