Executive Summary
On 19 August 2026, the Government of Vietnam issued a package of seven decrees, Decree Nos. 327-333/2026/ND-CP, forming a significant part of the regulatory framework for implementing the new Cybersecurity Law and related cybersecurity and personal data protection requirements.
The package follows the entry into force of the Law on Cybersecurity No. 116/2025/QH15 (“Cybersecurity Law“) on 1 July 2026. As discussed in our January 2026 Client Update titled “Law on Cybersecurity Comes into Operation on 1 July 2026: Establishing a Unified Legal Framework on Cybersecurity and Network Information Security in Vietnam“, the Cybersecurity Law consolidated and replaced the former Law on Cybersecurity 2018 and Law on Network Information Security 2015, thereby establishing a unified legal framework governing cybersecurity and network information security in Vietnam.
Although issued as a coordinated package, the seven decrees should not be characterised narrowly as seven implementing decrees of the Cybersecurity Law alone. In particular, Decree 330 establishes the administrative sanctions framework for personal data protection, while Decree 328 was issued pursuant to a broader body of legislation, of which the Cybersecurity Law is only one component.
Decrees 327 and 329 to 333 took effect on 19 August 2026, while Decree 328 will take effect on 5 October 2026.
For businesses, Decrees 330 to 333 warrant particular attention. Collectively, they introduce or further elaborate requirements relating to personal data protection and cross-border personal data transfers, cybersecurity protection for information systems (“IS“), the licensing of cybersecurity products and services, regulatory cooperation, data localisation, and local presence requirements. Decrees 327 to 329, meanwhile, form part of the broader regulatory framework governing unlawful information and conduct in cyberspace, fake and false information, and cybersecurity protection forces.
This Update highlights the provisions of the seven-decree package that are likely to have the greatest practical implications for businesses operating in, or providing services to customers in, Vietnam.
The Seven-Decree Package
The seven-decree package comprises the following:
- Decree No. 327/2026/ND-CP (“Decree 327“): Prevention and handling of information and conduct in cyberspace that infringe national security, public order and social safety;
- Decree No. 328/2026/ND-CP (“Decree 328“): Prevention and combating of fake and false information;
- Decree No. 329/2026/ND-CP (“Decree 329“): Cybersecurity protection forces;
- Decree No. 330/2026/ND-CP (“Decree 330“): Administrative sanctions in the fields of cybersecurity and personal data protection;
- Decree No. 331/2026/ND-CP (“Decree 331“): Cybersecurity protection for IS;
- Decree No. 332/2026/ND-CP (“Decree 332“): Business of cybersecurity products and services; and
- Decree No. 333/2026/ND-CP (“Decree 333“): Detailed provisions and measures for implementing the Cybersecurity Law.
Taken together, the seven decrees also reflect the consolidation and restructuring of Vietnam’s previous cybersecurity and network information security framework following the adoption of the Cybersecurity Law. Several of the decrees carry forward, revise or integrate regulatory mechanisms that were previously addressed under separate instruments, including rules on cybersecurity protection of IS, cybersecurity products and services, and the detailed implementation of the former Cybersecurity Law. The transitional provisions of the new decrees preserve the application of certain previous rules to specified existing systems, contracts and pending regulatory procedures. The relevant continuity and transitional arrangements are discussed below where they are material to businesses.
Key Developments
Decree 330 Introduces a More Developed Enforcement Framework for Cybersecurity and Personal Data Protection
Decree 330 is particularly significant for businesses because it establishes the administrative sanctions regime for violations in the fields of cybersecurity and personal data protection.
The policy materials accompanying the development of Decree 330 indicate that the new regime was intended to address practical gaps and difficulties under the previous administrative sanctions framework and to bring relevant categories of violations in cyberspace within a more coherent enforcement framework. The Ministry of Public Security (“MPS“) also emphasised a preventive objective: the sanctions regime is intended not only to address violations after they occur, but also to encourage organisations and businesses to take a more proactive approach to cybersecurity and personal data protection.
The maximum monetary fine in the cybersecurity field is VND200 million (approximately US$7,800) for an organisation and VND100 million (approximately US$3,900) for an individual. However, potential liabiity for personal data protection violations is considerably higher. For organisations involved in the unlawful purchase or sale of personal data, the maximum fine may reach ten times the proceeds derived from the violation. For violations involving cross-border transfers of personal data, an organisation may be fined up to 5% of its revenue generated in the Vietnamese market during the immediately preceding financial year. For other personal data protection violations, the maximum fine for an organisation is VND3 billion (approximately US$117,000).
