On August 19, 2026, the Government issued Decree 330/2026/ND-CP prescribing administrative sanctions for violations in the fields of cybersecurity and personal data protection. The Decree took effect immediately on August 19, 2026, marking a significant strengthening of sanctions for violations arising in the collection, processing, storage, provision, transfer, and use of personal data.
The article below focuses on analyzing the key provisions of Decree No. 330/2026/ND-CP and provides several recommendations for businesses to proactively review and enhance their compliance in personal data processing activities.
Scope of regulation and applicable entities

Decree No. 330/2026/ND-CP consists of 04 chapters and 82 articles, providing regulations on administrative violations in the fields of cybersecurity and personal data protection; forms and levels of sanctions; remedial measures; sanctioned entities; competence to impose sanctions and make violation records; and enforcement of administrative sanctioning decisions.
The Decree applies to Vietnamese individuals and organizations, as well as foreign individuals and organizations committing violations falling within the scope of the Decree in Vietnam and in areas falling under the prescribed jurisdiction. Organizations include enterprises, their affiliated units, and other organizations as prescribed by law.
Notably, household businesses, households, and residential communities committing violations under the Decree are subject to fines applicable to individuals.
Risks of sanctions may arise throughout the entire personal data lifecycle
Decree No. 330/2026/ND-CP provides sanctions for various groups of violations, including violations of personal data protection principles; processing data beyond the permitted scope or for improper purposes; failure to ensure data accuracy and updates; retaining data longer than necessary; violations concerning consent and data subject rights; and the unlawful collection, provision, disclosure, deletion, destruction, de-identification, transfer, purchase, or sale of personal data.
In addition to the above-mentioned violations, the Decree contains separate provisions on sanctions for failure to notify, or improper notification, of personal data incidents; failure to conduct, or incomplete performance of, Data Protection Impact Assessments (DPIA); violations of conditions for transferring personal data abroad; failure to appoint personnel or a department responsible for personal data protection as required; and violations in the provision of data protection services and personal data processing services. These are procedural and internal compliance obligations that many businesses may overlook because they are not directly associated with data leakage. Therefore, businesses should separately review these provisions rather than focusing solely on the more visible violations carrying high fines.
Accordingly, compliance responsibilities no longer stop at preventing data leakage but extend throughout the entire personal data lifecycle within an enterprise.
Additional sanctions and remedial measures
An important feature of Decree No. 330/2026/ND-CP is that sanctions are not limited to monetary fines. Under Article 4, the two principal forms of sanctions are warnings and fines. Depending on the nature and severity of the violation, an organization may also have its license or professional practice certificate revoked for 01-24 months, have its operations suspended for 01-24 months, or have exhibits and means used for violations confiscated.
In addition, Article 5 provides for various remedial measures that businesses may be required to undertake depending on the specific violation, including:
– Restoring the original condition of information systems and remedying cybersecurity incidents or data leakage;
– Destroying or deleting personal data processed in violation of regulations to the extent that such data cannot be recovered;
– Remitting unlawful proceeds obtained from the violation;
– In certain cases, revoking domain names associated with the violation.
This means that a data-related violation may not only result in direct financial losses but may also affect a business’s business continuity if its operations are suspended, as well as the commercial value of its entire database.
Businesses may not automatically treat silence as consent
One of the issues to which businesses should pay particular attention is the regulation on consent of personal data subjects under Clause 2, Article 43 of Decree No. 330/2026/ND-CP.
The provision imposes sanctions on acts such as processing data after collection without valid consent; establishing a default-consent mechanism; failing to ensure that data subjects can choose to consent to each specific processing purpose; or designing interfaces or instructions that cause data subjects to misunderstand the distinction between consent and refusal. In particular, businesses may not automatically regard a customer’s failure to respond or silence as consent.
For certain violations concerning consent, businesses may be subject to fines of up to VND 70 million.
This regulation directly affects many common business activities, including:
– Customer information registration forms;
– Websites and applications;
– Cookies and tracking technologies;
– Email marketing;
– SMS/call marketing;
– Loyalty programs;
– Collection of information for advertising purposes;
– Sharing customer information with partners.
Businesses should redesign their consent mechanisms to ensure that consent is active, clear, specific, and demonstrable.
Business processes data without consent
Under Clause 1, Article 43 of Decree No. 330/2026/ND-CP, processing personal data after collection without valid consent from the data subject may be subject to a fine ranging from VND 30 million to VND 50 million, unless otherwise provided by law. Cases where personal data may be processed without consent under the Law on Personal Data Protection – for example, for national security purposes, saving lives, performing obligations under a signed contract, or at the request of a competent authority – shall not constitute violations.
In addition to monetary fines, violating organizations may be required to take remedial measures, including destroying or deleting unlawfully collected personal data to the extent that it cannot be recovered and remitting unlawful proceeds obtained from the violation. Therefore, the risks to businesses are not limited to financial penalties but may also include the loss of the right to use the entire database developed through unlawful processing activities.
Business processes data for improper purposes
Clause 1, Article 39 of Decree No. 330/2026/ND-CP provides for fines ranging from VND 20 million to VND 40 million for certain violations of personal data protection principles, including:
– Processing data beyond the permitted scope;
– Processing data inconsistently with the identified or consented purpose;
– Processing data beyond what is necessary to achieve the intended purpose;
– Failing to ensure data accuracy;
– Failing to promptly correct, update, or supplement data when errors are identified;
– Retaining data longer than necessary;
– Failing to proactively prevent, detect, and coordinate in addressing violations of personal data protection regulations.
