Draft sanctioning of administrative violations in the field of data that have a great impact on business activities

Insights
Draft sanctioning of administrative violations in the field of data that have a great impact on business activities
Posted on: 31/12/2025

    Vietnam is entering a critical phase in data management, with new regulations set in place to shape the future of data-related activities. In November 2024, the Data Law was approved by the 15th National Assembly and officially took effect on July 1, 2025 ("Data Law 2024"). This is the first time that Vietnam has enacted an in-depth law, laying the legal foundation for the management, security, processing and use of digital data[1].

     

     

    In order to effectively implement the Data Law and put it into practice, in December 2025, the Ministry of Public Security presided over the development and collection of comments on the Draft Decree on sanctioning administrative violations in the field of data ("Draft Decree"). The draft Decree is in the finalization stage, marking an important step in establishing an enforcement and sanctioning mechanism for the Data Law and related regulations, setting out urgent requirements for businesses to proactively review and improve the level of compliance. The following article analyzes the main impacts of the Draft Decree on businesses, and suggests some recommendations to help businesses proactively prepare for this important new legal framework.

    1. Draft Decree on completing the legal framework in the field of data

    In recent years, the situation of data trading is currently common and public, many acts have not been handled because of the lack of legal regulations[2]. Many businesses collect customers' personal data and allow third parties to access it, but the lack of a strict control mechanism has facilitated the illegal transfer and sale of data. In fact, many businesses are not aware of the responsibility to protect as well as the possible consequences and have not applied sufficient technical solutions to protect data and effectively respond to the risks of information disclosure and leakage.

    Through the initial implementation of the Data Law 2024 and its guiding documents, there are many difficulties and obstacles in practice. In this context, the Ministry of Public Security has researched and developed a Draft Decree on Sanctioning Administrative Violations in the field of data to fill the legal gap in sanctions to create a unified, transparent, and effective legal framework. For businesses, the Draft brings both opportunities and challenges that directly affect business activities from the development of new products and services, the application of artificial intelligence to market analysis[3].

    2. Impact of the Draft Decree on enterprises

    Challenges in compliance and data risk management for businesses

    Firstly, the detailed sanctions framework increases the legal pressure of businesses.

    Each violation is clearly defined by the draft and accompanied by corresponding fines, making it easy for regulators to apply when businesses do not comply with data regulations. The Draft Decree not only sanctions "misconduct", but also "weak governance". Accordingly, businesses not only exploit data legally, but also take responsibility for post-inspection. Many behaviors do not stem from intentional errors or obvious infringements, but stem from the lack of a methodical data management mechanism, lack of internal processes or failure to maintain legal conditions throughout the operation process. This approach shows that the Draft Decree is not only aimed at punishing serious violations that have occurred, but also aims to force businesses to invest in data governance capacity in the first place. In Article 12 of the Draft Decree, the Ministry of Public Security proposes a fine of up to VND 120,000,000 for acts related to data administration and management activities.

    Second,  increase the burden of compliance costs in business operations.

    The establishment of a detailed sanctioning framework and a relatively high sanction level in the form of a fine of up to 2,000,000,000 VND[4], this fine will have to be urgent for the case of violating organizations, forcing enterprises not only to face the risk of being sanctioned when violating, but also to face the risk of being sanctioned when violating,  but also have to actively invest significantly to prevent risks from the beginning. Compliance costs are therefore no longer limited to the legal aspect, but extend to investments in technology infrastructure, security systems, data governance processes, and dedicated human resources.

    Third, the risk of business interruption.

    In addition to the form of fines, Clause 3, Article 4 of the Draft Decree also stipulates many remedial measures that directly affect the operation of enterprises, leading to significant financial impacts. For businesses with data-driven business models, the suspension or suspension of databases, information systems, or data processing services can disrupt the entire chain of operations – from service delivery, customer care to revenue streams – and in many cases,  the actual damage far exceeds the amount of fines to be paid.

    Not only stopping at direct financial losses, some measures such as forcing public notice of violations and remedial measures can also seriously affect the reputation, brand and credibility of businesses in the market. In the context of increasingly fierce competition in the digital economy, being associated with the image of "violating data regulations" or "information leakage incidents" has the risk of degrading the trust of customers and partners, leading to a loss of market share reduce brand value and have difficulty attracting investors as well as long-term cooperation opportunities.

     

     

    Positive aspects of the Draft for businesses

    On the other hand, the Draft Decree also brings positive effects and can be considered an opportunity for businesses.

    First of all, the Draft Decree creates a strong incentive for businesses to improve internal data governance standards. Strict requirements on confidentiality, information safety, decentralization of access, storage and sharing, along with strict sanctions, force businesses to see data not only as a business asset but also as an object of legal risk management. For businesses, the message is clear: invest seriously in data governance capabilities – not just to comply with the law, but also to build trust with customers, partners and society in an era where data is a measure of credibility and [5]competitiveness. Investing in technology systems, control processes, and dedicated data personnel not only helps businesses minimize the risk of sanctions, but also contributes to improving management efficiency, optimizing data mining, improving decision-making quality and competitiveness in the long term. 

    In addition, in the context of Vietnam's deeper and deeper integration into the international economy, the completion of the legal framework and sanctioning mechanism in the field of data is of great significance in strengthening the confidence of foreign partners and investors. A clear legal framework is a prerequisite for digital businesses to integrate with international standards; helping businesses feel secure in investing in technology such as blockchain, decentralized digital identification, cross-border data authentication, etc. This is especially significant for businesses operating in the fields of technology, finance, e-commerce, and digital services – industries where data plays a key role in business models.

    3. Some recommendations for businesses

    The data legal system in Vietnam is changing, bringing both challenges and opportunities for businesses. While controls help enhance data security and security, a clear legal framework also helps businesses operate more transparently and confidently in the digital economy.

    The draft is being consulted until January 2025, so businesses need to proactively prepare as soon as possible options to adapt to new regulations on data.

    First, businesses need to assess the current level of compliance against the requirements of the Data Law 2024 and the Draft Decree, thereby identifying legal risk issues that may arise when the official sanctioning mechanism is applied.

    In addition, it is essential to develop or update internal policies on data governance, decentralization, information security, and data leak handling processes. Businesses should also consider investing in upgrading technological infrastructure, establishing a mechanism for monitoring, tracking and controlling data access to meet increasingly stringent post-inspection requirements.

    In addition, during the period when the Draft is still collecting comments, enterprises can actively monitor and contribute opinions through industry associations or appropriate consultation channels, participate in discussion programs to reflect practical problems in the implementation process and contribute ideas. Early preparation and a proactive compliance approach not only help businesses minimize the risk of sanctions in the future, but also create a solid foundation for sustainable business activities in the increasingly standardized and closely monitored digital economy environment.

    In conclusion, the Draft Decree is an important step in the process of building a digital nation, contributing to the protection of business activities in the field of data and creating a platform for managing and exploiting data in a transparent, effective and responsible manner. However, opportunity comes with responsibility. Businesses cannot view data as a "gold mine" without barriers. Each act of processing, storing or transferring data needs to be carefully considered from a legal perspective. The Decree under construction is expected to complete the missing "piece" to ensure a balance between economic development and the protection of privacy and safety of each individual in the digital space - a key factor in the modern business environment.