Decree 330 further introduces revenue-based penalties for certain serious cross-border personal data transfer violations. Under Article 56, an organisation may, in the circumstances specified in the Decree, be fined a percentage of its total revenue generated in the Vietnamese market during the immediately preceding financial year if it:
- transfers personal data across borders without preparing the required impact assessment dossier;
- conceals or falsely declares data flows resulting in personal data leakage or loss; or
- continues a transfer after an order to stop.
The applicable bands are:
- 1%-2% where the violation results in the leakage or loss of personal data of between 10,000 and fewer than 100,000 Vietnamese data subjects;
- 2%-3% where it affects between 100,000 and fewer than one million Vietnamese data subjects; and
- 3%-5% where it affects one million or more Vietnamese data subjects.
The 3%-5% band also applies where an organisation continues a cross-border transfer after an order to stop and this causes harm to national defence or national security.
Where an organisation subject to these revenue-based penalties generated no revenue in the Vietnamese market during the immediately preceding financial year, or where the applicable percentage-based fine would be below VND3 billion, Decree 330 instead prescribes corresponding fixed penalty bands. These range from VND200 million to VND500 million, VND500 million to VND1 billion, and VND1 billion to VND3 billion, based on the same data-subject thresholds and, where applicable, the national defence or national security consequence described above.
Importantly, not every cross-border transfer violation attracts a revenue-based penalty. Decree 330 separately provides fixed fines of VND30 million to VND50 million for certain compliance failures relating to cross-border transfer impact assessment dossiers and related procedural obligations, and VND50 million to VND100 million for specified substantive failures, including certain deficiencies concerning contractual arrangements, data-subject consent or notification, security measures and regulatory cooperation.
The enforcement framework is not limited to cross-border transfers or major data incidents. Decree 330 also imposes penalties for failures concerning personal data processing impact assessment dossiers, including failures to prepare, maintain, submit or update the relevant dossier. Certain failures may also result in the suspension of personal data processing until the applicable impact assessment obligations have been fulfilled.
For certain serious cross-border transfer violations under Article 56(3), the consequences may extend beyond monetary penalties. Decree 330 provides for suspension of cross-border personal data transfer activities for six to 12 months, together with other remedial measures provided by Decree 330. In practical terms, documentation and impact assessment requirements should no longer be viewed as merely formal compliance exercises. Businesses should reassess their personal data compliance programmes from an enforcement perspective, particularly where their operations involve sensitive personal data, large datasets or regular cross-border data flows.
Decree 331 Establishes a More Structured Framework for Cybersecurity Protection of IS
Decree 331 develops the framework for classifying IS into five levels and prescribes corresponding cybersecurity measures, responsibilities and obligations.
Importantly, the scope of Decree 331 should be read carefully. It applies to agencies, organisations and individuals participating in or connected with the construction, establishment, management, operation, upgrading or expansion of IS in Vietnam that support information technology (“IT“) applications in the activities of State agencies and organisations, or IT applications for the provision of online services to individuals and businesses. Other relevant organisations and individuals are encouraged to apply Decree 331 for the protection of their IS.
Accordingly, businesses should not assume that every internal corporate IT system is automatically subject to mandatory classification under Decree 331. A threshold question is whether the particular system falls within the scope of Decree 331.
For systems within Decree 331’s scope, classification takes into account several factors, including the nature and function of the system, the information processed, and the potential consequences of a cybersecurity incident. Level 1 includes information systems used for an organisation’s internal operations that process only public information; no data-subject threshold is specified for Level 1. Level 2 includes certain online-service IS processing basic personal data of fewer than 100,000 data subjects or sensitive personal data of fewer than 10,000 data subjects. Level 3 includes, among other criteria, certain online-service systems processing basic personal data of 100,000 or more data subjects or sensitive personal data of 10,000 or more data subjects.
The applicable protection requirements become more extensive as the classification level increases. Decree 331 also provides for cybersecurity risk assessments in prescribed circumstances and establishes procedures for proposing, appraising and approving information-system classifications.
For IS that were already under investment or construction before 1 July 2026, Decree 331 contains transitional arrangements. Relevant organisations have six months from the effective date of the Cybersecurity Law to complete appraisal and approval of the system level under the previous framework, and 12 months from that date to satisfy the cybersecurity conditions, standards and protection measures corresponding to the applicable level under Decree 331.
Businesses within the scope of Decree 331 should therefore first identify the relevant IS, determine the applicable classification level and assess any gaps between their existing cybersecurity arrangements and the requirements applicable to that level. Businesses with IS already under investment or construction before 1 July 2026 should also review the transitional deadlines applicable to those systems.
