[REVISION HISTORY]
Vietnam data governance and cybersecurity regulation
Updated 5 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-24 14:25 UTC → 2026-09-11 09:03 UTC ·
added
removed
Vietnam is advancing its digital regulatory landscape through new enforcement and capacity-building measures. Following the implementation of the Personal Data Protection Law on January 1, 2026, the Ministry of Public Security drafted a decree to establish administrative sanctions for cybersecurity and data protection violations. These proposed penalties include fines up to 10 times the illegal revenue for unauthorized data sales and up to 3 billion VND for other violations, aiming to strengthen digital sovereignty. To support these legal frameworks, the Prime Minister issued Decision No. 1555/QD-TTg, which creates a national training and development framework for data governance. Recent regulatory actions have moved from drafts to formal decrees. Decree No. 330/2026/NĐ-CP, effective August 19, 2026, establishes administrative penalties for cybersecurity and personal data violations, applying to both domestic and foreign entities. Under this decree, unauthorized collection or processing of personal data without explicit consent can result in fines of up to 70 million VND. Additionally, sending unsolicited advertising via email, text, or phone calls can result in fines of 10-20 million VND for individuals and up to 40 million VND for organizations. Decree No. 333/2026/NĐ-CP, also effective August 19, 2026, provides implementation measures for the Law on Cybersecurity. It mandates identity verification for telecommunications and internet service users via Vietnamese mobile numbers or legal electronic identification, and requires users engaging in commercial livestreaming livestreamers to verify accounts using personal identification numbers. The decree also allows for the indefinite suspension of social media accounts that infringe on national security or for repeat offenders. These regulations specifically target rising threats such as AI-driven deepfakes used for impersonation and fraud. accounts. Expanding its digital control, the government issued Decree 328/2026/NĐ-CP, effective October 5, 2026, to combat fake news news. This decree integrates the VNeID electronic identification application, allowing citizens to report misinformation directly. Complementing these measures, Circular 126/2026/TT-BTC, effective September 1, 2026, requires individuals and false organizations to pay actual costs for printing, copying, or photographing requested information. Concurrently, authorities are intensifying proactive information management through Steering Committee 35. This strategy focuses on providing timely, accurate, and official information to fill gaps and prevent the spread of false narratives on social media, aiming to clarify misunderstandings before they escalate.
Versions
- 2026-09-11 09:03 UTC Vietnam data governance and cybersecurity regulation
- 2026-08-24 14:25 UTC Vietnam data governance and cybersecurity regulation
- 2026-08-24 02:16 UTC Vietnam data governance and cybersecurity regulation
- 2026-08-23 08:21 UTC Vietnam data governance and cybersecurity regulation
- 2026-08-23 02:48 UTC Vietnam data governance and cybersecurity regulation
- 2026-08-14 19:38 UTC Vietnam data governance and cybersecurity regulation
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.