Decree 330/2026/ND-CP sanctioning administrative violations in cybersecurity and personal data protection
- Summary
- Content
- Status
- Vietnamese
- Related documents
- Diagram
- Download
Please log in to your Advanced Package to view the full text. Do not have an account yet? Register here.
Please log in to use this function
Please log in to use this function
ATTRIBUTE
| Issuing body: | Government | Effective date: | Known Please log in to a subscriber account to use this function. Don’t have an account? Register here |
| Official number: | 330/2026/ND-CP | Signer: | Pham Gia Tuc |
| Type: | Decree | Expiry date: | Updating |
| Issuing date: | 19/08/2026 | Effect status: | Known Please log in to a subscriber account to use this function. Don’t have an account? Register here |
| Fields: | Administrative violation, Information - Communications |
The Effect status of this document is known.This feature is available to Advanced account holders. Please log in to a subscriber account to view Effect status. Don’t have an account? Register here
THE GOVERNMENT No. 330/2026/ND-CP | THE SOCIALIST REPUBLIC OF VIETNAM Hanoi, August 19, 2026 |
DECREE
On sanctioning of administrative violations in the fields of cybersecurity and personal data protection
Pursuant to Law No. 63/2025/QH15 on Organization of the Government;
Pursuant to Law No. 72/2025/QH15 on Organization of Local Administration;
Pursuant to Law No. 64/2025/QH15 on Promulgation of Legal Documents, which is amended and supplemented by Law No. 87/2025/QH15;
Pursuant to Law No. 116/2025/QH15 on Cybersecurity;
Pursuant to Law No. 91/2025/QH15 on Personal Data Protection;
Pursuant to Law No. 15/2012/QH13 on Handling of Administrative Violations, which is amended and supplemented by Law No. 54/2014/QH13, Law No. 18/2017/QH14, Law No. 67/2020/QH14, Law No. 09/2022/QH15, Law No. 11/2022/QH15, Law No. 56/2024/QH15, Law No. 88/2025/QH15, Law No. 116/2025/QH15, and Law No. 120/2025/QH15;
Pursuant to Law No. 148/2025/QH15 on Digital Transformation;
Pursuant to Law No. 20/2023/QH15 on E-Transactions;
Pursuant to Law No. 122/2025/QH15 on E-Commerce;
Pursuant to Law No. 71/2025/QH15 on the Digital Technology Industry;
At the proposal of the Minister of Public Security;
The Government hereby promulgates the Decree on sanctioning of administrative violations in the fields of cybersecurity and personal data protection.
Chapter I
GENERAL PROVISIONS
Article 1. Scope of regulation
1. This Decree prescribes administrative violations; completed and ongoing administrative violations; forms and levels of sanctions and remedial measures applicable to each administrative violation; subjects liable to administrative sanctions; competence to impose administrative sanctions, specific fine levels that may be imposed by each title holder, and competence to make records of administrative violations; and the implementation of administrative sanctions and remedial measures in the fields of cybersecurity and personal data protection.
2. Other administrative violations related to the fields of cybersecurity and personal data protection that are not specified in this Decree, but are prescribed in other Decrees of the Government on sanctioning of administrative violations in relevant fields of state management, shall be sanctioned in accordance with such Decrees.
3. In case an act concurrently violates this Decree and decrees on sanctioning administrative violations in other state management fields, the competent agency must correctly determine the nature of the act and the legal basis to apply for sanctioning. In case an act is concurrently specified in this Decree and in a decree on sanctioning of administrative violations in another field of state management, this Decree shall apply if the act of violation is committed in the fields of cybersecurity and personal data protection; in case the constituent elements of the act constitute a violation of other obligations, responsibilities, or prohibitions falling under the scope of another specialized field of state management, the decree of such field shall apply.
Article 2. Subjects and principles of application
1. Vietnamese individuals and organizations; foreign individuals and organizations that commit administrative violations in the fields of cybersecurity and personal data protection in the territory, internal waters, territorial sea, contiguous zone, exclusive economic zone, or continental shelf of the Socialist Republic of Vietnam; or on aircraft with Vietnamese nationality or seagoing ships under the Vietnamese flag (hereinafter referred to as individuals and organizations), unless otherwise specified by treaties to which the Socialist Republic of Vietnam is a contracting party.
2. The organizations prescribed in Clause 1 of this Article include:
a) Sole proprietorships, joint stock companies, limited liability companies, partnerships, and affiliated units of enterprises;
b) Organizations that are established in accordance with the Law on Cooperatives;
c) Organizations that are established in accordance with the Law on Investment;
d) Socio-political organizations, socio-professional organizations, other social organizations;
dd) Foreign enterprises or branches, representative offices, or business locations of foreign enterprises providing telecommunications, Internet, cyber content provision, information technology, or cybersecurity services, or providing cross-border services; foreign agencies and organizations directly participating in or relevant to personal data processing activities of Vietnamese citizens and people of Vietnamese origin with undetermined nationality residing in Vietnam who have been granted identity certificates;
e) Public telecommunications, video game, and Internet access service provision points;
g) Enterprises providing information content services on mobile telecommunications networks and cyberspace;
h) Non-business units, social organizations, socio-professional organizations, and foreign non-governmental organizations using radio frequencies;
i) Domain name registrars; organizations and enterprises registering domain names;
k) Information system managers and information system operating units;
l) Other organizations as specified by law.
3. Business households, households, and residential communities committing administrative violations specified in this Decree shall be subject to the same fine levels as individuals.
4. The Ministry of National Defence shall manage cybersecurity regarding military and national defense tasks; the Ministry of Public Security shall manage cybersecurity regarding Army units engaged in civil or economic activities according to its competence; for overlapping issues (if any), the Ministry of Public Security and the Ministry of National Defence shall agree on a coordination regulation.
Article 3. Statute of limitations for sanctioning administrative violations
1. The statute of limitations for sanctioning administrative violations in the fields of cybersecurity and personal data protection shall be 01 year.
2. The time of termination of an act of violation to calculate the statute of limitations for sanctioning is the date on which the individual or organization completes the obligations as specified by regulations or the date on which such act of violation actually terminates as confirmed by a competent agency.
3. In addition to Clause 2 of this Article, agencies or persons competent to sanction administrative violations shall, based on relevant legal documents, dossiers, documents and circumstances of each specific case, determine whether the acts of violation are completed administrative violations or in-progress administrative violations in accordance with the Government’s decree detailing a number of articles and measures for enforcement of the current Law on Handling of Administrative Violations.
Article 4. Sanctioning forms
1. Principal sanctions imposed for administrative violations in the fields of cybersecurity and personal data protection include:
a) Caution;
b) Fine.
2. Depending on the nature and severity of their violations, violating organizations and individuals may also be subject to one or several of the following additional sanctions:
a) Deprivation of the right to use licenses or practice certificates for a definite term of between 01 month and 24 months, including: License to provide social network services; License to establish an aggregate information website; License to trade in cybersecurity products and services; Certificate of eligibility to do business in personal data processing services; business licenses or practice certificates for industries or professions with violations of regulations on personal data processing;
b) Suspension of operations for a definite term of between 01 month and 24 months;
c) Confiscation of material evidence of administrative violations and means used to commit administrative violations (hereinafter collectively referred to as administrative violation material evidence or means);
d) Expulsion applied to foreigners committing administrative violations.
3. The additional sanctions specified in Clause 2 of this Article shall be applied in tandem with the principal sanctions for specific acts of violation specified in Chapter II of this Decree.
4. In the process of considering and handling a violation case, if the act of violation is found to show signs of crime, the transfer of the violation case file for examination for penal liability, and the transfer of the violation case file for administrative sanctioning in case of no examination for penal liability, shall be carried out in accordance with Article 62 and Article 63 of the Law on Handling of Administrative Violations.
Article 5. Remedial measures
Individuals and organizations committing acts of administrative violations specified in this Decree may be subject to one or more remedial measures as follows:
1. Forcible restoration of the original state of the information system.
2. Revocation or return of information, data, programs, software, malicious codes, digital accounts, digital certificates, products, equipment, services, Internet resources, domain names, IP addresses, ASNs, subscriber numbers, telecommunications number blocks, tools, means or law-violating elements on cybersecurity and personal data protection.
3. Forcible implementation of measures to remedy cybersecurity breaches, data leaks, information conflicts on the network or risks of causing damage to agencies, organizations, or individuals; forcible revocation of domain names due to the commission of violations.
4. Forcible elimination of violating elements in activities of designing, building, managing, and operating information systems; personal data processing activities; technical procedures; management mechanisms; service provision contracts; and activities of connecting, storing, transmitting, and sharing data.
5. Forcible correction of untruthful or misleading information; forcible correction of results of appraisal, assessment, inspection, or certification; forcible public notification, public apology, or provision of full and transparent information to organizations or individuals affected by the acts of violation.
6. Forcible application of necessary technical and management measures to prevent and remedy risks of cybersecurity and cyber safety breaches caused by the acts of violation; forcible implementation of cybersecurity protection measures for information systems critical to national security.
7. Forcible full implementation of rights of personal data subjects; forcible correction, update, supplementation, or deletion of inaccurate personal data, or personal data unlawfully collected, processed, used, disclosed, or transferred.
8. Forcible refund or forcible disgorgement of illicit profits obtained from committing the administrative violations in the fields of cybersecurity and personal data protection.
9. Forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been illegally sold, dispersed or destroyed.
10. Forcible re-inspection of cybersecurity for products, equipment, services, and software serving the protection of state secrets.
Article 6. Execution of forms of administrative sanctioning and remedial measures in each state management field
1. The proceeds from the commission of administrative violations related to personal data protection as specified in this Decree mean the total value in kind, money, valuable papers, assets or other material benefits directly or indirectly obtained by organizations or individuals from the commission of law-violating acts on personal data protection. In case an organization or individual commits multiple administrative violations or repeatedly commits administrative violations, the proceeds from the acts of violation shall be determined according to each act of administrative violation and each time of violation.
2. The proceeds from the commission of administrative violations related to personal data protection are determined as follows:
a) The proceeds from acts of unlawfully buying and selling personal data are determined as the total transaction value recorded on contracts, invoices, payment documents, message history, electronic transactions, bank account statement data, e-wallets, or other similar methods directly related to such transactions, without deducting any expenses incurred during the commission of violations;
b) The proceeds from acts of unlawfully collecting, processing, using, or transferring personal data without committing the acts of unlawfully buying and selling personal data are determined as the total actual revenue obtained by violating organizations or individuals from business activities using unlawfully collected, processed, used, or transferred personal data, without deducting any expenses incurred during the commission of violations.
3. Organizing the execution of decisions on sanctioning of administrative violations and decisions on application of remedial measures:
a) Violating individuals and organizations are responsible for strictly and fully executing the decisions on sanctioning administrative violations or decisions on application of remedial measures within the time limits stated in the decisions;
b) Competent persons having issued sanctioning decisions or agencies of persons competent to sanction are responsible for organizing the execution of decisions; guiding and urging violating individuals and organizations to implement obligations in accordance with regulations;
c) The execution of forms of sanctioning and remedial measures shall comply with the Law on Handling of Administrative Violations and relevant laws; ensuring correct order, procedures, publicity, objectivity, and proper time limits.
4. Urging and inspecting the compliance:
a) Agencies and persons competent to sanction are responsible for monitoring and inspecting the execution of sanctioning decisions and decisions on application of remedial measures against violating individuals and organizations;
b) In case of necessity, competent agencies may request violating individuals and organizations to report in writing and provide documents proving the complete execution of sanctioning decisions or remedial measures;
c) The inspection shall be recorded in minutes or documents confirming the execution results to be filed in the administrative violation sanctioning dossiers.
5. Reporting on the execution results:
a) Violating individuals and organizations are responsible for reporting on the results of execution of sanctioning decisions and decisions on application of remedial measures at the request of competent agencies;
b) Agencies and persons competent to sanction shall implement the regime of statistics, consolidation, and reporting on the results of execution of decisions on sanctioning administrative violations in accordance with law.
6. Handling of cases of non-compliance:
a) Upon the expiration of the execution time limit stated in the decisions, if violating individuals or organizations fail to voluntarily comply, they shall be subject to enforcement in accordance with the Law on Handling of Administrative Violations;
b) Individuals and organizations intentionally delaying, shirking, or obstructing the execution of sanctioning decisions or decisions on application of remedial measures shall be handled in accordance with law depending on the nature and severity of their violations;
c) Expenses for organizing the execution and enforcement shall be paid by violating individuals and organizations in accordance with law.
Article 7. Provisions on fine levels and sanctioning competence
1. Sections 1 to 5, Chapter II of this Decree prescribe the fine levels applicable to administrative violations in the field of cybersecurity committed by individuals. In case organizations commit the same act of violation, the fine level applied to organizations is twice that applied to individuals.
Section 6, Chapter II of this Decree prescribes the fine levels applicable to administrative violations in the field of personal data protection committed by organizations. In case individuals commit the same act of violation, the fine level applied to individuals is one-half of the fine level applied to organizations.
2. The sanctioning competence of the title holders specified in Chapter III of this Decree is the competence applied to a single act of administrative violation committed by organizations. In case of imposition of fines, the competence to sanction individuals is one-half of the competence to sanction organizations.
3. The maximum fine level in the field of cybersecurity is VND 200,000,000 for organizations and VND 100,000,000 for individuals.
