Vietnam Decree 330: what the new personal-data fines mean for companies
Tech Ops Asia (Công Ty Tech Ops Asia TNHH) is a Da Nang tech and cyber consultancy. We implement systems, run workshops, and help companies see where personal data actually moves. We are not a law firm. Fine bands below are organisational figures drawn from the official decree listing and public legal commentaries published in the first three weeks after 19 August 2026. Confirm the exact article with Vietnam-licensed counsel before you act.
What actually changed on 19 August 2026?
The duties did not change. The consequences did. Vietnam already had a Personal Data Protection Law (Law 91/2025/QH15) and its implementing decree (Decree 356/2025/ND-CP), both effective 1 January 2026. Those instruments replaced the older Decree 13/2023 regime. Until mid-August, many businesses could describe the duties and still not answer a board question: what happens if we miss?
Decree 330/2026/ND-CP, issued and effective 19 August 2026, is the sanctions layer for two connected fields: cybersecurity (Law 116/2025/QH15) and personal data protection. Official listing: the Government portal record for Nghị định 330/2026/NĐ-CP.
| Layer | Instrument | What it does |
|---|---|---|
| Duties: cyber | Law 116/2025/QH15 | Cybersecurity obligations for systems and online activity. |
| Duties: personal data | Law 91/2025/QH15 (PDPL) | Consent, rights, transfers, security, accountability. |
| How to implement | Decree 356/2025/ND-CP | Forms, DPIA / transfer assessments, timelines. |
| What you pay if you miss | Decree 330/2026/ND-CP | Fines, extra sanctions, remedial orders. Live now. |
That is why law-firm notes from early 2026 still say “a dedicated penalty decree has not been issued.” Those pages are outdated. Acclime’s 4 September 2026 briefing is the cleanest public English summary of the turning point: compliance now has to show up in systems, contracts, vendors, and daily operations, not only in a privacy policy.
Does Decree 330 apply to my company, including foreign-owned ones?
Yes, for almost every operating company in Vietnam, and for some organisations that never opened a Vietnam entity. The test is whether you collect, store, use, disclose, transfer, or otherwise process personal data, not whether you call yourself a tech company.
Public commentaries (Acclime, DFDL, CNC) describe a wide scope:
- Vietnamese and foreign individuals and organisations that commit covered violations in Vietnam’s territory and maritime zones
- Foreign organisations involved in processing personal data of Vietnamese citizens, and of specified persons of Vietnamese origin residing in Vietnam who hold an identity certificate, even with no branch here
- Household businesses, at individual fine levels
- Ordinary HR, payroll, CRM, CCTV, visitor logs, accounting, and vendor files, not only apps and e-commerce
Offshore involvement does not remove exposure. A parent company in Singapore reading the Da Nang HR drive, a regional CRM, an AWS region outside Vietnam, or an IT vendor with standing remote access can all sit inside a cross-border flow. Remote access is not automatically a “transfer” in every architecture, but you cannot assume it is not one. Map the path.
Household businesses and some micro-enterprises have DPIA / transfer-assessment exemptions under Decree 356, unless they sell personal-data processing, handle sensitive data, or process a large number of people. Exemption from a dossier is not exemption from consent, security, or Decree 330 fines.
How could this affect a normal company this week?
Most violations will not look like a Hollywood breach. They look like an ordinary Tuesday. Below is the operator map we use in Da Nang, the places a privacy policy never reaches.
