Logo
Contact
Contact
Luật Việt An
Công ty Luật Việt An
Viet An Law
Viet An Law Firm

Decree 330/2026/ND-CP on Administrative Penalties for Personal Data Protection Violations in Vietnam

Decree 330/2026/ND-CP on administrative penalties for personal data protection violations in Vietnam marks an important transition in the enforcement mechanism for personal data protection in the country. Previously, enterprises had to fulfill numerous obligations regarding personal data protection, but the administrative sanctions were not fully regulated. However, as of August 19, 2026, the legal system has been relatively fully established in the direction of the Law prescribing obligations – the guiding Decree prescribing the method of implementation – the sanctioning Decree prescribing penalties. Developing a comprehensive personal data protection policy is now critical to avoid non-compliance with data protection laws.

Specific regulations on administrative fines for data breaches in Vietnam from August 19, 2026

Previously, Decree 13/2023/ND-CP regulated personal data protection. From January 1, 2026, Decree 356/2025/ND-CP officially takes effect, guiding the provisions of the Personal Data Protection Law 2025 and replacing Decree 13/2023/ND-CP.

However, in the period prior to August 19, 2026, there was no specialized administrative sanctioning decree that fully and directly prescribed acts of personal data privacy violations and their corresponding fine levels. This partly caused the actual enforcement of personal data protection obligations to fail to create sufficient compliance pressure on enterprises.

From August 19, 2026, when Decree 330/2026/ND-CP takes effect, this gap regarding sanctions is resolved. Acts of violating regulations on personal data protection from Article 39 to Article 71 are specifically identified, accompanied by corresponding fine levels and remedial measures.

This is a point that enterprises must pay special attention to because, from this moment, obligations that were previously viewed primarily from the perspective of compliance obligations can transform into financial penalty risks and actual operational risks if the enterprise fails to implement the regulations properly.

The maximum fine level in the field of personal data protection in Vietnam is 3 billion VND

The maximum fine level in the field of personal data protection in Vietnam is 3 billion VND

According to Clause 4, Article 7 of Decree 330/2026/ND-CP, the maximum fine level in the field of personal data protection is as follows:

  • Acts of buying and selling personal data: 10 times the revenue obtained from the violating act;
  • Acts of violating regulations on cross-border personal data transfer: 5% of the total revenue of the preceding year of that organization;
  • Other acts of personal data privacy violations in the field of personal data protection: 3 billion VND.

Thus, personal data protection penalties can be extremely large, especially for acts associated with data business activities or cross-border data transfers. This is the basis for enterprises to consider personal data protection as an important content in risk management and legal compliance.

Silence must not be automatically considered as consent to process personal data in Vietnam

Article 43 of Decree 330/2026/ND-CP specifically prescribes the fine levels for acts violating regulations on the consent of the personal data subject, specifically:

A fine ranging from 30,000,000 VND to 50,000,000 VND for:

  • Processing personal data after collection without obtaining the consent of the personal data subject, except in cases where the law provides otherwise;
  • Attaching mandatory conditions, or refusing to provide services if the personal data subject does not consent to the processing of personal data for other purposes not related to the content of that service provision agreement;
  • Setting a default method of consent, or creating unclear indications that cause confusion between consent and non-consent for the personal data subject;
  • Requesting consent in a manner that is not expressed through a clear and specific method, or failing to ensure the ability to verify the determination that the personal data subject has given consent, the time, and the consented content;
  • Failing to provide the personal data subject with transparent information regarding the type of personal data being processed, the purpose of personal data processing, the rights and obligations of the personal data subject, the Data Controller, or the Data Controller and Processor, resulting in consent that is not based on voluntariness and clear knowledge;
  • Using a form of requesting consent that does not ensure the personal data subject is allowed to consent to each purpose of personal data processing;
  • Failing to record or store logs of the consent of the personal data subject, or failing to prove that consent has been obtained upon the request of the personal data subject or the inspection and examination request of the competent state agency;
  • Failing to notify the personal data subject that their sensitive personal data is being processed.

A fine ranging from 50,000,000 VND to 70,000,000 VND for:

  • Intentionally continuing to process personal data after the personal data subject has requested to stop or restrict processing, or when the competent state agency requires it in writing;
  • Collecting and processing personal data when the personal data subject remains silent or does not respond to the request for consent, or arbitrarily considering silence as consent.

