You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 13, 2024

Decree on Sanctions for Cybersecurity Violations in Vietnam Nearing Enactment

On May 2, 2024, Vietnam’s Ministry of Justice published on its online platform the most recent version of the draft decree on administrative sanctions for violations in the field of cybersecurity (“Draft Sanction Decree”) to gather feedback and contributions from the community and stakeholders. After receiving the Ministry of Justice’s assessment, the Ministry of Public Security (“MPS”), in charge of drafting the Draft Sanction Decree, may make further revisions before submitting it to the government for review and final decision on enactment. The decree is expected to have an effective date of June 1, 2024.

The stringent penalties for infringements involving personal data of the previous draft version remain in this Draft Sanction Decree—a sign of the proactive stance of the MPS in enforcing the Personal Data Protection Decree (“PDPD”).

Effective Date and Transitional Provisions

It is important to note that the Draft Sanction Decree does not impose any new obligations on organizations or individuals, and only sets out the administrative sanctions that could be imposed on violators as soon as June 1, 2024, which is indicated as the effective date in Article 49. This signals the MPS’s eagerness to begin taking enforcement actions against recalcitrant organizations and individuals that have not complied with the various obligations imposed on them under the Law on Network Information Security (enacted in 2015), the Law on Cybersecurity (enacted in 2018) and its guiding decree (Decree 53 – enacted in 2022), and the most recent PDPD (enacted in 2023).

Article 50.1 of the Draft Sanction Decree outlines the transitional provisions regarding administrative violations in the cybersecurity field. It clarifies that the decree does not have retroactive effect, by stating that violations occurring before its effective date, but discovered or under review after such effective date will be subject to the regulations on administrative sanctions in force at the time of the violation. Additionally, in cases where the Draft Sanction Decree either lacks sanctions or introduces lighter sanctions for past acts, those lighter provisions will prevail in handling the violations.

Adjustments to Fines and Penalties

The sanctions under the Draft Sanction Decree applicable to violations have been slightly adjusted, with changes to the amount of monetary fines, and the number of additional penalties and/or remedial measures applicable. Businesses will be happy to note that many of the fines in the chapter related to PDPD violations have been decreased compared to the previous draft. However, the maximum fixed monetary fine imposed by the Draft Sanction Decree is still VND 1 billion (approximately USD 40,000), as proposed in the previous draft, and the penalty of up to 5% of the violating enterprise’s turnover of the immediately preceding fiscal year in the Vietnamese market also still applies to certain extreme violations, including:

  • Second and subsequent violations of the regulations on personal data protection in marketing and advertising activities;
  • Second and subsequent violations of the regulations on illegal collection, transfer, purchase and sale of personal data; and
  • Disclosure or misplacement of the personal data of 5 million or more data subjects who are Vietnamese citizens.

In the case of cross-border disclosure or misplacement or cross-border transfer of the personal data of over 5 million data subjects who are Vietnamese citizens the fine can range from 3% to 5% of the enterprise’s prior fiscal year turnover in the Vietnamese market.

Additional penalties applicable to certain violations may also be imposed, including, among others, revocation of licenses for business lines requiring personal data collection, and confiscation of exhibits and means used for conducting violations. Remedial measures may also be imposed, including, among others, suspension from processing of personal data for 1-3 months; forcible destruction or unrecoverable deletion of personal data; and forcible return of illegal profits obtained from the violations; public apology. The Draft Sanction Decree reshuffled these additional penalties and remedial measures for some of the violations.

Other Changes to the Draft

Interestingly, the Draft Sanction Decree includes new language that would exclude weekends and national holidays from the 72-hour timeline to address requests related to data subjects’ rights and to notify the MPS of PDPD violations, unless the law stipulates otherwise. This might be a sign that the MPS is modifying its original stance and that the 72-hour timeline is referring to 72 hours of working days (i.e., 3 working days). The MPS also did not amend some references to a 48-hour timeline, which was introduced in the previous draft but was deemed to be a typo or a mistake.

Finally, the Draft Sanction Decree no longer includes Article 50.2 from the previous draft, which was meant to annul various penalties for administrative violations in the fields of post, telecommunications, radio frequencies, information technology, and electronic transactions under Decree No. 15/2020/ND-CP, as amended (“Decree 15”). It is thus expected that these sanctions will continue to apply even after the promulgation of the Draft Sanction Decree. However, according to the principle of handling administrative violations in Vietnam, a company cannot be fined twice for the same violation. Therefore, the authority may need to choose whether it wishes to apply the sanction under the Draft Sanction Decree or Decree 15.

Outlook

As this Draft Sanction Decree progresses through the final stages of adoption, stakeholders are encouraged to stay informed and promptly comply with the legal requirements applicable to them—especially with their obligations under the PDPD—before the Draft Sanction Decree takes force (expected to be June 1, 2024).

We will continue to monitor developments closely and provide updates as this important legislative process unfolds.