This is particularly important for businesses operating CRM, HRM, ERP systems, e-commerce platforms, or AI systems that use customer data.
For example, a business may collect a customer’s telephone number for the purpose of performing a contract but subsequently use the list for advertising purposes or provide it to a third party without an appropriate legal basis, thereby potentially giving rise to compliance risks.
Illegal purchase and sale of personal data
One of the most notable provisions is Article 53, which provides sanctions for the unlawful purchase and sale of personal data.
Under the published regulations, an organization engaging in the unlawful purchase or sale of personal data may be fined from 02 to 10 times the proceeds obtained from the violation. Where the proceeds cannot be determined or no proceeds were obtained, the fine may be determined based on the scale and nature of the data.
For certain cases involving the purchase or sale of basic personal data of 10,000 or more individuals, or sensitive personal data of 2,000 or more individuals, the fine may range from VND 500 million to VND 1 billion. For particularly serious violations, the fine applicable to an organization may reach VND 1-3 billion.
A notable point is that, in certain cases, sanctions are no longer based solely on a fixed monetary amount but are directly linked to the unlawful proceeds obtained from the violation, thereby significantly increasing the financial risks faced by businesses.
Biometric and sensitive personal data require enhanced controls
For highly sensitive types of data, businesses need to strengthen controls over processing purposes, scope, and protection measures.
Under Article 70 of Decree No. 330/2026/ND-CP, certain acts involving the exploitation or use of biometric data beyond the original purpose or failure to ensure the required protection measures may be subject to fines ranging from VND 70 million to VND 150 million for organizations.
Accordingly, businesses should pay particular attention to reviewing the legal basis, processing purposes, access rights, and security mechanisms when using:
– Facial recognition;
– Fingerprints;
– Biometric identification;
– Health data;
– Financial data;
– Location data;
– Other types of sensitive personal data.
Personal data protection becomes an integral requirement of corporate governance
From a corporate governance perspective, Decree No. 330/2026/ND-CP demonstrates that personal data protection is shifting from a purely legal-administrative requirement to a compliance obligation embedded throughout business operations.
Businesses should, at a minimum, review the following:
First, review the Data Mapping.
Identify what types of data the business collects, where the data comes from, what purposes it serves, where it is stored, who has access to it, and with whom it is shared.
Second, review the consent mechanism.
In particular, businesses should review websites, applications, registration forms, contracts, marketing programs, and digital platforms that involve the use of personal data.
Third, review processing purposes.
Data should not be used for purposes different from those identified or without an appropriate legal basis.
Fourth, control third parties.
Review contracts with providers of CRM, cloud, marketing, HR, payroll, AI, call center, data processing, and other services that have access to personal data.
Fifth, review cross-border data transfers.
This is particularly important for FDI enterprises, multinational corporations, and businesses using servers or software located overseas.
Sixth, establish data retention and deletion mechanisms.
Businesses should not retain data indefinitely merely on the grounds that it “may be needed for future use.”
Finally, assign internal responsibilities.
Businesses should clearly identify the department or personnel responsible for personal data protection and establish coordination mechanisms for responding to incidents.
Recommendations for businesses
Decree No. 330/2026/ND-CP took effect on August 19, 2026. Therefore, businesses should not wait until an inspection takes place or an incident occurs before conducting a compliance review.
In particular, businesses engaged in large-scale personal data processing should prioritize conducting a Personal Data Protection Compliance Audit, focusing on:
– Inventorying all personal data currently being processed;
– Classifying personal data and sensitive personal data;
– Identifying the legal basis for each processing activity;
– Reviewing mechanisms for obtaining and retaining evidence of consent;
– Reviewing personal data protection policies;
– Reviewing contracts with customers, employees, and third parties;
– Reviewing data transfer and sharing activities;
– Reviewing cross-border data transfers;
– Establishing procedures for receiving and handling data subject requests;
– Establishing procedures for responding to personal data breaches.
Decree No. 330/2026/ND-CP represents an important step toward strengthening sanctions and enhancing compliance responsibilities in the fields of cybersecurity and personal data protection in Vietnam.
For businesses, particularly those operating in technology, e-commerce, finance and banking, insurance, healthcare, education, human resources, and those processing large volumes of customer data, personal data protection should be regarded as an integral component of risk management and corporate governance, rather than merely an IT function.
If your business needs to assess its compliance level or develop and update its personal data protection framework in accordance with Decree No. 330/2026/ND-CP, Siglaw is ready to accompany you and provide tailored legal consulting solutions aligned with your business’s specific characteristics.
Contact Siglaw firm for professional advice and support on personal data protection, compliance reviews, and legal risk management.
Head Office in Hanoi: No. 44/A32 – NV13, Area A, Geleximco, Le Trong Tan Street, Tay Mo Ward, Hanoi.
Southern Branch: No. 103–105 Nguyen Dinh Chieu Street, Xuan Hoa Ward, Ho Chi Minh City.
Central Branch: VIFC DN – ICT Building, Software Park No. 2, Nhu Nguyet Street, Hai Chau Ward, Da Nang.
Hotline: 0961 366 238
Email: vp@siglaw.com.vn
Facebook: https://www.facebook.com/hangluatSiglaw