Therefore, if an organization collects and processes data when the data subject remains silent or does not respond to the request for consent and arbitrarily considers silence as consent, it shall be fined from 50 to 70 million VND.

Enterprises must design a mechanism to request and record consent in a proactive, clear, and verifiable manner, instead of relying on the data subject’s non-response to automatically determine that they have consented. This standard should be firmly integrated into the enterprise’s personal data protection policy.

Intentionally providing the personal data of others in Vietnam can result in a fine of up to 30 million VND

According to Clause 2, Article 42 of Decree 330/2026/ND-CP, a fine ranging from 20,000,000 VND to 30,000,000 VND shall be imposed on individuals committing one of the following acts:

  • Collecting, using, disclosing, modifying, falsifying, destroying, or illegally accessing the personal data of others, causing damage to the lawful rights and interests of that person;
  • Intentionally providing the personal data of others for the purpose of fraud, or causing confusion for relevant agencies, organizations, and individuals;
  • Taking advantage of the exercise of personal data subject rights beyond the necessary scope or inconsistent with the purpose of exercising the rights, causing difficulties or obstructing the lawful business activities of agencies and organizations;
  • Refusing to participate in coordinating the prevention and combat of personal data infringement activities upon the official request of the competent state agency.

Refusing to provide personal data to the data subject upon a valid request in Vietnam can result in a fine of up to 20 million VND

According to Clause 1, Article 49 of Decree 330/2026/ND-CP, a fine ranging from 10,000,000 VND to 20,000,000 VND shall be imposed for the act of refusing to provide personal data to the personal data subject themselves upon a valid request.

In addition, the act of providing personal data to other agencies, organizations, and individuals without the consent of the personal data subject can result in personal data protection penalties ranging from 20,000,000 VND to 30,000,000 VND.

Trading personal data can result in administrative fines for data breaches up to 10 times the revenue obtained in Vietnam

According to Clause 1, Article 53 of Decree 330/2026/ND-CP, an organization committing the act of illegally buying and selling personal data may be fined from 2 times up to a maximum of 10 times the revenue obtained from the violating act.

The sanctioned acts include: providing, sharing, or exchanging personal data to acquire assets or other benefits contrary to regulations; transferring personal data for a fee without an agreement; or having an agreement that does not define the transfer purpose or failing to perform correctly according to the agreed purpose.

The above fine level also applies to the act of failing to establish a technical system and transparent mechanism for the data subject to give clear consent for each transfer; processing data contrary to the consented purpose; or failing to de-identify personal data when transacting on a data exchange.

With administrative fines for data breaches potentially reaching up to 10 times the revenue, illegal trading of personal data becomes one of the behavioral groups with exceptionally large financial risks that enterprises must strictly control.

Failing to create a personal data processing impact assessment dossier in Vietnam can result in a fine from 20,000,000 VND to 30,000,000 VND

According to Clause 1, Article 55 of Decree 330/2026/ND-CP, a fine ranging from 20,000,000 VND to 30,000,000 VND shall be imposed for the following acts of violating regulations on personal data processing impact assessment:

  • Commencing personal data processing activities but failing to create or maintain a personal data processing impact assessment dossier at the enterprise’s headquarters;
  • Failing to submit 01 original copy of the personal data processing impact assessment dossier to the Department of Cybersecurity and High-Tech Crime Prevention (Ministry of Public Security) within 60 days from the first day of personal data processing;
  • Intentionally failing to complete the impact assessment dossier upon the request of the specialized agency in cases where the dossier is incomplete or not in accordance with regulations;
  • Failing to periodically update the personal data processing impact assessment dossier every 06 months when there are changes according to legal regulations;
  • Failing to update the dossier within a 10-day time limit when falling into one of the cases requiring an update according to the provisions of the law.