| Everyday activity | How Decree 330 can land |
|---|---|
| Website or app with one “I agree” box for marketing, analytics, and account creation | Bundled or default consent. Organisational fines in the VND 30–70 million band for consent defects, including treating silence as consent. Data collected that way can be ordered deleted so it cannot be recovered. |
| Zalo OA, SMS, or email blasts to customers who never opted in | Marketing without prior consent (Acclime cites up to VND 40 million). The same campaign can overlap consumer-protection and advertising rules, so one blast can sit under several statutes. |
| HR files, CVs, and a biometric timeclock | Employee data is still personal data. Biometrics used beyond the original purpose sit in a higher band (Acclime: VND 50–150 million). Old candidate databases with no retention rule are a deletion failure waiting for a request. |
| Google Workspace, Microsoft 365, or AWS / GCP in Singapore | Storage or processing on a platform outside Vietnam is a classic cross-border transfer. Missing transfer assessments are a fixed-fine problem; a leak of that data can become a percentage of last year’s Vietnam revenue. |
| Parent company or overseas founder with admin access | Group access is a data flow. If it was never labelled a transfer, the dossier and the contract are probably both wrong. |
| Pasting customer or staff data into ChatGPT, Gemini, or a vendor AI | That is processing, and often a transfer to an overseas platform. It also sits on the AI-governance problem: you cannot evidence what left the company. |
| A customer asks “send me everything you have on me” | PDPL timelines are short. Commentaries cite two working days to acknowledge, then 10–20 days to implement depending on the right. Refuse or stall and Decree 330 has a specific fine for not providing data to the person it belongs to. |
| A mailbox leak or ransomware on Friday afternoon | DFDL: failure to notify the data-protection authority within 72 hours of discovering a harmful (or potentially harmful) breach is VND 40–60 million, plus mandatory notification and remediation. Some cyber incidents compress that to 24 hours. |
| You process data but never built a DPIA file | Viet An / LTS: VND 20–30 million for not creating, keeping, or submitting the impact-assessment dossier within 60 days of first processing, and a possible order to stop processing until it is done. |
| You sell a product that processes other companies’ personal data | That can be a licensed activity under Decree 356. CNC: operating without the eligibility certificate, or with unqualified protection staff, is its own penalty stack, including being told to stop the service. |
Two second-order hits matter as much as the fine. A buyer or investor will ask for the DPIA / transfer file. And if the authority orders you to stop a transfer or delete a dataset, payroll, booking, or support can halt while the lawyers argue. That is a continuity event, not a compliance memo.
What are the actual fine levels?
Personal-data fines in Decree 330 use the organisational amount as the base. For the same act, an individual’s fine is generally half. Cybersecurity sections flip that: the stated amount is the individual fine, and organisations pay twice. Do not mix the two columns.
| Conduct (organisational) | Indicative exposure |
|---|---|
| Serious cross-border transfer failures that cause a leak, or continuing a transfer after an order to stop (Art. 56) | Up to 5% of prior-year revenue in the Vietnam market. DFDL/CNC scale the percentage with the number of people affected (about 1–2% / 2–3% / 3–5%). If there is no such revenue, or the percentage falls under the statutory floor, a fixed fallback applies (commentaries cite bands up to VND 3 billion). |
| Unlawful trading of personal data (Art. 53) | 2 to 10 times proceeds. If proceeds cannot be counted, scale-based fixed fines apply; CNC cites VND 500 million to 1 billion at large volume. |
| Other personal-data violations (statutory ceiling) | Up to VND 3 billion (~USD 114,000). A ceiling, not the default ticket. |
| Unlawful technical collection at scale (Art. 48) | DFDL/CNC: from about VND 100–200 million at smaller counts up to VND 500–800 million when thousands of people, or sensitive data, are involved. |
| Consent defects; processing without a valid basis | VND 30–50 million; silence-as-consent VND 50–70 million. |
| Missing DPIA dossier / late A05 filing | VND 20–30 million, plus a possible processing stop. |
| Missing transfer-impact dossier | DFDL: VND 30–50 million, plus a possible transfer or service stop. |
| 72-hour breach notification miss | DFDL: VND 40–60 million, plus ordered notification and fixes. |
| Cybersecurity-only breaches (for contrast) | Much lower caps: about VND 100 million individual / VND 200 million organisation. Data is the expensive column. |
Acclime’s worked example is worth keeping: a transfer without the required assessment, then a leak of 1.2 million Vietnamese records, can reach 3–5% of last year’s Vietnam revenue. On VND 1,000 billion of revenue that is VND 30–50 billion, which is not the VND 3 billion “other violations” cap.
Extra sanctions sit beside the money: licence or operations suspended for 1–24 months, deletion of unlawfully processed or transferred data, a freeze on further overseas transfers, surrender of unlawful gains, public correction, and (for foreign individuals) deportation. The Ministry of Public Security’s 2026 draft Criminal Code amendment also floats personal-data offences. That draft is not law; the direction of travel is administrative first, with criminal later for the worst conduct.
The limitation period is generally one year. For a continuing violation, the clock does not automatically start on day one; Decree 330 tells you when the violation is treated as ended.
Is the fine the thing that can stop the business?
Usually not. A VND 40 million marketing ticket is painful, but an order to delete a customer file you cannot rebuild, or to stop sending data to the regional ERP, can pause invoicing, payroll, or support. CNC and Acclime both stress those remedial powers: cease processing until the dossier is accepted, destroy data so it cannot be recovered, or suspend the transfer.
That is why a printed privacy policy is no longer the deliverable. A regulator or a buyer’s counsel can now ask you to show the consent log, the retention job, the vendor contract, the transfer file, and who answers a deletion request on day two.
Who should I hire, a law firm or a tech consultant?
