Companies that collect, store, or share data in Vietnam should check how they handle it before November 11, 2026. That is when Decree 363/2026/ND-CP on penalties for data violations in Vietnam takes effect. Issued on September 19, 2026, it sets fines for data violations and the steps authorities may require to correct them. Foreign organizations connected with data activities in Vietnam can also fall within its scope.
For managers, Vietnam data compliance means knowing whether the company’s written rules are followed in daily work. Information may be held by different departments, overseas group companies, and outside suppliers. Looking at these arrangements together helps reveal problems that an individual team might miss.

Why Vietnam Issued Decree 363/2026/ND-CP on Penalties for Data Violations in Vietnam
Vietnam’s Data Law has applied since July 1, 2025. It sets responsibilities for collecting, using, and protecting data. Earlier penalties were spread across different rules and did not adequately cover the problems seen in practice. There appears to be widespread unlawful data trading and poor information protection among businesses.
One concern was what happened after a business shared information with a partner. The practice showed that businesses could give partners access without enough control over how the information was later used or passed on. Hence, Vietnam now needs a separate set of penalties to improve compliance and discourage violations.
Decree 363/2026/ND-CP on penalties for data violations in Vietnam gives authorities specific penalties and ways to require problems to be corrected. For a company, a data problem may therefore lead to a fine and an interruption to its work. Managers should involve the people who collect and use the information, as well as the legal and IT teams, when deciding what needs to improve.
Quick Reference
Decree 363/2026/ND-CP on penalties for data violations in Vietnam covers violations involving the collection, storage, use, and protection of data. It can apply to ordinary businesses as well as companies selling data services. Violations covered by the separate cybersecurity and personal data protection penalty rules are excluded.
The decree takes effect on November 11, 2026. An organization can face a fine of up to VND 200 million for a single violation. Depending on the violation, it may also have to stop an activity or restore, correct, or delete data. Managers should find out where the company falls short and who will put it right. Duties that already apply must still be met before that date.
Issues for Businesses in Vietnam
Understand Which Rules Apply
Decree 363/2026/ND-CP on penalties for data violations in Vietnam applies alongside Decree 330, which covers Vietnam personal data protection penalties and cybersecurity penalties. A violation covered by Decree 330 falls outside Decree 363. A business may therefore need to look at both decrees, depending on the information involved and what it does with that information.
The review should include more than customer and employee records. Data rules can also apply to business information that does not identify a person, such as production figures. A company based overseas may still be covered if it takes part in, or is connected with, data activities in Vietnam.
Managers do not need to work through every penalty provision themselves. They need to know which parts of the business may be affected and where problems are most likely. The fine depends on the violation and the circumstances. The maximum amount does not apply automatically to every problem.
Know What Data the Business Holds
The company can start by reviewing a list of the information it holds, where it came from, who uses it, and where it is sent. The reviewing process should include files kept by individual departments and suppliers, as well as information in the main company systems. This helps the business work out what it may use and what protection is needed.
The Vietnam Data Law places some data in categories called core data and important data. These categories carry additional requirements and are defined by legal criteria and official lists. A file does not fall into either category simply because it is valuable or confidential. The team should also check whether its classification needs to change when its use changes.
Having a copy of information does not mean the company may use it for any purpose. It should check whether the information may be shared, analyzed, or used for a new project. When buying a Vietnamese company, these checks should form part of the legal review before the two businesses combine their systems.
Check Storage and Deletion
Decree 363 covers unsafe storage and failures to follow required procedures or standards. The business should know where its files and backups are kept, including copies held by suppliers. The decree does not require every database to be moved into Vietnam. The answer depends on the data and the laws that apply.
Storage procedures should explain who may change records, how the company can retrieve them, and what happens if equipment fails or a supplier stops providing a service. Managers should be satisfied that the business can get back the information it needs without relying entirely on one person or provider.
The company also needs to know how long to keep information and when to delete it. Keeping everything forever can create unnecessary risk. Deleting files automatically may remove records that the law requires the company to keep. The team should check the relevant periods and how deletion works, including for copies held by suppliers.
Control Access and Protect Information
The decree covers access without permission, shared login details, and changes made improperly to access records. It also penalizes failure to encrypt data when encryption is legally required. The company needs protection that meets the requirements for its data and activities. The decree does not prescribe one technology for every file.
It is important for a company to review who can read, download, change, and delete information. Access should match the work each person does. When someone leaves or a supplier finishes its work, access that is no longer needed should be removed. Records of activity can help explain what happened if data is lost or used improperly.