Sanctioning violations of personal data protection regulations for social network platforms and online media services in Vietnam

According to Clauses 1 and 2, Article 65 of Decree 330/2026/ND-CP, sanctioning violations of personal data protection regulations for social network platforms and online media services is prescribed as follows:

Failing to create a personal data processing impact assessment dossier in Vietnam can result in a fine from 20,000,000 VND to 30,000,000 VND

A fine level of 50,000,000 to 70,000,000 VND

This fine level applies when an organization providing social network services, online media services, or digital content platforms commits one of the following acts:

  • Failing to clearly notify the content of personal data collected when users install and use social networks and online media services.
  • Failing to provide an option allowing users to opt out of the collection and sharing of data files (cookies).
  • Failing to provide a “Do Not Track” option, or failing to ensure that usage activities are only tracked with the user’s consent.
  • Failing to publicly disclose the security policy transparently or failing to explain clearly and understandably how personal data is collected, used, stored, and shared.
  • Failing to provide a mechanism for users to access, edit, and delete personal data; to independently set privacy settings for their accounts; and to report violations regarding security and privacy.
  • Failing to clearly notify the content of personal data that will be collected when users install and use applications.

A fine level of 70,000,000 to 150,000,000 VND

This fine level applies to the following acts:

  • Forcing users to provide images or videos containing all or part of their identification documents as a mandatory condition to authenticate regular user accounts, in cases where specialized laws do not require identification.
  • Over-the-top applications and social networks using non-public technological features to eavesdrop, record calls, read text messages, or automatically extract contacts and media files on the device without the consent of the personal data subject, and not falling under cases where the law provides otherwise.
  • Illegally collecting personal data beyond the scope agreed upon with the user when installing the service.

Some related questions

Is an enterprise penalized if it processes personal data but fails to create an impact assessment dossier?

An enterprise that commences processing personal data but fails to create or maintain a personal data processing impact assessment dossier can be fined from 20 million VND to 30 million VND according to Clause 1, Article 55 of Decree 330/2026/ND-CP. This constitutes clear non-compliance with data protection laws.

How much is the fine for illegally trading personal data?

An organization that illegally buys and sells personal data can be fined from 2 times up to a maximum of 10 times the revenue obtained from the violating act. This is one of the most notable sanctions of Decree 330/2026/ND-CP for personal data business activities.

Can an application automatically access contacts, messages, or files on a user’s device?

Using non-public technological features to eavesdrop, record calls, read messages, or automatically extract contacts and media files without the consent of the data subject, and not falling under cases permitted by law, can result in a fine from 70 million VND to 150 million VND.

What should enterprises do to limit the risk of being penalized under Decree 330/2026/ND-CP?

Enterprises should review their entire process of collecting, storing, using, sharing, and transferring personal data; check the mechanism for requesting and storing consent; create and update the personal data processing impact assessment dossier; and review the privacy policy, application interface, cookies, “Do Not Track” mechanism, and data access permissions on devices. Proactively reviewing helps enterprises detect and rectify unsuitable points before the risk of being penalized arises.

The above is the content regarding decree 330/2026/ND-CP on administrative penalties for personal data protection violations in Vietnam. If customers need consulting services on a personal data protection policy according to regulations, please contact Viet An Law for the best support!

Fast & Reliable Legal Assistance
Fill out the form below and get connected with a lawyer quickly.

    Legal Updates & Insights
    All Post ➙
    Decree 292/2026/ND-CP on foreign trade management in Vietnam takes effect Sept 5, 2026, replacing Decree 69. Key changes: decentralized licensing,…
    Learn invalidation vs cancellation of trademark registration Vietnam: non-use for 5 years, bad faith grounds, patent & IP rights procedures.…
    Expert guide to IP litigation and dispute resolution in Vietnam. Learn court vs. administrative options, evidence requirements, and how intellectual…
    Contact Us via Zalo
    Contact Us via Zalo
    Contact Us
    -

    (+84) 9 61 67 55 66
    (Zalo / WhatsApp / Viber)

    Contact Us via WhatsApp
    Contact Us via WhatsApp
    Viet An Law Firm
    Viet An Law Firm
    Hanoi Office
    3rd Floor, Hoang Ngan Plaza Building, 125 Hoang Ngan, Yen Hoa Ward, Ha Noi City
    info@vietanlaw.com
    (+84) 9 61 57 18 18
    HCM office
    Room 04.68, 4th Floor, River Gate Residence, 151 – 155 Ben Van Don Street, Khanh Hoi Ward, HCM City
    info@vietanlaw.com
    (+84) 9 61 37 18 18
    Opening hours:
    Monday - Friday: (08:00-17:00) Saturday: (08:00-12:30)
    Copyrights © 2026 Viet An Law Firm. All rights reserved

    +84 9 61 67 55 66

    Hotline
    -
    Hotline
    Zalo Chat
    -
    Zalo Chat