Vietnam Personal Data Protection Penalties: What Decree No. 330/2026/ND-CP Means for Companies
Vietnam personal data protection penalties took effect on August 19, 2026. Decree No. 330/2026/ND-CP sets out both the fines and the corrective measures that follow when a company mishandles personal data or falls short of the cybersecurity rules.
It is worth being clear about what the Decree does and does not do, because the distinction shapes how a company should respond. The Decree does not replace the substantive obligations under the Personal Data Protection Law and its implementing rules; its main role is to establish the administrative penalties and corrective measures that may follow when those requirements are breached. What has changed is the price of failing to meet them, and that price is now high enough that the question has moved out of the IT department and onto the board agenda.
The fine ranges are written for organizations, and an individual who commits the same violation is fined at half the stated amount. For most personal data violations the ceiling is VND 3 billion, which is substantial by the standards of Vietnamese administrative penalties and a deliberate signal about how seriously this area is now treated.
Two situations are calculated on an entirely different basis. Where personal data has been bought or sold illegally, the fine is set at two to ten times the proceeds obtained from the violation, so the more profitable the conduct, the larger the penalty becomes. Certain serious cross-border transfer violations can instead be calculated by reference to revenue, with the applicable rate reaching up to five percent of the organization’s revenue in the Vietnamese market in the immediately preceding financial year.
It is also a mistake to treat the fine as the end of the matter, because in practice the corrective measures are often the more disruptive consequence. Depending on the violation, an authority may require a company to correct or delete data, complete an impact assessment file it should have prepared earlier, surrender illegal gains, notify the people whose data was affected, or suspend processing or transfer altogether until the required work has been done.
The reach of the rules extends well beyond companies incorporated in Vietnam. Certain foreign digital and cross-border service providers fall within scope, as do foreign organizations directly involved in processing the personal data of Vietnamese citizens. A group serving Vietnamese customers from a regional hub, or giving an overseas parent access to a Vietnamese customer database, should therefore establish its position on the record rather than assume that the absence of a local entity places it outside the system.
Begin with an inventory of the personal data the company actually uses, covering customers, employees, job applicants, suppliers and website visitors, and record for each category the purpose, the responsible team, the system it sits in, its source, who receives it and how long it is kept. Sensitive personal data should be marked separately. The exercise supports the principles set out in the Vietnam Personal Data Protection Law, and it is difficult to answer any of the questions that follow without it.
The law requires processing for a clear and lawful purpose, limited to what is necessary, which sounds straightforward until the review reaches forms, applications, cookies, cameras, employee files and marketing lists that have accumulated over several years. Remove the fields that no longer serve the stated purpose, and set a retention rule in place of the common practice of keeping data indefinitely because nobody has decided when it should go.
Where consent is the legal basis being relied on, it must be voluntary, clear, informed and capable of being proved later, and this is where most consent processes fail. Silence, a preselected box, or consent forced for an unrelated purpose will not survive scrutiny. The person should be able to choose between purposes rather than accept them as a package, sensitive data processing should be explained rather than buried, and the consent record should still be retrievable months later when someone asks for it.
Vietnamese law permits processing without consent in a defined set of cases, and a company relying on one of them should be able to identify the exact ground, explain why the processing is necessary, state the limits it has applied and produce the evidence behind that reasoning. The basis should be revisited whenever the purpose or the data changes, because an exception that fitted the original activity may not fit what that activity has since become. A general statement that the processing is needed for business will not be enough.
People exercising their rights need a clear contact point and simple forms for access, correction, deletion, withdrawal, restriction and objection, and the company needs an owner for the process who can bring in processors where they hold the data. Procedural information must be given within two working days of a valid request, while the period for completing the request itself differs according to its type, so the log should show the correct date rather than a single date applied to everything.
Identify who decides why and how data is processed and who merely follows instructions, then record each role in writing. Contracts should deal with purpose, instructions, access, retention, deletion, rights requests and cooperation during an incident, and internal access should be limited to the people who need it. This review sits naturally within wider work on Vietnam data compliance under the Data Law.
Where an impact assessment is required, the file has to be created and maintained at the company’s headquarters, and one original must be sent to the responsible unit at the Ministry of Public Security within 60 days of the first processing activity. It is not a one-off document either, and should be reviewed after any change that affects what it describes.
