DPO Radio

AesirX ComplianceOne | Decree 327 Vietnam Information Handling

Overview Image

327/2026/NĐ-CP: Scope and Current Status

Decree 327/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day, with no transitional runway; every duty and clock applies from the date of issue. It runs to 16 articles across five chapters, with the Ministry of Public Security as lead authority, detailing Điều 14 of Cybersecurity Law 116/2025/QH15.

The decree covers preventive duties for information-system owners and a deliberately broad class of service providers, seven families of handling measures, each ending in an open catch-all rather than a closed list, the powers of the specialized cybersecurity protection force, the duties of the people who posted the information, and a coordination mechanism with a designated focal point on continuous standby.

Three clock families structure compliance: the 24-hour serious-attack report, data provision within 24 hours or 3 in emergencies, and removal within 24 hours or 6 in emergencies, with the removal and data-provision clocks mirrored onto posters, not only providers. If removal is not completed in time, the specialized force may access and delete the information directly.

Overview Image

How Decree 327 Relates to the Vietnam Cybersecurity Law 2025

Cybersecurity Law 116/2025/QH15 is the parent instrument; Decree 327 is its procedural child for violating information and acts, promulgating the protective-measures procedure slot that the implementation roadmap had tracked as a planned item.

Its boundaries with two siblings matter. Decree 328 governs fake and false information specifically, and is in force only from 5 October 2026, content directions before then arise under this decree's machinery, not that one's. And Decree 327 itself prescribes duties and measures without penalty figures: administrative fine schedules for these fields sit in Decree 330/2026/NĐ-CP, whose cybersecurity amounts are stated per individual with organizations at twice the level, so no exposure figure should be quoted without that attribution rule.

Technical Provisions and Compliance Obligations

ProvisionWhat It EstablishesOperational Implication
Điều 5Preventive duties: user identification and fake-account blocking, retention and state-secret compliance, cooperation and platform interoperability, immediate response to warnings, and the 24-hour serious-attack reportThe duty set is standing, not request-triggered
Điều 5 khoản 1 điểm hPayment and digital-asset providers act on warning lists and suspend flagged accountsFinancial-sector providers carry a named duty inside a cybersecurity decree
Điều 6The managerial and technical control catalogue over content and accounts, plus electronic-evidence preservationControls and evidence handling are inspectable, not internal conveniences
Điều 7Seven handling-measure families — blocking, suspension, domain, content-control and account measures among them — each ending in an open catch-allMeasure intake must handle directions that no closed list anticipated
Điều 7 khoản 2 điểm hRemoval of unlawful or false information within 24 hours, 6 in emergencies; on failure the force may itself access and deleteThe clock has a stated consequence, not only a deadline
Điều 7 khoản 11Information and electronic data provided within 24 hours of a request, 3 in emergenciesOut-of-hours extraction and approval capability is assumed by the text
Điều 10Poster-side duties mirroring the clocks: removal including copies, links and re-shares within 24 or 6 hours, data provision within 24 or 3Organizations are exposed as posters too, not only as providers
Điều 13Electronic data and evidence preserved without loss, distortion, damage or harmChain-of-custody discipline is a statutory expectation
Điều 14 khoản 2A designated coordination focal point on 24/24-hour standby for emergency requests, execution and result reportingStandby is continuous availability, staffed and provable
Điều 14 khoản 3, khoản 4Standardized coordination forms and channels are delegated to the Ministry of Public Security, and to the Ministry of National Defence for military systemsWatch for ministerial guidance; the decree itself numbers no forms

ObligationTimelineReference
Decree takes effect19 August 2026, no transitional provisionsĐiều 15
Report a qualifying cyberattack24 hours from detectionĐiều 5 khoản 1 điểm g
Provide information and electronic data24 hours from the requestĐiều 7 khoản 11 điểm a
Provide data in emergency situations3 hoursĐiều 7 khoản 11 điểm b
Remove unlawful or false information24 hours from the requestĐiều 7 khoản 2 điểm h
Remove in emergencies6 hoursĐiều 7 khoản 2 điểm h
Poster removes content, copies, links and re-shares24 hours; 6 in emergenciesĐiều 10 khoản 7
Poster provides related information and data24 hours; 3 in emergenciesĐiều 10 khoản 9
Emergency coordination standbyContinuous, 24/24 hoursĐiều 14 khoản 2

Forms and Data Requirements

The decree numbers no official forms of its own. Standardized coordination forms, and the methods of sending, receiving, authenticating and responding to coordination requests, are delegated to the Ministry of Public Security, and to the Ministry of National Defence for military information systems. Everything ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

Overview Image

How ComplianceOne Supports Decree 327 Compliance

The instrument is carried as an active framework whose duty families, measure catalogue and clocks each name the article they were read from, including the open catch-alls, which are presented as open rather than rounded down to a closed list.

