DPO Radio

Decree 327/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day, with no transitional runway; every duty and clock applies from the date of issue. It runs to 16 articles across five chapters, with the Ministry of Public Security as lead authority, detailing Điều 14 of Cybersecurity Law 116/2025/QH15.
The decree covers preventive duties for information-system owners and a deliberately broad class of service providers, seven families of handling measures, each ending in an open catch-all rather than a closed list, the powers of the specialized cybersecurity protection force, the duties of the people who posted the information, and a coordination mechanism with a designated focal point on continuous standby.
Three clock families structure compliance: the 24-hour serious-attack report, data provision within 24 hours or 3 in emergencies, and removal within 24 hours or 6 in emergencies, with the removal and data-provision clocks mirrored onto posters, not only providers. If removal is not completed in time, the specialized force may access and delete the information directly.

Cybersecurity Law 116/2025/QH15 is the parent instrument; Decree 327 is its procedural child for violating information and acts, promulgating the protective-measures procedure slot that the implementation roadmap had tracked as a planned item.
Its boundaries with two siblings matter. Decree 328 governs fake and false information specifically, and is in force only from 5 October 2026, content directions before then arise under this decree's machinery, not that one's. And Decree 327 itself prescribes duties and measures without penalty figures: administrative fine schedules for these fields sit in Decree 330/2026/NĐ-CP, whose cybersecurity amounts are stated per individual with organizations at twice the level, so no exposure figure should be quoted without that attribution rule.
| Provision | What It Establishes | Operational Implication |
|---|---|---|
| Điều 5 | Preventive duties: user identification and fake-account blocking, retention and state-secret compliance, cooperation and platform interoperability, immediate response to warnings, and the 24-hour serious-attack report | The duty set is standing, not request-triggered |
| Điều 5 khoản 1 điểm h | Payment and digital-asset providers act on warning lists and suspend flagged accounts | Financial-sector providers carry a named duty inside a cybersecurity decree |
| Điều 6 | The managerial and technical control catalogue over content and accounts, plus electronic-evidence preservation | Controls and evidence handling are inspectable, not internal conveniences |
| Điều 7 | Seven handling-measure families — blocking, suspension, domain, content-control and account measures among them — each ending in an open catch-all | Measure intake must handle directions that no closed list anticipated |
| Điều 7 khoản 2 điểm h | Removal of unlawful or false information within 24 hours, 6 in emergencies; on failure the force may itself access and delete | The clock has a stated consequence, not only a deadline |
| Điều 7 khoản 11 | Information and electronic data provided within 24 hours of a request, 3 in emergencies | Out-of-hours extraction and approval capability is assumed by the text |
| Điều 10 | Poster-side duties mirroring the clocks: removal including copies, links and re-shares within 24 or 6 hours, data provision within 24 or 3 | Organizations are exposed as posters too, not only as providers |
| Điều 13 | Electronic data and evidence preserved without loss, distortion, damage or harm | Chain-of-custody discipline is a statutory expectation |
| Điều 14 khoản 2 | A designated coordination focal point on 24/24-hour standby for emergency requests, execution and result reporting | Standby is continuous availability, staffed and provable |
| Điều 14 khoản 3, khoản 4 | Standardized coordination forms and channels are delegated to the Ministry of Public Security, and to the Ministry of National Defence for military systems | Watch for ministerial guidance; the decree itself numbers no forms |
| Obligation | Timeline | Reference |
|---|---|---|
| Decree takes effect | 19 August 2026, no transitional provisions | Điều 15 |
| Report a qualifying cyberattack | 24 hours from detection | Điều 5 khoản 1 điểm g |
| Provide information and electronic data | 24 hours from the request | Điều 7 khoản 11 điểm a |
| Provide data in emergency situations | 3 hours | Điều 7 khoản 11 điểm b |
| Remove unlawful or false information | 24 hours from the request | Điều 7 khoản 2 điểm h |
| Remove in emergencies | 6 hours | Điều 7 khoản 2 điểm h |
| Poster removes content, copies, links and re-shares | 24 hours; 6 in emergencies | Điều 10 khoản 7 |
| Poster provides related information and data | 24 hours; 3 in emergencies | Điều 10 khoản 9 |
| Emergency coordination standby | Continuous, 24/24 hours | Điều 14 khoản 2 |
The decree numbers no official forms of its own. Standardized coordination forms, and the methods of sending, receiving, authenticating and responding to coordination requests, are delegated to the Ministry of Public Security, and to the Ministry of National Defence for military information systems. Everything ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

The instrument is carried as an active framework whose duty families, measure catalogue and clocks each name the article they were read from, including the open catch-alls, which are presented as open rather than rounded down to a closed list.
Directions and requests can be recorded with verified receipt time, scope, responsible owner, execution steps and completion proof, the evidence that distinguishes a met 6-hour clock from an assumed one.
Evidence preservation runs as chain-of-custody work: what was captured, by whom, when, and that it reached the authority without loss or distortion.
The provider and poster duty sets are held side by side, because one organization can be both, and the two roles carry mirrored but distinct clocks.
The clocks here start when a direction arrives, not when a team notices it. Receipt time is verified and recorded, because the difference between hour one and hour five is the whole compliance question.
The consequence is part of the record. Where removal fails on time, the force may act directly; a fact worth having in the file that explains why the window was met.
Open catch-alls are carried as open. A direction that fits no enumerated measure family still gets intake, execution and evidence, instead of falling between categories.
Provider and poster roles stay distinct on the same event, so mirrored clocks are answered in the role each request actually names.
Coordinates direction execution, escalation and the 24-hour attack report on one evidence chain.
Explore Incident ResponseKeeps warnings, responses and authority interactions connected to the case.
Explore Incident OperationsAssigns the standing duties (verification, controls, standby) to accountable owners.
Explore Program GovernanceTracks recurring control reviews, fake-account screening and vulnerability remediation.
Explore Monitoring ProgramsOrganizations operating under Decree 327 should confirm:
See how ComplianceOne records directions, runs the removal and data-provision clocks, and preserves the custody evidence this decree tests.

Yes. It was issued on 19 August 2026 and took effect the same day under Điều 15, with no transitional provisions or grace periods stated in the text.
Information-system owners and a deliberately broad class of service providers carry the preventive and execution duties, and the people who posted the information carry mirrored removal and data-provision duties of their own. The decree also reaches payment and digital-asset providers with warning-list obligations.
Removal of unlawful or false information within 24 hours of the specialized force's request, or 6 hours in emergencies, after which the force may access and delete directly. Information and electronic data within 24 hours, or 3 in emergencies. Posters answer mirrored clocks for their own content and data.
No. It prescribes duties and measures without penalty figures. Administrative fine schedules for these fields sit in Decree 330/2026/NĐ-CP, and any amount quoted from there needs its individual-versus-organization attribution rule.
Decree 328 governs fake and false information specifically and takes effect on 5 October 2026. Until then, and for the broader class of violating information generally, directions and clocks arise under this decree's machinery. The two are siblings under the same parent law.

Test direction intake, clock evidence, custody records and the standby duty against the signed decree.

Review your provider and poster exposure, your out-of-hours capability, and your coordination readiness.