Vietnam: New Data Sanctions Regime Has Real Teeth – What Decree 330/2026 Means for Your Business

On 19 August 2026, the Vietnamese Government issued Decree No. 330/2026/ND-CP setting out administrative sanctions in the fields of cybersecurity and personal data protection (“Decree 330”). Decree 330 took effect immediately on its signing date and is relevant to any entities that collect. If your business collects, stores, processes, discloses, transfers, or otherwise handles personal data in Vietnam, or operates information systems, online platforms, or content on Vietnam’s cyberspace, this Decree is already relevant to you.

Key takeaways

1. Broad scope: Decree 330 applies to Vietnamese and foreign individuals and organisations committing violations within Vietnam’s territory, waters, and airspace, including private enterprises, cooperatives, foreign-invested entities, foreign companies providing cross-border telecoms/internet/content services, and foreign organisations otherwise involved in processing the personal data of Vietnamese citizens.

2. The fines jump dramatically for data violations: for cybersecurity, the maximum fines are VND 100,000,000 (approx. USD 3,800) for individuals and VND 200,000,000 (approx. USD 7,600) for organisations (organisations are fined at twice the individual rate for the same conduct). For personal data protection, the penalties are markedly higher: (i) up to 10 times the illicit proceeds for unlawful trading in personal data (with a floor as high as VND 1 to 3 billion for large-scale or sensitive breaches where proceeds cannot be quantified); (ii) up to 5% of prior-year revenue for unlawful cross-border transfer of personal data; and (iii) up to VND 3 billion as a general cap for other personal data violations. Fines under Decree 330 apply to organisations as the base rate, with individuals fined at half the organisational rate for the same conduct.

3. Scale matters: fines scale with the number of data subjects affected and the sensitivity of the data involved. For example, unauthorised technical collection of personal data ranges from VND 100 to 200 million (approx. USD 3,800 to 7,600) (fewer than 500 basic-data subjects or fewer than 100 sensitive-data subjects) up to VND 500 to 800 million (approx. USD 18,800 to 30,200) (5,000 or more basic-data subjects or 1,000 or more sensitive-data subjects); unlawful trading ranges from VND 70 to 100 million (approx. USD 2,600 to 3,800) up to VND 1 to 3 billion (approx. USD 37,700 to 113,200) depending on scale and impact on national security, macroeconomic stability, life, health, or reputation.

4. The violations you’re most likely to run into on a normal business day now carry clear, prescribed sanctions:

  • Failure to act on cybersecurity threats: failure to implement managerial and technical measures to prevent, block, remove, or eliminate unlawful content on cyberspace, or failure to implement measures required by competent state authorities in relation to cybersecurity incidents or cybersecurity threats, is subject to fines of VND 10 to 50 million (approx. USD 380 to 1,900) for individuals, doubled for organisations;

  • Data localization non-compliance: non-compliance with data localization requirements in Vietnam, where the entity falls within the scope of a state authority’s data localisation order, is subject to fines of VND 30 to 50 million (approx. USD 1,130 to 1,900), together with a compulsory remedial measure requiring implementation of data localization in accordance with the competent state authority’s requirements;

  • Missing the 72-hour breach notification window: failure to notify the data protection authority within 72 hours of discovering a breach that causes or is capable of causing harm attracts fines of VND 40 to 60 million (approx. USD 1,500 to 2,300); broader notification and cooperation failures attract further fines and mandatory remedial measures;

  • Consent and data subject rights failures: separate violations covering consent mechanics (e.g., default opt-in, unclear consent flows), failure to honour access, rectification, erasure, or restriction requests within prescribed deadlines, unlawful disclosure or public release of data, and non-compliant cross-border transfer or sharing arrangements each carry distinct fine bands generally between VND 10 to 80 million (approx. USD 380 to 3,000), plus remedial obligations (e.g., deletion of unlawfully processed data, disgorgement of illicit gains, public correction or apology);

  • Missing impact assessment reports: failure to prepare and submit a data processing impact assessment report is subject to fines of VND 20 to 30 million (approx. USD 750 to 1,130); failure to prepare and submit a cross-border data transfer impact assessment report is subject to fines of VND 30 to 50 million (approx. USD 1,130 to 1,900), together with compulsory remedial measures requiring the entity to prepare the report or cease providing services;

  • Cross-border transfer failures – the heaviest sanctions in the Decree: failure to obtain clear consent from and provide notice to data subjects regarding the overseas transfer of their data, or failure to execute a contract or agreement between the data transferor and the overseas data recipient, or failure to ensure adequate protective measures when transferring personal data abroad, is subject to fines of VND 50 to 100 million (approx. USD 1,900 to 3,800). Where such violations result in leakage or loss of personal data across borders, the penalties are revenue-based: 1 to 2% of the preceding financial year’s revenue in the Vietnamese market where the breach affects 10,000 to fewer than 100,000 data subjects; 2 to 3% where it affects 100,000 to fewer than 1,000,000 data subjects; and 3 to 5% where 1,000,000 or more data subjects are affected.

5. It’s not just about fines: authorities may also suspend or revoke licences (1 to 24 months), suspend operations (1 to 24 months), confiscate exhibits/instrumentalities, deport foreign violators, and impose remedial measures such as data deletion, restoration of systems, disgorgement of illicit gains, and mandatory public correction or notification to affected data subjects.

The bottom line: Decree 330 sharply increases exposure for personal data violations compared to cybersecurity-only breaches, with fines potentially reaching VND 3 billion or a percentage of revenue – materially higher than typical administrative fine caps in Vietnam. If your business processes personal data at scale, runs cross-border data transfers, or operates a data-driven business model, now is the time to stress-test your compliance posture: consent flows, breach response protocols (especially the 72-hour notification window), data subject request handling timelines, and cross-border transfer arrangements should all be reviewed against this new regime, which is already in force.

The information provided here is for information purposes only and is not intended to constitute legal advice. Legal advice should be obtained from qualified legal counsel for all specific situations.

DFDL offers integrated regional support across 10 jurisdictions. View our Vietnam location profile for further details.

Key Contacts