You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 8, 2020

New Penalties for Posting Fake News on Social Networks

On February 3, 2020, the Vietnamese Government issued Decree No. 15/2020/ND-CP stipulating penalties for administrative violations in the fields of postal services, telecommunications, radio frequency, information technology, and electronic transactions (“Decree 15”). Decree 15 will replace the existing decree on penalties in the technology and telecom sectors (Decree No. 174/2013/ND-CP) and will take effect on April 15, 2020.

One of the most notable features provided by Decree 15 is the introduction of specific administrative penalties for users who post or share fake news on social networks, which will be imposed in addition to any civil and/or criminal liabilities related to distortion, slander, defamation and the like.

Penalties for Social Network Users

In particular, Article 101 of Decree 15 sets out the penalties for violations of regulations on the use of social networks. These include administrative fines of between VND 10 million (approx. USD 430) and VND 20 million (approx. USD 860) on social network users who commit the following violations:

  1. Posting or sharing false information (fake news) or untruthful, distorted, or slanderous information that offends the reputation of agencies or organizations or the honor and dignity of individuals;
  2. Posting or sharing information that advocates unsound customs, superstition, obscenity, or depravity which is not in line with the traditions and fine customs of the nation;
  3. Posting or sharing graphic depictions of acts of slashing, killing, accidents, or horror;
  4. Posting or sharing fabricated information that causes panic among the population or incites violence, crime, social evils or gambling, or that serves gambling activities;
  5. Posting or sharing press, literature and art works or publications without the permission of the copyright holder, or works that have not been approved for circulation, or have been banned or revoked;
  6. Advertising, promoting, or sharing information about banned goods and services;
  7. Posting or sharing inaccurate maps of Vietnam;
  8. Posting or sharing links to websites with banned content.

Higher administrative fines of VND 20 million (approx. USD 860) to VND 30 million (approx. USD 1,290) are imposed on the disclosure of information classified as state secrets or personal secrets, but which is not serious enough to face criminal punishment.

Moreover, in all of the above cases, the violators would also be required to remove the fake news or violating content that was posted or shared.

Penalties for Social Network Providers

Correspondingly, Decree 15 also imposes additional penalties on social network providers who fail to prevent fake news from being posted on their social networks.

In particular, Article 100.3 of Decree 15 imposes an administrative fine of VND 50 million (approx. USD 2,130) up to VND 70 million (approx. USD 3,000) on social network providers who fail to block or remove violating information (including fake news) from their platforms, and/or who intentionally provide, store, or transmit the violating content listed in items 1-7 above, or information that is considered not to be in the country’s interest.

Violating social network providers would also be required to remove the fake news or violating content that was posted or shared, and be subject to suspension of their social network license and/or revocation of their social network’s domain name.

Penalties in Other Fields

In addition to the foregoing newly stipulated penalties on fake news, the administrative penalties on various other violations in the fields of postal services, telecommunications, radio frequency, information technology and electronic transactions have also been overhauled. For example, penalties related to data privacy and security have been slightly increased. Notably, penalties on violations related to collecting personal information without consent are increased from VND 10 million (approx. 430) to VND 20 million (approx. USD 860); and penalties on violations related to adopting adequate cybersecurity measures are increased from VND 20 million (approx. USD 860) to VND 50 million (approx. USD 2,150).

For more information on Decree 15, please contact us at [email protected].