4. Maximum fine levels in the field of personal data protection:
a) The maximum fine level in the sanctioning of administrative violations for acts of buying and selling personal data is 10 times the proceeds from the acts of violation; in case there are no proceeds from the acts of violation or the fine calculated based on the proceeds from the acts of violation is lower than the maximum fine level specified at Point c of this Clause, the fine level specified at Point c of this Clause shall apply;
b) The maximum fine level in sanctioning administrative violations against an organization committing an act of violation of regulations on cross-border transfer of personal data shall be 5% of the revenue of the immediately preceding year of such organization; in case there is no revenue of the immediately preceding year or the fine calculated based on revenue is lower than the maximum fine level specified at Point c of this Clause, the fine level specified at Point c of this Clause shall apply;
c) The maximum fine level in the sanctioning of administrative violations for other acts of violation in the field of personal data protection is VND 03 billion;
d) The maximum fine levels specified at Points a, b and c of this Clause are applicable to organizations; for individuals committing the same acts of violation, the maximum fine levels are one-half of the fine levels applicable to organizations.
Article 8. Sanctioning of administrative violations in the electronic environment
1. Evidence proving acts of violation in the electronic environment:
a) Evidence proving administrative violations in the electronic environment include representation forms of data messages, information, images, audio, digital documents and other forms of data collected directly or online on electronic devices and information systems of violating organizations or individuals, or collected on electronic devices and information systems of other organizations or individuals;
b) Persons competent to sanction administrative violations are responsible for inspecting and assessing the reliability and integrity of electronic evidence; and have the right to request related organizations and individuals to provide data, information, images, audio, digital documents and other forms of data to prove acts of violation in accordance with law;
c) Electronic evidence collected under Point a, Clause 1 of this Article have legal validity and serve as grounds for handling administrative violations for the acts of administrative violation specified in this Decree.
2. Making of written records of administrative violations in the electronic environment:
a) An administrative violation record in the electronic environment is a record made, digitally signed, sent, received, stored, and managed by electronic methods;
b) The making of written records of administrative violations in the electronic environment must ensure the authentication of identities of record makers, violators, representatives of violating organizations, witnesses (if any), and interpreters (if any). Information and data in written records are not altered after being digitally signed by legally valid digital signatures of administrative violation record makers, violators, representatives of violating organizations, witnesses (if any), and interpreters (if any). Assuring the integrity, safety and confidentiality of data in accordance with law on electronic transactions and cybersecurity;
c) Written records of administrative violations are digitally signed by competent record makers and violators or lawful representatives of violating organizations; in case violators or representatives of violating organizations cannot use digital signatures in electronic sanctioning procedures, biometric authentication means using facial images or fingerprints shall be used to identify them in accordance with law and in substitution for digital signatures of violators or representatives of violating organizations;
d) Written records of administrative violations made in the electronic environment have the same legal validity as written records made in paper form, and serve as grounds for issuing decisions on sanctioning administrative violations.
3. Issuance of decisions on sanctioning of administrative violations in the electronic environment:
a) A decision on sanctioning of an administrative violation in the electronic environment is a decision made, digitally signed, sent, stored, and managed by electronic methods;
b) The issuance of decisions on sanctioning administrative violations in the electronic environment must ensure that they are digitally signed with legally valid signatures by persons with sanctioning competence; the entire content and data of decisions are safely and securely stored, and neither modified nor altered after being issued; in case violating individuals or organizations do not have access to the electronic systems, agencies with sanctioning competence shall ensure the notification of sanctioning decisions via messages or emails, and simultaneously archive electronic copies of the decisions in the information systems issuing sanctioning decisions;
c) A decision on sanctioning of an administrative violation issued in the electronic environment has the same legal validity as a decision issued in paper form, serving as a basis for organizing the execution of the sanctioning decision, collecting and paying fines, and implementing remedial measures in accordance with regulations.
4. Conditions for the handling of administrative violations in the electronic environment shall comply with the Government’s Decree No. 118/2021/ND-CP of December 23, 2021, detailing a number of articles and measures for implementation of the Law on Handling of Administrative Violations, as amended and supplemented under Decree No. 68/2025/ND-CP and Decree No. 190/2025/ND-CP.
Chapter II
ADMINISTRATIVE VIOLATIONS, SANCTIONING FORMS
AND REMEDIAL MEASURES
Section 1
VIOLATIONS OF REGULATIONS
ON PROTECTION OF NATIONAL SECURITY AND ASSURANCE OF SOCIAL ORDER AND SAFETY IN CYBERSPACE
Article 9. Providing or sharing information in cyberspace containing law-violating content, affecting security and order
1. A fine from VND 5,000,000 to VND 10,000,000 shall be imposed for the following acts:
a) Providing or sharing information aimed at inciting, mobilizing or enticing others to commit acts infringing upon security and social order;
b) Providing or sharing information that threatens, incites conflicts, causes division, or negatively impacts the security and order situation;
c) Providing or sharing information containing content that incite or entice mass gatherings, affecting social order and safety and operations of agencies or organizations;
d) Providing or sharing unverified information related to history and revolutionary traditions.
2. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts, which is not serious enough for penal liability examination:
a) Providing or sharing information containing untruthful content about national sovereignty, security and national defense, affecting security and order;
b) Providing or sharing information containing inappropriate content, affecting the dignity of the nation, the national flag, the national emblem, the national anthem, great figures, leaders, cultural celebrities, and national heroes;
c) Providing or sharing inappropriate information related to ethnicity, belief, religion, gender or race, causing negative impacts in the society;
d) Creating, posting or sharing fake information in cyberspace, affecting security and order;
dd) Providing or sharing information containing untruthful or distorted content, affecting the normal operation or reputation of agencies, organizations or the People’s administration.
3. Remedial measure(s):
a) Forcible removal and deletion of violating information for the acts specified in Clauses 1 and 2 of this Article;
b) Forcible correction of untruthful information for the acts specified in Clauses 1 and 2 of this Article.
Article 10. Creating and disseminating information in cyberspace containing content that infringes upon the economic management order
1. A fine from VND 5,000,000 to VND 10,000,000 shall be imposed for any of the following acts:
a) Providing or sharing information about products, goods or valuable papers without ensuring accuracy in accordance with law, affecting the lawful rights and interests of organizations or individuals or the market order;
b) Providing or sharing promotional content for products, services, equipment or goods that have not been confirmed or permitted for use in medical examination and treatment activities by competent agencies in accordance with law.
2. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Posting or disseminating information on unlawfully buying, selling, exchanging, gifting, collecting, leasing, lending or using digital accounts, which is not serious enough for penal liability examination;
b) Posting or disseminating information on buying and selling goods or services prohibited by law, which is not serious enough for penal liability examination;
c) Posting or disseminating information on advertising, buying, selling, exchanging, or gifting counterfeit money, counterfeit valuable papers, or counterfeit payment instruments, which is not serious enough for penal liability examination.
3. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for establishing websites, social networks or accounts, dedicated pages, or groups on social networks, or electronic forums to post, disseminate, or instruct the commission of the acts specified in Clauses 1 and 2 of this Article.
4. Additional sanction(s): Suspension of operations from 01 month to 03 months for organizations committing the acts of violation specified in Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible removal or deletion of information in cyberspace containing content that infringes upon the economic management order, for the acts of violation specified in Clauses 1, 2 and 3 of this Article;
b) Forcible revocation or forcible surrender of domain names due to the commission of the acts of violation specified in Clause 3 of this Article;
c) Forcible correction of information in cyberspace containing content that infringes upon the economic management order, for the acts specified in Clauses 1, 2 and 3 of this Article;
d) Forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been illegally sold, dispersed or destroyed for the acts specified in Clauses 1, 2, and 3 of this Article.
Article 11. Creating and disseminating information in cyberspace containing untruthful or unverified content, causing confusion among the public, and affecting social order
1. A fine from VND 5,000,000 to VND 10,000,000 shall be imposed for any of the following acts:
a) Providing or sharing information containing content unconformable with the fine customs, traditions, social morality, or likely to cause negative impacts to the community;
b) Providing or sharing information containing content encouraging or instructing the commission of acts in contravention of law, which is not serious enough for penal liability examination;
c) Providing or sharing information about methods, therapies, remedies, or medical examination and treatment techniques that have not been permitted by competent agencies or verified in accordance with specialized regulations;
d) Providing or sharing information recommending the alteration, delay or non-application of medical examination and treatment methods or regimens recognized by competent agencies without appropriate professional recommendations.
2. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for the following acts:
a) Creating or disseminating untruthful or unverified information affecting the lawful rights and interests of organizations or individuals and the information environment in cyberspace;
b) Creating or disseminating information containing content unconformable with the fine customs, traditions, social morality, or likely to cause negative impacts to the community;
c) Creating or disseminating information containing content encouraging or instructing the commission of acts in contravention of law, which is not serious enough for penal liability examination;
d) Creating or disseminating information about methods, therapies, remedies, or medical examination and treatment techniques that have not been permitted by competent agencies or verified in accordance with specialized regulations;
dd) Creating or disseminating information recommending the alteration, delay or non-application of medical examination and treatment methods or regimens recognized by competent agencies without appropriate professional recommendations.
3. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for establishing or managing websites, social networks or accounts, groups, dedicated pages on social networks, or electronic forums to post or instruct the commission of the acts specified in Clauses 1 and 2 of this Article.
4. The sanctionable acts specified at Points d and dd, Clause 1, and Clause 2 of this Article do not apply to cases where individuals share personal experiences or information about their medical examination and treatment process, provided that such sharing is not intended for advertising, professional consultancy, providing instructions on alternative treatments, or obtaining profits from the provision of medical examination and treatment products, services, or methods.
5. Additional sanction(s):
a) Confiscation of material evidence and means of administrative violations for the acts of violation specified in Clauses 1, 2, and 3 of this Article;
b) Suspension of operations from 01 month to 03 months for enterprises committing the acts of violation specified in Clause 3 of this Article.
6. Remedial measure(s):
a) Forcible removal or deletion of information in cyberspace containing fabricated or untruthful content that causes confusion among the public or affect social order, for the acts of violation specified in Clauses 1, 2 and 3 of this Article;
b) Forcible revocation or forcible surrender of domain names due to the commission of the acts of violation specified in Clause 3 of this Article;
c) Forcible correction of information in cyberspace containing fabricated or untruthful content aimed at causing confusion among the public or affecting social order, for the acts specified in Clauses 1, 2 and 3 of this Article;
d) Forcible refund or forcible disgorgement of illicit profits obtained from committing the acts of violation specified in Clauses 1, 2, and 3 of this Article.
Article 12. Violations of regulations on responsibilities for preventing and handling information in cyberspace containing law-violating content
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the violations:
a) Managing, operating or having the ability to control websites, social networks or accounts, groups, or dedicated pages on social networks but failing to deploy measures to prevent, detect, block, remove or delete information containing law-violating content;
b) Failing to deploy managerial or technical measures to prevent, detect, block, remove or delete information containing law-violating content.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the violations:
a) Managing, operating or having the ability to control websites, social networks or accounts, groups, or dedicated pages on social networks but failing to deploy measures to prevent, detect, block, remove or delete information containing law-violating content upon request of competent functional agencies;
b) Failing to provide information or documents on law-violating acts posted or shared on information systems, products, or services by organizations or individuals upon request of competent functional agencies.
3. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to arrange connection ports or necessary technical conditions for the task of assuring information security and cybersecurity at the request of the Ministry of Public Security;
b) Failing to prevent or stop providing telecommunications and Internet services in case of riots, rebellions, or use of telecommunications services to infringe upon national security or oppose the State of the Socialist Republic of Vietnam;
c) Failing to deploy or maintain technical measures at the request of competent state agencies to block access to law-violating websites, applications, platforms, or domain names, allowing users in Vietnam to continue accessing or using services, platforms, or domain names subject to blocking;
d) Failing to invest in, update and upgrade technical systems and network technologies to meet state management requirements on cybersecurity and data security; failing to proactively review and update technological solutions and technical plans to ensure effective blocking and to minimize the capability to access law-violating websites, applications, platforms, or domain names at the request of competent state agencies;
dd) Failing to comply with decisions on mobilizing part or whole of the Internet infrastructure in case of handling dangerous cybersecurity situations;
e) Failing to provide information serving the protection of national security at the request of the specialized cybersecurity protection force under the Ministry of Public Security.
4. Additional sanction(s): Suspension of operations from 01 month to 03 months for enterprises committing the violations specified in Clause 2, Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible removal or deletion of information in cyberspace containing law-violating content, for the acts of violation specified in Clauses 1, 2 and 3 of this Article;
b) Forcible revocation or forcible surrender of domain names for committing the acts of violation specified at Point b, Clause 2 of this Article.
Article 13. Violations of regulations on protection of information being personal secrets, working secrets, business secrets, family secrets and private life in cyberspace
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Posting information being working secrets, business secrets, personal secrets, family secrets and private life in cyberspace that affects the honor, prestige, dignity, lawful rights and interests of agencies, organizations and individuals, which is not serious enough for penal liability examination;
b) Failing to comply with requests of specialized cybersecurity protection forces regarding the prevention and combat of cyber espionage and the protection of information classified as state secrets in accordance with law;
c) Unlawfully altering, removing or disabling technical measures established and used to protect information classified as state secrets.
2. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means for the acts of violation specified at Points a and c, Clause 1 of this Article;
b) Suspension of operations for a definite term of between 01 month and 03 months for the acts of violation specified at Points b and c, Clause 1 of this Article.
