
Administratve penalties in data protection field
Mai Nguyen

On 19 August 2026, the Government of Vietnam issued Decree No. 330/2026/NĐ-CP establishing administrative penalties for violations in the fields of cybersecurity and personal data protection(“Decree 330”). Being effective from August 19, 2026, Decree 330 provides a detailed sanctions framework for non- compliance with the Personal Data Protection Law, the Cybersecurity Law and their guiding regulations.With the issuance of Decree 330 the practical grace period previously perceived by many businesses may be drawing to a close, with active regulatory enforcement in these areas expected to commence.Decree 330 has extraterritorial effect and applies to both onshore and offshore companies. For offshore companies, it applies to those that provide telecommunications, internet, online-content, information-technology, cybersecurity, or cross-border services and that are involved in or related to the processing of personal data of Vietnamese citizens and certain other people of Vietnamese origin.Decree 330’s provides for:
administrative penalties for violations relating to the protection of national security and public order in cyberspace, including the dissemination of unlawful, false, or unverified information;
sanctions for cyberattacks, unauthorized access, introduction of harmful code or programs, and failure to cooperate with specialized cybersecurity forces; and
sanctions for personal data protection violations, such as consent, cross-border data transfers, impact assessments, breach notification, and data-subject rights, among others with maximum fines of up to 5% of an organization’s preceding-year revenue for cross-border transfer violations, or up to VND 3 billion for other data-protection breaches.
Decree 330 was issued in the context Vietnam is actively enforcing consumer protection regulations against major companies, including privacy-related provisions such as requirements to obtain proper consent for the collection and use of personal data.