RELATED INSIGHTS​ 

April 4, 2024
On March 18, 2024, the president of the Supreme Court of Thailand announced the establishment of a specialized Technology Crime Division within the Criminal Court of Thailand. This represents a significant commitment to cybercrime within the Thai judiciary and a step forward in Thailand’s ability to investigate cybercrime. The rise in cybercrime investigations in recent years has made it increasingly difficult for Thailand’s traditional criminal courts to consider and issue enforcement orders in support of ongoing investigations in a timely manner. The new Technology Crime Division addresses this challenge. This new division has jurisdiction over cybercrime and technology-related crime, fraud or extortion using computers, and criminal offenses relating to personal data protection laws. In addition, this new division has jurisdiction over all requests from competent law enforcement officers seeking court orders under the Computer Crimes Act B.E. 2550, the Personal Data Protection Act B.E. 2562, and the Cybersecurity Act B.E. 2562. The Technology Crime Division will have trainees and judges with expertise in technology and cybercrime—not only to facilitate expert prosecution of cybercrime but also to offer critical and time-sensitive support to law enforcement investigations of alleged cybercrime. The Technology Crime Division is not yet operational. The president of the Supreme Court is expected to announce the division’s opening date in the coming months. For more details on Thailand’s measures for dealing with cybercrime, please contact Michael Ramirez at [email protected] or Piyawat Vitooraporn at [email protected].
March 29, 2024
Thailand’s Cybersecurity Regulating Committee (CRC) released a notification under the Cybersecurity Act on February 22, 2024, setting key operational obligations for critical information infrastructure (CII) organizations. The notification takes effect on June 20, 2024. CII organizations are state or private entities that carry out services related to national security, public services, banking and finance, information technology and telecommunications, transportation and logistics, energy and public utilities, or public health. CII organizations will be identified by the National Cyber Security Committee (NCSC) and notified of their status. The key obligations of CII organizations are laid out below. Reporting to the National Cyber Security Agency (NCSA) CII organizations must provide the following to the NCSA: A list of executive and operational staff, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list within 15 days following any changes. A list of internal departments or individuals who are the responsible persons, owners, and holders of the computer systems, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list at least 7 days prior to any changes (or within 15 days after the change if there is a necessary reason). Policies, Guidelines, and Procedures As specified in the National Cyber Security Committee (NCSC) guidelines, CII organizations must prepare the following internal documents by June 20, 2025: Cybersecurity practice guidelines, consisting of an inspection plan, risk assessment, and incident response plan. Cybersecurity standards framework, consisting of measures for risk identification, risk prevention, threat detection and monitoring, incident responses, and resilience and recovery. CII organizations must also prepare the following: Mechanisms, procedures, and steps for monitoring and detecting
March 29, 2024
Vietnam’s Ministry of Public Security (MPS) is drafting two reports to present to the government in May 2024 to advocate for the development and adoption of a Law on Personal Data Protection. These reports include an assessment of the policy impact of the proposal to develop a personal data protection law, and an assessment of the current state of social relations related to personal data protection. Decree No. 13/2023/ND-CP on Personal Data Protection (PDPD), adopted in April 2023, became the first comprehensive legal instrument on data protection in Vietnam. When the National Assembly was debating its text and adoption in 2022 and 2023, questions were raised as to the status of this new regulation and the legality to adopt a decree before a law. In accordance with the public announcements made throughout the development of the PDPD assuring that a law would be developed at a later stage, the MPS is now advocating for the development of a Personal Data Protection Law and has drafted the two reports pursuant to the Law on the Promulgation of Legal Documents. The main arguments advanced by the MPS in the two reports are as follows: As the right to privacy is enshrined in the Constitution, any restrictions thereof must be made through a law and not a decree. The MPS is notably referring to the lawful basis for processing and limited exceptions to consent under the PDPD. This may be a sign that the MPS intends to widen the exceptions to consent under the new law. The definitions of “personal data” and “personal data protection” need to be harmonized to consolidate the regulatory framework. The MPS indicates that there are 69 legal documents directly related to “personal data protection” in Vietnam with more than 10 different definitions, while “personal information” appears in
March 28, 2024
Recently, Vietnam has witnessed a dramatic increase in cyber fraud, causing significant financial losses and posing a grave threat to both Vietnamese and foreign entities. With the increasing reliance on digital technology and the widespread adoption of online platforms, the country has become fertile ground for cybercriminals to exploit vulnerabilities and conduct various fraudulent activities. This article aims to present an overview of addressing cyber fraud in Vietnam and offers practical advice for businesses to safeguard themselves from becoming victims of such illicit activities.