Draft decree on administrative sanctions for violations in the field of cyber security and personal data protection: The economic burden on businesses

Insights
Draft decree on administrative sanctions for violations in the field of cyber security and personal data protection: The economic burden on businesses
Posted on: 27/03/2026

    The Draft Decree on sanctioning administrative violations in cyber security and personal data protection ("Draft Decree") is formed in the context that the law on cyber security and personal data protection ("PDP") will be officially implemented from the beginning of 2026.

    Accordingly, obligations related to cyber security and PDP of enterprises are set throughout the operation process. Along with these obligations are increasingly strict sanctions with large fines to ensure that the new regulations are strictly enforced in practice. Although, the new regulations are considered progressive and close to the trend of data governance in the world. However, the problem of compliance is not only a legal issue but also associated with costs and technical resources when it requires businesses to be able to both optimize economically and ensure to avoid potential sanctioning risks.

     

    Obligations related to cyber security and PDP of enterprises are set throughout the operation process. 

     

    Sanctioning violations in the field of cyber security

    Violations due to failure to ensure the safety of telecommunications infrastructure

    Currently, the distribution of Internet products and services is increasingly popular. However, many businesses often have little interest in equipping infrastructure that is secure enough to ensure information security. In addition, service providers also do not instruct Internet agents to implement, leading to the situation that Internet access points are easily attacked and information stolen. Since then, information is easily stolen and more and more bad actors are taking advantage of it to trade and transfer for profitable purposes in cyberspace. On that basis, requirements for ensuring the safety of telecommunications infrastructure are set. Specifically, according to Point a, Clause 1, Article 20 of the Draft Decree, in case of failing to deploy technical and professional systems to ensure safety and security, a fine of 10 to 20 million VND will be imposed. Although the fine is not too high, it is in line with the context that the State sets requirements for the responsibility of businesses in cybersecurity. In addition to fines, a number of remedial measures are also applied simultaneously in some cases such as forced restoration of the original state applied when there is an act of damaging fiber optic lines, antennas or equipment of the transmission system.[1]

    Violations due to failure to implement measures to supervise and protect information systems

    Previously, the penalty frame for acts of failing to apply safety measures was determined from 10-70 million VND.[2] According to Article 25 of the Draft Decree, the fine for failing to promulgate regulations on information system protection in the design, construction, operation, use, upgrade and cancellation of information systems is 25 to 50 million VND, higher than 10-20 million VND at the previous time. Similarly, acts of failing to inspect and supervise compliance, failing to coordinate with information system managers or failing to apply necessary management and technical measures are all grounds for imposing a fine of 50 to 100 million VND. The violations are built on the inheritance from the old regulations, but the fine is increased by 5 times to deter and urge the implementation of enterprises in the responsibility to protect information system security.

    Violations due to failure to ensure cyber information security

    Ensuring cyber information security is one of the top goals in the Cyber Security Law 2025. According to Clause 2, Article 25 of the Law on Cyber Security 2025, businesses when providing services in cyberspace are required to authenticate information when users register for digital accounts and keep information and user accounts confidential. At that time, compliance becomes a mandatory obligation, requiring businesses to establish authentication mechanisms and secure account management throughout the service lifecycle. For example, businesses need to implement appropriate user authentication measures such as authentication via phone numbers, emails, or forms of multi-factor authentication (MFA). At the same time, the system must also apply security measures such as encryption of login information, access control, recording of access logs, and detection of abnormal login behaviors to prevent the risk of unauthorized appropriation or use of user accounts. In fact, many major tech platforms have adopted these measures such as Google and Facebook. In case of non-compliance, the enterprise will be sanctioned from 75 to 100 million depending on the severity. Accompanied by additional sanctions such as enterprises will be deprived of the right to use business licenses from 01 to 03 months. Not only financial and administrative sanctions, these violations can also cause significant consequences for business operations. The deprivation of the right to use a business license may interrupt or stagnate the provision of services in cyberspace, directly affecting revenue and relations with customers and partners. At the same time, being sanctioned in the field of cybersecurity can also negatively impact the reputation and reliability of businesses in the market.

