DPO Radio

Decree 330/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day. It runs to 82 articles across four chapters: general provisions, the violation schedules, sanctioning authority, and implementation. It is promulgated, in force, and not a proposal.
The decree sanctions administrative violations across both cybersecurity and personal data protection – one shared instrument, not a PDPL-only or cybersecurity-only decree. It expressly reaches Vietnamese and foreign individuals and organizations, including foreign enterprises providing telecommunications, Internet, content or cross-border data-processing services involving data of Vietnamese citizens.
This instrument promulgates the earlier shared draft enforcement overlay. Historical draft references are preserved as aliases, but readiness work built against draft assumptions needs re-checking against the signed schedules rather than carrying forward unchanged.

The obligations themselves continue to come from the parent stacks: the Personal Data Protection Law 91/2025/QH15 with Decree 356/2025 and the Decision 778 procedures, and Cybersecurity Law 116/2025/QH15 with its implementing lineage. Decree 330 adds the consequence layer, which failures are sanctionable, at what level, by whom, and with which corrective measures.
The fine architecture in Điều 7 is load-bearing for every number on this page. Cybersecurity fines (Điều 9–38) are stated per individual, and an organization pays twice the stated level, to a ceiling of 200 million VND for organizations and 100 million VND for individuals. Personal-data fines (Điều 39–71) are stated per organization, and an individual pays half. Three personal-data maxima go beyond the fixed scales: unlawful buying or selling of personal data can reach ten times the gross revenue obtained from the violation, without deducting costs under Điều 6 khoản 2; cross-border transfer violations can reach 5% of the organization's preceding-year revenue; and other personal-data violations are capped at 3 billion VND for organizations.
Decree 330 is not the general sanctions instrument for the Vietnam AI Law. It does, however, contain a dedicated personal-data penalty article for AI systems and virtual worlds: Điều 67 covers annual compliance assessment, algorithmic explanation, automated-processing opt-out, identification-record rights, risk classification and related safeguards.
| Provision | What It Establishes | Operational Implication |
|---|---|---|
| Điều 3 | Statute of limitations of one year from completion of the violating act | Date every remediation record; an inspection can reach back a year |
| Điều 4 | Penalty forms: warning, fines, deprivation of the right to use a licence or practising certificate and suspension of operations for 1–24 months, confiscation and deportation | Track supplementary-penalty exposure alongside the fine bands |
| Điều 5 | Ten corrective measures, from forced system restoration and forced remediation of data leakage to forced fulfilment of data-subject rights and disgorgement of illegal gains | Corrective measures need completion evidence, not only fine payment |
| Điều 7, Điều 6 khoản 2 | Fine attribution and maxima: cybersecurity ceilings of 200M VND for organizations and 100M VND for individuals; 3B VND personal-data ceiling; up to 5% of revenue for cross-border violations; and 10× gross revenue from unlawful data trading without cost deduction | Read every amount with its attribution rule and calculation basis |
| Điều 8 | Electronic evidence has legal value; violation records and sanction decisions may be created, digitally signed, served and stored electronically, with biometric authentication available where the violator cannot use a digital signature | Preserve integrity, identity, service and storage evidence for electronic enforcement records |
| Điều 29 | Content removal and blocking within 24 hours of a request from the Ministry of Public Security's specialised cybersecurity force, or 6 hours in urgent cases threatening national security | Start the clock from the authority request and preserve its receipt time and urgency basis |
| Điều 34 | Digital-account authentication duties with 90-day authentication-log retention | Retain and produce authentication logs on demand |
| Điều 37 | Registration, opt-out and confirmation records retained at least one year; absent another user agreement, no more than 3 advertising messages or emails, or 1 advertising call, per recipient in 24 hours; messages only from 07:00–22:00 and calls from 08:00–17:00 | Keep consent and opt-out evidence and enforce the statutory frequency and time windows |
| Điều 43 | Consent violations at 30–50 million VND; deliberate continued processing after a stop or restriction request, and treating silence as consent, at 50–70 million VND (organizational levels) | Consent, stop requests and the basis for processing must be provable |
| Điều 45 | Obstructing withdrawal or restriction, failing to stop processing, or failing to propagate a valid request at 20–30 million VND (organizational level) | Withdrawal and restriction workflows need completion and downstream evidence |
| Điều 54, 64, 70 | 72-hour breach-notification clocks — harm-qualified authority notification, and authority-plus-subject notification for finance-sector sensitive-data leaks and for location and biometric data | Notification timelines need timestamped evidence per data category |
| Điều 60–65 | Sector and context-specific personal-data duties for children, employment, health and insurance, advertising, finance and digital platforms | Map processing context to the applicable safeguards and retain evidence of the resulting controls |
| Điều 66–71 | Technology-specific duties for big data, AI and virtual worlds, blockchain, cloud, location and biometric data, and public recording | Assess technology-specific controls rather than relying on a general privacy review |
| Điều 67 | AI and virtual-world penalties of 20–50M, 50–70M and 70–100M VND by tier, with 3–6 month suspension for khoản 3 violations | Evidence annual assessment, explanation, opt-out, identification-record rights, risk classification, human review and security controls |
| Điều 81 | Transitional rules, including lex mitior — the lighter rule applies to pre-effective-date conduct | Assess open findings under both regimes before concluding exposure |
| Obligation | Timeline | Reference |
|---|---|---|
| Decree takes effect | 19 August 2026 | Điều 80 |
| Statute of limitations | 1 year from completion of the act | Điều 3 |
| Remove or block violating content | 24 hours from the specialised cybersecurity force's request; 6 hours in urgent cases threatening national security | Điều 29 |
| Cooperate with the specialised cybersecurity force | 24 hours | Điều 18, Điều 26, Điều 30 |
| Retain digital-account authentication logs | 90 days | Điều 34 |
| Retain advertising registration, opt-out and confirmation records | At least 1 year | Điều 37 khoản 2 điểm b |
| Respond with information about the procedure for a valid data-subject request | 2 working days | Điều 44 khoản 1 điểm d |
| Complete access, rectification or data-provision requests | 10 days; 15 days where a processor or third party must act; extension up to 10 days | Điều 44 khoản 3 điểm b |
| Complete withdrawal, restriction or objection requests | 15 days; 20 days where a processor or third party must act; extension up to 15 days | Điều 44 khoản 3 điểm a |
| Complete erasure requests | 20 days; 30 days where a processor or third party must act; extension up to 20 days | Điều 44 khoản 3 điểm c |
| Apply requested personal-data protection measures | 15 days; extension up to 15 days | Điều 44 khoản 3 điểm d |
| File the original personal-data processing impact assessment dossier | 60 days from the first day of processing | Điều 55 khoản 1 điểm b |
| Update a processing impact assessment when a specified update is triggered | 10 days | Điều 55 khoản 1 điểm đ |
| File the original cross-border transfer impact assessment dossier | 60 days from the first transfer | Điều 56 khoản 1 điểm b |
| Complete a cross-border transfer impact assessment after an authority request | 30 days from receipt of the request | Điều 56 khoản 1 điểm c |
| Notify a qualifying personal-data breach to the authority | 72 hours | Điều 54 khoản 3 |
| Notify finance-sector sensitive-data leaks to authority and subjects | 72 hours | Điều 64 khoản 1 |
| Notify location or biometric data incidents to authority and subjects | 72 hours | Điều 70 khoản 1 |
| Deprivation of the right to use a licence or practising certificate; suspension of operations | 1–24 months | Điều 4 khoản 2 |
Decree 330 prescribes no appendix forms of its own. Administrative violation records are made on the forms of the general administrative-violations framework, and the personal-data notifications it sanctions run on the forms of the PDPL stack – Mẫu số 08 for breach notification among them. Everything ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

