Vietnam proposes harsh penalties for procedural breaches in new data protection draft

Vietnam’s Ministry of Public Security has initiated consultations on a draft decree that introduces severe administrative penalties for cybersecurity and personal data breaches, raising concerns over its broad scope and potential operational impact on businesses and individuals.

Vietnam’s Ministry of Public Security has opened a consultation on a draft decree that would set administrative penalties for breaches of cybersecurity and personal data rules, filling one of the last major enforcement gaps left after the Personal Data Protection Law took effect on 1 January 2026. According to the draft and subsequent summaries by advisers in Vietnam, the measure is designed to apply to Vietnamese and foreign organisations and individuals, with fine levels that can rise sharply for companies and with extra sanctions such as licence suspension in some cases.

The most immediate concern is that the draft appears to convert several procedural failings into highly punitive offences. The text reviewed by Vietnam Business Law suggests that missed or incomplete impact assessment filings, late breach notices and other documentary lapses could attract substantial corporate fines, even where the underlying data issue is limited. For personal data cases, forvismazars says the draft sets a ceiling of VND 3 billion for organisations, while also allowing penalties to rise according to the number of affected data subjects.

That approach has drawn criticism because it can blur the line between paperwork failures and substantive harm. The Vietnam Business Law analysis argues that one provision on impact assessment breaches is drafted so broadly that it may punish the loss or exposure of data as a standalone offence, while another part of the draft explicitly ties liability to a transfer that results in a threshold breach. In practical terms, that could leave compliant companies arguing over wording before enforcement officers rather than facing a clearly defined rule.

The draft also goes beyond company conduct and would fine individuals for failing to protect their own personal data. That is unusual by international standards, and the same analysis says it may be especially hard on older people and other vulnerable users who are often targeted by fraud and scams. It also notes a basic legal problem: neither the law nor the draft explains clearly what it means, in practice, for a person to have “failed to protect” their own information.

For businesses, the proposed regime is also notable for its severity on procedural breaches. The article by HMPLaw says some offences that are largely administrative, such as delayed handling of data subject requests, late breach reporting and missing assessment files, could still trigger large fines and temporary suspension of data processing activity. That combination raises the risk that a compliance lapse could become an operational shutdown for data-intensive firms.

Another issue is that the draft does not appear to mirror the exemptions already written into the law itself. Vietnam Business Law points out that micro-enterprises, household businesses and some startups are not subject to certain impact assessment and officer-designation duties under the Personal Data Protection Law, yet the draft decree does not clearly preserve those carve-outs. The same critique says the draft also seems to narrow breach notification rules and shorten the reporting window from the law’s 72 hours to two working days, which could create a direct conflict between the parent statute and the enforcement text.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.