3. Remedial measure(s):
a) Forcible formulation and application of state secret protection measures to prevent and combat the disclosure or loss of state secrets through technical channels, for the acts of violation specified in Clause 1 of this Article;
b) Forcible destruction of products, equipment, services or software causing the disclosure or loss of state secrets, or failing to assure cybersecurity, for the acts of violation specified at Points a and c, Clause 1 of this Article; in case they are related to documents or objects containing state secrets, the Law on Protection of State Secrets shall apply;
c) Forcible re-inspection of cybersecurity for products, equipment, services and software serving the protection of state secrets, for the acts of violation specified at Point a, Clause 1 of this Article;
d) Forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been illegally sold, dispersed or destroyed for the acts specified at Point a, Clause 1 of this Article.
Article 14. Violations of regulations on preventing and combating acts of using cyberspace, information technology or electronic means to infringe upon economic management order, which are not serious enough for penal liability examination
1. A fine from VND 5,000,000 to VND 10,000,000 shall be imposed for: selling, leasing, lending or gifting their digital account information, including: bank accounts, bank cards, e-wallets, mobile money accounts, securities accounts, trading accounts, insurance accounts, tax accounts, and other digital accounts having financial transaction functions.
2. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following violations:
a) Using false identities, forged documents or records, or unlawfully using information of others to establish enterprises, or to set up or register bank accounts, bank cards, e-wallets, mobile money accounts, securities accounts, trading accounts, insurance accounts, tax accounts, and other digital accounts having financial transaction functions, which is not serious enough for penal liability examination;
b) Using digital accounts having financial transaction functions as intermediary tools to trade, receive, transfer money, and make payments to other beneficiaries, unless otherwise licensed by competent agencies;
c) Renting, leasing, providing or using the services of receiving messages, calls, or other forms to authenticate information or identify digital accounts having financial transaction functions, unless otherwise licensed by competent agencies;
d) Using digital accounts to unlawfully buy, sell, trade or convert foreign currencies.
3. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following violations:
a) Establishing or using websites, digital accounts or electronic interfaces that cause confusion about the information-providing subjects of agencies, organizations or individuals;
b) Providing, sharing or using digital content without ensuring regulations on copyright, related rights and intellectual property in cyberspace, which is not serious enough for penal liability examination;
c) Using authentication information, login information or access rights to digital accounts in contravention of law;
d) Establishing, operating, providing services or supporting activities for trading floors, applications, or digital platforms that fail to ensure conditions for service provision in accordance with law;
dd) Providing information, advertising or conducting business activities for goods in contravention of law on commerce, quality, origin and conditions for goods circulation, which is not serious enough for penal liability examination.
4. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following violations:
a) Providing, establishing, or operating information systems, websites, applications, or trading floors for peer-to-peer lending, virtual currencies, virtual assets, and similar forms without licenses or approvals of competent agencies;
b) Providing, establishing, or operating information systems, websites, applications, or trading floors for foreign currencies, metals, oil, gemstones, and similar forms without licenses or approvals of competent agencies;
c) Providing, transmitting or disseminating messages, calls, or emails using names or identification information of agencies or organizations in contravention of law.
5. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Using cyberspace to interfere with, alter, or falsify transaction information or information on money-receiving accounts in contravention of law;
b) Using cyberspace to mobilize capital, receive or distribute money sources in a manner that fails to ensure transparency or is in contravention of law;
c) Organizing or carrying out multi-level marketing business activities in cyberspace that fail to meet operating conditions in accordance with law;
d) Providing, sharing or carrying out securities trading activities in cyberspace in contravention of law;
dd) Using cyberspace to campaign for, receive, manage or distribute community support contributions without ensuring publicity and transparency in accordance with law;
e) Using information of digital accounts, social network accounts, or electronic accounts of organizations or individuals ultra vires or without the consent of account holders.
6. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for any of the following violations:
a) Opening digital accounts without following the order and procedures prescribed by law, or maintaining digital accounts having financial transaction functions using fake identification information or information not found in the national population database or the database on organizations and enterprises, including: bank accounts, bank cards, e-wallets, mobile money accounts, securities accounts, trading accounts, and other types of digital accounts having financial transaction functions;
b) Opening digital accounts for persons on the list of those banned from opening and using digital accounts.
7. Additional sanction(s): Confiscation of material evidence and means of administrative violations, money in digital accounts for one of the acts of violation specified in Clause 1 of this Article.
8. Remedial measure(s):
a) Forcible removal or deletion of information for the acts of violation specified at Point b, Point dd, Clause 3 of this Article;
b) Forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been illegally sold, dispersed or destroyed as specified in Clauses 1 and 2, Clause 3, Clause 4, Clause 5, Clause 6 of this Article.
Article 15. Violations of regulations on preventing and combating acts of using cyberspace, information technology or electronic means to infringe upon social order, which are not serious enough for penal liability examination
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Posting or sharing promotional information on prize-winning games in cyberspace in contravention of law, which is not serious enough for penal liability examination;
b) Using information or identification forms of agencies or organizations in contacting or exchanging information in cyberspace without ensuring authenticity in accordance with law;
c) Posting or sharing information related to belief or spiritual activities in contravention of law on social network platforms or messaging applications;
d) Posting or sharing information cheering or encouraging the commission of illegal racing in cyberspace, which is not serious enough for penal liability examination;
dd) Posting or promoting information on wildlife in contravention of law on wildlife protection in cyberspace;
e) Posting or sharing images, videos, audio, or articles containing pornographic or depraved content on social network platforms, messaging applications, or websites, which is not serious enough for penal liability examination;
g) Livestreaming content, images, or acts unconformable with cultural standards or social morality in cyberspace;
h) Establishing websites or digital platforms to post information on service provision in contravention of law;
i) Posting or sharing cinematic works, television programs, videos, music, or other digital content without satisfying regulations on copyright and related rights;
k) Livestreaming or sharing content of sports events, art performances, or cinematic works from sources not yet permitted for dissemination as specified by regulations;
l) Copying, providing, or distributing software or mobile applications without ensuring conditions for use in accordance with regulations on intellectual property rights;
m) Using artificial intelligence (AI) technology to create digital products with similar content or exploiting original works without ensuring requirements on intellectual property rights in accordance with law;
n) Producing, providing or sharing software or supporting tools to interfere with or alter the copyright management mechanisms of software or operating systems in contravention of law;
o) Providing equipment or software supporting the reception or decoding of television signals that fail to meet conditions as specified by law;
p) Instructing or sharing methods of accessing websites, applications, or digital platforms whose access scope has been restricted as specified by law.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Establishing or operating websites, social networks, information systems, or applications providing prize-winning games or programs in cyberspace that fail to meet conditions as specified by law;
b) Providing information technology services, hardware, software, domain names, applications, or digital platforms containing content that fails to ensure regulations on copyright, related rights, and industrial property, which is not serious enough for penal liability examination;
c) Establishing websites, social networks, dedicated pages on social networks, information systems, or applications containing content advertising prostitution, pornography, or depravity, which is not serious enough for penal liability examination;
d) Organizing filming or online broadcasting of images containing pornographic or depraved content on information systems, websites, or social networks, which is not serious enough for penal liability examination;
dd) Providing information technology services, hardware, software, or other services to support or serve the filming or online broadcasting of images containing pornographic or depraved content, which is not serious enough for penal liability examination;
e) Failing to censor, block or eliminate pornographic or depraved content, social vices, and other law-violating acts on information systems, websites, or social networks, which is not serious enough for penal liability examination;
g) Posting or sharing information on goods, substances, or products on the lists of those banned from business or circulation in accordance with law in cyberspace, which is not serious enough for penal liability examination;
h) Posting or sharing information on buying and selling human tissues or body parts in contravention of law in cyberspace, which is not serious enough for penal liability examination;
i) Posting or sharing information instructing or encouraging the commission of acts in contravention of law;
k) Posting promotional information for lending services in contravention of law on interest rates and lending activities in cyberspace;
l) Posting information on buying and selling weapons, explosives, supporting tools, uniforms, rank badges, insignias, or identity numbers of the People’s Public Security or the Vietnam People’s Army in cyberspace;
m) Providing online payment services for applications or websites engaging in pornographic, depraved, or prostitution content or activities, which is not serious enough for penal liability examination.
3. Additional sanction(s): Confiscation of material evidence and means of administrative violations for the acts of violation specified in Clauses 1 and 2 of this Article.
4. Remedial measure(s):
a) Forcible removal or deletion of information for the acts of violation specified in Clause 1 of this Article;
b) Forcible recall or destruction of products or equipment, or cessation of provision of services harming cybersecurity, or failing to meet conditions, standards or technical regulations prescribed by law, or having no license or failing to act in accordance with the license, for the act of violation specified in Clause 2 of this Article;
c) Forcible elimination of security-harming features or components of programs, products, equipment, services or software, for the act of violation specified in Clause 2 of this Article;
d) Forcible refund or forcible disgorgement of illicit profits earned through the commission of the acts of violation specified in Clauses 1 and 2 of this Article;
dd) Forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been illegally sold, dispersed or destroyed, for the acts specified in Clauses 1 and 2 of this Article.
Section 2
VIOLATIONS AGAINST REGULATIONS
ON PREVENTION AND COMBAT OF CYBERATTACKS
Article 16. Violations of regulations on prevention and combat of cyberattacks
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Providing, sharing or using informatics programs affecting the safety and stable operation of information systems, computer networks, and electronic means;
b) Introducing programs, command codes or applications into information systems, affecting the management, storage, and exploitation of data of organizations or individuals;
c) Interfering with or impacting to affect the stable operation or data transmission capability of telecommunications networks, the Internet, computer networks, or electronic means in contravention of law;
d) Accessing, impacting or interfering with data stored or transmitted via telecommunications networks, the Internet, computer networks, or electronic means ultra vires or in contravention of law, which is not serious enough for penal liability examination;
dd) Exploiting, using, providing or sharing information or data; detecting, testing or using technical weaknesses or vulnerabilities of information systems in contravention of regulations on cybersecurity and cyber safety;
e) Committing acts affecting the normal operation of telecommunications networks, the Internet, computer networks, or electronic means;
g) Failing to fully and promptly provide information and documents related to cyberattacks at the request of competent agencies in accordance with law.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for the following acts:
a) Producing, buying, selling, exchanging, or gifting informatics programs or information technology software that harm computer networks, telecommunications networks, or electronic means, which is not serious enough for penal liability examination;
b) Failing to coordinate with specialized cybersecurity protection forces in applying measures to block or eliminate acts of cyberattack;
c) Unlawfully providing cyberattack services, which is not serious enough for penal liability examination.
3. Additional sanction(s):
a) Confiscation of material evidence and means of administrative violations for the acts of violation specified in Clauses 1 and 2 of this Article;
b) Expulsion from the territory of the Socialist Republic of Vietnam for foreigners committing the acts of violation specified in Clause 1 and Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible recall of products and equipment, and cessation of the provision of services that harm cybersecurity, for the acts of violation specified in Clause 1 and Clause 2 of this Article;
b) Forcible destruction or irrecoverable deletion of data unlawfully appropriated, bought, sold or exchanged, for the acts of violation specified at Points a and b, Clause 1, and Point a, Clause 2 of this Article;
c) Forcible surrender of IP addresses, ASNs, domain names and digital accounts, for the acts of violation specified at Points a, b, c, d, dd and e, Clause 1, and Points a and c, Clause 2 of this Article;
d) Forcible disgorgement of illicit profits obtained for the acts of violation specified at Point dd, Clause 1, Point a, Clause 2 of this Article;
dd) Forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been illegally sold, dispersed or destroyed, for the acts specified in Clauses 1 and 2 of this Article.
Article 17. Violations of regulations on prevention and combat of cyber-terrorism
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Sharing, commenting on or spreading information containing content supporting or promoting law-violating activities regarding terrorism in cyberspace, which is not serious enough for penal liability examination;
b) Providing or sharing information containing content calling for, campaigning for, or instructing the commission of acts in violation of law on cybersecurity and safety, which is not serious enough for penal liability examination;
c) Posting or sharing information containing content cheering violent or extremist acts or causing negative impacts on security, order, and social safety, which is not serious enough for penal liability examination.
2. A fine from VND 20,000,000 to VND 50,000,000 shall be imposed for the following acts:
a) Supporting or creating conditions for the use of cyberspace to provide, receive, or mobilize financial support sources in contravention of law on counter-terrorism, which is not serious enough for penal liability examination;
b) Supporting organizations or individuals in using cyberspace to restrict, evade, or reduce the effectiveness of cybersecurity and safety assurance measures of competent agencies, which is not serious enough for penal liability examination;
c) Calling for or mobilizing financial sources in contravention of law on counter-terrorism in cyberspace, which is not serious enough for penal liability examination;
d) Providing or sharing inaccurate information related to terrorism or terrorist financing activities, or committing acts affecting the counter-terrorism operations of competent agencies, which is not serious enough for penal liability examination.
3. Additional sanction(s):
a) Confiscation of material evidence and means of administrative violations for the acts of violation specified in Clauses 1 and 2 of this Article;
b) Expulsion from the territory of the Socialist Republic of Vietnam for foreigners committing the acts of violation specified in Clauses 1 and 2 of this Article.