Check cross-border transfers and the review should take in overseas cloud storage, regional HR systems, access granted to a foreign parent, payroll tools and analytics platforms. For a covered transfer, prepare the assessment file before or during the transfer and submit it within 60 days of the first one, then extend the review to recipient contracts, security arrangements, any required notices or consent, and the controls that apply if the recipient passes the data on again.
A processor should tell the controlling company promptly on discovering a violation, and that company should then record the event, protect the evidence, stop further harm and decide which notices are legally required. The 72-hour reporting penalty applies where the violation causes or may cause the serious harm described in the rules. Other recording and reporting duties may still apply in cases that fall outside it, so its absence does not mean there is nothing to do.
When a legal condition requires action, work out whether the data must be deleted, destroyed, returned or de-identified, because the correct response depends on the trigger and on the role the company plays, and the method chosen should prevent recovery or re-identification rather than simply removing the data from view. It is also worth asking each team where its contact lists and customer records originally came from, since personal data cannot be treated as an ordinary item for sale, including in data exchange transactions.
Q1: Does every personal data breach carry a fine of five percent of revenue?
The revenue percentage applies only to specified serious cross-border transfer violations, while most personal data offenses sit in fixed ranges, so the facts and the applicable calculation rules should be checked before anyone states an amount.
Q2: Must a company collect fresh consent from everyone?
No, there is no general requirement to start again. The right question is whether the consent already held is valid, can be proved and covers the purpose for which the data is being used today. Fresh consent becomes necessary when the existing record is insufficient, or when the purpose has changed and no other legal basis applies to the new one.
Q3: Does outsourcing remove the company’s responsibility?
No. The parties have different legal roles, but outsourcing does not transfer away the responsibilities of the company that decides why and how the data is processed. What it changes is where the work sits, so contracts, instructions, access controls, request handling, deletion and the incident reporting line should all reflect the division of roles as it actually operates.
Vietnam personal data protection penalties are already in force, and with a ceiling of VND 3 billion and a revenue-based calculation available in the most serious cross-border cases. The most useful starting point is not a policy document but the records and systems the business uses every day: the consent evidence, the request dates, the vendor terms, the assessment files, the overseas transfers and the incident log.
Hanh Pham is a Legal Research Specialist at ANT Lawyers with more than 10 years of experience, supporting legal teams through regulatory research, authority liaison, documentation review, and knowledge development. She has been trained in corporate, civil law and related areas.
This article was reviewed for legal accuracy by Tuan Nguyen, a lawyer at ANT Lawyers advising on cybersecurity and personal data protection matters in Vietnam.
Founded in 2012, ANT Lawyers is a Vietnam law firm with offices in Hanoi, Ho Chi Minh City and Da Nang. Our employment lawyers advise on hiring, work permits, internal labour regulations and termination disputes in Vietnam. We combine legal analysis with practical understanding of Vietnam’s regulatory environment and local administrative practice.
This article is for general informational purposes only, does not constitute legal advice, and does not create a lawyer-client relationship. Vietnamese laws, regulations and administrative practice change over time, and the correct position for any matter depends on its specific facts and the rules in force when action is taken. Verify the current position before relying on anything stated here, and consult qualified counsel on your specific situation.
Vietnam Decree No. 314/2026/ND-CP on Data Exchange Transactions: FDI Impact
Evidence for Contract Disputes in Vietnam: Can Your Company Prove Its Case?
Vietnam Company Location Strategy: 8 Checks Before Signing an Office, Factory or Warehouse Lease
Buying a Vietnamese Company: 10 Legal Checks Before a Foreign Investor Signs
How ANT Lawyers Could Help Your Business?
You could reach ANT Lawyers for advice via email ant@antlawyers.vn or call our office at (+84) 24 730 86 529
At first look, an unpaid invoice would mean the amount the debtor needs to pay.…
Vietnam has cut back the list of business activities that need special approval. Vietnam Resolution…
From September 5, 2026, Vietnam bans the import of goods made wholly or partly with…
Law No. 11/2026/QH16 amending the Customs Law was passed on August 23, 2026 and takes…
Vietnam has updated its penalties for labor, social insurance and foreign-worker violations. The new rules…
A divorce granted abroad may end the marriage under the law of the country where…
This website uses cookies.