Directions and requests can be recorded with verified receipt time, scope, responsible owner, execution steps and completion proof, the evidence that distinguishes a met 6-hour clock from an assumed one.

Evidence preservation runs as chain-of-custody work: what was captured, by whom, when, and that it reached the authority without loss or distortion.

The provider and poster duty sets are held side by side, because one organization can be both, and the two roles carry mirrored but distinct clocks.

Built for Direction-Driven Operations

The clocks here start when a direction arrives, not when a team notices it. Receipt time is verified and recorded, because the difference between hour one and hour five is the whole compliance question.

The consequence is part of the record. Where removal fails on time, the force may act directly; a fact worth having in the file that explains why the window was met.

Open catch-alls are carried as open. A direction that fits no enumerated measure family still gets intake, execution and evidence, instead of falling between categories.

Provider and poster roles stay distinct on the same event, so mirrored clocks are answered in the role each request actually names.

Related Modules

Incident ResponseIncident Response

Coordinates direction execution, escalation and the 24-hour attack report on one evidence chain.

Explore Incident Response

Incident OperationsIncident Operations

Keeps warnings, responses and authority interactions connected to the case.

Explore Incident Operations

Program GovernanceProgram Governance

Assigns the standing duties (verification, controls, standby) to accountable owners.

Explore Program Governance

Monitoring ProgramsMonitoring Programs

Tracks recurring control reviews, fake-account screening and vulnerability remediation.

Explore Monitoring Programs

Audit TrailAudit Trail

Preserves request, execution, approval and custody history.

Explore Audit Trail

Compliance Readiness Checklist

Organizations operating under Decree 327 should confirm:

A coordination focal point is designated and reachable 24/24 hours, with staffing evidence.

Serious-attack reporting can reach the specialized force within 24 hours of detection.

Data-provision requests can be met in 24 hours, and 3 in emergencies, outside business hours included.

Removal directions complete inside 24 hours, and 6 in emergencies — including copies, links and re-shares where the poster duty applies.

User identification and fake-account screening operate as standing controls.

Electronic evidence is preserved with chain-of-custody discipline.

Payment and digital-asset warning-list duties are assigned where the sector applies.

Measure intake can process directions from the open catch-all families, not only the enumerated ones.

Vulnerability remediation on authority notice has an owner and a record.

Exposure conversations route fine figures through the separate penalty decree with its attribution rule.

Background Image

See Decree 327 Compliance in Action

See how ComplianceOne records directions, runs the removal and data-provision clocks, and preserves the custody evidence this decree tests.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

Yes. It was issued on 19 August 2026 and took effect the same day under Điều 15, with no transitional provisions or grace periods stated in the text.

Information-system owners and a deliberately broad class of service providers carry the preventive and execution duties, and the people who posted the information carry mirrored removal and data-provision duties of their own. The decree also reaches payment and digital-asset providers with warning-list obligations.

Removal of unlawful or false information within 24 hours of the specialized force's request, or 6 hours in emergencies, after which the force may access and delete directly. Information and electronic data within 24 hours, or 3 in emergencies. Posters answer mirrored clocks for their own content and data.

No. It prescribes duties and measures without penalty figures. Administrative fine schedules for these fields sit in Decree 330/2026/NĐ-CP, and any amount quoted from there needs its individual-versus-organization attribution rule.

Decree 328 governs fake and false information specifically and takes effect on 5 October 2026. Until then, and for the broader class of violating information generally, directions and clocks arise under this decree's machinery. The two are siblings under the same parent law.

Next Steps

Icon Image

Start a Compliance Pilot

Test direction intake, clock evidence, custody records and the standby duty against the signed decree.

Icon Image

Discuss Your Compliance Needs

Review your provider and poster exposure, your out-of-hours capability, and your coordination readiness.