---
title: Effective data protection measures for businesses
description: What data protection measures should businesses adopt to prevent data leaks, stay compliant with the law, and control costs? Find out now!
slug: bien-phap-bao-ve-du-lieu
type: news
locale: en-US
author: Tony Dang
date: "2026-09-07T10:09:41.815Z"
lastmod: "2026-09-07T10:09:41.709Z"
thumbnail: "https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/bien-phap-bao-ve-du-lieu.png"
sabo: Customer data leaks, systems going down due to cyberattacks, or penalties for failing to comply with legal regulations are risks that any business can face if it has not implemented proper data protection measures. As digital transformation accelerates, data has become a core asset, but it is also a prime target for cybercriminals. This article summarizes the latest legal regulations businesses need to comply with, data protection measures ranging from foundational to advanced, and solutions suited to businesses of every size.
---

<h2><strong>1. Why should businesses prioritize data protection?</strong></h2><p>Business data includes many different types of information, such as customer data, financial records, internal documents, and operational information considered trade secrets. Each type of data has its own value and becomes an attractive target for cyberattackers, especially as businesses undergo digital transformation and store an increasing amount of information online.</p><p>When a&nbsp;<a href="https://www.vnetwork.vn/en-US/news/data-breach-la-gi/">data breach</a> occurs, meaning data is leaked or lost, businesses face serious consequences. Brand reputation suffers, customers lose trust, and in many cases businesses also bear legal liability if data is mishandled. The cost of remediation, from investigating the root cause to restoring systems, is often far greater than the cost of preventive investment.</p><p>Current cyberattack trends focus heavily on the web application layer, where businesses typically store and process data directly. Common attack methods include exploiting application vulnerabilities, denial of service attacks that disrupt data access, and&nbsp;<a href="https://www.vnetwork.vn/en-US/news/phishing-la-gi-3-hinh-thuc-tan-cong-phishing/">phishing</a> tactics targeting internal employees. As a result, deploying multiple layers of data protection at once, from legal compliance to internal governance and web application security, has become a mandatory requirement rather than an option.</p><figure class="image"><img style="aspect-ratio:1920/1080;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/vi-sao-doanh-nghiep-can-chu-trong-bao-ve-du-lieu.png" alt="vi-sao-doanh-nghiep-can-chu-trong-bao-ve-du-lieu.png" width="1920" height="1080"><figcaption><i>Why should businesses prioritize data protection?</i></figcaption></figure><h2><strong>2. Legal regulations on data protection in Vietnam</strong></h2><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/cac-quy-dinh-phap-ly-ve-bao-ve-du-lieu-tai-viet-nam.png" alt="cac-quy-dinh-phap-ly-ve-bao-ve-du-lieu-tai-viet-nam.png" width="1672" height="941"><figcaption><i>Legal regulations on data protection in Vietnam</i></figcaption></figure><p>Data protection is not only a technology requirement but also a legal obligation. Vietnam’s legal framework on cybersecurity and data has just undergone a major update between 2025 and 2026, and businesses need to understand these changes clearly to avoid relying on documents that are no longer in effect.</p><h3><strong>2.1. Cybersecurity Law 2025 (No. 116/2025/QH15)</strong></h3><p>On December 10, 2025, the 15th National Assembly passed the&nbsp;<a href="https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Luat-An-ninh-mang-2025-so-116-2025-QH15-666020.aspx">Cybersecurity Law 2025</a>, numbered 116/2025/QH15, comprising 8 chapters and 58 articles, 15 more articles than the 2018 Cybersecurity Law. This law officially takes effect on July 1, 2026, and simultaneously replaces two earlier documents: the 2018 Cybersecurity Law (No. 24/2018/QH14) and the 2015 Law on Network Information Security (No. 86/2015/QH13). Merging the two former laws addresses the previous overlap in regulatory authority between the Ministry of Public Security and the Ministry of Information and Communications, while also unifying the concept of "cybersecurity" in place of "network information security."</p><p>Businesses providing services in cyberspace in Vietnam should note the responsibilities carried over and expanded under the new law, including warning users of cybersecurity risks, developing incident response plans, and applying technical solutions to prevent data leakage or loss during information collection and processing.