4. Remedial measure(s):
a) Forcible removal or deletion of programmes or software, recall or destruction of products or equipment, or cessation of provision of services harming cybersecurity for the acts of violation specified in Clauses 1 and 2 of this Article;
b) Forcible bringing out of the territory of the Socialist Republic of Vietnam or forcible re-export of goods, articles or means, for the acts of violation specified in Clauses 1 and 2 of this Article;
c) Forcible destruction or irrecoverable deletion of data unlawfully appropriated, bought, sold or exchanged, for the acts of violation specified in Clauses 1 and 2 of this Article;
d) Forcible deletion and forcible correction of untruthful or misleading information for the violations specified in Clauses 1 and 2 of this Article;
dd) Forcible recall of products, equipment, services or software failing to ensure quality, for the acts of violation specified in Clauses 1 and 2 of this Article;
e) Forcible revocation of subscriber numbers, prefixes, telecommunications number blocks; Internet resources, domain names, Internet protocol (IP) addresses, autonomous system numbers (ASNs); management codes or service provision numbers, for the acts of violation specified in Clauses 1 and 2 of this Article;
g) Forcible surrender of IP addresses, ASNs, domain names and digital accounts, for the acts of violation specified in Clauses 1 and 2 of this Article;
h) Forcible disgorgement of illicit profits obtained for the acts of violation specified in Clauses 1 and 2 of this Article.
Article 18. Violations of regulations on prevention and handling of dangerous cybersecurity situations
1. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to coordinate in blocking, removing, or deleting information containing inciting content in cyberspace that pose a risk of causing riots, security disturbances, or terrorism, within 24 hours at the latest from the time of receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security;
b) Failing to implement or delaying coordination for more than 24 hours upon receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security regarding coordination in deploying technical and professional solutions to prevent, detect, and handle dangerous cybersecurity situations;
c) Failing to implement or delaying coordination for more than 24 hours upon receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security regarding coordination with specialized cybersecurity protection forces in preventing, detecting, and handling dangerous cybersecurity situations;
d) Failing to implement or delaying coordination for more than 24 hours upon receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security regarding the deployment of plans for preventing and responding to cybersecurity emergencies, blocking, eliminating, or mitigating damage caused by dangerous cybersecurity situations;
dd) Failing to implement or delaying coordination for more than 24 hours upon receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security regarding coordination in collecting relevant information; and conducting continuous monitoring and supervision of dangerous cybersecurity situations;
e) Failing to implement or delaying coordination for more than 24 hours upon receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security regarding the cessation of provision of network information in specific areas or disconnection of international network gateways concerning dangerous cybersecurity situations;
g) Failing to allocate forces and means to prevent and eliminate dangerous cybersecurity situations.
2. Remedial measure(s): Forcible application of necessary technical and management measures to prevent and remedy the risks of cybersecurity and cyber safety breaches caused by the act of violation specified in Clause 1 of this Article.
Section 3
VIOLATIONS OF REGULATIONS ON THE IMPLEMENTATION OF CYBERSECURITY PROTECTION ACTIVITIES
Article 19. Violations of regulations on the unlawful provision or use of cyberinformation
1. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Unlawfully accessing others’ networks or digital devices to seize control of digital devices or alter or delete information stored on digital devices or alter setup parameters of digital devices or collect others’ information, which is not serious enough for penal liability examination;
b) Intruding into, modifying, or deleting information of other organizations or individuals in the network environment;
c) Obstructing service provision activities of information systems;
d) Preventing access to information of other organizations or individuals in the network environment, unless otherwise permitted by law;
dd) Compromising the safety and confidentiality of information of other organizations or individuals that is exchanged, transmitted, or stored in the network environment.
2. Additional sanction(s): Expulsion from the territory of the Socialist Republic of Vietnam for foreigners committing the acts of violation specified in Clause 1 of this Article.
Article 20. Violations of regulations on the management of sending information on the network
1. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Sending commercial information to the electronic addresses of recipients without their consent or when the recipients have refused;
b) Having no method for information recipients to refuse the receipt of information.
2. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Spoofing the origin of sending information on the network;
b) Failing to provide necessary technical and professional conditions upon request of competent state agencies.
3. A fine from VND 50,000,000 to VND 75,000,000 shall be imposed for failing to apply preventive measures or failing to handle upon receiving notices from organizations or individuals regarding the transmission of information in violation of law.
4. Remedial measure(s): Forcible elimination of law-violating information transmitted or disseminated on the network, for the act of violation specified at Point a, Clause 1 of this Article.
Article 21. Violations of regulations on response to cybersecurity incidents
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Failing to disclose information about incident-receiving addresses on websites or portals;
b) Failing to declare dossiers, provide or update information on incident response points of contact, cybersecurity technical personnel, and incident response within the scope of management to the specialized cybersecurity protection force under the Ministry of Public Security;
c) Updating information on incident response points of contact outside the prescribed time limit upon any changes;
d) Violating the operating regulation of the national cybersecurity incident response network or failing to comply with coordination requests of the coordinating agency.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Failing to report to the specialized cybersecurity protection force under the Ministry of Public Security upon receiving information or detecting incidents regarding information systems within the scope of management;
b) Failing to deploy incident response activities and report in accordance with regulations after detecting incidents or receiving requests from specialized cybersecurity protection forces.
3. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to consolidate and report the developments of incidents to the specialized cybersecurity protection force under the Ministry of Public Security upon request;
b) Failing to establish or designate a specialized cybersecurity incident response unit or failing to establish an Incident Response Team;
c) Failing to record, receive notifications, or report cybersecurity incidents in accordance with proper processes;
d) Failing to develop cybersecurity incident response plans;
dd) Incompletely implementing incident response coordination requests of the Ministry of Public Security.
4. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Failing to assign points of contact to carry out incident response coordination activities or failing to participate in the national cybersecurity incident response network;
b) Failing to implement incident response coordination requests of the specialized cybersecurity protection force under the Ministry of Public Security;
c) Failing to arrange premises, connection ports, and necessary technical conditions at the request of the Ministry of Public Security;
d) Failing to organize incident response activities within the sectors, localities, and scopes under their management;
dd) Failing to coordinate with the specialized cybersecurity protection force under the Ministry of Public Security, service providers, and functional agencies in recovering several activities, data, or necessary connections to minimize damage to information systems or adverse impacts on society;
e) Failing to coordinate during the time when incidents have not been thoroughly remedied;
g) Failing to handle consequences caused by their information system incidents affecting citizens, other agencies, or organizations;
h) Failing to store or provide information related to subscriber IP addresses, servers, IoT devices, log files, and DNS resolution service logs within the scope of management;
i) Failing to establish environments for installing monitoring and sampling equipment and providing network data streams;
k) Failing to establish 24/7 standing points of contact or failing to allocate human and material resources ready to coordinate and deploy solutions to respond to and remedy the consequences of incidents in case the sources of attacks are determined to originate from subscribers under their enterprises or upon request of the Ministry of Public Security.
5. Remedial measure(s):
a) Forcible restoration of the original state of the information system for the acts of violation specified in Clauses 1, 2, 3, 4 of this Article;
b) Forcible revocation or elimination of data, information or network connections causing cybersecurity breaches in case of the acts of violation specified in Clauses 1, 2, 3 and 4 of this Article.
Article 22. Violations of regulations on prevention, detection, stopping and handling of malicious software
1. A fine from VND 15,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Having no measures to manage, prevent, detect, or block the dissemination of malicious software;
b) Failing to report to competent state agencies on malicious software filtering systems during the transmission, receipt, and storage of information on their systems in accordance with law.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Having no malicious software filtering systems during the transmission, receipt, or storage of information on the systems of enterprises providing email, information transmission and storage services;
b) Failing to prevent, block or handle the dissemination of malicious software in accordance with guidelines and requests of competent state agencies;
c) Failing to deploy professional technical systems to prevent, detect, block, and promptly handle malicious software.
3. Additional sanction(s): Deprivation of the right to use licenses for provision of social network services for a definite term of between 01 month and 03 months for the violations specified in Clauses 1 and 2 of this Article in case of recidivism.
4. Remedial measure(s):
a) Forcible restoration of the original state of the information system affected by malicious software, for the acts specified in Clauses 1 and 2 of this Article;
b) Forcible implementation of measures to overcome the state of cybersecurity insecurity for the acts of violation specified in Clauses 1 and 2 of this Article;
c) Forcible elimination or destruction of malicious software, malicious codes or malicious data unlawfully disseminated, for the acts of violation specified in Clauses 1 and 2 of this Article.
Article 23. Violations of regulations on safety supervision and protection measures for information systems
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for the following acts:
a) Failing to promulgate regulations on cybersecurity assurance in the design, construction, management, operation, use, upgrade and cancellation of information systems;
b) Failing to prepare dossiers proposing information system levels for level 3 to level 5;
c) Putting information systems into operation without having their cybersecurity levels approved for level 3 to level 5;
d) Incompletely deploying cybersecurity assurance measures corresponding to cybersecurity dossiers whose levels have been approved for level 3 to level 5.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to inspect and supervise compliance with regulations on cybersecurity assurance, keeping system logs as specified by regulations, or failing to assess the effectiveness of the applied managerial and technical measures;
b) Failing to coordinate with information system managers in monitoring information system safety at the request of competent state agencies;
c) Failing to organize the implementation, urging, inspection, and supervision of cybersecurity assurance tasks;
d) Obstructing or failing to exchange system monitoring information and data between the units hired by information system managers and the specialized cybersecurity assurance forces.
3. Additional sanction(s): Deprivation of the right to use the License to establish an aggregate information website for a definite term of between 01 month and 06 months, for the acts specified in Clauses 1 and 2 of this Article in case of recidivism.
4. Remedial measure(s):
a) Forcible restoration of the original state of the information system for the acts specified in Clauses 1 and 2 of this Article;
b) Forcible implementation of measures to overcome the state of cybersecurity insecurity or risk of cybersecurity insecurity for the acts specified in Clauses 1 and 2 of this Article;
c) Forcible elimination of cybersecurity-violating elements in the process of designing, building, managing, operating, using, upgrading or destroying information systems, for the acts specified in Clauses 1 and 2 of this Article.
Article 24. Violations of regulations on ensuring information system security by level
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for failing to prepare dossiers for level proposal or failing to organize the appraisal and approval of dossiers for level proposal as specified by regulations.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for failing to expand or upgrade national important information systems before putting them into operation and exploitation.
3. Additional sanction(s): Deprivation of the right to use the License to establish an aggregate information website for a definite term of between 01 month and 03 months, for the acts specified in Clauses 1 and 2 of this Article in case of recidivism.
4. Remedial measure(s):
a) Forcible restoration of the original state of the information system for the acts specified in Clauses 1 and 2 of this Article;
b) Forcible implementation of measures to remedy the risk of cybersecurity breach or cybersecurity breach, for the acts specified in Clauses 1 and 2 of this Article;
c) Forcible removal of infringing elements regarding cybersecurity, for the acts specified in Clauses 1 and 2 of this Article.
Article 25. Violations of regulations on prevention of online information conflicts
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Failing to notify and incompletely providing information upon discovering signs or acts causing information conflicts on the network or upon discovering that information or information systems are compromised;
b) Failing to receive or handle information on information conflicts on the network to respond to incidents and block information conflicts on the network;
c) Failing to coordinate with professional agencies in accurately identifying the origins causing information conflicts on the network;
d) Failing to coordinate with professional agencies to eliminate information conflicts on the network.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Failing to filter and block information at the request of professional agencies or at the reasonable requests of the parties suffering from information conflicts on the network;
b) Failing to prevent sabotaging information originating from its own information systems or failing to cooperate in identifying sources, repelling and overcoming consequences of cyberattacks from information systems of domestic and foreign organizations and individuals;
c) Failing to develop plans to remedy information conflicts on the network within the scope of management;
d) Failing to consolidate and report the results of remedying information conflicts on the network to professional agencies;
dd) Failing to coordinate in remedying information conflicts on the network.
3. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for failing to remedy information conflicts on the network within the scope of management.
4. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for failing to cooperate in identifying the sources or failing to remedy the consequences of information conflicts on the network.
5. Remedial measure(s):
a) Forcible implementation of measures for preventing, blocking, filtering, eliminating and remedying information conflicts on the network for the acts of violation specified in Clauses 2, 3 and 4 of this Article;
b) Forcible restoration of the normal operation of the information system, for the acts specified in Clauses 1, 2, 3 and 4 of this Article.
Article 26. Violations of regulations on cybersecurity protection for information systems critical to national security
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following violations of regulations on the establishment of information systems critical to national security:
a) Failing to conduct or incompletely conducting reviews and establishment of information systems critical to national security in respect of information systems within the scope of management in accordance with regulations;
b) Failing to review and establish information systems critical to national security in respect of information systems within the scope of management after receiving notifications from specialized cybersecurity protection forces;
c) Failing to send dossiers of national important information systems already approved by the Prime Minister to the Ministry of Public Security, the Ministry of National Defence, or the Government Cipher Committee according to management decentralization for establishing the List of information systems critical to national security;
d) Failing to transfer to the Ministry of Public Security, the Ministry of National Defence, or the Government Cipher Committee according to management decentralization the dossiers of cybersecurity level appraisal which are deemed to have sufficient grounds for inclusion in the List of information systems critical to national security, so as to appraise the dossiers requesting the inclusion of information systems in the List of information systems critical to national security.
2. A fine from VND 30,000,000 to VND 40,000,000 shall be imposed for any of the following violations of regulations on cybersecurity appraisal:
a) Failing to conduct cybersecurity appraisals as a basis for deciding to build information systems satisfying the criteria for information systems critical to national security;
b) Failing to conduct cybersecurity appraisals as a basis for upgrading information systems satisfying the criteria for information systems critical to national security.
