Special Alert | Decree 330 – Tightening Cybersecurity and Personal Data Protection Enforcement

On 19 August 2026, the Government issued Decree No. 330/2026/ND-CP on administrative penalties in the fields of cybersecurity and personal data protection (“Decree 330”), which took effect immediately. The Decree was introduced against the backdrop of increasingly complex violations in cyberspace, ranging from cyberattacks, false information and online fraud to the unlawful collection, use, exchange and sale of personal data.

Notably, prior to Decree 330, relevant sanctions were dispersed across different regulations, certain obligations under cybersecurity and personal data protection laws lacked corresponding penalties, and some existing fines were considered insufficiently deterrent. The promulgation of Decree 330, therefore, tightens enforcement by providing more specific violations, penalties and remedial measures, thereby bringing obligations under the Law on Cybersecurity 2025 and the Law on Personal Data Protection within a more concrete enforcement framework.

Key Takeaways

  • Violations relating to Security and Public Order in Cyberspace and Prevention of Cyberattacks: Liability may arise not only from directly creating unlawful content or carrying out cyberattacks, but also from sharing or disseminating such content, and failures to cooperate with competent functional agencies in cyberattack prevention.
  • Violations in the Implementation of Cybersecurity Protection Activities: Decree 330 emphasises practical safeguards, from system and child protection in cyberspace to data storage and local presence in Vietnam. Violations may result in service suspension, in addition to monetary penalties.
  • Violations relating to Management of Cybersecurity Products and Services: Stricter digital-account authentication, identification, logging and security requirements, with the use of AI or deepfake to falsify biometric data also subject to sanctions.
  • Violations relating to Anti-Spam Messages, Emails and Calls: Greater focus on consent, opt-out rights and service-provider responsibilities.
  • Personal Data Protection Violations: Specific sanctions for obligations relating to processing purposes, retention, consent, unlawful data transfers and data trading, impact assessments and personal data protection personnel.
  • Transitional Provisions: Clarifies the application of more favourable provisions to violations committed before the effective date of Decree 330.

In this article, we will discuss some key highlights of Decree 330 and provide practical insights into the implications of the new enforcement regime for businesses’ cybersecurity and personal data protection compliance.

Violations relating to Security and Public Order in Cyberspace and Prevention of Cyberattacks

Decree 330 establishes sanctions for a broad range of conduct affecting security and public order in cyberspace, including the provision, sharing or dissemination of unlawful, false or unverified information. Depending on the violation, fines may reach VND 30 million for individuals and VND 60 million for organisations, together with remedial measures such as mandatory removal, deletion or correction of the relevant information.

Accordingly, liability is not limited to those directly creating unlawful content, but also extends to its provision, sharing or dissemination. In practice, false or unverified posts may spread rapidly through corporate social media accounts, community groups, accounts managed by page administrators or automated sharing functions of online platforms, potentially causing public concern or confusion. Liability may also arise for organisations managing or operating platforms or systems where they fail to take necessary measures to detect, prevent or remove unlawful content or to cooperate with competent authorities. Businesses operating websites, digital platforms, social networks or other channels hosting user-generated content should therefore pay particular attention to content governance and removal mechanisms, as well as their ability to respond promptly to requests from competent authorities.

Beyond content-related risks, Decree 330 also introduces specific sanctions for cyberattack-related conduct against the backdrop of increasingly automated and sophisticated attacks, particularly with the use of artificial intelligence (AI). Sanctionable conduct includes unauthorised access to or interference with data, improper exploitation or use of technical vulnerabilities, as well as failure to fully and timely provide relevant information and documents upon request by competent authorities.

Notably, cyberattack-related liability is not limited to directly carrying out an attack. Decree 330 also sanctions failure to cooperate with specialised cybersecurity forces in preventing and eliminating cyberattacks, with fines of up to VND 50 million for individuals and VND 100 million for organisations. Businesses should therefore focus on prevention, detection, response and coordination, while maintaining appropriate internal mechanisms to address incidents and respond to competent authorities in a timely manner.

Violations in the Implementation of Cybersecurity Protection Activities

Provisions in this section of Decree 330 demonstrate that cybersecurity liability may arise not only from directly accessing or compromising information systems, but also from failures to implement required protective measures for systems under an organisation’s or individual’s management. Decree 330 therefore places emphasis on the practical implementation of cybersecurity obligations, rather than merely adopting internal policies or procedures.

Key areas covered by this group of provisions include the prevention, detection and handling of malware; security monitoring and protection of information systems; protection of children in cyberspace; and data-storage and local-presence requirements. For businesses, these provisions require the implementation of technical and organisational measures in practice, as well as the ability to demonstrate compliance when required.