These controls can also help protect intellectual property in Vietnam. A confidentiality agreement is useful, but it does not give permission for every use or transfer of information. The company should check that the promises in its contracts are reflected in what people can actually access and do.
Keep Records and Check Suppliers
If an authority checks the business, the company should be able to explain how it follows the rules. Useful records may include data classifications, permissions, contracts, technical records, and evidence that earlier problems were fixed. The decree penalizes blocking required audits, giving inaccurate information, and failing to carry out required follow-up work.
An authority may also require the company to carry out a self-audit. This does not mean every business must buy an external audit each year. Managers should make sure the necessary records are available and that someone takes responsibility for fixing the problems found.
Supplier contracts need to cover what data work will be done, for how long, and the responsibilities of each party, including confidentiality. The company should know who deals with requests or incidents and what happens to the information when the service ends. Suppliers handling core or important data must also have the required ability to keep it safe.
Review Overseas Use and Data Services
A company may process data overseas through a regional reporting system, a cloud service, or a foreign supplier. These arrangements should be checked before a new system or service is approved. Depending on the activity, assessments and safeguards may be required. A change in who receives the data or how it is used can mean the arrangements need to be reviewed again.
For data exchange transactions under Decree 314, the buyer should check where the data came from, whether it may be sold, and how it may be used. The decree does not make all data freely available for sale. Buying it also does not automatically allow overseas use. The company should check its intended use, including sharing with group companies or suppliers.
Companies selling data-analysis or aggregation services should also check the separate notification and reporting duties under Decree 347. These duties took effect on September 15, 2026. Covered providers already operating before that date have 20 working days after that date to notify the National Data Center. These duties do not automatically apply to every company that prepares internal reports. A business selling data services should check which rules apply to its activities.
Plan How to Respond to a Violation
Depending on the violation, a company may have to stop an activity or restore, correct, or delete data. Doing this can cost more than the fine and interrupt normal work. The effect may be greater where the information is used for customer services or by several suppliers.
If an authority sends a request or decision, first the company needs to check what it requires and when the company must respond. Keep the relevant evidence and involve any suppliers whose help is needed. Before changing or deleting anything, identify the records and systems affected. This helps avoid removing useful information while leaving other copies of the same data untouched.
If in doubt, the company should seek legal advice promptly, particularly if the company wants to make a complaint or challenge the decision in court. It also needs to understand which duties and deadlines continue during that process. Paying the fine does not, by itself, complete any work required to correct the violation. Someone should be responsible for that work and for keeping a record of what was done.
Frequently Asked Questions
Q1: Does Decree 363 replace the personal data penalty rules?
No. Decree 330 continues to cover cybersecurity and personal data protection penalties. Violations covered by that decree fall outside Decree 363.
Q2: Must all company data be stored in Vietnam?
No general requirement follows from this decree. Where data may be stored or processed depends on the information, the business activity, and the other laws that apply.
Q3: Can preparation wait until November 11, 2026?
The company must still meet duties that already apply. A violation that continues when Decree 363 takes effect can be covered by its penalties. Some data-service duties also have earlier deadlines.
Conclusion
For a company involved in data collection, storage, transaction, a useful next step is to review of what the company does today and where it falls short. The company can start with data that is subject to special restrictions, overseas processing, and work carried out by suppliers and take action to comply.
About the Author
Hanh Pham is a Legal Research Specialist at ANT Lawyers with more than 10 years of experience, supporting legal teams through regulatory research, authority liaison, documentation review, and knowledge development. She has been trained in corporate, civil law and related areas. This article has been reviewed by Tuan Nguyen, Managing Partner, ANT Lawyers; member of the Hanoi Bar Association and Vietnam Bar Association.
About ANT Lawyers, a Law Firm in Vietnam
Founded in 2012, ANT Lawyers is a Vietnam law firm with offices in Hanoi, Ho Chi Minh City and Da Nang. Our data compliance lawyers advise on personal data protection, data processing, cross-border data transfers, cybersecurity and compliance requirements in Vietnam. We combine legal analysis with practical understanding of Vietnam’s regulatory environment and local administrative practice.
General Disclaimer
This article is for general informational purposes only, does not constitute legal advice, and does not create a lawyer-client relationship. Vietnamese laws, regulations and administrative practice change over time, and the correct position for any matter depends on its specific facts and the rules in force when action is taken. Verify the current position before relying on anything stated here, and consult qualified counsel on your specific situation.
How ANT Lawyers Could Help Your Business?
You could reach ANT Lawyers for advice via email ant@antlawyers.vn or call our office at (+84) 24 730 86 529



