• Instgram
  • LinkeIn
  • Lexologoy

Vietnam: Decree No. 330/2026/ND-CP – Personal Data Protection Enters Its Enforcement Era

2026年09月18日(金)

We published a newsletter regarding Decree No. 330/2026/ND-CP – Personal Data Protection Enters Its Enforcement Era in Vietnam. To view PDF version, please click the following link.

Decree No. 330/2026/ND-CP – Personal Data Protection Enters Its Enforcement Era

Decree No. 330/2026/ND-CP – Personal Data Protection Enters Its Enforcement Era

14th September 2026
One Asia Lawyers Vietnam Office
 

I. Introduction

For the past year, Vietnam’s personal data protection regime has had obligations without teeth. As discussed in our previous newsletter, Personal Data Protection Landscape – Overview of the early 2026, the Law on Personal Data Protection No. 91/2025/QH15, (“PDPL”) and its implementing Decree No. 356/2025/ND-CP set out extensive duties for organizations handling personal data (“PD”), but the dedicated sanctioning instrument remained in draft. However, that gap has now closed since August 19, 2026, on which the Government issued Decree No. 330/2026/ND-CP on administrative sanctions in the fields of cybersecurity and personal data protection (“Decree 330”), effective immediately upon signing.

The significance of Decree 330 lies less in any single headline figure than in a simple structural fact: the conduct it penalizes is drawn directly from ordinary, everyday business operations: recruitment, marketing, CCTV, staff monitoring, incident response, and the use of AI. In this newsletter, we set out how Decree 330 fits within the existing framework, analyze the violation categories most likely to affect enterprises, and translate them into concrete compliance priorities.

II. Analysis of the Key Violation Categories

Decree 330 has a broad territorial reach. Its provisions extend to violations committed in cyberspace falling within Vietnam’s jurisdiction and may apply directly to foreign enterprises that process the personal data of Vietnamese individuals, even where they have no physical presence in Vietnam.[1] This is particularly relevant for foreign-invested enterprises (“FIEs”) whose overseas parent companies or affiliates handle the personal data of Vietnamese employees or customers.

The limitation period for administrative sanctions is one year, calculated from the date on which the violation is completed.[2] Unless otherwise indicated, the fines set out below apply to organizations; individuals are subject to fines at 50% of the corresponding organizational rate.[3]

1. Penalty Ceiling

The general maximum fine for ordinary violations is VND 3 billion. Two categories, however, escalate sharply and target the highest-risk conduct: the unlawful purchase or sale of PD is punishable by up to ten times the unlawful gain, and violations of the cross-border data transfer rules are punishable by up to 5% of the enterprise’s prior-year turnover in Vietnam. For FIEs engaged in intra-group offshore transfers, this turnover-based ceiling makes the cross-border compliance file the single highest-exposure item on the agenda.[4]

2. Consent and Processing Limits

While the PDPL has prescribed that silence is not consent, Decree 330 further strengthens this principle by making it a punishable act to treat a user’s non-response or inaction as agreement to processing (up to VND 70 million).[5] In addition, processing personal data without valid consent[6] and failing to notify a data subject that their sensitive personal data is being processed, are both punishable at VND 30-50 million.[7]

3. Sensitive and Biometric Data

Enterprises processing biometric data must apply appropriate safeguards to storage and transmission; failure attracts VND 50-70 million, rising to as much as VND 150 million where biometric data is used beyond its original purpose without consent. This provision is directly engaged by the now-ubiquitous fingerprint and facial-recognition timekeeping systems.[8]

4. Employment Context

Several provisions map onto routine HR practice. In particular, enterprises that fail to delete the data of unsuccessful candidates face fines of VND 20-50 million[9], a pointed reminder that recruitment data cannot be retained indefinitely “just in case.” At the employment stage, deploying monitoring software, CCTV or other data-collection devices without notifying employees attracts VND 50-70 million.[10] The message is clear: both the line between recruitment and employment data, and transparency toward staff about workplace surveillance, are now enforcement priorities rather than drafting niceties.

5. Marketing and Behavioural Tracking

On social-network and online-media platforms, enterprises must give users a means to refuse cookie collection and a “do not track” or consent-based tracking option; the absence of such mechanisms, and, more broadly, tracking a user’s activity to conduct behavioural or targeted advertising without consent, is punishable at VND 50-70 million,[11] bringing cookie and ad-tech practices squarely within scope.

