Data Security Compliance with the Personal Data Protection Decree (PDPD) in Vietnam
Thales can help organisations to protect sensitive data and to comply with a Data-centric Security approach.
The Vietnamese Government announced the Personal Data Protection Decree (Decree 13/2023/ND-CP) on 17 April 2023, and it comes into effect in July 2023. The PDPD aims to fill these gaps in the fragmented legal framework and to provide a comprehensive and consistent approach to personal data protection, extending safeguards for personal data to over 97 million people in Vietnam.
As one of the leaders in data security, Thales enables organizations to comply with PDPD Requirements by recommending the appropriate data security and identity management technologies.
Regulation Overview
Personal Data Protection Decree 13/2023/ND-CP, which is in effect on 1 July 2023. includes 44 articles marking a significant milestone in protecting personal data in the country.
Thales can help organisations to protect sensitive data and to comply with PDPD requirements with a Data-centric Security approach. Organisations can leverage Thales’ suite of identity and data security solutions to become compliant today and stay compliant in the future.
CipherTrust Platform unifies data discovery, classification, and protection and provides unprecedented granular access controls, all with centralised key management. You can rely on Thales CipherTrust Data Security Platform to discover, protect and control your organisation's sensitive data, wherever it resides.
Discover: Data Discovery & Classification
The first step in protecting sensitive data is finding the data wherever it is in the organisation, classifying it as sensitive and typing it (e.g. PII, financial, IP, HHI, customer-confidential, etc.) so you can apply the most appropriate data protection techniques. It is also important to monitor and assess data regularly to ensure new data is not overlooked and your organisation does not fall out of compliance. CipherTrust Data Discovery and Classification efficiently identifies structured as well as unstructured sensitive data on-premises and in the cloud.
Protect Data At Rest
Protect:
Once an organisation knows where its sensitive data is, protective measures such as encryption or tokenisation can be applied. For encryption and tokenisation to successfully secure sensitive data, the cryptographic keys themselves must be secured, managed and controlled by the organisation.
Control:
Organisations need to control access to their data and centralise key management.Every data security regulation and mandate require organisations to be able to monitor, detect, control and report on authorised and unauthorised access to data and encryption keys. The CipherTrust Data Security (CDSP) Platform allows administrators to create a strong separation of duties between privileged administrators and data owners as well as to enforce very granular, least-privileged-user access management policies. CDSP delivers robust enterprise key management across multiple cloud service providers (CSP) and hybrid cloud environments to centrally manage encryption keys and configure security policies so organisations can control and protect sensitive data in the cloud, on-premise and across hybrid environments.
Protect Data-in-Motion/Transit
Thales High Speed Encryptors (HSE) provide network-independent, data-in-motion encryption (layers 2, 3, and 4) ensuring data is secure as it moves from site-to-site, or from on-premises to the cloud and back.
Thales OneWelcome identity & access management solutions provide both the security mechanisms and reporting capabilities organisations need to comply with PDPD requirements. Our solutions protect sensitive data by enforcing the appropriate access controls when users log into applications that store sensitive data. By supporting a broad range of authentication methods and policy-driven role-based access, our solutions help enterprises mitigate the risk of a data breach due to compromised or stolen credentials or through insider credential abuse.
The Vietnamese Government announced the Personal Data Protection Decree (Decree 13/2023/ND-CP) on April 17, 2023, and it comes into effect in July 2023. Before the issuance of the Decree, personal data protection in Vietnam was governed by 19 different laws and regulations,...
Indonesia passed its first Personal Data Protection (PDP) Law in 2022. The PDP Law is an effort to enhance the existing regulatory framework on personal data protection, it signifies the development of policies on personal data protection and confidentiality and strengthens...
This ebook shows how Thales data security solutions enable you to meet global compliance and data privacy requirements including - GDPR, Schrems II, PCI-DSS and data breach notification laws.
Perhaps the most comprehensive data privacy standard to date, GDPR affects any organisation that processes the personal data of EU citizens - regardless of where the organisation is headquartered.
Any organisation that plays a role in processing credit and debit card payments must comply with the strict PCI DSS compliance requirements for the processing, storage and transmission of account data.
Data breach notification requirements following loss of personal information have been enacted by nations around the globe. They vary by jurisdiction but almost universally include a “safe harbour” clause.