Hire the person who can close the gap you actually have. Paper and filings are a legal product; logs, access, and workflows are a systems product. Mixing them up wastes a quarter.
| Option | What they actually do |
|---|---|
| Vietnam-licensed law firm / corporate secretary (Acclime, DFDL, Viet An, and peers) | Legal opinions, DPIA and transfer dossiers, regulator language, licensed data-processing applications, and employment or consumer-law overlap. They will not sit in your Google Workspace, Zalo OA, or AWS account and turn a policy into logs. Many health checks stop at documents. |
| Tech Ops Asia, systems workshop and implementation (Da Nang) | A data-flow map, consent and retention that actually run, vendor and cloud review, a data-subject request path, and a 72-hour breach drill, in English or Vietnamese. We are not counsel. We do not file A05 dossiers or tell you that you are “compliant.” We make the operating evidence a lawyer can stand on. |
| Owner / IT lead, DIY | Fine for a household business or tiny shop that only has a Zalo chat and a cash book, and can write down what they collect this week. The moment you have a cloud inbox, a booking tool, ads, or a parent company, DIY usually produces a policy that does not match the systems. |
Can a workshop help, or do I need a lawyer?
A workshop helps when the company cannot yet list its systems, owners, and overseas paths, which is most companies we meet. A half-day or one-day session can produce a living inventory, a first-pass risk list, and a two-week fix queue. It does not replace a Vietnam-licensed lawyer for the dossier or a disputed legal basis.
If you already use AI on staff or customer data, this is also the start of a wider AI-governance programme (inventory, risk, evidence). That is a different product, a practitioner course and an AI management system, and it is not a substitute for PDPL filings. Part 3 of this series covers how those offers stack without pretending one certificate solves Vietnam law.
Want a systems read of Decree 330, not another policy PDF?
We run a practical workshop for Vietnamese companies and foreigners operating here: data-flow map, cloud and vendor paths, consent and retention gaps, and a breach-response drill. Bring your counsel if you have one. We will not pretend to be them.
What should a company do in the next 30 days?
Start with the flows that can freeze the business, not a 40-page rewrite of the privacy notice.
- List every system that holds a name, phone, ID image, or staff record, including Zalo, WhatsApp, CCTV, and the founder’s laptop.
- Mark which of those sit outside Vietnam or are reachable from outside Vietnam.
- Check whether consent is specific, logged, and withdrawable. Silence is not consent.
- Name one person who answers access and deletion requests within the statutory clocks.
- Write a 72-hour notification drill and time it from discovery, not from “when we felt sure.”
- If you process at any real scale, ask counsel whether a DPIA and a transfer-impact file were due from 1 January 2026, and whether they were updated when you added a cloud or a vendor.
Part 2 of this series will walk those six items as a checklist against real Vietnam stacks. Part 3 will cover how to buy help (workshop, lawyer, and later an AI-governance course module) and what each one cannot do.
FAQ
Does Decree 330 apply to foreign-owned companies in Vietnam?
Yes if you process personal data here, or a foreign organisation is involved in processing personal data of Vietnamese citizens or specified persons of Vietnamese origin residing in Vietnam. The registered address is not the test; the data path is.
What is the maximum personal-data fine?
For organisations: up to 10× proceeds for unlawful trading, up to 5% of prior-year Vietnam-market revenue for specified serious cross-border failures, and up to VND 3 billion for other personal-data violations. Individuals are generally at half those organisational amounts.
Is Google Workspace or AWS Singapore a cross-border transfer?
Often yes. Overseas servers and foreign platforms sit inside the statutory transfer picture, though some HR and contract-execution cases are carved out. Map the architecture rather than guessing from the brand name on the invoice.
Should I hire a law firm or a tech consultant?
Use a law firm for opinions and filings, and a tech consultant for systems, logs, and the workshop. Many mid-size and FDI companies need both. Tech Ops Asia does the systems side from Da Nang.
Can a workshop make us compliant?
No. It can stop you guessing and give counsel something real to file against. A one-day “compliant” stamp is not a thing anyone can honestly sell.
Sources
- Government portal: Nghị định 330/2026/NĐ-CP (issued and effective 19 August 2026)
- Acclime Vietnam: Setting penalties for personal data protection violations (4 September 2026; updated 7 September)
- DFDL: Sanctions under Decree 330 (3 September 2026)
- DFDL: PDPL 2026 for foreign organisations (duties layer; pre-decree enforcement note is now historical)
- Viet An Law: Decree 330 penalties
- CNC Counsel: key sanctions for enterprises
- LTS Law: Decree 330 overview
Related reading
- Part 2: the company systems checklist (next)
- Part 3: lawyer, workshop, or course: how to buy help (next)
- Tech Ops Asia services: workshops and implementation