</p><h3><strong>2.2. Decree 85/2016/ND-CP and Circular 12/2022/TT-BTTTT</strong></h3><p><a href="https://www.vnetwork.vn/en-US/news/5-cap-do-an-toan-thong-tin/">Decree 85/2016/ND-CP</a> classifies information systems in Vietnam into 5 security levels, based on their level of importance and the scope of impact should an incident occur. According to the appendix issued with Circular 12/2022/TT-BTTTT guiding Decree 85/2016/ND-CP, level 2 information systems (under Clause 2, Article 8 of Decree 85/2016/ND-CP), or level 3 and above, are required to use a web application firewall product.</p><p>It is worth noting that both of these documents were issued under the 2015 Law on Network Information Security, which ceased to be effective on July 1, 2026, when the 2025 Cybersecurity Law officially took effect. At the time this article was updated, regulators had not yet issued an official replacement decree for classifying information system security levels under the new legal framework, so Decree 85/2016/ND-CP and Circular 12/2022/TT-BTTTT remain in effect during this transition period. Businesses with information systems at level 2 (under Clause 2, Article 8 of Decree 85/2016/ND-CP) or level 3 and above should proactively review their current compliance status and monitor for new guiding documents once issued.</p><h3><strong>2.3. Personal Data Protection Law (No. 91/2025/QH15)</strong></h3><p>The&nbsp;<a href="https://www.vnetwork.vn/en-US/news/luat-so-91-2025-qh15/">Personal Data Protection Law</a> No. 91/2025/QH15 was passed by the National Assembly on June 26, 2025, and officially took effect on January 1, 2026. This is Vietnam’s first dedicated law comprehensively governing the collection, processing, and protection of personal data, replacing the earlier Decree 13/2023/ND-CP. Decree 356/2025/ND-CP, issued on December 31, 2025, and effective the same day as the law, sets out detailed procedures and implementation measures.</p><p>Businesses that collect customer data such as contact information, purchasing behavior, or biometric data all fall within the scope of this law, regardless of organizational size. Compliance not only helps businesses avoid legal risk but also strengthens customer trust during transactions.</p><figure class="table" style="width:100%;"><table class="ck-table-resized"><colgroup><col style="width:32.22%;"><col style="width:16.95%;"><col style="width:50.83%;"></colgroup><tbody><tr><td><strong>Legal document</strong></td><td><strong>Effective date</strong></td><td><strong>Key content</strong></td></tr><tr><td>Cybersecurity Law 2025 (No. 116/2025/QH15)</td><td>July 1, 2026</td><td>Replaces the 2018 Cybersecurity Law and the 2015 Law on Network Information Security</td></tr><tr><td>Decree 85/2016/ND-CP and Circular 12/2022/TT-BTTTT</td><td>Decree: July 1, 2016. Circular: October 1, 2022</td><td>Classifies information systems into 5 security levels; mandates a WAF for level 2 systems (under Clause 2, Article 8 of Decree 85/2016/ND-CP) or level 3 and above</td></tr><tr><td>Personal Data Protection Law (No. 91/2025/QH15) and Decree 356/2025/ND-CP</td><td>January 1, 2026</td><td>Governs the collection, processing, and protection of personal data</td></tr><tr><td>Decree 332/2026/ND-CP</td><td>August 19, 2026</td><td>Trading of cybersecurity products and services</td></tr></tbody></table></figure><h2><strong>3. Data protection measures businesses should implement</strong></h2><p>To meet the legal requirements above and reduce the risk of data leaks, businesses need to deploy multiple layers of protection together, from internal governance to web application security. These are data protection measures that any organization, large or small, should adopt.</p><h3><strong>3.1. Access control and multi-factor authentication</strong></h3><p><a href="https://www.vnetwork.vn/en-US/news/access-control-la-gi/">Access control</a> is a measure that helps businesses tightly manage who is allowed to access which type of data, through identity verification and corresponding permission assignment for each user. Access is typically assigned based on job role, department, or seniority, ensuring each employee can only access the scope of data necessary for their work.</p><p>In addition to access control, multi-factor authentication (MFA) adds another layer of protection by requiring users to verify their identity through multiple methods, for example an OTP code sent to their phone combined with a login password. Businesses can apply tools such as SSH keys to protect remote access to servers, or a centralized identity management system with MFA enabled to easily grant and revoke permissions as personnel change, minimizing the risk of data leakage from excessive access or compromised accounts.