DO EMPLOYERS HAVE TO DELETE EMPLOYEES' PERSONAL DATA WHEN THEY LEAVE THEIR JOBS?
Effective January 1, 2026, the Personal Data Protection Law 2025 officially comes into force, imposing a series of new legal obligations on businesses regarding the collection, processing, and storage of employee information. Among these, one of the most notable provisions is the mandatory obligation to delete employees' personal data upon the termination of their employment contracts. So, how is this regulation understood and applied in practice?
Index
I. Scope of employee's personal data
II. Obligations of the Employer regarding the Employee's personal information
1. Obligation to process data during the recruitment phase
2. Obligation to delete personal data when an employee quits
3. Related obligations during the employment process
III. Practical legal evaluation of Company X's behavior
b. Legal analysis of Company X's behavior
I. Scope of employee's personal data
According to Article 2 of the Personal Data Protection Law 2025, personal data is classified into two types:
o Basic personal data:
- Date of birth; date of death or disappearance;
- Gender;
- Place of birth, place of birth registration, permanent residence, temporary residence, current residence, hometown, contact address;
- Nationality;
- Personal image;
- Phone number, ID card number, personal identification number, passport number, driver's license number, license plate number, personal tax code, social insurance number, health insurance card number;
- Marital status;
- Information regarding family relationships (parents, children);
- Information about the individual's digital accounts; personal data reflecting activities and activity history in cyberspace;
- Other information associated with a specific person or that helps identify a specific person not falling under the provisions of Clause 4, Article 2 of Decree 13/2023/ND-CP:
o Sensitive personal data:
- Political views, religious views;
- Health status and private life recorded in medical records, excluding information about blood type;
- Information related to racial origin, ethnic origin;
- Information about the individual's inherited or acquired genetic characteristics;
- Information about physical attributes and unique biological characteristics of the individual;
- Information about the individual's sex life and sexual orientation;
- Data on crimes and criminal acts collected and stored by law enforcement agencies;
- Customer information of credit institutions, foreign bank branches, intermediary payment service providers, and other authorized organizations, including: Customer identification information according to the law, account information, deposit information, deposited asset information, transaction information, information on organizations or individuals as guarantors at credit institutions, bank branches, and intermediary payment service providers;
- Data on the individual's location determined through positioning services;
- Other personal data legally stipulated as specific and requiring necessary security measures.
Notably, data that has been de-identified, meaning personal data that has been processed to the point where a specific individual can no longer be identified, is no longer considered personal data and can be used widely.
II. Obligations of the Employer regarding the Employee's personal information
1. Obligation to process data during the recruitment phase
Not stopping at the termination phase of the employment contract, the Personal Data Protection Law 2025 also clearly stipulates the enterprise's obligation to process employee information at the time of recruitment.
Specifically, during the recruitment process, the enterprise is only allowed to require candidates to provide information that serves properly and directly for recruitment purposes. That information must be processed based on the applicant's consent, and must be deleted or destroyed in case of non-recruitment, unless otherwise agreed by the parties.
This regulation aims to prevent the situation where enterprises collect information of candidates rampantly, retain it indefinitely, and the information may be made public without the candidates' consent.
2. Obligation to delete personal data when an employee quits
Pursuant to Article 25 of the Personal Data Protection Law 2025, the employer has the obligation to delete or destroy the personal data of the employee upon termination of the employment relationship. This is a mandatory regulation, independent of the unilateral will of the employer.
However, this regulation is not absolute. The law recognizes two important groups of exceptions allowing the continued retention of data after the employee quits:
- First case: If the employee and the employer have a separate agreement to retain a part or all of the data after the contract terminates, that agreement will take precedence based on the principles of voluntariness and equality.
- Second case: Certain specific legal areas such as tax, social insurance, accounting, etc., may require the retention of personnel records and documents for a certain period. In these cases, the employer must comply with specialized regulations and cannot delete data before the mandatory deadline.
Thus, employers are obligated to delete the personal data of employees when they leave their jobs, except for the aforementioned exceptions.
3. Related obligations during the employment process
Besides the obligation to delete data, the Personal Data Protection Law 2025 also sets out several important requirements that employers must comply with throughout the human resources management process:
- The employee's personal data must be stored within the time limit prescribed by law or as agreed upon by the parties, and must not be arbitrarily retained indefinitely.
