You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 25, 2026

Vietnam Issues Cybersecurity and Personal Data Protection Sanctions Decree

Vietnam has enacted a new decree establishing administrative penalties for violations in the fields of cybersecurity and personal data protection. Decree No. 330/2026/NĐ-CP (Decree 330), issued and effective from August 19, 2026, provides a detailed sanctions framework for noncompliance with the Law on Personal Data Protection (including its implementing regulations under Decree 356/2025/ND-CP) and the Law on Cybersecurity, together with their guiding decrees.

The issuance of Decree 330 signals that the practical grace period previously perceived by many businesses may be drawing to a close, with active regulatory enforcement in these areas expected to commence in earnest.

Scope and Key Provisions

Decree 330 has extraterritorial effect and applies to both onshore and offshore companies. For offshore companies, it applies to those that (1) provide telecommunications, internet, online-content, information-technology, cybersecurity, or cross-border services and (2) are involved in or related to the processing of personal data of Vietnamese citizens and certain other people of Vietnamese origin.

Decree 330’s key provisions cover the following areas:

  • Administrative penalties for violations relating to the protection of national security and public order in cyberspace, including the dissemination of unlawful, false, or unverified information.
  • Sanctions for cyberattacks, unauthorized access, introduction of harmful code or programs, and failure to cooperate with specialized cybersecurity forces.
  • Sanctions for personal data protection violations, such as consent, cross-border data transfers, impact assessments, breach notification, and data-subject rights, among others—with maximum fines of up to 5% of an organization’s preceding-year revenue for cross-border transfer violations, or up to VND 3 billion for other data-protection breaches.

Personal Data Protection Penalties

The key sanctions for personal data protection violations are as follows:

  • Consent violations: Fines of up to VND 70 million (approx. USD 2,642), plus potential additional sanctions and remedial measures including irreversible deletion of personal data collected without consent and confiscation of illegal profits.
  • Data breach notification violations: Fines of up to VND 80 million (approx. USD 3,019), with potential remedial measures including mandatory breach notification and implementation of prevention and remedial measures as directed by the regulator.
  • Data processing impact assessment (DPIA) violations: Fines of up to VND 100 million (approx. USD 3,774), with potential remedial measures including mandatory DPIA submission and suspension of personal data processing until the filing obligation is successfully completed.
  • Cross-border transfer impact assessment (TIA) violations: Fines of up to 5% of preceding-year revenues or up to VND 3 billion (approx. USD 113,208), with potential additional sanctions and remedial measures including mandatory TIA submission and suspension of cross-border personal data transfers until the filing obligation is successfully completed.
  • Data protection officer and department appointment violations: Fines of up to VND 30 million (approx. USD 1,132), with potential remedial measures including mandatory appointment of a qualified person and mandatory issuance of policies and documents relating to personal data protection responsibilities.

Transitional Provisions

Decree 330 includes a transitional clause including a provision that where a cybersecurity or personal data protection violation was committed before Decree 330 took effect but is only discovered, or remains under review or resolution, after that date, the sanctions regime in force at the time of the violation will generally apply. However, where Decree 330 imposes no liability or lighter liability for the same conduct, companies may invoke the more favorable provisions.

Outlook and Recommendations

Decree 330 taking effect immediately upon its issuance is a signal that the regulator intends to commence active enforcement. For context, the Vietnam Competition Commission has recently been very active in enforcing consumer protection regulations against major companies, including privacy-related provisions such as requirements to obtain proper consent for the collection and use of personal data. With Decree 330 now in effect, the Ministry of Public Security (the authority responsible for data protection and cybersecurity) has full power to impose penalties for noncompliance with the Law on Personal Data Protection and the Law on Cybersecurity, notably including requirements relating to data protection impact assessments, cross-border data transfer impact assessments, data localization, data protection officers (DPOs) and forms and mechanisms for obtaining consent.

This is particularly significant given that businesses have had over three years to prepare—from the issuance of Decree No. 13/2023/NĐ-CP on personal data protection, which took effect on July 1, 2023, through to the enactment of the Law on Personal Data Protection effective January 1, 2026. Companies should reassess their compliance status and ensure they are prepared to demonstrate compliance when requested by the relevant authorities.

RELATED INSIGHTS​ 

March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing
March 16, 2026
Thailand’s Securities and Exchange Commission (SEC) has broadened the definition of institutional investors, expanded the types of qualifying investments, and updated financial qualification thresholds for various investor categories through a revised notification on the definitions of institutional investors, ultra-high net worth investors, and high net worth investors. The amended framework, which came into force on March 1, 2026, adds digital asset business operators, investment planners, and investment consultants to the roster of entities recognized as institutional investors, and broadens the definition of investment to account for digital tokens. Expanded Definition of Institutional Investors Under the SEC’s revised notification, the category of institutional investors now expressly includes digital asset business operators licensed under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). This addition recognizes the growing role of digital asset platforms and service providers in Thailand’s investment ecosystem and aligns the regulatory treatment of digital markets with that of traditional markets. The definition of institutional investors now also encompasses investment planners and investment consultants approved by the SEC. Previously, only SEC-approved investment analysts held this status; the expansion covers a broader scope of professionals who possess comparable expertise and experience in evaluating investment opportunities. Broadened Investment Definition The revised framework now defines investment to mean direct or indirect investment in a wider range of assets beyond deposits. Specifically, the definition covers: Securities under the Securities and Exchange Act Derivatives under the Derivatives Act Investment tokens offered to the public Government-issued digital tokens (G-tokens) as specified in a separate SEC notification This expansion ensures that financial status assessments reflect the full spectrum of an investor’s holdings, including emerging digital assets. Updated Financial Qualification Thresholds The amended SEC notification also provides updated qualification thresholds for angel investors, ultra-high net worth investors, and high net worth investors. While the core criteria
March 13, 2026
Vietnam’s Law on Intellectual Property (IP Law) has undergone continuous amendment in recent years, with the latest amendment issued at the end of 2025. Among the amended and supplemented provisions, the regulation that has perhaps attracted the most attention is a provision relating to the use of protected IP objects by artificial intelligence (AI) systems. Specifically, Article 7 of the 2025 IP Law introduces a completely new Clause 5, which reads in full as follows: “Organizations and individuals are permitted to use texts and data relating to intellectual property objects that have been lawfully published, and which the public is allowed to access, for the purposes of scientific research, experimentation, and training of artificial intelligence systems, provided that such use will not unreasonably affect the legitimate rights and interests of the authors and intellectual property rights holders in accordance with this Law. With respect to texts and data that are objects protected by copyright and related rights, the use of the texts and data as set forth herein must also be in accordance with the regulations of the Government.” Analyzing this newly added provision in the context of how it was conceived, as well as the challenges that still lie ahead, can provide some interesting insights. From Aspirations to Flight in Science and Technology From the end of 2024 and throughout 2025—the 50th anniversary of the country’s reunification—Vietnam witnessed numerous sweeping changes in many areas, including legislative development. It could be said that no sessions of the National Assembly have ever adopted as many laws, resolutions, and major policies as this one. The aspirations of the highest-level leadership have been concretized into major law and policy projects, which were drafted, developed, and passed at record speed. All of this was aimed at building a foundation for Vietnam to achieve