Decree 332 Regulates the Business of Cybersecurity Products and Services
Decree 332 establishes the regulatory framework for the business of cybersecurity products and services, including licensing requirements, the import and export of cybersecurity products, regulatory inspections and continuing obligations of licensed businesses. It identifies four categories of cybersecurity products and eight categories of cybersecurity services that are subject to the regulated business framework.
The policy materials accompanying the development of Decree 332 indicate an attempt to balance regulatory control with facilitating the development of the cybersecurity industry. MPS noted that cybersecurity products and services may provide direct access to, or intervene in, IS and therefore require appropriate regulatory controls. At the same time, the drafting process sought to reduce administrative procedures, clarify business conditions and facilitate compliance by cybersecurity businesses.
A Business Licence for Cybersecurity Products and Services is valid for ten years. Foreign-invested economic organisations are subject to additional requirements, including that the remaining term of their investment project in Vietnam must exceed five years from the date the licence is issued.
Certain regulated cybersecurity services are also subject to specific personnel requirements. Providers of cybersecurity assessment and consultancy services must employ at least five appropriately qualified technical personnel residing in Vietnam, while providers of cybersecurity monitoring services must employ at least 12 such personnel. For specified cybersecurity services, additional requirements also apply to the enterprise’s legal representative.
Compliance obligations do not end once a licence has been obtained. Licensed organisations and enterprises must continue to satisfy the licensing conditions and comply with the ongoing obligations under Decree 332. The annual reporting period runs from 1 January to 31 December, and the relevant report must be submitted to MPS before 31 January of the following year.
The transitional arrangements are also relevant to existing operators. Cybersecurity product and service contracts that were entered into and remained valid before Decree 332 took effect may continue to be performed. In addition, applications for the grant, exchange, supplementation, reissuance or extension of a licence that were received by MPS before 1 July 2026 but remained unresolved are subject to the procedures, requirements and conditions under Decree 332.
Cybersecurity businesses should therefore assess not only whether their activities require a licence, but also whether they satisfy the applicable personnel, investment-term, reporting and continuing-compliance requirements. Businesses involved in the import or export of regulated cybersecurity products should separately determine whether the relevant import or export licensing requirements apply.
Decree 333 Provides the Core Operational Rules under the Cybersecurity Law
Decree 333 provides the core operational rules under the Cybersecurity Law. Decree 333 provides detailed rules across a broad range of matters, including cybersecurity appraisal, assessment of cybersecurity conditions, inspection, monitoring, incident response, network information security and Internet Protocol (“IP“)-address identification, as well as data localisation and local presence requirements discussed separately below. Decree 333 also prescribes procedures for applying a range of cybersecurity protection measures, including the removal of unlawful, false or fake information and, in prescribed circumstances, the suspension or cessation of information-system operations.
The policy materials accompanying the development of Decree 333 indicate that the new framework was designed to selectively carry forward provisions of Decree No. 53/2022/ND-CP that remained appropriate, while revising, supplementing or removing other provisions to align the implementing framework with the Cybersecurity Law. MPS also sought to broaden and clarify the framework for network information security, including more specific obligations concerning user authentication, regulatory cooperation and the prevention and handling of unlawful online content.
One practical feature is the use of short regulatory-response periods. Telecommunications enterprises and providers of Internet, web-hosting, data-centre and telecommunications application services must block or remove unlawful online content, services or applications within 24 hours of receiving a request by written notice, telephone or email from the specialised cybersecurity protection force under MPS. They may also be required to refuse or temporarily suspend services provided to organisations or individuals using those services to post unlawful information online.
More broadly, domestic and foreign enterprises providing services on telecommunications networks, the Internet and value-added services in cyberspace in Vietnam are subject to network information security requirements under Decree 333. These include requirements concerning user authentication and account protection, as well as cooperation with the specialised cybersecurity protection force and other competent State authorities.
Decree 333 also introduces a more specific framework for IP-address identification. Telecommunications and Internet service providers must maintain prescribed technical information linking IP addresses to subscriber information, with relevant system logs retained for at least 12 months. Upon a valid written or electronic request from the specialised cybersecurity protection force for cybersecurity protection, verification, investigation or handling of cybersecurity violations, the relevant IP-address identification information must generally be provided within 24 hours. In urgent cases relating to national security, the prevention or combating of cyberterrorism or cyberattacks, or particularly serious crimes, the information must be provided within three hours.
These requirements reinforce the need for affected businesses to maintain operational regulatory-response mechanisms capable of receiving and validating requests, promptly escalating them to appropriate legal and technical personnel, preserving and retrieving the required technical information and implementing the required response within the applicable statutory period.