3. A fine from VND 40,000,000 to VND 50,000,000 shall be imposed for any of the following violations of regulations on cybersecurity inspection and cybersecurity monitoring:
a) Failing to assess cybersecurity conditions for information systems prior to putting them into operation and use;
b) Failing to develop regulations, processes, and plans for cybersecurity assurance; failing to arrange system operation and administration personnel;
c) Failing to develop plans to respond to and remedy cybersecurity incidents for information systems in accordance with law;
d) Failing to develop technical measures for cybersecurity monitoring and protection, and system protection measures;
dd) Failing to formulate measures to protect state secrets, and prevent and combat disclosure and loss of state secrets via technical channels;
e) Having no measures to assure physical security as specified by the law;
g) Managers of information systems critical to national security failing to conduct cybersecurity inspections and cybersecurity monitoring of information systems within their scope of management in accordance with law;
h) Failing to coordinate with specialized cybersecurity protection forces during cybersecurity inspections and cybersecurity monitoring in accordance with law;
i) Failing to deploy or participate in incident response and remediation activities when cybersecurity incidents occur or upon request of the presiding and coordinating forces;
k) Failing to promptly report to specialized cybersecurity protection forces on serious cybersecurity incidents regarding information systems within their scope of management;
l) Failing to implement measures according to the guidelines of specialized cybersecurity protection forces and other appropriate measures to block, handle, and remedy consequences within 24 hours from the time of receiving notifications.
4. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Failing to conduct annual periodic cybersecurity inspections;
b) Failing to conduct cybersecurity inspections and cybersecurity monitoring upon state management requests on cybersecurity;
c) Failing to notify cybersecurity inspection results in writing to specialized cybersecurity protection forces as specified by regulations;
d) Failing to remedy security weaknesses and vulnerabilities as recommended by specialized cybersecurity protection forces as specified by regulations after the time limit expires;
dd) Violating regulations, procedures and plans on cybersecurity assurance for information systems critical to national security;
e) Violations of regulations on personnel operating and managing systems, and protecting cybersecurity;
g) Violations of regulations on conditions for assuring cybersecurity for equipment, hardware and software as system components;
h) Violations of regulations on technical measures and physical security to supervise and protect cybersecurity.
5. Remedial measure(s):
a) Forcible implementation of cybersecurity assurance measures for information systems critical to national security, for the acts of violation specified in Clauses 1, 2, 3 and 4 of this Article;
b) Forcible correction of results of cybersecurity appraisal, assessment, inspection or certification, for the acts specified in Clauses 2, 3 and 4 of this Article.
Article 27. Violations of regulations on cybersecurity protection for information systems not included in the List of information systems critical to national security
1. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to coordinate with specialized cybersecurity protection forces in implementing cybersecurity protection measures upon discovering that information systems within the scope of management are related to acts in violation of law on cybersecurity;
b) Failing to notify specialized cybersecurity protection forces upon discovering law-violating acts regarding cybersecurity in respect of information systems of state agencies, central and local political organizations;
c) Failing to implement or incompletely implementing requests of specialized cybersecurity protection forces regarding the remediation of security weaknesses and vulnerabilities and law-violating acts regarding cybersecurity.
2. Remedial measure(s): Forcible implementation of cybersecurity assurance measures in accordance with regulations, for the acts of violation specified in Clause 1 of this Article.
Article 28. Violations of regulations on cybersecurity protection for national cyberspace infrastructure and international network connection gateways
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to coordinate with specialized cybersecurity protection forces in cybersecurity monitoring of the national cyberspace infrastructure and international network gateways;
b) Failing to coordinate or provide information and data serving the investigation and handling of law-violating acts upon written requests;
c) Failing to arrange premises, connection ports, conditions, and necessary professional and technical measures for specialized cybersecurity protection forces to perform cybersecurity protection tasks in accordance with law;
d) Failing to deploy cybersecurity protection measures; failing to implement cybersecurity protection requests of specialized cybersecurity protection forces.
2. Remedial measure(s): Forcible implementation of cybersecurity assurance measures in accordance with regulations, for the acts of violation specified in Clause 1 of this Article.
Article 29. Violations of regulations on assurance of cyberinformation security
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to authenticate information when users register digital accounts;
b) Failing to keep users’ information and accounts confidential.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Failing to prevent the sharing of information, delete information, or remove services and applications containing content violating the regulations of the Law on Cybersecurity within 24 hours from the time of receiving requests from the specialized cybersecurity protection force under the Ministry of Public Security, and save system logs to serve the verification, investigation and handling of violations against law on cybersecurity for a period of time as specified by the law; in urgent cases threatening to infringe upon national security, requirements for preventing and deleting information must be satisfied within 06 hours;
b) Providing services on telecommunications networks, the Internet, and value-added services for organizations and individuals that post information containing content specified in Clauses 1 and 2, Clause 3, Article 13, and Clauses 1 and 2, Article 14 of the Law on Cybersecurity in cyberspace; failing to stop providing the above-mentioned services upon requests of the specialized cybersecurity protection force or competent functional agencies;
c) Failing to apply data protection measures in accordance with law and store such data in Vietnam for a period prescribed by the Government when collecting, exploiting, analyzing, and processing personal information data, data on relationships of service users, and data created by service users in Vietnam;
d) Foreign enterprises providing services on telecommunications networks or the Internet, and value-added services in cyberspace in Vietnam failing to establish branches or representative offices in Vietnam.
3. Remedial measure(s):
a) Forcible implementation of measures to assure cyberinformation security as specified for the acts of violation specified in Clauses 1 and 2 of this Article;
b) Forcible cessation of provision of telecommunications or Internet services, or forcible cessation of telecommunications or Internet connections in Vietnam, for the acts of violation specified at Point a, Clause 2 of this Article;
c) Forcible deletion from digital application stores intended for the Vietnamese market, for the acts of violation specified at Point a, Clause 2 of this Article.
Article 30. Violations of regulations on coordination with specialized cybersecurity protection forces in investigating and handling law-violating acts
1. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to provide or delaying the provision of user information for more than 24 hours to the specialized cybersecurity protection force under the Ministry of Public Security without a plausible reason upon receiving written requests for serving the investigation and handling of law-violating acts regarding cybersecurity;
b) Failing to implement requests of the specialized cybersecurity protection force under the Ministry of Public Security regarding the management and provision of Internet services to organizations or individuals committing acts of violation specified in Clauses 1, 2 and 3, Article 13 of the Law on Cybersecurity;
c) Failing to deploy managerial measures to prevent, detect, block, remove or delete information containing content specified in Clauses 1, 2 and 3, Article 13 of the Law on Cybersecurity on information systems within the scope of management upon request of specialized cybersecurity protection forces.
2. Remedial measure(s): Forcible implementation of measures to assure cyberinformation security as specified for the acts of violation specified in Clause 1 of this Article.
Article 31. Violations of regulations on child protection in cyberspace
1. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to implement measures to control information on systems or services provided by enterprises that cause harm to children, or infringe upon children and children’s rights;
b) Failing to prevent the sharing of, and delete, information containing content that causes harm to children, or infringe upon children and children’s rights;
c) Lacking warning labels for information technology products or services bearing content detrimental to children;
d) Failing to deploy appropriate measures in accordance with Vietnam’s law to ensure the detection, identification, and prevention of children directly creating or using service accounts with their own information;
dd) Failing to develop features according to legal guidelines to assist parents or lawful guardians of children in creating accounts for children under the information of such parents or lawful guardians in accordance with civil law, and in managing and monitoring the activities of children;
e) Failing to disable or destroy service accounts directly created or used by children which have been identified by functional agencies and requested in writing or via other appropriate unified forms of exchange.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Posting, disseminating, sharing, storing, exchanging, or using information, images, or audio containing pornographic, depraved, or violent content related to children;
b) Posting, sharing, or disseminating information insulting the honor, reputation, dignity, or affecting the health and normal psychophysiological development of children, which is not serious enough for penal liability examination.
3. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Failing to coordinate with competent agencies in ensuring children’s rights in cyberspace;
b) Inciting, enticing, luring, or forcing children to follow, share, or disseminate information containing content harmful to children, infringing upon children or children’s rights, or participating in other law-violating activities.
4. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means for the acts of violation specified in Clause 2 of this Article;
b) Expulsion from the territory of the Socialist Republic of Vietnam for foreigners committing the act of violation specified in Clause 2 of this Article.
5. Remedial measure(s):
a) Forcible implementation of measures to protect children in cyberspace as specified for the acts of violation specified in Clause 1 of this Article;
b) Forcible deletion and forcible correction of information for the acts of violation specified in Clause 2 of this Article;
c) Forcible revocation of subscriber numbers, prefixes, telecommunications number blocks; Internet resources, domain names, Internet protocol (IP) addresses, autonomous system numbers (ASNs); management codes and service provision numbers; forcible surrender of IP addresses, ASNs, domain names and digital accounts, for the acts of violation specified in Clause 2 of this Article;
d) Forcible disgorgement of illicit profits earned through the commission of administrative violations, or forcible disgorgement of an amount of money equivalent to the value of administrative violation material evidence or means which have been consumed, dispersed or destroyed, for the acts of violation specified in Clause 2 of this Article.
Article 32. Violations of regulations on the implementation of cybersecurity protection measures
1. A fine from VND 25,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Enterprises providing services on telecommunications networks or the Internet, and value-added services in cyberspace, and information system managers failing to delete unlawful information or untruthful information in cyberspace infringing upon national security, social order and safety, or the lawful rights and interests of agencies, organizations, or individuals as specified by regulations upon receiving requests from specialized cybersecurity protection forces;
b) Failing to suspend or request the cessation of operation of information systems, or revoke domain names upon receiving requests from specialized cybersecurity protection forces.
2. Additional sanction(s): Confiscation of administrative violation material evidence or means, for the acts of violation specified in Clause 1 of this Article.
3. Remedial measure(s):
a) Forcible implementation of cybersecurity assurance measures for the acts of violation specified in Clause 1 of this Article;
b) Forcible revocation of domain names for committing the acts of violation specified in Clause 1 of this Article.
Article 33. Violations of regulations on data storage and establishment of branches or representative offices in Vietnam
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to store data or incompletely storing national security-sensitive data in accordance with the Decree detailing a number of articles of the 2025 Law on Cybersecurity;
b) Failing to execute decisions requesting the storage of national security-sensitive data and the establishment of branches or representative offices in Vietnam;
c) Failing to ensure the duration of system log storage serving the investigation and handling of law-violating acts regarding cybersecurity as specified at Point b, Clause 2, Article 25 of the 2025 Law on Cybersecurity.
2. Additional sanction(s): Expulsion from the territory of the Socialist Republic of Vietnam for foreigners committing the act of violation specified in Clause 1 of this Article.
3. Remedial measure(s):
a) Forcible data storage and establishment of branches or representative offices in Vietnam;
b) Forcible cessation of provision of telecommunications or Internet services, or forcible cessation of telecommunications or Internet connections in Vietnam, for the acts of violation specified in Clause 1 of this Article.
Section 4
VIOLATIONS AGAINST REGULATIONS ON MANAGEMENT OF CYBERSECURITY PRODUCTS AND SERVICES
Article 34. Violations of regulations on authentication, identification and security of digital accounts
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Failing to authenticate or identify with lawful identity papers, or authenticating or identifying with unlawful identity papers for digital accounts subject to mandatory authentication and identification as specified by law;
b) Lacking warning measures for owners when their digital accounts incur monetary, financial, securities, or other transferable asset transactions in cyberspace via electronic or other methods in accordance with the disclosed internal regulations;
c) Failing to store device information, IP addresses, and login times of digital accounts for at least 90 days;
d) Failing to suspend transactions or freeze digital accounts serving monetary, financial, securities, or other transferable asset transactions in cyberspace upon discovering errors, mistakes, or information leaks, or upon receiving notifications or requests from specialized cybersecurity protection forces;
dd) Inaccurately identifying information of holders of digital accounts serving monetary, financial, securities, or other transferable asset transactions in cyberspace via electronic methods;
e) Failing to save account authentication traces, failing to keep access logs, or lacking abnormality detection mechanisms for digital accounts having financial transaction functions.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Using identity papers of others to authenticate digital accounts;
b) Using fake identity papers, creating, editing, or collaging images of identity papers, or using other deceitful tricks to authenticate digital accounts;
c) Using artificial intelligence (AI), Deepfake, or high-tech technical measures to forge biometric data (faces, voices) for unlawful account authentication.
3. Remedial measure(s): Forcible restoration of the original state for the acts of violation specified in Clauses 1 and 2 of this Article.
Article 35. Violations of regulations on business in cybersecurity
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Failing to manage dossiers and documents on technical and technological solutions of cybersecurity products;
b) Failing to compile, store and secure information of customers using cybersecurity products and services;
c) Failing to report to the Ministry of Public Security on the business, export, and import of cybersecurity products and services as specified by regulations.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to carry out procedures for exchanging licenses for doing business in cybersecurity products and services in case enterprises change their names, lawful representatives, or change or supplement the cybersecurity products and services they provide;
b) Failing to carry out procedures for reissuing licenses in case the licenses for doing business in cybersecurity products and services are lost or damaged;
c) Failing to refuse to provide cybersecurity products and services upon discovering organizations or individuals violating the law or violating the agreed commitments on use of cybersecurity products and services;
d) Failing to suspend or cease the provision of cybersecurity products and services at the request of competent state agencies;
dd) Failing to conduct conformity certification or declaration of conformity and to use conformity marks as specified by regulations prior to bringing cybersecurity products into market circulation;
e) Providing cybersecurity services inconsistently with the details stated in the licenses for doing business in cybersecurity products and services.
