You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 25, 2026

Vietnam Issues Cybersecurity and Personal Data Protection Sanctions Decree

Vietnam has enacted a new decree establishing administrative penalties for violations in the fields of cybersecurity and personal data protection. Decree No. 330/2026/NĐ-CP (Decree 330), issued and effective from August 19, 2026, provides a detailed sanctions framework for noncompliance with the Law on Personal Data Protection (including its implementing regulations under Decree 356/2025/ND-CP) and the Law on Cybersecurity, together with their guiding decrees.

The issuance of Decree 330 signals that the practical grace period previously perceived by many businesses may be drawing to a close, with active regulatory enforcement in these areas expected to commence in earnest.

Scope and Key Provisions

Decree 330 has extraterritorial effect and applies to both onshore and offshore companies. For offshore companies, it applies to those that (1) provide telecommunications, internet, online-content, information-technology, cybersecurity, or cross-border services and (2) are involved in or related to the processing of personal data of Vietnamese citizens and certain other people of Vietnamese origin.

Decree 330’s key provisions cover the following areas:

  • Administrative penalties for violations relating to the protection of national security and public order in cyberspace, including the dissemination of unlawful, false, or unverified information.
  • Sanctions for cyberattacks, unauthorized access, introduction of harmful code or programs, and failure to cooperate with specialized cybersecurity forces.
  • Sanctions for personal data protection violations, such as consent, cross-border data transfers, impact assessments, breach notification, and data-subject rights, among others—with maximum fines of up to 5% of an organization’s preceding-year revenue for cross-border transfer violations, or up to VND 3 billion for other data-protection breaches.

Personal Data Protection Penalties

The key sanctions for personal data protection violations are as follows:

  • Consent violations: Fines of up to VND 70 million (approx. USD 2,642), plus potential additional sanctions and remedial measures including irreversible deletion of personal data collected without consent and confiscation of illegal profits.
  • Data breach notification violations: Fines of up to VND 80 million (approx. USD 3,019), with potential remedial measures including mandatory breach notification and implementation of prevention and remedial measures as directed by the regulator.
  • Data processing impact assessment (DPIA) violations: Fines of up to VND 100 million (approx. USD 3,774), with potential remedial measures including mandatory DPIA submission and suspension of personal data processing until the filing obligation is successfully completed.
  • Cross-border transfer impact assessment (TIA) violations: Fines of up to 5% of preceding-year revenues or up to VND 3 billion (approx. USD 113,208), with potential additional sanctions and remedial measures including mandatory TIA submission and suspension of cross-border personal data transfers until the filing obligation is successfully completed.
  • Data protection officer and department appointment violations: Fines of up to VND 30 million (approx. USD 1,132), with potential remedial measures including mandatory appointment of a qualified person and mandatory issuance of policies and documents relating to personal data protection responsibilities.

Transitional Provisions

Decree 330 includes a transitional clause including a provision that where a cybersecurity or personal data protection violation was committed before Decree 330 took effect but is only discovered, or remains under review or resolution, after that date, the sanctions regime in force at the time of the violation will generally apply. However, where Decree 330 imposes no liability or lighter liability for the same conduct, companies may invoke the more favorable provisions.

Outlook and Recommendations

Decree 330 taking effect immediately upon its issuance is a signal that the regulator intends to commence active enforcement. For context, the Vietnam Competition Commission has recently been very active in enforcing consumer protection regulations against major companies, including privacy-related provisions such as requirements to obtain proper consent for the collection and use of personal data. With Decree 330 now in effect, the Ministry of Public Security (the authority responsible for data protection and cybersecurity) has full power to impose penalties for noncompliance with the Law on Personal Data Protection and the Law on Cybersecurity, notably including requirements relating to data protection impact assessments, cross-border data transfer impact assessments, data localization, data protection officers (DPOs) and forms and mechanisms for obtaining consent.

