Thân Trọng Lý – Luật sư Thành viên
Decree No. 330/2026/ND-CP was issued by the Government of Vietnam on 19 August 2026 and took effect the same day (“Decree 330/2026”). No grace period, no transitional runway. It finally puts real teeth behind the Law on Personal Data Protection No. 91/2025/QH15, which has been in force since 1 January 2026 without a matching sanction to enforce it.
Most of the conversation has circled the same three numbers, VND 3 billion, 5 per cent of revenue, ten times the proceeds of a violation. Clients ask me about them first. In my view, none of the three is what should keep a compliance officer up at night.
The real shift is not the ceiling, it’s the onus
Read the Decree closely and one idea runs through nearly every article. The business now has to prove it complied. It is no longer the regulator’s job to prove that it didn’t.
Article 43.1(g) fines a business VND 30 to 50 million simply for failing to keep a consent log, or for being unable to produce one when a data subject asks or the authority inspects. Nobody needs to have complained. No data needs to have leaked. The absence of the record is the violation and entails risks.
A company that has quietly done everything right for years, but never wrote any of it down, is exposed under this Decree in a way it never was before.
Article 44 deserves more attention than it’s getting
This is the provision I expect in-house teams to reach for most often. It sets hard, numeric deadlines for responding to data subjects.
- 2 working days to acknowledge a valid request
- 10 days to grant access, correction or provision of data
- 15 days to act on a withdrawal of consent, restriction or objection
- 20 days to act on an erasure request
Miss them, and the controller pays VND 30 to 40 million. This is, in substance, a statutory service level agreement. If your organisation doesn’t already have a data subject request workflow built around these exact numbers, that’s the first document you should draft after reading this article.
Watch the 500-person line, not just the headline fines
Article 48.3 penalises collecting personal data unlawfully by technological means. Fines start at VND 100 to 200 million for as few as 500 basic data subjects and rise to VND 500 to 800 million past 5,000.
I suppose that five hundred people is not a large number. A tracking SDK, a background collection feature, a modest scraping job, any of these can put an organisation over that line before anyone in the business realises it.
Foreign investors should read Article 56 carefully
The Decree reaches foreign enterprises providing cross-border services and foreign organisations processing Vietnamese citizens’ data, no local commercial presence required.
The revenue-based penalty does not apply across the board. Article 56.3 reserves it for three specific failures, a missing transfer impact assessment, concealed or misdeclared data flows that lead to a breach, or transferring data after a stop order by the authority. For those, fines run from 1 per cent up to 5 per cent of revenue depending on scale. Add to that a six to twelve-month suspension of cross-border transfer activity, and an obligation to make the overseas recipient destroy the data and prove it. For any group running HR, CRM or cloud infrastructure outside Vietnam, this is the single largest operational exposure in the Decree.
Recommendation
Three things worth doing immediately for businesses. First, review your consent mechanism and, more importantly, your ability to prove it. Second, build a response workflow around the Article 44 deadlines. Finally, map every technology-enabled collection point and cross-border data flow you have.
The question a regulator will ask next is not whether your business leaked data. It’s whether you can prove you did things properly. Those are very different conversations to be having.
This article reflects the author’s personal views and does not constitute legal advice on any specific matter.