3. A fine from VND 50,000,000 to VND 75,000,000 shall be imposed for any of the following acts:
a) Failing to maintain any of the conditions for being granted licenses for doing business in cybersecurity products and services;
b) Failing to coordinate and create conditions for implementing professional measures upon request of competent state agencies.
4. A fine from VND 75,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Doing business in cybersecurity products and services without licenses;
b) Doing business in cybersecurity products and services that cause harm to national defense, security, and order, which is not serious enough for penal liability examination;
c) Providing inaccurate or fake information to be granted licenses for doing business in cybersecurity products and services.
5. Additional sanction(s): Deprivation of the right to use the license for business in cybersecurity products and services for a definite term of between 03 months and 06 months, for the acts of violation specified at Points a and e, Clause 2, and Point b, Clause 4 of this Article.
6. Remedial measure(s): Forcible disgorgement of illicit profits earned through the commission of the acts of violation specified at Points c, d, dd, e, Clause 2 and Clause 4 of this Article.
Article 36. Violations of regulations on import of cybersecurity products
1. A fine from VND 75,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Importing cybersecurity products on the list of imports subject to licensing without licenses;
b) Providing inaccurate or fake information to be granted licenses for importing cybersecurity products.
2. Additional sanction(s): Deprivation of the right to use the License to trade in cybersecurity products and services for a definite term of between 01 month and 03 months, for the act specified in Clause 1 of this Article.
3. Remedial measure(s):
a) Forcible disgorgement of illicit profits earned through the commission of the acts of violation specified in Clause 1 of this Article;
b) Forcible revocation of cybersecurity products for the acts of violation specified in Clause 1 of this Article.
Section 5
VIOLATIONS OF REGULATIONS ON ANTI-SPAM MESSAGES, SPAM EMAILS, AND SPAM CALLS
Article 37. Violations of regulations related to emails and messages providing information on products and services
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the violations:
a) Sending advertising emails or advertising messages to recipients without their consent;
b) Labeling advertising emails or advertising messages incorrectly or incompletely as specified by regulations;
c) Making advertising calls to users without their clear consent;
d) Making advertising calls to users who have disagreed to receive advertising calls in the customer consent collection dossiers;
dd) Sending advertising registration messages when users have refused or failed to reply to receive advertising registration messages;
e) Sending advertising messages to users who have refused to receive advertising messages.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Failing to label advertising emails and advertising messages as specified by regulations;
b) Failing to store information on advertising registration, refusal requests, and confirmations of refusal requests for advertising emails, advertising messages, and advertising calls for at least 01 year;
c) Sending advertising messages or making advertising calls without being granted brand names, or using phone numbers to send advertising messages or make advertising calls.
3. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to provide free mechanisms for users to receive and handle notifications on spam emails;
b) Lacking measures to avoid loss and block emails of service users;
c) Failing to coordinate with domestic and international Internet service providers, and domestic and foreign messaging service providers to restrict and block spam emails;
d) Failing to confirm the receipt of email or message refusal requests in terms of time limits, forms, or content in accordance with law;
dd) Lacking measures to limit the quantity, speed, and frequency of messaging;
e) Failing to limit the messaging frequency from each sending source, or failing to block messages posing risks of information insecurity as specified by regulations;
g) Concealing their own names or electronic addresses when sending emails or messages;
h) Failing to coordinate with telecommunications enterprises licensed to establish mobile telecommunications networks domestically and internationally to block spam messages;
i) Failing to implement measures to block spam messages at the request of competent state agencies;
k) Failing to block sender-spoofed spam messages before sending them to service users;
l) Failing to cease providing content services via messages at the requests of customers;
m) Incompletely implementing requests for coordination, blocking, and handling of spam messages;
n) Sending more than 03 advertising messages to 01 phone number, or 03 advertising emails to 01 electronic address, or making more than 01 advertising call to 01 phone number within 24 hours without other agreements with users;
o) Sending advertising messages outside the timeframe of 07:00 to 22:00 every day or making advertising calls outside the timeframe of 08:00 to 17:00 every day without agreements with users;
p) Lacking measures to inspect the clear prior consent of users when sending advertising messages or advertising emails, or making advertising calls;
q) Failing to provide tools for users to look up or store agreements on the registration or refusal of advertising calls and advertising registration messages to serve the inspection, examination, and settlement of complaints and denunciations;
r) Failing to instruct service users on methods to combat spam messages, spam calls, and spam emails;
s) Failing to implement reporting regimes, or implementing reporting regimes inconsistently with regulations, or untruthfully reporting on activities of using brand names and/or preventing and blocking spam messages and spam calls as specified by regulations.
4. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Failing to comply with requests for coordination, blocking, and handling of spam messages;
b) Failing to implement requests of the Ministry of Public Security for handling notifications and feedbacks on spam messages;
c) Failing to implement measures to restrict spam emails at the request of competent state agencies;
d) Failing to provide information and block the dissemination sources of spam emails or malicious software at the request of competent state agencies;
dd) Failing to implement measures to assess the status of spam messages on mobile telecommunications networks of messaging service providers according to the guidelines of the Ministry of Public Security;
e) Advertising calls lacking full information on the full names and positions of the callers; lacking names and addresses of the advertising units before providing advertising content, or lacking freight information in case of advertising for charged services.
5. A fine from VND 70,000,000 to VND 80,000,000 shall be imposed for any of the following acts:
a) Lacking complete forms of refusing to receive advertising emails or advertising messages;
b) Sending or disseminating spam emails, spam messages, or malicious software that cause less serious consequences; making spam calls;
c) Generating mass missed calls to entice users into calling or messaging content service provision numbers to gain illicit profits, provide information, or advertise;
d) Exploiting or using service numbers or telecommunications subscriber numbers for improper purposes;
dd) Opening outgoing directions for toll-free service numbers or premium-rate service numbers, or using them to send or receive messages;
e) Sending advertising registration messages in contravention of regulations of the Ministry of Public Security;
g) Sending any advertising registration messages to phone numbers on the Do-Not-Call Register;
h) Failing to store or incompletely storing advertising call log information (including audio records of advertising calls) as specified by regulations to serve the inspection, examination, supervision, and settlement of complaints and denunciations.
6. A fine from VND 80,000,000 to VND 90,000,000 shall be imposed for any of the following acts:
a) Advertising via emails, messages, or calls, or providing messaging and calling services via the Internet without systems for receiving and handling refusal requests of recipients;
b) Sending advertising messages or making advertising calls to phone numbers on the Do-Not-Call Register.
7. A fine from VND 90,000,000 to VND 100,000,000 shall be imposed for failing to block or recall subscriber numbers used to disseminate spam messages or spam calls.
8. Additional sanction(s):
a) Suspension of the provision of services to new customers for a term of between 01 month and 03 months, for the acts of violation specified at Points c, d, e and h, Clause 3, and Clauses 5 and 6 of this Article;
b) Suspension of the right to use brand names for a definite term of between 01 month and 03 months for the acts of violation specified at Points a and b, Clause 2, Points d, g, h, i and o, Clause 3, and Points a and b, Clause 5 of this Article.
9. Remedial measure(s):
a) Forcible refund or forcible disgorgement of illicit profits earned through the commission of the acts of violation specified at Points d and dd, Clause 5 of this Article;
b) Forcible revocation of telecommunications prefixes and number blocks due to the commission of the acts of violation specified at Points b and c, Clause 4, and Clause 5 of this Article;
c) Forcible revocation of telephone numbers for committing the acts of violation specified in Clause 1 of this Article.
Article 38. Violations of regulations on provision of email services, advertising messages, advertising calls, and content services via messages
1. A fine from VND 5,000,000 to VND 10,000,000 shall be imposed for any of the following acts:
a) Lacking websites using Vietnam’s national domain names when providing advertising email services, Internet messaging services, or content services via messages;
b) Providing incomplete or unclear information about services on websites prior to service provision, including: service names, corresponding command codes, service descriptions, usage methods, corresponding service charges, service cancellation instructions, customer support phone numbers, and commitments to agree to use services;
c) Failing to provide tools and applications allowing users to proactively block spam emails and send feedbacks on spam emails;
d) Lacking measures to block, filter, and update the list of spam email dissemination sources, or lacking solutions to avoid loss and wrongful blocking of users’ emails;
dd) Failing to supervise, control, and scan their own email server systems to ensure they do not become spam email dissemination sources;
e) Failing to make periodic reports and statistics as specified by regulations by competent state agencies.
2. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Failing to provide freight information prior to charging when users call premium-rate service switchboards or information inquiry services;
b) Failing to instruct subscribers to send spam message notifications and reply to the received spam message notifications;
c) Incompletely storing data of content service provision via messages as specified by regulations;
d) Failing to develop, update, provide, and share the shared list of IP addresses/domain names disseminating spam emails with the Ministry of Public Security (the Department of Cybersecurity and High-Tech Crime Prevention) and other telecommunications and Internet enterprises.
3. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Providing information on products and services via emails while the email sending servers are not located in Vietnam;
b) Providing Internet messaging services while the messaging service servers are not located in Vietnam;
c) Providing information on products and services via messages without using messaging numbers granted as specified by regulations;
d) Providing email advertising or message advertising services without systems for receiving and handling requests to refuse advertising emails or advertising messages;
dd) Failing to provide free functions for receiving notifications on spam messages or spam emails from users;
e) Failing to deploy spam message blocking systems capable of blocking spam messages by sending sources or keywords in the content of the sent messages;
g) Failing to allow enterprises that have been granted management codes to technically connect with their systems to provide services;
h) Failing to store data of content service provision via messages as specified by regulations;
i) Failing to provide users with tools and applications to send feedbacks on spam messages and spam calls, and failing to allow users to proactively block spam messages and spam calls;
k) Failing to provide, update, and share shared spam message templates with the Ministry of Public Security (the Department of Cybersecurity and High-Tech Crime Prevention) and other telecommunications enterprises;
l) Failing to filter and block IP addresses/domain names disseminating or being abused to disseminate spam emails under their management;
m) Failing to implement measures to assess the status of spam messages and spam calls on their own telecommunications networks;
n) Using brand names not granted by the Ministry of Public Security (the Department of Cybersecurity and High-Tech Crime Prevention) or brand names already granted by the Ministry of Public Security (the Department of Cybersecurity and High-Tech Crime Prevention) to other organizations or individuals, or using brand names after they are revoked;
o) Using brand names to send spam messages, make spam calls, or provide services in violation of law according to conclusions of state agencies.
4. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Charging service fees for failed messages, messages not provided with services, messages provided with services but containing content different from the command codes disclosed by the enterprises, or messages derived from scammed users;
b) Failing to implement measures to block advertising messages and advertising calls to the Do-Not-Call Register;
c) Failing to block or revoke electronic addresses used to disseminate spam messages, spam emails, and spam calls at the request of competent state agencies;
d) Failing to develop and operate technical systems to prevent and block spam messages, spam emails, and spam calls;
dd) Failing to develop and connect their own technical systems for brand name management to the National Brand Name Management System;
e) Failing to perform tasks of coordinating the blocking and handling of spam emails and spam calls, and other professional measures at the request of the Ministry of Public Security (the Department of Cybersecurity and High-Tech Crime Prevention).
5. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed on any telecommunications enterprise providing Internet telephony (VoIP) or SIP Trunk services for committing any of the following acts:
a) Failing to deploy or maintain technical mechanisms to automatically block the entire SIP Trunk and VoIP traffics generating calls to public telecommunications networks without valid voice brand names as specified by regulations;
b) Failing to supervise, analyze, and detect abnormal call traffics according to technical criteria promulgated or guided by competent state agencies;
c) Failing to implement or incompletely implementing measures to warn, restrict, suspend, or terminate the service provision to customers showing signs of generating spam calls, scam calls, or impersonation calls at the request of competent agencies or according to internal supervision results;
d) Failing to store or promptly provide logs, technical data, and identification information related to SIP Trunk and VoIP traffics serving the inspection, examination, investigation, and verification in accordance with law.
6. Additional sanction(s):
a) Suspension of operations of service provision to new customers from 01 month to 03 months for the acts of violation specified in Clause 4 of this Article;
b) Suspension of SIP Trunk and VoIP service provision from 01 month to 03 months for telecommunications enterprises violating the regulations specified in Clause 5 of this Article.
7. Remedial measure(s): Forcible revocation of identifier names for committing the acts of violation specified in Clause 4 of this Article.
Section 6
VIOLATIONS OF REGULATIONS ON PERSONAL DATA PROTECTION
Article 39. Violations of regulations on personal data protection principles and prohibited acts
1. A fine from VND 20,000,000 to VND 40,000,000 shall be imposed for the violations:
a) Processing personal data beyond the scope or inconsistently with the personal data processing purposes that have been determined, consented to, or agreed upon, or exceeding the necessary level to achieve such purposes;
b) Failing to ensure the accuracy of personal data, or failing to promptly rectify, update, or supplement them upon detecting errors or when necessary;
c) Storing personal data beyond the necessary timeframe suitable for the personal data processing purposes, unless otherwise specified by law;
d) Failing to proactively prevent, detect, and promptly coordinate with competent agencies in handling all law-violating acts regarding personal data protection.
2. A fine from VND 40,000,000 to VND 60,000,000 shall be imposed for the violations:
a) Committing acts of opposing or obstructing personal data protection activities of agencies, organizations, or individuals;
b) Using personal data of others to commit acts in contravention of law.
