From the PUBG case: How should online games protect player data?
Online games do not only store usernames and passwords. They may also process names, dates of birth, phone numbers, usage history and information related to virtual items. In Vietnam, Decree 147/2024/ND-CP introduces requirements concerning authentication, data retention and information security. If player data is exposed, the impact can extend beyond the game and become a cybersecurity, privacy and corporate responsibility issue.
The discussion surrounding PUBG can therefore be viewed beyond the operation of a single game. When an online service serves a large user base and stores their data, the ability to protect accounts, control access, detect attacks and respond to data exposure becomes part of the quality of the service itself.

What requirements must online games meet to protect players in Vietnam?
An online game cannot simply be launched on the Internet and offered to users in Vietnam without corresponding responsibilities. Decree 147/2024/ND-CP, effective from December 25, 2024, classifies online video games into G1, G2, G3 and G4 categories and sets conditions for each type.
For G1 games, where multiple users interact simultaneously through a company-operated server system, requirements go beyond game content. Providers are also expected to maintain information security measures, protect user rights, prepare backup systems and ensure data recovery capability in case of incidents.
Several notable requirements include:
Requirement | Meaning for players and providers |
Account authentication | Helps reduce unidentified or fraudulent accounts |
Player information retention | Makes the provider a custodian of personal data |
Controls for players under 18 | Adds protection obligations for younger users |
Management of user communications | Helps reduce abusive or unlawful content |
Backup and redundancy | Reduces impact when infrastructure fails |
Information security controls | Makes cybersecurity part of service operations |
The key point is that online game security should not be measured only by whether the servers remain available. A service can stay online while player accounts are still being hijacked, data is being accessed without authorization or information is being extracted from internal systems.
What player data can become a target?
Under Article 56 of Decree 147/2024/ND-CP, users registering for online games are required to provide their full name, date of birth and a Vietnamese mobile phone number. For users under 16, registration is tied to information from a parent or legal guardian.
Providers must retain this information throughout the period of service use and for six months after the user stops using the service.
Those are only the identity-related fields. A gaming platform may also generate and process other types of operational data, such as:
account names and player IDs;
login history;
service usage records;
virtual items, virtual currency and reward points;
payment or transaction-related information;
customer support history;
IP addresses and device information, depending on platform design;
interactions between accounts.
What damage can occur if player data is exposed?
A gaming data breach does not only create the risk of account or virtual-item theft. When account information is combined with data from other sources, the risk can expand into phishing, account takeover and social engineering.
For example, names, phone numbers, dates of birth or usernames may help attackers craft more personalized scam messages. If users reuse passwords between games, email, social media and other services, leaked credentials may also be tested elsewhere through credential stuffing.
The risks can be grouped into four main categories:
Account takeover: Attackers attempt to gain control of accounts, virtual items or associated privileges.
Targeted fraud: Player data may be used to create more convincing fake emails, login pages or support messages.
Cross-platform compromise: Reused passwords or linked email addresses may allow attacks to spread beyond the game platform.
Privacy and legal exposure: Once a company stores personal data, an incident is no longer purely technical. It may trigger reporting, remediation and compliance obligations.
Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 took effect on January 1, 2026. Decree 356/2025/ND-CP provides further detail on personal data processing, retention, data subject rights and responses to personal data violations.
PLAYER DATA WARNING: Data exposed from an entertainment platform does not necessarily create risks only inside that platform. Names, phone numbers, account details and activity history, when combined with information leaked elsewhere, may support impersonation, phishing, credential stuffing and targeted social engineering.
Why is online game player data protection also a lesson for enterprise cybersecurity?
An online game player data protection is a clear example of a modern digital service: it has users, accounts, personal data, databases, APIs, payment systems, server infrastructure and integrations with other systems.
These are the same layers found in digital banking, e-commerce, SaaS, customer portals and many enterprise applications.
The business function may be different, but the security principles are largely the same.
Any company operating a customer-facing platform should be able to answer questions such as:
What customer data are we collecting?
Where are those data stored and for how long?
Who has access to the databases?
Do privileged accounts use MFA and least privilege?
Are access logs retained and monitored?
Can we detect unusually large data downloads?
Are backups tested for successful restoration?
If a breach occurs, who activates the incident response process?
Can we determine which data and how many users were affected?
Vietnam’s current cybersecurity framework also places greater responsibility on organizations that operate information systems. Decree 331/2026/ND-CP on cybersecurity protection for information systems and Decree 330/2026/ND-CP on administrative penalties in cybersecurity and personal data protection both took effect on August 19, 2026.
What should businesses do to reduce the risk of user data exposure?
No single security control can prevent every data breach. Effective protection needs to cover identity, applications, infrastructure, data and incident response.
Business security checklist:
Build a Data Inventory to identify what data are collected and where they are stored.
Classify personal and highly sensitive data.
Apply Least Privilege to employee and administrator accounts.
Enable MFA for privileged or high-risk accounts.
Perform regular vulnerability assessments across websites, APIs, servers and applications.
Encrypt sensitive data in storage and transit where appropriate.
Monitor login events, data downloads and privilege changes.
Define retention policies and delete data when it is no longer required.
Test backups and recovery capability instead of only confirming that backups exist.
Prepare an Incident Response Plan before a breach happens.
If an incident has already occurred, the first hours are critical for containment and for understanding the scope of impact. IPSIP Vietnam has outlined six steps for responding to enterprise data leakage incidents, including confirming the incident, isolating affected systems, preserving evidence and determining the scale of exposure.
What does IPSIP Vietnam’s cybersecurity perspective suggest?
The online gaming industry illustrates a principle that applies to almost every digital service: when a company collects data to provide a service, it also assumes responsibility for protecting that information throughout its lifecycle.

For Vietnamese businesses, the lesson is not limited to PUBG or the gaming sector. Customer portals, SaaS platforms, CRM systems, e-commerce applications and membership services can all become attractive targets when they hold valuable data. Identifying what data are being stored, limiting access, testing for vulnerabilities and building the ability to detect and respond to incidents should happen before a data breach occurs.
References
Government of Vietnam - Decree 147/2024/ND-CP on the Management, Provision and Use of Internet Services and Online Information
National Assembly of Vietnam - Law No. 91/2025/QH15 on Personal Data Protection
Government of Vietnam - Decree 331/2026/ND-CP on Cybersecurity Protection for Information Systems
Government of Vietnam - Decree 330/2026/ND-CP on Administrative Penalties in Cybersecurity and Personal Data Protection