</p><figure class="image"><img style="aspect-ratio:1920/1080;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/xac-thuc-da-yeu-to-mfa.png" alt="xac-thuc-da-yeu-to-mfa.png" width="1920" height="1080"><figcaption><i>Multi-factor authentication (MFA)</i></figcaption></figure><h3><strong>3.2. Applying the Zero Trust model to data access control</strong></h3><p>The&nbsp;<a href="https://www.vnetwork.vn/en-US/news/zero-trust-la-gi/">Zero Trust</a> model operates on the principle of not automatically trusting any access, even from within the internal network. Every data access request must be authenticated and have its permissions verified before being approved. This approach helps reduce risk when an employee’s account is compromised or when an unfamiliar device attempts to access a system containing important data, and it is typically deployed alongside access control and MFA to form a complete identity control layer starting at the network infrastructure level.</p><h3><strong>3.3. Encrypting data at rest and in transit</strong></h3><p>Data encryption is the process of converting information into a form that cannot be read without the appropriate decryption key. This measure needs to be applied in both states of data, at rest on servers or devices and in transit between systems over a network. Even if data is stolen, proper encryption renders the information worthless to an attacker who does not possess the decryption key.</p><h3><strong>3.4. Regular data backup using the 3-2-1 strategy</strong></h3><p>Regular data backup helps businesses recover information quickly when incidents occur, such as hardware failure, accidental operations, or ransomware attacks. The 3-2-1 strategy is widely adopted by businesses, involving keeping 3 copies of data, on 2 different types of storage media, with 1 copy stored in a location separate from the main system. Businesses can combine&nbsp;<a href="https://www.vnetwork.vn/en-US/news/cloud-storage-la-gi/">cloud storage</a> with local backups to improve recovery capability when an incident occurs.</p><figure class="image"><img style="aspect-ratio:1672/941;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/sao-luu-dinh-ky-la-mot-trong-nhung-bien-phap-bao-ve-du-lieu-cho-doanh-nghiep.png" alt="sao-luu-dinh-ky-la-mot-trong-nhung-bien-phap-bao-ve-du-lieu-cho-doanh-nghiep.png" width="1672" height="941"><figcaption><i>Regular backup is one of the data protection measures for businesses</i></figcaption></figure><h3><strong>3.5. Monitoring and logging abnormal access</strong></h3><p>Continuously monitoring data access activity helps businesses detect abnormal behavior early, before it causes significant damage. Fully logging login information, access times, and actions performed on the system also makes it easier to trace the source when an incident occurs. Without a monitoring mechanism in place, businesses typically only discover a data leak after the damage has already spread, making remediation far more difficult and costly.</p><h3><strong>3.6. Security awareness training for employees</strong></h3><p>Many data leak incidents originate from human error, such as employees clicking on phishing links or using weak passwords. Businesses need to organize regular security awareness training to help employees recognize phishing emails, understand proper procedures for handling customer data, and know how to report incidents promptly. This is a low cost measure with a clearly effective reduction in risk, and it is especially suitable for businesses that do not yet have a dedicated security team. It is also an important transitional step before moving on to the defense layer at the software application level, since employees are the ones who directly operate those applications every day.</p><figure class="image"><img style="aspect-ratio:1920/1080;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/dao-tao-nhan-thuc-bao-mat-cho-nhan-vien.png" alt="dao-tao-nhan-thuc-bao-mat-cho-nhan-vien.png" width="1920" height="1080"><figcaption><i>Security awareness training for employees</i></figcaption></figure><h3><strong>3.7. Securing the web application layer</strong></h3><p>At the software layer, where businesses directly process data through websites and applications, the two most common risk groups that need to be controlled are data exploitation vulnerabilities and service disruption attacks.&nbsp;<a href="https://www.vnetwork.vn/en-US/news/chong-tan-cong-sql-injection/">SQL injection</a> and&nbsp;<a href="https://www.vnetwork.vn/en-US/news/tan-cong-xss-la-gi/">XSS</a> are two of the most common vulnerabilities on the&nbsp;<a href="https://www.vnetwork.vn/en-US/news/owasp-la-gi-va-cach-chong-khai-thac-lo-hong-web-app-hieu-qua/">OWASP Top 10</a> list, frequently exploited by attackers to steal data directly from a database or a user’s browser. With SQL injection, attackers insert malicious code into input fields to make unauthorized queries against a database, while XSS exploits vulnerabilities in a web interface to steal login session information or users’ personal data. OWASP, a non-profit organization dedicated to researching web application security, regularly updates this list of vulnerabilities to help businesses prioritize the right fixes.