The instrument is carried as an active enforcement framework whose every fine area, deadline and requirement names the article it was read from, so an exposure record traces to the signed text rather than to a summary of it.
The statutory fine schedules are held with both the stated level and the attribution rule, individual versus organization, so the number a reviewer sees is the one that applies to them. The revenue-percentage and gain-multiple maxima are recorded as such, not flattened into a fixed figure.
The timed obligations are held as deadlines rather than prose: the data-subject request periods, DPIA and cross-border dossier periods, 72-hour notification clocks, authority-request takedown windows, 90-day authentication-log retention and one-year advertising-record retention are things a programme can be measured against.
The draft-era readiness content was not discarded. The draft framework remains addressable as a legacy record, and the corrective-measure, consent, assessment and incident evidence built under the parent stacks is what an inspection under this decree will ask for.
The stated fine is not always the payable fine. Every band this instrument carries records whether the stated level is the individual or the organizational one, and what multiplier the other party pays.
Quoted maxima are ceilings, not totals. Revenue-percentage and gain-multiple rules can exceed the fixed scales, and multiple violations accumulate, exposure records say so rather than implying a single cap.
Each obligation names the article it came from. When counsel asks where an exposure figure comes from, the answer is a citation to the signed decree.
The draft is retained, not erased. Readiness history built under the draft overlay keeps its identity, and the succession from draft to signed instrument is recorded on both records.