Skip to content
← Back to Case Studies
CASE STUDYManufacturing · 200 Employees · HCMC

How a 200-Person Manufacturing Company Discovered 340+ PII Exposures in Their Google Workspace

Representative case study based on typical audit findings. Details anonymized.

CLIENT OVERVIEW

A foreign-invested manufacturing company based in Ho Chi Minh City with approximately 200 employees. The company uses Google Workspace Business across all departments and had recently completed a GDPR compliance review for their European parent company.

THE CHALLENGE

With Vietnam's PDPL now in force and the July 1, 2026 electronic labor contract deadline approaching, the company's compliance team needed to understand their actual exposure — not just their assumed posture based on GDPR. Three specific challenges stood out:

  • They had never audited their Google Workspace for Vietnamese PII specifically
  • They assumed GDPR compliance was sufficient for Vietnam — it is not
  • Their legal team needed evidence of a PDPL assessment for an upcoming due diligence process

THE SOLUTION

CompliScan performed a full Google Workspace audit over 48 hours using read-only API access. The scan covered Drive, Gmail, Sheets, and Docs across all active user accounts. No software was installed, and no files were downloaded or stored.

RESULTS

The audit revealed that despite GDPR-compliant processes, the company had significant Vietnamese-specific PII exposure that their generic compliance tools had not detected. The most critical finding: 23 files containing employee CCCD numbers were accessible to anyone with a link — not just internal staff.

RESULTS

347

Vietnamese PII Files Identified

Files containing CCCD numbers, tax IDs, phone numbers, or bank account data

23

Publicly Exposed Files

Files shared with 'Anyone with link' containing sensitive PII including CCCD numbers

89

Unencrypted Email Findings

Emails with unencrypted tax IDs or national ID numbers in plain text

3

Days to Remediation Roadmap

Business days from audit completion to delivery of prioritized remediation plan

We had no idea how much personal data was exposed in our Drive. CompliScan showed us exactly what to fix.

[Client Name], HR Director

Foreign-invested manufacturing company, Ho Chi Minh City

Ready to see your results?

Get a full Google Workspace PII scan in 48 hours.