</p><p>To better visualize how dangerous an XSS vulnerability can be, you can watch a demo video simulating a real XSS attack and how WAF Free detects and blocks the malicious payload before it reaches user data:</p><figure class="media"><oembed url="https://youtu.be/fFcyPGCa5Yk?si=WXrrW2vv8ichfAqs"></oembed></figure><p>Alongside the risk of data theft through application vulnerabilities,&nbsp;<a href="https://www.vnetwork.vn/en-US/news/ddos-la-gi-va-cach-ngan-chan-cac-loai-tan-cong-ddos-server/">DDoS</a> attacks, while not directly stealing data, can bring a system down, preventing businesses from accessing or processing data in time during important situations such as financial transactions or customer service. Deploying protection against SQL injection and XSS together with multi-layer DDoS mitigation helps protect data comprehensively at the web application layer, both blocking data theft and maintaining system availability even while under high-volume attack.</p><p>Button;Try it now;https://partner.vnetwork.vn/?utm_source=google&amp;utm_medium=blog&amp;utm_campaign=waf_free&amp;utm_term=bienphapbaovedulieu;_blank</p><h3><strong>3.8. Summary table of business data protection measures</strong></h3><figure class="table" style="width:100%;"><table class="ck-table-resized"><colgroup><col style="width:23.71%;"><col style="width:34.42%;"><col style="width:41.87%;"></colgroup><tbody><tr><td><strong>Measure</strong></td><td><strong>Main purpose</strong></td><td><strong>Risk if ignored</strong></td></tr><tr><td>Access control and MFA</td><td>Limit access scope by role; multi-layer authentication</td><td>Employees or attackers access data beyond their authorized scope</td></tr><tr><td>Zero Trust</td><td>Access control without default trust</td><td>A compromised account can easily spread its access</td></tr><tr><td>Data encryption</td><td>Protect data if stolen</td><td>Data can be read directly if leaked</td></tr><tr><td>Regular backup</td><td>Recover data when an incident occurs</td><td>Permanent data loss when a system fails</td></tr><tr><td>Access monitoring</td><td>Early detection of abnormal behavior</td><td>Data leaks discovered too late</td></tr><tr><td>Employee training</td><td>Reduce risk from human error</td><td>Employees unintentionally create openings for phishing attacks</td></tr><tr><td>Web application security</td><td>Block data theft and maintain system availability</td><td>Data stolen or system down, disrupting transactions</td></tr></tbody></table></figure><h2><strong>4. The data protection cost challenge for small and medium businesses</strong></h2><p>The pressure to protect data comes not only from the threat of attacks but also from the cost of investment, particularly for small and medium businesses. According to a survey published by VNETWORK on&nbsp;<a href="https://vietnamnet.vn/giai-bai-toan-chi-phi-bao-mat-website-cho-doanh-nghiep-nho-2550525.html">VietNamNet</a> in 2026, as many as 42.1% of businesses face budget difficulties for security, most of them small businesses. Meanwhile, the number of cyberattacks targeting domestic businesses continues to rise, making the challenge of balancing budget against the level of data protection more urgent than ever.</p><p>Notably, even businesses that have already allocated budget for security are not guaranteed a corresponding level of protection. According to the report "Vietnam Enterprise Cybersecurity Landscape 2026" by VNETWORK, cited by&nbsp;<a href="https://tuoitre.vn/vnetwork-doanh-nghiep-viet-dau-tu-bao-mat-nhung-chi-1-3-dat-muc-bao-ve-tuong-xung-20260406143627128.htm">Tuoi Tre</a>, only about 33% of Vietnamese businesses have multi-layered security systems, while DDoS attacks affected 57% of businesses surveyed in 2025. This shows that the issue is not only whether a business invests in security, but whether it invests in the right place, at the defense layer the business is actually missing.</p><p>In practice, the cost of data protection does not necessarily scale in proportion to the size of the investment. Many security solutions today are designed on a free or low cost model, helping small businesses access data protection technology from the very start without needing a dedicated technical team or complex infrastructure. This is also an approach widely adopted by cybersecurity providers in Vietnam to help the small and medium business community overcome budget barriers.</p><figure class="image"><img style="aspect-ratio:1920/1080;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/bai-toan-chi-phi-bao-ve-du-lieu-cua-doanh-nghiep-smes.png" alt="bai-toan-chi-phi-bao-ve-du-lieu-cua-doanh-nghiep-smes.png" width="1920" height="1080"><figcaption><i>The data protection cost challenge for SMEs</i></figcaption></figure><h2><strong>5. WAF Free - A Free Web/App Protection Solution for Businesses</strong></h2><p>To help businesses solve the cost challenge described above, while also contributing to data protection at the web application layer, VNETWORK offers a web application firewall,&nbsp;<strong>WAF Free</strong>, a free starting solution within the Web/App/API security ecosystem,&nbsp;<a href="https://www.vnetwork.vn/en-US/products/waap/"><strong>VNIS</strong></a>, suited to SMEs that want to access this technology without a large budget or a dedicated technical team.