Vietnam Personal Data Protection: Decree 330/2026/ND-CP Sets Heavy Penalties and Fines Up to 5% of Revenue for Cross-Border Transfer Violations
Vietnam's personal data protection framework has officially transitioned from legislative build-out to active, high-stakes enforcement. On August 19, 2026, the Government issued and immediately put into effect Decree No. 330/2026/ND-CP ("Decree 330"), which establishes the first comprehensive administrative penalty and sanctioning regime for personal data protection and cybersecurity violations. Decree 330 completes the enforcement mechanism for the Law on Personal Data Protection No. 91/2025/QH15 (PDPL) and its main implementing regulation, Decree No. 356/2025/ND-CP ("Decree 356").
Simultaneously, the Ministry of Public Security (MPS) has introduced significant administrative reforms, including electronic email submissions for impact assessment dossiers and the decentralization of dossier review to provincial police forces.
The Multi-Tiered Sanctions Framework of Decree 330
Decree 330 comprises 82 articles, 33 of which are dedicated specifically to personal data protection. It introduces a multi-tiered fine structure that combines fixed statutory ranges, fines based on illegal proceeds, and fines calculated as a percentage of global or local revenue:
- Revenue-Based Fines (Up to 5% of Revenue): For particularly serious violations relating to cross-border personal data transfers (such as transferring sensitive personal data without applying physical security, encryption, or anonymization, or continuing transfers after being ordered to stop), organizations face administrative fines of up to 5% of their revenue from the immediately preceding year.
- Proceeds-Based Fines (Up to 10x Proceeds): The unlawful purchase, sale, or trade of personal data can attract administrative fines of up to 10 times the illegal proceeds derived from the violation. These proceeds are calculated based on the aggregate transaction value or total actual revenue generated from business activities involving the data, without deducting any operating costs.
- Fixed Fine Caps (Up to VND 3 Billion): Other general violations of personal data protection are subject to fixed fines of up to VND 3 billion for organizations (and up to half of that for individuals).
- Operational Sanctions (Suspensions & Destruction): Beyond monetary fines, Decree 330 grants authorities the power to order the mandatory destruction or irrecoverable deletion of unlawfully processed data, the suspension of personal data processing or cross-border transfers, or the suspension of service provision for 6 to 12 months. For data-dependent businesses, these operational suspensions pose a greater existential risk than the monetary fines.
Key Compliance Risk Categories and Fines
1. Consent Collection and Design
Fines of VND 30 million to VND 50 million apply to companies using default consent mechanisms, pre-checked boxes, forced consent for unrelated purposes, or unclear instructions. Treating silence or non-response as consent, or continuing to process data after a request to stop, carries fines of VND 50 million to VND 70 million, along with the confiscation of means used and the mandatory deletion of all collected data.
2. Data Subject Rights and Response Timelines
Failure to establish procedures for handling data subject requests, or failing to respond to a valid request within the statutory 2-working-day timeline, is subject to fines of VND 10 million to VND 40 million.
3. Impact Assessment Dossiers (DPIA and DTIA)
Failing to prepare, submit, or update a Personal Data Processing Impact Assessment (DPIA) within the prescribed timeline carries a fine of VND 20 million to VND 30 million. Procedural violations for the Cross-Border Personal Data Transfer Impact Assessment (DTIA) carry fines of VND 30 million to VND 50 million. Substantive DTIA violations—such as failing to execute a written contract allocating responsibility between the transferring and receiving parties, or failing to implement appropriate security measures—attract fines of VND 50 million to VND 100 million. Crucially, companies can be ordered to suspend data processing or transfers until their dossiers are completed and confirmed by the MPS1.
4. Sector- and Technology-Specific Violations
- Artificial Intelligence, Big Data, and Cloud Computing: Violations of periodic compliance assessments, automated processing transparency, human oversight, or risk classification can result in fines of up to VND 100 million and system suspensions of up to 6 months.
- Vulnerable Data Subjects: Failing to delete or destroy children's personal data when mandatory attracts fines of up to VND 200 million and processing suspensions of up to 6 months.
- Recruitment and Employment: Collecting candidate data beyond recruitment purposes, failing to delete unsuccessful candidate data, or monitoring devices/using cameras without notifying employees carries fines of up to VND 100 million.
Procedural Reforms: Electronic Dossier Submissions and Decentralization
To streamline compliance and address bottlenecks, the MPS has overhauled the administrative procedures for submitting DPIA and DTIA dossiers:
- Electronic Email Filing (A05 Guidance): In June 2026, the Department of Cybersecurity and Hi-tech Crime Prevention (A05) issued unofficial guidance enabling electronic submission of DPIA and DTIA dossiers. Enterprises submit electronic copies to a dedicated A05 email address. Once approved via email, the enterprise submits a single hard copy for archiving.
- Provincial Police Decentralization: To resolve the back-log at the national level, the Government issued Resolution No. 22/2026/NQ-CP (effective April 29, 2026, to March 1, 2027). The A05 will now classify and forward DPIA and DTIA dossiers to provincial police departments for review and feedback based on area, scale, and fields. While this reduces national-level bottlenecks, compliance teams should expect localized variations in review standards and timelines.
Verbatim Quotes
"On 19 August 2026, the Government issued Decree No. 330/2026/ND-CP on administrative penalties for violations in the fields of cybersecurity and personal data protection (“Decree 330”). Effective immediately upon issuance, Decree 330 comprises 82 articles, of which 33 articles specifically provide for violations in the field of personal data protection." — Conventus Law / DFDL, August 2026
"Specifically, for organisations: (i) the unlawful purchase or sale of personal data may be subject to a fine of up to 10 times the proceeds derived from the violation; (ii) certain serious violations relating to cross-border personal data transfers may be subject to a fine of up to 5% of the revenue of the immediately preceding year2; and (iii) other violations in the field of personal data protection are subject to a maximum fine of VND 3 billion." — Conventus Law / DFDL, August 2026
"In early June 2026, the A05 issued unofficial guidance... on the new procedure for submission of DPIA and CTIA dossiers... Enterprise submits electronic copies of the DPIA and CTIA dossiers to a dedicated A05 email address... On April 29, 2026, the government issued Resolution No. 22/2026/NQ-CP... providing for decentralization of the authority to handle DPIA and CTIA dossiers." — Nishimura & Asahi, September 3, 2026
-
An instance of Cross-border data flows require proactive state logging and approval immediately upon execution. — Vietnam enforces upfront DTIA dossiers with hard-stop suspension powers until the state confirms compliance — proactive approval, not after-the-fact investigation. ↩︎
-
An instance of Sovereign data penalties now target global corporate revenue and personal executive liability. — Vietnam moves past warnings to confiscate turnover-proportionate fines with transfer suspensions, making data violations a revenue-level corporate event. ↩︎