Among these, certain violations relating to the protection of children in cyberspace may attract fines of up to VND 100 million for individuals and VND 200 million for organisations, including failure to cooperate with competent authorities in safeguarding children’s rights in cyberspace, or inciting, enticing, inducing or coercing children to view, share or disseminate content that is harmful to or infringes upon children and their rights. For violations relating to data storage, retention of system logs and requirements to establish a branch or representative office in Vietnam, fines may reach VND 50 million for individuals and VND 100 million for organisations.

It should also be noted that the risks under Decree 330 extend beyond monetary penalties. Depending on the violation, remedial measures may include mandatory system restoration, implementation of cybersecurity measures, suspension of licences, compulsory data storage or establishment of a local presence in Vietnam and, in certain cases, suspension of services or connectivity. For digital platforms, telecommunications providers or businesses heavily dependent on online systems, service disruption may have significant commercial consequences, potentially exceeding the monetary penalty itself. Businesses should therefore consider potential operational disruption and remediation costs when assessing risks under Decree 330, rather than focusing solely on maximum fines.

Violations relating to Management of Cybersecurity Products and Services

Within the framework for managing cybersecurity products and services, Decree 330 gives particular attention to digital accounts, including bank accounts and cards, e-wallets, mobile money, securities, transaction, insurance and tax accounts, as well as other digital accounts with financial transaction functions.

For these accounts, Decree 330 imposes requirements concerning account authentication, identification and security. Sanctionable conduct includes failure to conduct authentication and identification as required, or to retain device information, IP addresses and login times for the prescribed minimum period. Notably, the use of artificial intelligence, deepfake or other advanced technologies to falsify biometric data for unlawful account authentication may attract fines of up to VND 50 million for individuals and VND 100 million for organisations.

These provisions demonstrate that digital-account management does not end with identity verification at the registration stage, but extends throughout the account lifecycle. Businesses operating platforms or services involving digital accounts, particularly those used for financial transactions, should therefore integrate authentication records, access logging and abnormal-activity detection into their account governance and security mechanisms.

Violations relating to Anti-Spam Messages, Emails and Calls

Decree 330 specifies violations relating to advertising emails, messages and calls, including sending advertisements without consent, continuing to contact users after they have opted out, failing to comply with requirements on advertising labels, sender identification, frequency and permitted advertising hours, and failing to retain opt-in or opt-out information. Service providers are also required to implement tools and technical measures to block, filter and control sources of spam emails.

As regards penalties, sending advertising emails or messages without the recipient’s consent, or making advertising calls without clear consent, may attract fines of up to VND 20 million for individuals and VND 40 million for organisations. Different penalty levels apply to violations concerning advertising labels, sender identification, retention of opt-in or opt-out information, frequency and permitted advertising hours.

An important distinction is that consent to receive advertising and consent to process personal data are related but not necessarily identical. A customer providing a phone number for authentication codes, delivery updates or after-sales support does not automatically permit the business to use that number for advertising calls. Similarly, obtaining an email address from an earlier transaction does not, by itself, permit its use for marketing communications. Businesses should therefore manage consent by purpose and communication channel, rather than relying on a single consent status for all activities.

Service providers may be subject to significantly higher penalties. For example, failure to block or withdraw subscriber numbers used to disseminate spam messages or calls may attract fines of up to VND 100 million for individuals and VND 200 million for organisations. This demonstrates that responsibilities for preventing and combating spam messages and calls extend beyond parties directly conducting advertising activities to service providers responsible for detecting and addressing the sources of such communications, thereby strengthening their accountability in addressing the widespread practice of unsolicited advertising calls and messages.

Personal Data Protection Violations

Personal data protection is one of the areas with the broadest and most direct impact on business operations. Decree 330 provides sanctions for a wide range of obligations, from processing purposes, retention periods and consent to data transfers, impact assessments and data protection personnel. Sanctionable conduct may arise not only from complex data-processing activities but also from ordinary business processes such as recruitment, employee management, customer service, marketing, CCTV use and engagement of service providers.

 Processing Purposes, Retention and Consent

Article 39 sanctions processing beyond the defined scope or purpose and retaining personal data longer than necessary, with fines of up to VND 20 million for individuals and VND 40 million for organisations. This has significant practical implications where employee, customer or applicant data is retained across multiple systems without consistent deletion periods. Businesses should therefore establish appropriate retention periods for different categories of data and ensure that deletion mechanisms operate in practice, rather than existing only in internal policies.

Article 43 further focuses on the mechanisms for obtaining and managing consent. Sanctionable conduct includes processing without valid consent; making unrelated processing purposes a condition of service provision; default consent; unclear or misleading instructions; failure to allow separate consent for each purpose; and failure to record and retain consent information. In particular, collecting or processing personal data where the data subject remains silent or does not respond to a request for consent, and treating such silence or non-response as consent, may attract fines of up to VND 35 million for individuals and VND 70 million for organisations.