3. Additional sanction(s): Confiscation of administrative violation material evidence or means for the acts specified at Points a and c, Clause 1 and Point b, Clause 2 of this Article;
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data processed ultra vires or for improper purposes, or stored beyond the prescribed time limit, for the acts of violation specified at Points a and c, Clause 1 of this Article;
b) Forcible disgorgement of illicit proceeds from the commission of the violations specified at Point a, Point c, Clause 1 and Point b, Clause 2 of this Article;
c) Forcible public apology to personal data subjects in the mass media, for the act of violation specified at Point b, Clause 2 of this Article;
d) Forcible correction, update, or supplementation of personal data to ensure accuracy at the request of personal data subjects or upon detection of errors, for the act of violation specified at Point b, Clause 1 of this Article.
Article 40. Violations of regulations on taking advantage of personal data protection activities to commit law-violating acts
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts taking advantage of personal data protection activities:
a) Using the guise of personal data protection activities to conceal, legitimize, or facilitate violations of law;
b) Taking advantage of the use of forces, means, and measures for preventing and combating personal data infringement activities in order to appropriate, falsify, or process personal data in contravention of regulations;
c) Using personal data protection activities to commit fraudulent acts or infringe upon the lawful rights and interests of agencies, organizations, or individuals.
2. Additional sanction(s): Confiscation of administrative violation material evidence or means used to commit the acts of violation specified in Clause 1 of this Article.
3. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data unlawfully appropriated or processed, for the acts of violation specified in Clause 1 of this Article;
b) Forcible disgorgement of illicit proceeds from the commission of the acts of violation specified in Clause 1 of this Article;
c) Forcible public apology to personal data subjects in the mass media, for the acts of violation specified at Points b and c, Clause 1 of this Article.
Article 41. Violations of regulations on processing personal data affecting security and order
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for the following acts of processing personal data that affect security and order:
a) Processing personal data to create, consolidate, or disseminate fabricated, untruthful, distorted, inciting, or panic-causing information, or information affecting security and order;
b) Providing, transferring, disseminating, or disclosing personal data while clearly knowing that such data will be used for the purpose of infringing upon security and order;
c) Modifying, falsifying, erasing, destroying, appropriating, or disrupting personal data processing in order to affect the normal operation of agencies or organizations;
d) Committing other acts affecting, or posing a risk of affecting, security and order.
2. Additional sanction(s): Confiscation of administrative violation material evidence or means used to commit the acts of violation specified in Clause 1 of this Article.
3. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data processed to affect security and order, for the acts of violation specified in Clause 1 of this Article;
b) Forcible disgorgement of illicit proceeds from the commission of the acts of violation specified in Clause 1 of this Article;
c) Forcible removal or revocation of information and personal data unlawfully provided, transferred or disclosed, for the act of violation specified at Point b, Clause 1 of this Article.
Article 42. Violations of obligations on personal data protection of personal data subjects
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Intentionally disclosing or losing one’s own personal data, affecting social order and safety or causing damage to related agencies, organizations, or individuals;
b) Intentionally permitting another person to use one’s personal data to commit acts in contravention of law;
c) Intentionally providing fake or untruthful personal data for the purpose of fraud or causing confusion to relevant agencies, organizations, or individuals;
d) Intentionally creating a fabricated situation regarding the leakage or loss of one’s own personal data in order to evade liability, claim compensation, or seek illicit gains, affecting the reputation or assets of other organizations or individuals;
dd) Intentionally failing to fully and accurately provide one’s own personal data in accordance with mandatory provisions of law or signed contracts, causing legal identification risks or financial damage to Personal Data Controllers and Processors.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed on any individual for committing any of the following acts:
a) Unlawfully collecting, using, disclosing, modifying, falsifying, destroying, or accessing personal data of others, causing damage to their lawful rights and interests;
b) Intentionally providing personal data of others for fraudulent purposes, causing confusion for related agencies, organizations, or individuals;
c) Taking advantage of the exercise of the rights of personal data subjects beyond the necessary scope or inconsistently with the purposes of exercising such rights, causing difficulties or obstructing the lawful business activities of agencies or organizations;
d) Refusing to participate in coordinating the prevention and combat of personal data infringement activities upon receiving official requests from competent state agencies.
3. Additional sanction(s): Confiscation of administrative violation material evidence or means for the acts specified in Clause 2, Clause 3 of this Article.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of others’ personal data unlawfully collected, for the act of violation specified at Point a, Clause 2 of this Article;
b) Forcible disgorgement of illegal proceeds from the commission of the violations specified at Point b, Point c, Clause 2 of this Article;
c) Forcible re-provision of accurate and complete personal data information in accordance with law or contracts, for the act of violation specified at Point dd, Clause 1 of this Article;
d) Forcible termination of acts of obstructing the lawful exercise of rights and obligations to process personal data, for the act of violation specified at Point c, Clause 2 of this Article.
Article 43. Violations of regulations on the consent of personal data subjects
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Processing personal data after collection without obtaining the consent of personal data subjects, unless otherwise prescribed by law;
b) Attaching mandatory conditions, refusing to provide services if personal data subjects do not consent to the processing of personal data for other purposes unrelated to such service provision agreements;
c) Establishing default consent methods, or creating unclear instructions that cause misunderstandings between consent and non-consent for personal data subjects;
d) Failing to express the request for consent in a clear and specific manner, or failing to ensure verifiability regarding the identification of the personal data subject who gave consent, the time and content consented to;
dd) Failing to provide personal data subjects with transparent information on the types of personal data to be processed, personal data processing purposes, and rights and obligations of personal data subjects, Personal Data Controllers, or Personal Data Controllers and Processors, leading to the fact that the consent is not based on voluntariness and clear awareness;
e) Using forms of requesting consent that fail to ensure that personal data subjects can give consent to each personal data processing purpose;
g) Failing to record or store logs on the consent of personal data subjects, or failing to prove that consent has been given upon the requests of personal data subjects or the inspection and examination requests of competent state agencies;
h) Failing to notify personal data subjects that their sensitive personal data are being processed.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Intentionally continuing to process personal data after personal data subjects have requested to stop or restrict the processing, or when competent state agencies request in writing;
b) Collecting or processing personal data when personal data subjects remain silent or fail to respond to the requests for consent, or arbitrarily considering silence as consent.
3. Additional sanction(s): Confiscation of administrative violation material evidence or means for the acts specified at Points a and c, Clause 1 and Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data collected or processed without valid consent, for the acts of violation specified at Points a and c, Clause 1, and Clause 2 of this Article;
b) Forcible disgorgement of illicit proceeds from the commission of the acts of violation specified in Clause 2 of this Article.
Article 44. Violations of regulations on procedures for exercising rights of personal data subjects
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed on any Personal Data Controller or Personal Data Controller-cum-Processor for committing any of the following acts:
a) Failing to establish clear processes, procedures, and forms to exercise the rights of personal data subjects;
b) Failing to clearly define the responsibilities of relevant departments within organizations to exercise the rights of personal data subjects;
c) Failing to provide information or failing to ensure that personal data subjects are informed of the procedures for exercising the rights specified in the Law on Personal Data Protection;
d) Failing to respond to personal data subjects or providing incomplete information on procedures upon receiving valid requests to access, rectify, provide, delete, withdraw consent, restrict, or object to the processing of personal data, or implement personal data protection measures and solutions past the time limit of 02 working days from the time of receiving such requests;
dd) Failing to notify personal data subjects of plausible reasons in case it is impossible to perform or it is necessary to extend the time limits for the requests to access, rectify, provide, delete, withdraw consent, restrict, or object to the processing of personal data, or implement personal data protection measures and solutions for personal data subjects.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed on Personal Data Processors or Third Parties that have received valid requests from Personal Data Controllers, or Personal Data Controllers and Processors, but fail to fulfill any of the following requests within the prescribed time limit:
a) Failing to stop processing personal data upon receiving requests to withdraw consent, restrict processing, or object to the processing of personal data within the time limits determined by Personal Data Controllers, or Personal Data Controllers and Processors;
b) Failing to rectify or provide personal data within the time limits determined by Personal Data Controllers, or Personal Data Controllers and Processors;
c) Failing to delete or destroy personal data or failing to restrict the processing of personal data within the time limits determined by Personal Data Controllers, or Personal Data Controllers and Processors.
3. A fine from VND 30,000,000 to VND 40,000,000 shall be imposed on Personal Data Controllers, or Personal Data Controllers and Processors, for any of the following acts of failing to fulfill the requests of personal data subjects within the prescribed time limit:
a) Failing to fulfill the requests to withdraw consent, restrict processing, or object to the processing of personal data within 15 days; failing to ensure the time limit of 20 days in case it requires Personal Data Processors or Third Parties to perform; failing to ensure the maximum extension period of 15 days in case an extension has been made;
b) Failing to fulfill the requests to access, rectify, or provide personal data within 10 days; failing to ensure the time limit of 15 days in case it requires Personal Data Processors or Third Parties to perform; failing to ensure the maximum extension period of 10 days in case an extension has been made;
c) Failing to fulfill the requests to delete personal data within 20 days; failing to ensure the time limit of 30 days in case it requires Personal Data Processors or Third Parties to perform; failing to ensure the maximum extension period of 20 days in case an extension has been made;
d) Failing to fulfill the requests to apply personal data protection measures and solutions within 15 days; failing to ensure the maximum extension period of 15 days in case an extension has been made.
4. Personal Data Processors and Third Parties shall not be sanctioned under the provisions of Clause 2 of this Article in case it is otherwise prescribed by law.
5. Remedial measure(s): Forcible full implementation of the rights of personal data subjects at lawful requests, and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clauses 2 and 3 of this Article.
Article 45. Violations of regulations on the right to withdraw consent and the right to restrict personal data processing
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for the violations:
a) Using methods and measures to conceal, block, or intentionally obstruct the exercise of the right to withdraw consent or requests for restriction by personal data subjects;
b) Failing to stop processing personal data since personal data subjects withdraw their consent or request restriction in accordance with proper procedures, unless the law otherwise specifies continued processing without consent under Article 19 of the Law on Personal Data Protection;
c) Personal Data Controllers, or Personal Data Controllers and Processors failing to send requests to Personal Data Processors or Third Parties to stop processing personal data of the subjects who have withdrawn their consent or requested restriction of personal data processing.
2. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data continuously processed after the data subjects withdraw their consent, for the act of violation specified at Point b, Clause 1 of this Article;
b) Forcible disgorgement of proceeds from the continued exploitation of personal data after the subjects withdraw their consent, for the act of violation specified at Point b, Clause 1 of this Article;
c) Forcible establishment and provision for personal data subjects of a clear and accessible technical mechanism to exercise the right to withdraw consent; forcible provision of implementation evidence to competent agencies, for the act of violation specified at Point a, Clause 1 of this Article;
d) Forcible sending of requests to Personal Data Processors or Third Parties to stop processing personal data of the subjects who withdraw their consent; forcible provision of implementation evidence, for the act of violation specified at Point c, Clause 1 of this Article.
Article 46. Violations of regulations on the right to access, rectify or request the rectification of personal data
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Personal Data Controllers, or Personal Data Controllers and Processors refusing or not allowing personal data subjects to access to view, rectify, or request the rectification of their own personal data after collection, unless otherwise specified by law;
b) Personal Data Processors or Third Parties arbitrarily rectifying personal data of personal data subjects without the written consent of Personal Data Controllers.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for intentionally delaying or failing to rectify personal data after confirming that the information is untruthful or fake, which affects the honor, dignity, reputation, and lawful rights and interests of personal data subjects.
3. No sanctioning under the provisions of this Article shall be imposed for the act of refusing or failing to rectify personal data if Personal Data Controllers, or Personal Data Controllers and Processors have reasonable grounds to prove that it falls under one of the following cases:
a) Rectification requests are aimed at committing fraud or falsifying information to evade legal obligations or commit law-violating acts;
b) The rectification of personal data upon request may infringe upon the lawful rights and interests of other organizations or individuals, or affect the fine customs, traditions, morality, or public interests;
c) Other cases as specified by the relevant law.
4. Remedial measure(s):
a) Forcible correction of personal data at the lawful requests of personal data subjects, for the acts of violation specified in Clause 2 of this Article;
b) Forcible destruction or irrecoverable deletion of personal data arbitrarily and unlawfully rectified, for the act of violation specified at Point b, Clause 1 of this Article.
Article 47. Violations of regulations on the processing of personal data in case consent of the personal data subjects is not required
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for the violations:
a) Failing to establish processes and regulations on personal data processing and determining the responsibilities of agencies, organizations, and individuals during the personal data processing;
b) Failing to conduct periodic inspections and assessments of compliance with law, and processes and regulations on personal data processing;
c) Lacking mechanisms to receive and handle feedbacks and recommendations from related agencies, organizations, and individuals.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for the violations:
a) Failing to deploy appropriate personal data protection measures, leading to the disclosure or loss of collected personal data;
b) Failing to assess risks that may occur during the personal data processing.
3. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for the violations:
a) Taking advantage of the cases of personal data processing without consent specified in Clause 1, Article 19 of the Law on Personal Data Protection to collect or process personal data beyond the necessary purposes and scope compared to the grounds prescribed by law;
b) Failing to prove the cases as specified by law of personal data processing without consent upon the inspection requests of competent state agencies.