Data Localisation and Local Presence
Decree 333 retains and further specifies Vietnam’s data localisation framework. Importantly, while domestic enterprises are subject to data-storage requirements in respect of the prescribed categories of data, the corresponding data localisation and local presence requirements for foreign enterprises arise only where the conditions specified in Decree 333 are met.
The categories of data required to be stored in Vietnam include personal information of users of services in Vietnam and prescribed user-generated data, including account names, service-use time, credit-card information, email addresses, the most recent log-in and log-out IP addresses, and telephone numbers registered and associated with an account or data.
Domestic enterprises must store the prescribed data in Vietnam.
For foreign enterprises, Decree 333 applies data localisation and local presence requirements to specified services, including (i) telecommunications; (ii) online data storage and sharing; (iii) domain-name registration and maintenance; (iv) e-commerce; (v) online payment; (vi) payment intermediation; (vii) online transport connectivity; (viii) social media; (ix) online gaming; (x) online applications; and (xi) certain other online information and communications services.
Importantly, a foreign enterprise providing a covered service in Vietnam is not subject to these requirements solely by virtue of providing that service. The requirements to store the prescribed data in Vietnam and establish a branch or representative office arise where the enterprise’s service has been used to commit a violation of cybersecurity law and the prescribed enforcement conditions have been met. These conditions include notification of the violation by MPS’s specialised cybersecurity protection force; up to three written requests for cooperation, prevention, investigation or handling over a period of up to six months; and the enterprise’s subsequent failure to remedy the violation, failure to comply fully with the requests, or obstruction or neutralisation of cybersecurity protection measures.
Where these conditions are met, MPS may issue a decision requiring the foreign enterprise to store the prescribed data in Vietnam and establish a branch or representative office responsible for legal compliance in Vietnam. The enterprise must complete the required arrangements within 12 months from the date of the MPS’s decision.
The minimum period for storing the prescribed data in Vietnam is 24 months. The required branch or representative office must be maintained until the enterprise ceases operating in Vietnam or ceases providing the relevant service there. Relevant system logs must also be retained for at least 12 months.
Foreign digital-service providers should therefore determine whether their services fall within the categories covered by Decree 333 and to maintain effective regulatory-response procedures. The data localisation and local presence requirements should be assessed by reference to the specific statutory triggers, rather than treated as automatic obligations applicable to every foreign service provider operating in Vietnam.
Decrees 327-329 Complete the Wider Cybersecurity Architecture
Decrees 327 to 329 complement the more business-focused requirements under Decrees 330 to 333 by addressing unlawful information and conduct in cyberspace, fake and false information, and the institutional framework for cybersecurity protection forces.
Decree 327 establishes rules for preventing and handling information and conduct involving IT, computer networks, telecommunications networks and electronic means that infringe national security, public order and social safety in cyberspace. It imposes obligations on relevant organisations and individuals concerning the removal of unlawful information and cooperation with competent authorities. Where a removal request is made by the specialised cybersecurity protection force or another competent authority, the relevant information must generally be removed within 24 hours, or within six hours in an emergency.
Decree 328 establishes a dedicated framework for preventing and combating fake and false information. Relevant Internet, telecommunications, social-network and cross-border information service providers are subject to obligations concerning the prevention, identification and handling of such information, cooperation with regulatory authorities, and the establishment of a 24/7 contact point to respond to specified regulatory requests. Unlike the other decrees in the package, Decree 328 takes effect on 5 October 2026.
Decree 329 principally governs the organisation, operation, coordination and mobilisation of cybersecurity protection forces. It is therefore more institutional in character than Decrees 330 to 333, but forms part of the broader enforcement architecture within which businesses and information system owners may be required to cooperate with the competent cybersecurity authorities.
For businesses, Decrees 327 and 328 are particularly relevant to online platforms, telecommunications and Internet service providers, social network operators and other businesses involved in hosting, transmitting or disseminating online content. Businesses operating in these areas should ensure that their internal escalation and content-response procedures enable them to respond to regulatory requests within the applicable statutory timeframes.
Key Implications for Businesses
The seven-decree package reflects the growing convergence of cybersecurity, personal data protection, digital content governance and information system management. For businesses, compliance with the new framework is therefore increasingly an operational and cross-functional issue, rather than merely a legal documentation exercise.
Decree 330 significantly increases the potential consequences of non-compliance, particularly in relation to personal data protection and cross-border personal data transfers. Decrees 331 and 332, meanwhile, require businesses within their respective scopes to assess information system classification and cybersecurity safeguards, as well as licensing and ongoing compliance requirements for cybersecurity products and services.