RELATED INSIGHTS​ 

December 11, 2025
On December 10, 2025, the National Assembly of Vietnam passed a new Cybersecurity Law, which will take effect on July 1, 2026. The new Cybersecurity Law was developed based on the consolidation of the 2018 Cybersecurity Law and the 2015 Law on Network Information Security. While the final approved version of the new Cybersecurity Law has not yet been published, according to official reports, the following notable requirements are confirmed to be included: The new Cybersecurity Law dedicates a specific article to prohibited acts related to cybersecurity, under which it strictly prohibits posting or disseminating information online that propagandizes against the Socialist Republic of Vietnam. The law also prohibits, among other things, (i) the appropriation, trading, seizure, or intentional disclosure of information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life; (ii) intentionally eavesdropping, recording, or filming online conversations without authorization; and (iii) the use of artificial intelligence (AI) or new technologies to conduct prohibited acts. The Ministry of Public Security (MPS) has the authority to require enterprises providing telecommunications, internet, and online services, as well as system administrators, to remove information violating cybersecurity laws from systems under their management. The MPS is also assigned responsibility for ensuring information security in cyberspace and data security, establishing mechanisms for IP address identity management, verifying digital account registration information, and issuing warnings and sharing information on cybersecurity threats. Information systems are classified into five levels (similar to the 2015 Law on Network Information Security) based on the degree of harm to national security and social order if an incident occurs. The MPS is the lead agency assisting the government in state management of cybersecurity. The Ministry of National Defense is responsible for managing military information systems, and the Government Cipher Committee manages cryptographic and cipher
December 4, 2025
Thailand has expanded the circumstances under which state agencies may bypass competitive bidding procedures to address urgent security challenges. On November 28, 2025, Thailand’s Ministry of Finance published the Ministerial Regulation Determining Cases of Procurement by Specific Method (No. 6) B.E. 2568 in the Royal Gazette, introducing a new pathway for procuring supplies and services needed to address cyber and military threats that may affect the stability of government agencies or the nation. For technology vendors, cybersecurity firms, and defense contractors, this regulatory change creates immediate opportunities to engage directly with government buyers facing urgent security challenges. New Fast-Track Category for Security Threats The regulation amends Thailand’s Public Procurement and Supplies Management Act B.E. 2560 (2017) to add a new category of procurement that qualifies for the “specific method”—a noncompetitive, direct selection process. Previously, agencies could use this expedited method only in limited circumstances, such as emergencies, cases with proprietary technology requirements, or national security operations. The new provision explicitly covers procurement of supplies related to preventing or resolving cyber or military threats that could impact the stability of a state agency or the country. This addition recognizes the urgent nature of modern security challenges, where competitive bidding timelines may leave agencies vulnerable during critical threat windows. State agencies dealing with active cyberattacks, preparing defensive measures against anticipated threats, or responding to military security concerns can now move directly to negotiate with qualified vendors rather than conducting lengthy public tender processes. Vendor Considerations Vendors offering cybersecurity solutions now have a regulatory avenue to work directly with government clients when stability concerns are present. These solutions include threat detection systems, anti-ransomware tools, incident response services, firewalls, and security consulting. Similarly, defense contractors providing military equipment or specialized security supplies can pursue direct engagement channels where traditional procurement methods would create
December 3, 2025
Thailand’s Civil Court has issued a regulation targeting the use of artificial intelligence (AI) in the preparation of pleadings and other documents submitted to the court. Effective November 17, 2025, the regulation aligns with September 2025 guidance from the president of the Supreme Court, and aims to safeguard accuracy, transparency, and public confidence in civil adjudication. The regulation applies to all parties submitting pleadings or any documents to the Civil Court that are prepared using AI tools or contain AI-generated content. It subjects AI used for these purposes to strict requirements on verification, disclosure, and accountability. Core Obligations The regulation imposes four principal obligations: Lawyers who use AI remain subject to duties of honesty, responsibility to the court, professional standards, and legal ethics, including the duty to assess the appropriateness of the AI tool for the work. Parties and lawyers must verify the accuracy and completeness of all facts, legal provisions, and citations in AI-generated content before submission. Parties and lawyers must disclose to the court any AI-generated content by clearly marking the beginning and end of the AI-generated portion with prescribed statements (see below). Additionally, a certification confirming the use of AI must be provided at the end of the pleading or document, stating that AI was used for certain portions and that the party has reviewed and certifies the accuracy of factual and legal content. Parties and lawyers bear the same full legal and ethical responsibility for AI-generated content as they do for personally authored documents; they cannot evade responsibility or avoid liability by citing AI-related errors. Likewise, parties must ensure that any AI-generated content is truthful, accurate, and unbiased. Prescribed Disclosure Language Each instance of AI-generated content must be preceded by the statement “[The following content was prepared using artificial intelligence]” and must end with “[End
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.