</p><p>Highlights of WAF Free include:</p><ul><li><strong>Easy integration:</strong> Simple configuration in just 2 minutes, requiring no in-depth expertise</li><li><strong>Comprehensive protection:</strong> Effectively blocks OWASP Top 10 vulnerabilities and defends against DDoS threats, keeping the website running stably</li><li><strong>Faster content delivery:</strong> Optimizes Web/App content delivery performance and improves user experience thanks to CDN infrastructure</li><li><strong>Real-time visibility:</strong> Provides a dashboard for monitoring traffic in real time</li><li><strong>Compliance support:</strong> Meets the requirement to deploy a WAF under Clause 2, Article 8 of Decree 85/2016/ND-CP</li></ul><figure class="image"><img style="aspect-ratio:1920/1080;" src="https://static.vncdn.vn/vnetwork.vn/pub/websites/uploads/1/94/giao-dien-portal-waf-free-bien-phap-bao-ve-du-lieu.png" alt="giao-dien-portal-waf-free-bien-phap-bao-ve-du-lieu.png" width="1920" height="1080"><figcaption><i>WAF Free VNETWORK portal interface</i></figcaption></figure><p>Businesses can start protecting their website and applications today at no cost, with just&nbsp;<a href="https://www.vnetwork.vn/en-US/news/huong-dan-kich-hoat-waf-free-3-buoc">3 simple activation steps</a> for WAF Free.</p><p>Button;Try it now;https://partner.vnetwork.vn/?utm_source=google&amp;utm_medium=blog&amp;utm_campaign=waf_free&amp;utm_term=bienphapbaovedulieu;_blank</p><h2><strong>6. Conclusion</strong></h2><p>Protecting business data is a process that combines legal compliance, internal governance measures, and web application security technology. Businesses do not need to deploy everything at once; instead, they should start with low cost, high impact measures such as access control and regular backups, then add a web application protection layer as the system scales. Try WAF Free today to begin protecting your business data in a simple, cost-free way.</p><h2><strong>FAQ - Frequently asked questions about data protection measures</strong></h2><h3><strong>1. Which data protection measure matters most for small businesses?</strong></h3><p>There is no single measure that fits every business, but access control and regular data backup are typically prioritized first because of their low cost and clearly effective risk reduction. In addition, businesses with a website or application serving customers should also consider adding a protection layer at the web application level.</p><h3><strong>2. Does data encryption slow down the system?</strong></h3><p>Modern data encryption is optimized to minimize the impact on system performance. With today’s hardware infrastructure and encryption algorithms, the resulting latency is typically negligible compared to the data protection benefits this measure provides.</p><h3><strong>3. Are businesses required to comply with the Personal Data Protection Law?</strong></h3><p>The Personal Data Protection Law No. 91/2025/QH15, effective from January 1, 2026, applies to every organization and individual that collects and processes personal data in Vietnam, regardless of business size. Therefore, any business that collects customer data in any form needs to review its compliance status under this law and its implementing Decree 356/2025/ND-CP.</p><h3><strong>4. How does the 2025 Cybersecurity Law differ from the 2018 Cybersecurity Law?</strong></h3><p>The 2025 Cybersecurity Law (No. 116/2025/QH15), effective from July 1, 2026, merges the 2018 Cybersecurity Law and the 2015 Law on Network Information Security into a single unified document, while also clarifying business responsibilities in data protection and cybersecurity incident response. Businesses currently following the two former laws need to update to this new legal framework.</p><h3><strong>5. How does a WAF differ from a traditional firewall in protecting data?</strong></h3><p>A traditional firewall primarily controls traffic at the network layer, while a web application firewall focuses on analyzing and filtering requests at the application layer, where vulnerabilities such as SQL injection or XSS are commonly exploited to steal data. These two protection layers are typically deployed together to increase overall defense effectiveness.</p><h3><strong>6. How often should data be backed up?</strong></h3><p>Backup frequency depends on how often data changes and how important it is. For transaction data or customer data that updates continuously, businesses should back up daily, while data that changes less frequently can be backed up weekly, as long as the practice of storing multiple copies in different locations is still followed.</p>