6. Governance and Accountability Obligations

Decree 330 attaches concrete figures to the “programmatic” duties that enterprises have tended to defer:

  • Data protection function: failure to designate a competent unit or personnel for PD protection, VND 10-30 million.[12]
  • Impact assessments: failure to prepare, maintain or submit a Data Protection Impact Assessment within the prescribed time, VND 20–30 million;[13] and for cross-border transfer impact assessments, VND 30-50 million.[14]
  • Data-subject requests: the absence of a process and forms to handle requests (view, rectification, provision, deletion, withdrawal of consent, restriction, objection) within the 02-working-day timeframe, VND 10-20 million.[15]
  • Breach notification: notifying the specialised authority later than 72 hours where the breach causes or may cause the harms specified by law, VND 40-60 million.[16]
  • CCTV notice: operating cameras or recording devices in public or customer-service areas without a clear notice, VND 10-20 million.[17]

7. AI, Big Data and Automated Decision-Making

Of particular significance for businesses deploying AI, Decree 330 introduces concrete sanctions for the use of AI and virtual-universe systems in automated decision-making without the required safeguards.

Enterprises must notify data subjects of, and explain, the operating principles of the automated algorithm and its impact on them. Failure to do so may result in a fine of VND 50-70 million.[18] Where an AI system makes automated decisions that affect an individual’s rights or interests, enterprises must also establish an oversight mechanism and provide the individual with an opportunity to request human re-assessment. Failure to meet these requirements may attract a fine of VND 70-100 million.[19]

This marks a notable development in Vietnam’s data protection regime. Until now, it was commonly understood that Vietnamese law did not impose a specific, enforceable obligation on automated decision-making comparable to Article 22 of the GDPR. Decree 330 changes that position by introducing an express obligation, backed by monetary sanctions. These requirements should also be considered alongside the obligations imposed on AI deployers under the Law on Artificial Intelligence No. 134/2025/QH15, which took effect on March 01, 2026.

8. Periodic Compliance Assessment

Finally, enterprises processing personal data in AI or virtual-universe systems must conduct an annual PD-protection compliance assessment, with failure penalized at VND 20-50 million. A parallel annual-assessment duty applies to finance-banking and credit-information activities, with failure penalized at VND 50-70 million.[20]

III. Compliance Roadmap for FIEs

Decree 330 makes clear that PD compliance is no longer the preserve of the legal or IT department; it reaches recruitment, marketing, HR, facilities (CCTV), data retention, incident response and AI. Against the categories above, enterprises should prioritize the following:

  1. Map processing against stated purposes and eliminate over-collection, with particular attention to recruitment and HR.
  2. Re-engineer consent, removing any “silence-as-consent” design and ensuring withdrawal, marketing opt-out and consent logging.
  3. Ring-fence sensitive and biometric data (notably biometric timekeeping) with dedicated safeguards and purpose-specific consent.
  4. Complete data processing impact assessment and cross-border transfer dossiers and submit them as soon as possible.
  5. Stand up a data-subject-request procedure operating within 2 working days, with standard forms.
  6. Formalize incident response to meet the 72-hour notification duty.
  7. Designate a PD-protection function (DPO) and document the appointment.
  8. Audit CCTV, employee-monitoring tools, cookies, AI and ad-tech, adding the required notices and transparency mechanisms.
  9. For AI/automated decision-making, build in human re-assessment and add algorithm notification/explanation clauses to privacy notices and internal regulations.
  10. Confirm any annual compliance-assessment obligation applicable to the enterprise’s sector or data profile.

IV. Conclusion

Decree 330 marks the transition of Vietnam’s data protection regime from a rights-declaring framework to an enforced one. With sanctions effective immediately and a reach that extends to offshore processors of Vietnamese data, the window for treating PDPL compliance as aspirational has closed. The most exposed enterprises, those conducting cross-border transfers, deploying AI-driven decisions, or relying heavily on marketing analytics, should treat the coming months as a remediation period, coordinating their legal, IT, HR and marketing functions around a single compliance plan. As implementing practice and enforcement guidance from the authorities develop, we will continue to monitor how these provisions are applied in the field.
———

[1] Article 2 of Decree 330
[2] Article 3 of Decree 330
[3] Article 7.1 of Decree 330
[4]Article 7.4 of Decree 330
[5]Article 43.2.(b) of Decree 330
[6] Article 43.1.(a) of Decree 330
[7] Article 43.1.(h) of Decree 330
[8] Article 70 of Decree 330
[9] Article 61.1.(d) of Decree 330
[10] Article 61.2.(c) of Decree 330
[11] Articles 65.1.((b) and 65.1.(c) of Decree 330
[12] Articles 57.1 and 57.2 of Decree 330
[13] Article 55.1 of Decree 330
[14] Article 56.1 of Decree 330
[15] Article 44.1 of Decree 330
[16] Article 54.3 of Decree 330
[17] Article 71.1.(a) of Decree 330
[18]Article 67.2.(a) of Decree 330
[19]Article 67.3.(b) of Decree 330
[20]Articles 67.1 and 64.1.(c) of Decree 330