This is particularly significant given that businesses have had over three years to prepare—from the issuance of Decree No. 13/2023/NĐ-CP on personal data protection, which took effect on July 1, 2023, through to the enactment of the Law on Personal Data Protection effective January 1, 2026. Companies should reassess their compliance status and ensure they are prepared to demonstrate compliance when requested by the relevant authorities.

RELATED INSIGHTS​ 

February 28, 2025
Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below. 1. Classification of Telecom Services The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows: Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.” Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added. 2. M2M Communication Services Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically: Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope. Onshore provision: Onshore M2M communication services will require a telecom license. 3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services) The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance
February 26, 2025
Tilleke & Gibbins has contributed the Vietnam chapter to Data Protection 2025, a comprehensive comparative guide in the Law Over Borders series from Global Legal Post. This Q&A-style resource offers detailed insights into data protection regulations across multiple jurisdictions, serving as an essential reference for organizations managing personal data in today’s global business environment. The Vietnam chapter examines the evolving data protection landscape in Vietnam, including analysis of relevant provisions in the Cybersecurity Law, the Law on Information Technology, and the upcoming Personal Data Protection Decree. The chapter addresses key aspects of data protection through the following topics: Regulatory framework: Analysis of national laws regulating personal data, jurisdictional scope, application to different entities, and regulated data processing activities. Data categories and processing: Overview of regulated personal data types, special categories requiring enhanced protection, and lawful processing requirements. Compliance requirements: Explanation of controller and processor obligations, technical and organizational measures, and data subject rights. Commercial communications and international transfers: Rules governing direct marketing and cross-border data flows. Regulatory oversight: Details on enforcement powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Thailand chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.
February 26, 2025
Tilleke & Gibbins has contributed the Thailand chapter to Data Protection 2025, a newly published comparative guide from Global Legal Post’s Law Over Borders series. This comprehensive Q&A-style resource provides insights into data protection regulations across multiple jurisdictions worldwide, offering valuable guidance for businesses navigating the complex landscape of global data privacy requirements. The Thailand chapter offers a detailed analysis of the country’s data protection framework, with particular focus on the Personal Data Protection Act (PDPA) that came into full effect in 2022. The chapter addresses key aspects of data protection in Thailand through the following topics: Regulatory framework: National laws governing personal data, scope of application, territorial reach, and regulated operations. Data categories and protection: Types of personal data covered, special categories subject to enhanced protection, and processing requirements. Compliance obligations: Requirements for lawful processing, organizational responsibilities, and data subject rights. Marketing and cross-border considerations: Rules for commercial communications and international data transfers. Enforcement mechanisms: Regulatory powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Vietnam chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.
February 20, 2025
Vietnam’s Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (Decree 147) was issued on November 9, 2024, and came into effect on December 25, 2024. Decree 147 represents a more stringently regulated digital landscape in Vietnam, creating challenges not only for offshore service providers offering cross-border services but also for onshore providers. As these new regulations impose stricter requirements, particularly in areas like content control, user authentication, data storage, and service license/notification, companies will need to adapt quickly to maintain compliance and minimize legal risks. The following are some of the key topics covered by Decree 147. [Note: Shortly after the issuance of Decree 147, Vietnam began a government restructuring process, with the aim of streamlining the government by consolidating and eliminating various ministries and agencies. Thus, the decree’s references to authorities such as the Authority of Broadcasting and Electronic Information (ABEI) and the Ministry of Information and Communications (MIC) are subject to change.] 1. Cross-Border Information Provision Cross-border information provision is defined broadly as the provision by overseas organizations and individuals of information and online information content services for service users in Vietnam to access or use. This wide-ranging definition encompasses various types of cross-border services, including social network services, online game services, and app store services. However, cross-border provision of online game services remains prohibited under Decree 147 (see further details below). Offshore providers of services on a cross-border basis who lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months (“regulated cross-border providers”) must adhere to stricter requirements. Specifically, they are required to, among other requirements: Notify the relevant authority of their contact information, including the location of the main server providing the service, within 60