info@cbilaw.vn
+ (84) 028 3979 8855

Penalties for Personal Data Protection Violations: What Risks Do Enterprises Face?

Decree No. 330/2026/ND-CP officially took effect on 19 August 2026, providing regulations on administrative penalties for violations in the fields of cybersecurity and personal data protection. Notably, certain violations may be subject to fines of up to VND 3 billion, ten (10) times the illicit proceeds, or 5% of revenue, together with remedial measures such as suspension of data processing, destruction/deletion of data, or disgorgement of illicit proceeds. What violations should enterprises be aware of, and what are the applicable penalties? CBI Law Firm provides an overview of the key provisions under Decree No. 330/2026/ND-CP below.

Illustrative image

1. Legal Basis

The regulations on penalties for violations in the field of personal data protection are currently based on:

  • Law on Personal Data Protection No. 91/2025/QH15;
  • Decree No. 356/2025/ND-CP, providing detailed regulations and measures for implementing the Law on Personal Data Protection; and
  • Decree No. 330/2026/ND-CP, providing regulations on administrative penalties for violations in the fields of cybersecurity and personal data protection.

Among these, Decree No. 330/2026/ND-CP directly prescribes the prohibited acts, applicable fines, additional penalties and remedial measures.

2. Key Penalties Enterprises Should Be Aware Of

2.1. DPIA Violations: Fines of up to VND 100 Million and Potential Suspension of Data Processing

Under Article 55 of Decree No. 330/2026/ND-CP, enterprises may be subject to fines ranging from VND 20 million to VND 30 million for violations such as:

  • failing to prepare a DPIA dossier as required;
  • failing to retain the DPIA dossier at the enterprise’s headquarters;
  • failing to submit the dossier within 60 days;
  • failing to complete the dossier as requested by the competent authority; or
  • failing to update the dossier within the prescribed period.

In particular, intentionally providing false information, falsifying the contents of the dossier, or failing to amend or supplement the dossier as requested may be subject to a fine ranging from VND 50 million to VND 100 million.

In addition to monetary fines, enterprises may be required to suspend personal data processing activities until they have fulfilled their DPIA obligations and obtained confirmation from the competent authority in accordance with applicable regulations.

2.2. CTIA Violations: Fines of up to VND 50 Million or up to 5% of Revenue

Under Article 56 of Decree No. 330/2026/ND-CP, violations of obligations relating to cross-border transfers of personal data may be subject to fines ranging from VND 30 million to VND 50 million, including failure to prepare a CTIA, failure to submit the dossier within 60 days, and failure to complete or update the dossier as required.

More notably, under Clause 3, Article 56 of Decree No. 330/2026/ND-CP, certain cross-border personal data transfer violations causing serious consequences may be subject to fines calculated as a percentage of the organization’s revenue in the immediately preceding fiscal year, specifically:

  • 1% to less than 2% of revenue: where the violation involves the disclosure or loss of data relating to from 10,000 to fewer than 100,000 Vietnamese personal data subjects;
  • 2% to less than 3% of revenue: where the violation involves from 100,000 to fewer than 1,000,000 personal data subjects;
  • 3% to 5% of revenue: where the violation involves 1,000,000 or more personal data subjects, or in certain cases where personal data is transferred after a decision suspending the transfer has been issued and the violation affects national defense or security.

Accordingly, where applicable, the penalty may reach 5% of revenue, making cross-border personal data transfers a significant compliance risk that enterprises should carefully monitor.

2.3. Consent Violations: Fines of up to VND 70 Million

Under Article 43 of Decree No. 330/2026/ND-CP, enterprises may be subject to fines ranging from VND 30 million to VND 50 million for processing personal data without valid consent, establishing a default consent mechanism, failing to ensure the ability to demonstrate consent, or failing to obtain separate consent for each processing purpose.

The fine may increase to VND 50 million to VND 70 million where an enterprise intentionally continues processing personal data after the data subject requests that processing be stopped or restricted, or treats silence or non-response as consent.

2.4. Processing Data in Violation of Applicable Principles: Fines of up to VND 60 Million

Under Article 42 of Decree No. 330/2026/ND-CP, certain acts, such as processing personal data beyond the permitted scope, processing data for purposes that are not appropriate, failing to ensure data accuracy, or retaining data for longer than necessary, may be subject to fines ranging from VND 20 million to VND 40 million.

Where personal data belonging to another person is used to commit an unlawful act, the applicable fine may be up to VND 60 million.

2.5. Illegal Purchase or Sale of Personal Data: Fines of up to 10 Times the Illicit Proceeds

One of the most notable sanctions applies to the illegal purchase or sale of personal data.

Under Article 53 of Decree No. 330/2026/ND-CP, for certain violations falling within its scope, the applicable fine may be calculated at two (02) to ten (10) times the illicit proceeds obtained from the violation.

Where no illicit proceeds are generated, or where the fine calculated based on the illicit proceeds does not reach the applicable statutory threshold, Decree No. 330/2026/ND-CP provides for fixed fines based on the type and quantity of personal data involved.

This is particularly relevant to enterprises engaging in the collection, exploitation, sharing, provision or transfer of personal data to third parties.

3. Not Just Monetary Fines: Enterprises May Also Face Suspension or Orders to Stop Data Processing

In addition to monetary fines, Decree No. 330/2026/ND-CP provides for additional penalties depending on the nature of the violation, including:

  • Suspension of the right to use licenses or professional practice certificates for 01 to 24 months;
  • Suspension of operations for 01 to 24 months;
  • Confiscation of material evidence and means of violation; and
  • Expulsion of foreign individuals who commit violations.

Enterprises may also be required to implement remedial measures, depending on the nature of the violation, including stopping data processing, destroying/deleting data, completing DPIA/CTIA dossiers, or disgorging illicit proceeds.

4. What Should Enterprises Proactively Review?

In light of the above sanctions, enterprises should proactively review:

  • DPIA: Has the enterprise correctly identified whether it is required to prepare a DPIA dossier?
  • CTIA: Does the enterprise conduct any activities involving the transfer, storage or granting of access to personal data from Vietnam to overseas locations?
  • Consent: Do the enterprise’s mechanisms for obtaining, recording and demonstrating consent satisfy applicable legal requirements?
  • Third Parties: Are data-sharing arrangements with service providers, partners and third parties adequately controlled?
  • Data Retention: Are data retention periods appropriate for the relevant processing purposes?
  • Incident Response: Does the enterprise have an appropriate procedure for responding to personal data incidents?

5. Compliance Review and Advisory Services

Compliance should not be limited to merely “having the required dossiers”. Enterprises should ensure that the entire lifecycle of personal data — from collection, processing, storage, sharing and transfer to consent management and incident response — is properly designed and operated in accordance with applicable laws.

CBI Law Firm assists enterprises in reviewing their personal data processing activities, assessing DPIA/CTIA obligations, identifying potential compliance risks, and developing appropriate compliance measures under the prevailing regulations.

This article is provided for general informational purposes only and does not constitute legal advice for any specific case. The laws and regulations referred to in this article are effective as of the date of publication but may have been amended, supplemented, replaced or expired at the time readers access this article. Accordingly, readers are advised to seek advice from qualified legal counsel before applying the information herein.

For any questions or legal assistance relating to personal data impact assessment procedures and other related legal services, please contact CBI Law Company Limited for further support.

Leave a Reply