Decree 333 has broader operational implications for digital and data-intensive businesses. Its regulatory response requirements call for appropriate internal escalation mechanisms, while foreign service providers should assess carefully the specific statutory conditions applicable to data localisation and local presence rather than treating those requirements as automatically applicable.
Taken together, the decrees reinforce the need for coordination among legal, compliance, data protection, IT and cybersecurity teams. Businesses should assess the new framework across their activities, systems, data flows and regulatory response procedures, rather than approaching each decree in isolation.
Recommended Actions
Businesses potentially affected by the new framework should consider the following steps:
- Map regulatory exposure. Identify which of Decrees 327 to 333 apply to the business, taking into account its digital services, IS, personal data processing, cross-border data transfers and cybersecurity products or services.
- Review regulatory-response protocols. Establish appropriate escalation procedures and 24/7 contact arrangements where required, to enable legal and technical teams to respond within the applicable statutory timeframes.
- Reassess personal data compliance. Review personal data processing impact assessments, cross-border transfer impact assessments, the handling of sensitive personal data, data security measures, and incident response procedures in light of the enforcement framework under Decree 330.
- Assess relevant IS. Determine whether relevant systems fall within the mandatory scope of Decree 331 and, where applicable, confirm their classification, corresponding cybersecurity requirements and any applicable transitional deadlines.
- Review cybersecurity licensing. Determine whether any cybersecurity products and services are subject to licensing under Decree 332 and assess the applicable personnel, investment-term, reporting and ongoing compliance requirements.
- Assess data localisation and local presence exposure requirements. Foreign enterprises providing services within the categories specified by Decree 333 should assess whether the statutory conditions triggering these requirements are met.
- Review contractual arrangements. Review contracts with IT, cloud, hosting and cybersecurity service providers to ensure that responsibilities for data management, access control, incident response, cybersecurity and regulatory cooperation are appropriately allocated.
Concluding Words
The issuance of Decree Nos. 327-333/2026/ND-CP represents an important next stage in the implementation of Vietnam’s new cybersecurity regulatory framework. Following the consolidation of the former cybersecurity and network information security regimes under the Cybersecurity Law, the seven decrees provide much of the detailed operational, compliance and enforcement architecture supporting the new framework.
For businesses, the significance of the package extends beyond the individual requirements of each decree. Cybersecurity, personal data protection, online-content governance, information system management, licensing and regulatory cooperation increasingly operate as interconnected compliance issues. Decrees 330 and 333 have particularly broad implications for businesses, while Decrees 331 and 332 warrant closer attention from businesses operating relevant IS or providing cybersecurity products and services. Decrees 327 to 329 complete the broader regulatory and institutional framework.
Businesses operating or providing services in Vietnam should therefore assess the seven decrees collectively, while carefully determining which requirements apply to their specific activities, systems and data flows. Rajah & Tann LCT Lawyers will continue to monitor the implementation of the new cybersecurity framework and provide further updates as regulatory and enforcement practice develops.
Further Information
Please feel free to reach out to our contact partners should you have queries on the above development.
For regional technology, media and telecommunications, and data and digital economy matters, please see Rajah & Tann Asia’s Technology, Media & Telecommunications Practice and Data & Digital Economy Practice, respectively, for more information.
This Update was authored by Chairwoman Vu Thi Que, Partner Trinh Minh Duc and Of Counsel Dr. Le Hong Phuc at Rajah & Tann LCT Lawyers.
Disclaimer
Rajah & Tann Asia is a network of member firms with local legal practices in Cambodia, Indonesia, Lao PDR, Malaysia, Myanmar, the Philippines, Singapore, Thailand and Vietnam. Our Asian network also includes our regional office in China as well as regional desks focused on Brunei, Japan and South Asia. Member firms are independently constituted and regulated in accordance with relevant local requirements.
The contents of this publication are owned by Rajah & Tann Asia together with each of its member firms and are subject to all relevant protection (including but not limited to copyright protection) under the laws of each of the countries where the member firm operates and, through international treaties, other countries. No part of this publication may be reproduced, licensed, sold, published, transmitted, modified, adapted, publicly displayed, broadcast (including storage in any medium by electronic means whether or not transiently for any purpose save as permitted herein) without the prior written permission of Rajah & Tann Asia or its respective member firms.
Please note also that whilst the information in this publication is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as legal advice or a substitute for specific professional advice for any particular course of action as such information may not suit your specific business and operational requirements. You should seek legal advice for your specific situation. In addition, the information in this publication does not create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on the information in this publication.