     

    Prime Minister Pham Minh Chinh presides over the meeting of the National Steering Committee on Cybersecurity. Source: Government Newspaper

     

    Sanctions in the field of PDP

    Violation of the rights of data subjects

    Article 4 of the Law on PDP 2025 recognizes a number of rights of personal data subjects such as: (i) The right to consent or disagreement, withdrawal of consent, Right to view, correct or request correction; (iii) The right to request deletion,... These are fundamental rights that are legislated in the period of digital assets and the need for information security is focused.

    Therefore, to ensure that the subject's rights are enforced in practice, the Draft Decree has introduced specific sanctions in case of violations by enterprises. Depending on the request of the data subject, the controller, controller and data processor must ensure the response within 02 working days and implement it within the prescribed time.[3] One of the situations that is expected to appear a lot in the near future is that when employees quit their jobs, they will often ask businesses to delete their personal data. Accordingly, according to Clause 4, Article 5 of Decree 356/2025/ND-CP, enterprises must be responsible for deleting data within 20 days or longer for complicated cases. At this time, businesses need to develop a process for receiving and processing requests to ensure the implementation and notification of processing results in a timely and fast manner. Because the delay in enforcing the rights of employees – data subjects can lead to a fine of 70 to 100 million VND and forced to apply additional penalties such as suspending the processing of data of enterprises for a certain period of time.[4]

    Violations in the implementation of administrative procedures on PDP

    The data processing impact assessment procedure is a mandatory procedure for the specialized personal data protection agency to assess the compliance situation and the level of risk in the process of controlling, processing and storing personal data of enterprises and related parties.  especially large enterprises. In addition, enterprises must carry out an impact assessment of personal data transfer when there is an activity of transferring data abroad. Therefore, the Draft Decree has added specific sanctions for violations related to these two procedures. For violations of personal data processing impact assessment, the controller, controller and personal data processor may be fined from VND 50 to VND 70 million when: [5] (i) failing to prepare or keep the data processing impact assessment dossier; (ii) failing to send the original to the Ministry of Public Security according to Form No. 02a (for enterprises); (iii) failing to comply with the request for correction and completion of the dossier within the prescribed time limit. This fine can also be multiplied in case the enterprise discloses or loses the personal data of a large number of data subjects.[6] Similar to these acts, the fine will be 70 to 100 million VND in case of transferring personal data abroad.

    Notably, many additional sanctions and remedial measures are applied simultaneously. For example, an enterprise must prepare or keep an impact assessment dossier on the processing of personal data but does not implement it. In this situation, the enterprise may be fined according to the above fine and suspended from its business license, accompanied by being forced to make or keep an impact assessment dossier in accordance with regulations. This shows that non-compliance with impact assessment obligations does not help businesses avoid the responsibility of carrying out procedures, but only increases compliance costs.

    Instead of waiting for the competent authority to inspect or issue sanctions, businesses will find a way to implement. It is very necessary for businesses to proactively implement procedures for reviewing operations, assessing risks, and carrying out administrative procedures for impact assessment right from this stage if personal data is processed. In the context that the State is strictly enforcing regulations on cyber security and personal data protection, the implementation of these regulations is no longer an option but forces businesses to enforce with the best option.

    Nguyen Viet Hung

    HM&P Law Firm

     

    Read moreDự thảo Nghị định xử phạt VPHC trong lĩnh vực an ninh mạng và bảo vệ dữ liệu cá nhân: Làm gì khi “gánh nặng kinh tế” đặt lên vai doanh nghiệp?


    [1] Clause 7, Article 20 of the Draft Decree.

    [2] Article 87 of Decree 15/2020/ND-CP.

    [3] Article 5 of Decree 356/2025/ND-CP details a number of articles and measures to implement the Law on PDP.

    [4] Clause 2, Article 58 of the Draft Decree.

    [5] Clause 1, Article 67 of the Draft Decree.

    [6] Clause 2, Article 67 of the Draft Decree.