Unlawful Transfer and Trading of Personal Data

Article 52 sets out requirements applicable to personal data transfers, including the allocation of data-protection responsibilities between the parties, protection of data-subject rights and cooperation mechanisms in the event of violations. In particular, transferring sensitive personal data without applying physical security measures to storage and transmission devices, encryption, anonymisation or other security measures during the transfer may attract fines of up to VND 40 million for individuals and VND 80 million for organisations.

Article 53, meanwhile, introduces one of the more significant penalty mechanisms under Decree 330 for the unlawful trading of personal data. For certain violations, fines may be calculated at between two and ten times the proceeds obtained from the violation. Unlike a fixed administrative penalty cap, this mechanism allows the level of exposure to increase with the proceeds derived from the violation.

Processing and Cross-Border Transfer Impact Assessments

Article 55 provides sanctions on failures to prepare, maintain, submit or update the Personal Data Processing Impact Assessment (“PDPIA”) dossier, as well as falsification of data or provision of misleading information. Article 56 applies a similar approach to the Cross-Border Personal Data Transfer Impact Assessment (“CPDTIA”) dossier and also provides sanctions for violations relating to onward transfers by data recipients.

The fact that late filing, failure to update or failure to maintain the dossiers may also be sanctioned demonstrates that PDPIA and CPDTIA should not be treated as one-off compliance exercises. Business data flows may change when a new system provider is engaged, data-hosting locations change, new data recipients are added or processing purposes expand. Changes that appear to concern only procurement, IT or operations may therefore also trigger the need to review and update the relevant impact-assessment dossiers.

For personal data processing impact assessments, intentionally falsifying data or providing inaccurate information in the PDPIA dossier, or refusing to revise or complete the dossier as required by the competent authority, may attract fines of up to VND 50 million for individuals and VND 100 million for organisations. For cross-border personal data transfers, fines may reach 5% of the organisation’s total revenue for the immediately preceding financial year in the Vietnamese market** where the organisation fails to prepare the CPDTIA dossier, conceals or misrepresents data flows, resulting in the breach or loss of personal data of at least one million Vietnamese citizens.

Beyond monetary penalties, businesses may also be required to suspend personal data processing until the relevant PDPIA obligations have been fulfilled, or suspend cross-border personal data transfers until the relevant CPDTIA obligations have been fulfilled. In certain cases, the recipient may also be required to delete data transferred in violation of applicable requirements. Businesses should therefore regularly review and update their PDPIA and CPDTIA in line with actual processing activities and data flows, particularly where a suspension of processing or cross-border transfers could directly affect business operations.

Personal Data Protection Personnel/Function

Article 57 provides sanctions for various violations relating to personal data protection personnel and functions, ranging from confidentiality obligations, training and the content of appointment documents to the qualifications and experience of designated personnel. In particular, failure to formally appoint personal data protection personnel or establish a personal data protection function, or appointing personnel who do not meet the prescribed qualification, experience or professional training requirements, may attract fines of up to VND 30 million for organisations.

Personal Data Protection in Specific Activities

Decree 330 also specifically addresses violations arising from several common processing activities. Article 60 imposes requirements concerning age verification and consent mechanisms when processing children’s personal data. Article 61 addresses recruitment and employee management, including unnecessary collection of recruitment data, use for improper purposes, excessive retention and the use of monitoring software or CCTV without adequate transparency. Article 71 sets out requirements for audio and video recording in public places or service areas and sanctions certain further uses of recorded data.

These provisions demonstrate that personal-data protection risks may arise from ordinary business operations. HR teams may face exposure by requesting excessive information from candidates or retaining unsuccessful applications for too long; facilities teams may create issues by installing CCTV without appropriate notice; and using CCTV data for analytics or identification may materially change the nature and risk of the processing. Personal-data protection responsibilities should therefore extend beyond legal or IT teams to the business functions that directly determine how data is collected, used and retained.

Transitional Provisions

Decree 330 also provides for transitional application in accordance with the principles on retrospective effect under the Law on Promulgation of Legislative Documents. Accordingly, violations committed before 19 August 2026 but discovered or sanctioned thereafter are, in principle, subject to the regulations in force at the time of the violation. However, Decree 330 will apply where it imposes no legal liability or provides for less severe legal liability for the relevant violation.

Conclusion

Decree 330 marks a significant transition in Vietnam’s cybersecurity and personal data protection framework, from establishing substantive obligations to providing a relatively comprehensive enforcement and penalty regime. Consolidating the relevant sanctions in a single instrument not only provides greater clarity on violations, penalties and remedial measures, but also establishes a clearer legal basis for inspection and enforcement in practice, thereby contributing to a safer and more transparent digital environment.

For businesses, Decree 330 demonstrates that compliance should go beyond adopting internal policies and procedures and must be capable of being implemented and evidenced in practice. Businesses should therefore review higher-risk activities, particularly system security, consent, data retention and transfers, impact assessments, marketing and context-specific data processing, while ensuring that compliance responsibilities are appropriately allocated across the relevant business functions.

Related Articles