Việt Nam Puts a Price on Privacy Violations: Nghị định 330/2026/NĐ-CP

For eight months, Việt Nam’s Luật Bảo vệ dữ liệu cá nhân has been in force without a price list. The law, effective since 1 January 2026, told companies what they must do with personal data and set headline penalty ceilings — but no decree spelled out which specific violation costs how much, so enforcement had little to work with. That gap closed on 19 August 2026, when the Government issued Nghị định 330/2026/NĐ-CP on administrative sanctions in cybersecurity and personal data protection, effective the same day.

What the document is

Nghị định 330/2026/NĐ-CP runs to 4 chapters and 82 articles. It is the enforcement companion to two recent framework laws: Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15 (passed 26 June 2025, in force since 1 January 2026) and Luật An ninh mạng số 116/2025/QH15 (in force since 1 July 2026). It was issued the same day as the two operational cybersecurity decrees we covered earlier — Nghị định 333 and 327 — completing a coordinated enforcement package: those decrees say what platforms and data handlers must do; this one says what it costs when they don’t.

The decree applies to Vietnamese and foreign individuals and organisations that commit violations within Vietnamese territory, including cyberspace under Việt Nam’s management. The statute of limitations is one year.

The fine schedule

For personal data protection violations, the stated amounts apply to organisations, with individuals fined half. The everyday tiers:

  • 20–40 million đồng: processing data beyond the declared scope or purpose, failing to keep data accurate or correct it promptly, retaining data longer than necessary, or failing to prevent and report violations.
  • 30–50 million đồng: processing personal data without the subject’s consent (outside legal exceptions), making consent a bundled condition of service, using misleading consent mechanisms, or failing to provide transparent information.
  • 40–60 million đồng: obstructing data protection activities or using another person’s data for unlawful purposes.
  • 50–70 million đồng: continuing to process data after the subject withdraws consent or authorities order a halt — and, notably, treating a data subject’s silence as consent.

The headline numbers sit above those tiers, translating the law’s caps into operational rules:

  • Trading personal data: fines of up to 10 times the proceeds of the violation.
  • Illegal cross-border data transfers: organisations face up to 5% of the previous year’s revenue; where there is no prior-year revenue, or the revenue-based figure would fall below the standard cap, a maximum of 3 billion đồng applies.
  • Other data protection violations: capped at 3 billion đồng for organisations.

For the cybersecurity sections of the decree, the convention flips: stated fines apply to individuals, and organisations pay double.

Beyond money, the decree provides supplementary sanctions — suspension of licences or practice certificates for 1–24 months, suspension of operations, confiscation of means of violation, and deportation for foreign violators — plus remedial measures including forced deletion or destruction of data, surrender of unlawful gains, forced correction, and public apology in the media.

What changes in practice

Until now, a company mishandling Vietnamese personal data faced mostly theoretical exposure: the law’s ceilings existed, but no schedule matched conduct to consequences. That asymmetry is gone. Consent hygiene is the most immediate compliance item — pre-ticked boxes, bundled consent, dark-pattern consent flows, and “no reply means yes” logic now map to specific fine brackets. Marketing databases, loyalty programmes, and HR records assembled under looser habits deserve a fresh audit. Companies moving Vietnamese data offshore — a routine fact of life for anyone on foreign cloud infrastructure — should treat the revenue-based penalty as board-level risk and confirm their transfer paperwork under the data protection framework is actually in place, not just planned. And the 10×-proceeds rule for data trading is aimed squarely at Việt Nam’s grey market in leaked customer databases, where fines under older rules were trivially small next to the profits.

The open questions are the usual ones for a young regime: how “revenue of the preceding year” will be computed for multinationals (Việt Nam revenue or global), how aggressively the rules will be enforced against offshore entities with no local presence, and how sanctioning practice will coordinate across this decree and the parallel cybersecurity decrees. With the decree effective immediately upon signing, there is no grace period — the first enforcement decisions will be the real guidance.

Sources

This post is general information, not legal advice.