Vietnam's Government promulgated Decree 330/2026/ND-CP on August 19, 2026, establishing the first dedicated administrative-penalty regime for the cybersecurity and personal data protection field, with fines reaching 70 million VND per violation. Published in the Government Electronic Newspaper on August 22, 2026, the decree took effect on its promulgation date, leaving organizations that process personal data of Vietnamese residents no transition window to align consent, impact-assessment, and cross-border transfer practices.

Structured across four chapters and 82 articles, the decree closes a gap that opened when the Law on Personal Data Protection (PDPL, Law 91/2025/QH15) entered force on January 1, 2026: until now, the PDPL and its guiding Decree 356/2025/ND-CP set substantive duties but no standalone fine schedule for breaching them. Decree 330 attaches monetary penalties, confiscation, and remedial orders to violations spanning consent, purpose limitation, data-subject rights, cross-border transfers, data protection impact assessments, and the designation of data protection personnel (Government Electronic Newspaper, August 22, 2026).

Who must comply, and from when?

The decree binds every Vietnamese and foreign individual or organization whose administrative violation in cybersecurity or personal data protection occurs within Vietnam's territory, internal waters, territorial sea, exclusive economic zone, continental shelf, or on Vietnamese-flagged vessels and aircraft, with effect from August 19, 2026. Article 1.2(d) explicitly captures foreign enterprises and their branches, representative offices, and business locations providing telecom, Internet, online content, IT, cybersecurity, or cross-border services, plus foreign agencies and organizations that process personal data of Vietnamese citizens and overseas Vietnamese of undetermined nationality resident in Vietnam.

Household businesses, family households, and residential communities are fined at the individual rate. Jurisdiction is split by portfolio: the Ministry of National Defense covers cybersecurity for military and defense tasks, while the Ministry of Public Security covers civilian matters, including the cybersecurity units of military bodies with civil or economic activity, under a coordination protocol for any overlap. Cross-border digital service providers handling Vietnamese residents' data therefore sit squarely in scope, with no separate grace period.

What fines apply to personal data protection violations?

The decree sets graduated fine tiers tied to the gravity of the conduct. The densest way to read them is as a ladder:

Violation clusterFine range (VND)Representative triggers
Principles and prohibited acts, lower20,000,000 to 40,000,000Processing beyond scope or purpose; failing to ensure accuracy or correct errors; retaining data longer than necessary; failing to prevent, detect, or cooperate
Principles and prohibited acts, higher40,000,000 to 60,000,000Obstructing or resisting data protection activities; using another person's data for unlawful acts
Consent violations, lower30,000,000 to 50,000,000Processing without valid consent; bundling consent with unrelated service conditions; default opt-in or misleading consent design; not logging consent; not notifying sensitive-data processing
Consent violations, higher50,000,000 to 70,000,000Continuing to process after a stop or restrict request, or a state authority's written order; treating a data subject's silence as consent

Beyond these two clusters, the decree also sets penalties for the full PDPL duty set: data-subject rights, withdrawal of consent, correction of data, collection, disclosure, deletion and de-identification, transfer, breach notification, data protection impact assessments, cross-border transfer, and the designation of data protection personnel.

What remedial measures and additional sanctions can regulators impose?

A fine is not the only consequence. Each cluster pairs monetary penalties with supplementary and remedial measures: confiscation of the means and instruments of the violation; forced deletion of personal data to a level where it cannot be restored; refund of any illicit gains; a public apology to the data subject through mass media; and forced correction, update, or supplementation of inaccurate data. The remedial orders are the operational sting: irreversible data deletion and a mandated public apology are reputational and technical burdens that the headline fine alone understates, and they apply alongside, not instead of, the monetary penalty.

How does Decree 330 fit Vietnam's broader data stack?

The decree creates no new substantive duties; it enforces the existing PDPL stack. The PDPL (Law 91/2025) entered force on January 1, 2026, guided by Decree 356/2025/ND-CP, which replaced Decree 13/2023/ND-CP, while the Law on Cybersecurity 2025 consolidates the 2018 and 2015 laws and takes effect on July 1, 2026, with a transition for pre-existing systems until July 1, 2027. The Ministry of Public Security leads PDPL policy and the Authority of Information Security supports implementation. For cross-border providers already aligning to the PDPL, Decree 330 makes the cost of non-alignment concrete and immediate, because enforcement can run from the in-force date.

Continuous, per-jurisdiction regulatory monitoring surfaces a change like this the moment a government gazette publishes it, before the first enforcement letter lands.

Take advantage of this real-time watch

Vietnam E-commerce Law: implementing decrees watchLive
Monitor the vn-platform-governance topic in real time: official publications, votes, guidance, enforcement and deadline changes tied to the milestones identified in the Strategy Bible wave 1 brief for VN.
Hourly Email 10+ news
This live monitoring job detected the news you are reading.
Activate this watch free now

For compliance teams, the immediate priorities are:

  • Confirm applicability: determine whether your organization, including any cross-border service line, processes personal data of Vietnamese residents, which brings it within Article 1.2(d).
  • Audit consent flows against the new tiers: default opt-in, bundled consent, and treating silence as consent are now expressly fined at 30 million to 70 million VND.
  • Verify that data protection impact assessments, cross-border transfer compliance, and designated data protection personnel or departments are in place and documented.
  • Prepare for remedial exposure, not only fines: be ready to irreversibly delete data and issue public apologies if ordered.
  • Brief the privacy and security teams: the decree is in force, so the alignment window is already closed.