- Enterprises are only permitted to apply technological and technical measures involving tracking or monitoring of employees (such as cameras, activity management software, etc.) when such measures comply with legal regulations and employees are clearly and transparently informed about their implementation.
III. Practical legal evaluation of Company X's behavior
a. Summary of events
Company X publicly posted on a digital platform a document listing over 420 names along with their titles and ranks categorized as "not to be rehired". Although phone numbers and citizen ID numbers were partially masked, the full names of the employees were still fully disclosed, along with titles and enough information to identify each specific individual within the professional community. This list was taken down shortly after, but it had already spread widely on social networks.
b. Legal analysis of Company X's behavior
It must be acknowledged that, in principle, the right to internal human resource management is a legitimate right of the enterprise. Employers fully have the right to:
- Create and retain a list of personnel not to be rehired for internal risk management purposes, under the exception conditions permitted by law.
- Reject applications from former employees who have committed serious violations.
- Provide employment background verification information when other employers proactively contact them to inquire about a specific candidate.
However, the boundary between the legitimate right of internal management and the violation of privacy lies precisely in the act of external publication. Posting the list publicly in the digital environment crossed that limit in several dimensions:
- Violation of the obligation to delete data after contract termination (Article 25 of the Personal Data Protection Law 2025): Not only did Company X fail to delete the data, but it also proactively disseminated the information outside its internal scope, an act wholly contrary to the spirit of the regulation. There is no basis in the Personal Data Protection Law 2025 or related specialized laws that allows publishing this list in a public environment.
- Processing personal data beyond the original scope of purpose: Information regarding employment history, job titles, and internal evaluations of employees was originally collected for human resource management purposes during their employment. Using this information to publicize the identities of employees after they have resigned is a purpose completely outside the initial scope, lacking legal basis.
- Infringement of privacy rights and the right to equal employment opportunities: An employee who has fulfilled their legal obligations retains the right to normally access the labor market after their contract is terminated. Having their identity exposed to the public with a "not to be rehired" label can cause severe damage to future career opportunities, far exceeding any sanctions permitted in employment relationships.
- Risk of setting a bad precedent in labor relations: If this behavior is not properly recognized and responded to, it could create a dangerous precedent: enterprises might use information power to pressure or punish employees beyond the scope of a terminated employment contract.
Therefore, comprehensively viewed, Company X maintaining a do-not-rehire list for internal management purposes is acceptable, provided that the list is kept confidentially within the enterprise and only used to serve the recruitment activities of that enterprise itself. However, the act of publicly posting it on a digital platform accompanied by sufficient personal identification information has absolutely no justifiable legal basis.
The fact that the list was taken down quickly may be a sign indicating negligence from the human resources department at the time, but that does not diminish the degree of the personal data protection violation that actually occurred.
IV. Practical lessons for enterprises
From the incident of Company X and in the context of the newly enacted Personal Data Protection Law 2025, enterprises need to draw the following important lessons:
- Establish clear internal personal data protection policies: Specifically stipulate what types of data are retained, for how long, who has access, and the mechanism for deleting data when an employee leaves.
- Clearly distinguish between internal management and external information disclosure: All information regarding resigned employees, whether negative or positive evaluations, must be processed within the scope of internal confidentiality and is not permitted to be released into the public environment.
- Verify employment history according to proper procedures: When another employer needs to verify information about a candidate who formerly worked at their enterprise, it should be done through direct, official, and controlled communication channels, not through public lists.
- Train HR teams on data protection law: Many practical violations stem from a lack of understanding of the legal limits of human resource management rights, not from malicious intent. Investing in internal legal training is the most effective preventive measure.
V. Conclusion
In summary, with the introduction of the Personal Data Protection Law 2025, the relationship between employers and employees is no longer simply about work and salary, but also encompasses legal responsibilities in protecting personal information. The obligation to delete data when an employee quits is one of the new mandatory requirements, requiring enterprises to proactively review and update their HR management processes to avoid the risk of legal violations. Furthermore, establishing internal personal data protection policies, as well as training HR personnel on the new regulations, are necessary steps that every enterprise should prioritize implementing right now.
DL PINNACLE LAW FIRM LLC
| Information | Contact |
|---|---|
| Address | 5th Floor, 25 Nguyen Van Nguyen, Tan Dinh Ward, Ho Chi Minh City |
| Hotline | 0914491911 |
| info@dlpinnacle.vn | |
| Website | https://www.dlpinnacle.vn |