4. Remedial measure(s):
a) Forcible establishment, promulgation and disclosure of processes and regulations on personal data processing; personal data protection measures; and mechanisms to receive feedbacks and recommendations in accordance with regulations, and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article;
b) Forcible cessation of personal data processing activities based on the grounds for consent exemption at variance with regulations, or ultra vires or beyond the purposes permitted by such grounds, for the acts of violation specified in Clause 3 of this Article;
c) Forcible destruction or irrecoverable deletion of all personal data collected or processed ultra vires, beyond the prescribed purposes or without lawful grounds, for the act of violation specified at Point a, Clause 3 of this Article;
d) Forcible compilation, archive and provision of documents proving the lawful grounds of personal data processing without consent at the request of competent agencies, for the act of violation specified at Point b, Clause 3 of this Article;
dd) Forcible implementation of appropriate personal data protection measures and risk assessments during personal data processing; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 2 of this Article.
Article 48. Violations of regulations on personal data collection
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for collecting personal data inconsistently with the specific and clear scope and purposes or without the consent of personal data subjects prior to collection as specified by law.
2. A fine from VND 50,000,000 to VND 80,000,000 shall be imposed for collecting, storing, or forming personal data warehouses from personal data transfer activities for use for purposes other than those consented to by personal data subjects.
3. In case technological or technical measures are applied to collect personal data in contravention of law, the fine levels are determined as follows:
a) A fine from VND 100,000,000 to VND 200,000,000 shall be imposed for collecting basic personal data of under 500 data subjects or collecting sensitive personal data of under 100 data subjects;
b) A fine from VND 200,000,000 to VND 300,000,000 shall be imposed for collecting basic personal data of between 500 and under 1,000 data subjects or collecting sensitive personal data of between 100 and under 200 data subjects;
c) A fine from VND 300,000,000 to VND 500,000,000 shall be imposed for collecting basic personal data of between 1,000 and under 5,000 data subjects or collecting sensitive personal data of between 200 and 1,000 data subjects;
d) A fine from VND 500,000,000 to VND 800,000,000 shall be imposed for collecting basic personal data of 5,000 data subjects or more or collecting sensitive personal data of 1,000 data subjects or more.
4. A fine from VND 50,000,000 to VND 80,000,000 shall be imposed for the act specified in Clause 1 of this Article if the object of the violation is sensitive personal data.
5. Additional sanction(s): Confiscation of administrative violation material evidence or means used to commit the acts of violation specified in Clauses 1, 2, 3 of this Article.
6. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of all personal data collected or processed in contravention of law, for the acts of violation specified in this Article;
b) Forcible disgorgement of proceeds from business activities using unlawfully collected personal data, for the acts of violation specified in Clause 2 of this Article.
Article 49. Violations of regulations on personal data provision
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for refusing to provide personal data to the personal data subjects themselves upon valid requests.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for providing personal data to other agencies, organizations, or individuals without the consent of personal data subjects, unless otherwise specified by law.
3. A fine equivalent to 2 times the fine levels specified in Clauses 2 and 3 of this Article shall be imposed for the act of providing sensitive personal data.
4. Remedial measure(s):
a) Forcible provision of personal data to the personal data subjects themselves upon valid requests, for the act of violation specified in Clause 1 of this Article;
b) Forcible recall of personal data wrongly provided, for the acts of violation specified in Clauses 2 and 3 of this Article;
c) Forcible disgorgement of proceeds from the commission of the violations specified in Clause 2 of this Article.
Article 50. Violations of regulations on personal data disclosure
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Disclosing personal data without specific purposes, or not falling under the cases permitted for disclosure in accordance with law;
b) Disclosing personal data beyond the scope and types necessary for the disclosure purposes;
c) Disclosing personal data but failing to accurately reflect the data from the original data sources;
d) Failing to strictly control and supervise the disclosure of personal data to ensure compliance with proper purposes, scopes, and law;
dd) Lacking measures to prevent unlawful access, use, disclosure, copying, modification, deletion, destruction, or other unlawful processing acts regarding disclosed data.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Disclosing personal data, thereby infringing upon the lawful rights and interests of personal data subjects;
b) Disclosing personal data without the consent of personal data subjects, unless otherwise permitted by law.
3. Remedial measure(s):
a) Forcible correction of information for the violations specified at Point c, Clause 1 of this Article;
b) Forcible removal or revocation of disclosed personal data, for the acts of violation specified in Clause 2 of this Article;
c) Forcible application of measures to control, supervise and secure personal data being disclosed; forcible provision of implementation evidence to competent agencies, for the acts of violation specified at Points d and dd, Clause 1 of this Article;
d) Forcible removal or revocation of personal data disclosed without specific purposes or ultra vires, for the acts of violation specified at Points a and b, Clause 1 of this Article.
Article 51. Violations of regulations on erasure, destruction, and de-identification of personal data
1. A fine from VND 10,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Failing to notify personal data subjects of the reasons in case it is impossible to perform the deletion or destruction of personal data after receiving requests;
b) The deletion or destruction of personal data is not performed through safe measures;
c) Lacking measures to prevent unlawful intrusion and recovery of deleted or destroyed data;
d) De-identifying personal data without strict control and supervision;
dd) Lacking measures to prevent unlawful access, copying, appropriation, disclosure, or loss of data during the de-identification process.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to delete or destroy personal data in the cases prescribed by law;
b) Personal Data Controllers, or Personal Data Controllers and Processors failing to request Personal Data Processors or Third Parties to delete or destroy personal data of personal data subjects in accordance with law;
c) Personal Data Processors failing to delete or return all personal data to Personal Data Controllers after the termination of personal data processing contracts or agreements;
d) Allowing the occurrence of unlawful access, copying, appropriation, disclosure, or loss of personal data during the de-identification process.
3. A fine from VND 50,000,000 to VND 60,000,000 shall be imposed for any of the following acts:
a) Intentionally and unlawfully recovering deleted or destroyed personal data;
b) Re-identifying personal data after such data have been de-identified, unless otherwise specified by law.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data, for the acts of violation specified at Points a and b, Clause 2 of this Article;
b) Forcible notification to personal data subjects of the impossibility to delete or destroy data in the case specified at Point a, Clause 1 of this Article;
c) Forcible destruction or irrecoverable deletion of re-identification results and unlawfully recovered personal data, for the acts of violation specified in Clause 3 of this Article;
d) Forcible application of measures to control, supervise and prevent unlawful access during the de-identification process; forcible provision of implementation evidence to competent agencies, for the acts of violation specified at Points d and dd, Clause 1 of this Article.
Article 52. Violations of regulations on personal data transfer
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Personal data transfer agreements failing to determine the responsibilities for protecting personal data during the transfer and processing of personal data; the responsibilities for exercising the rights of personal data subjects; and the coordination and compliance responsibilities of the parties in case of detecting violations of personal data protection regulations;
b) In case of sharing personal data among departments within the same agencies or organizations to process personal data consistently with the established processing purposes, such agencies or organizations fail to develop processes to control the sharing and use of personal data in accordance with regulations; or lack measures to prevent and combat internal personnel of the agencies or organizations from unlawfully sharing personal data with third parties.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the acts of transferring personal data under Point a and Point d, Clause 1, Article 17 of the Law on Personal Data Protection with fee collection to provide services to personal data subjects or to serve the lawful interests of personal data subjects but violating the following obligations:
a) Failing to clearly define the roles of Personal Data Controllers, Personal Data Processors, and Third Parties in personal data transfer activities;
b) Failing to define or limit the types of transferred personal data within the scope of the transfer purposes;
c) Failing to determine the retention periods of personal data in accordance with the transfer purposes; failing to delete or destroy personal data upon completion of purposes in accordance with law.
3. A fine from VND 50,000,000 to VND 80,000,000 shall be imposed for transferring sensitive personal data without physical security measures for storage and transmission devices, encryption measures, personal data anonymization, and other security measures during the transfer process.
4. Additional sanction(s): Confiscation of administrative violation material evidence or means, for the acts of violation specified in Clause 2 of this Article.
5. Remedial measure(s):
a) Forcible supplementation and finalization of personal data transfer agreements in accordance with regulations, and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article;
b) Forcible application of prescribed security measures to sensitive personal data being stored and transmitted, for the acts of violation specified in Clause 3 of this Article;
c) Forcible destruction or irrecoverable deletion of sensitive personal data transferred in case it is impossible to assure security in accordance with regulations, for the acts of violation specified in Clauses 2 and 3 of this Article.
Article 53. Violations of regulations on unlawful buying and selling of personal data
1. A fine from 2 times to a maximum of 10 times the proceeds shall be imposed for any of the following acts of illegally buying and selling personal data:
a) Providing, sharing, or exchanging to obtain assets or other benefits not falling under the cases specified in Clause 1, Article 17 of the Law on Personal Data Protection;
b) Transferring personal data with fee collection or other material benefits without personal data transfer agreements;
c) Transferring personal data with fee collection or other material benefits while personal data transfer agreements fail to determine the personal data transfer purposes, or failing to comply with the purposes in the personal data transfer agreements;
d) Transferring personal data with fee collection or other material benefits without establishing technical systems and transparent mechanisms for personal data subjects to give accurate and clear consent for each transfer, on the basis of accurately knowing the transfer purposes, and the organizations or individuals receiving and processing personal data;
dd) Transferring personal data with fee collection or other material benefits while processing personal data inconsistently with the transfer purposes consented to by personal data subjects, and suitable for the registered business lines;
e) Transferring personal data with fee collection or other material benefits without de-identifying personal data when trading on data exchanges.
2. In case the acts of violation specified in Clause 1 of this Article yield no proceeds, and the maximum fine equivalent to 10 times the proceeds obtained from the acts of violation is lower than VND 3,000,000,000, the fine level shall be determined up to the maximum level of the fine bracket of VND 3,000,000,000.
3. In case there are no proceeds obtained from the acts of violation specified in Clause 1 of this Article, the fine levels shall be determined as follows:
a) A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for buying and selling basic personal data of under 1,000 data subjects or buying and selling sensitive personal data of under 200 data subjects;
b) A fine from VND 100,000,000 to VND 300,000,000 shall be imposed for buying and selling basic personal data of between 1,000 and under 2,000 data subjects or buying and selling sensitive personal data of between 200 and under 400 data subjects;
c) A fine from VND 300,000,000 to VND 500,000,000 shall be imposed for buying and selling basic personal data of between 2,000 and under 10,000 data subjects or sensitive personal data of between 400 and 2,000 data subjects;
d) A fine from VND 500,000,000 to VND 1,000,000,000 shall be imposed for buying and selling basic personal data of 10,000 data subjects or more, or sensitive personal data of 2,000 data subjects or more;
dd) A fine from VND 1,000,000,000 to the maximum of VND 3,000,000,000 shall be imposed for the acts of unlawfully buying and selling personal data, infringing upon national defense, security and order, external affairs, macro-economy, or the life, health, honor, dignity, or property of personal data subjects, or the lawful rights and interests of organizations or individuals.
4. Additional sanction(s): Confiscation of administrative violation material evidence or means used to commit the acts of violation specified in this Article.
5. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of all unlawfully bought or sold personal data on all storage systems, for the acts of violation specified in this Article;
b) Forcible disgorgement of proceeds from the acts of violation specified in Clause 1 and Clause 2 of this Article;
c) Forcible notification to all affected personal data subjects of acts of violation and remedial measures, for the acts of violation specified in this Article.
Article 54. Violations of regulations on notification of violations of regulations on personal data protection
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Personal Data Processors discovering acts of violation but failing to promptly notify Personal Data Controllers, or Personal Data Controllers and Processors;
b) Personal Data Controllers, or Personal Data Controllers and Processors failing to make written records confirming the occurrence of acts violating personal data protection regulations;
c) Personal Data Controllers, Personal Data Controllers and Processors, or Personal Data Processors reporting data leak incident violations to specialized personal data protection agencies but intentionally concealing or providing false information about the nature of the incidents, the scale, types of personal data, and the number of affected personal data subjects.
2. A fine from VND 20,000,000 to VND 40,000,000 shall be imposed for failing to notify specialized agencies in charge of personal data protection in the following cases:
a) Detecting acts of violation of regulations on personal data protection;
b) Personal data being processed for wrong purposes or inconsistently with agreements;
c) Failing to ensure the rights or improperly exercising the rights of personal data subjects.
3. A fine from VND 40,000,000 to VND 60,000,000 shall be imposed on Personal Data Controllers, Personal Data Controllers and Processors, or Third Parties for notifying specialized agencies in charge of personal data protection later than 72 hours from the discovery of violations of regulations on personal data protection that harm or may harm national defense, national security, social order and safety, or infringe upon the life, health, honor, dignity, and property of personal data subjects.
4. A fine from VND 60,000,000 to VND 80,000,000 shall be imposed for any of the following acts:
a) Failing to implement measures to block acts of violation, or failing to remedy the occurred consequences;
b) Failing to coordinate with specialized personal data protection agencies in handling acts of violation.
5. Remedial measure(s):
a) Forcible full implementation of obligations to notify violations in terms of prescribed content, forms and time limits, and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1, Clause 2 and Clause 3 of this Article;
b) Forcible implementation of measures to prevent and remedy consequences caused by acts of violation at the request of specialized personal data protection agencies, for the act of violation specified at Point a, Clause 4 of this Article.
Article 55. Violations of regulations on personal data processing impact assessment
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for the violations:
a) Commencing personal data processing activities but failing to make or maintain Dossiers for personal data processing impact assessment at the headquarters of enterprises in accordance with Article 21 of the Law on Personal Data Protection;
b) Failing to send 01 original copy of the Dossier for personal data processing impact assessment (according to the form prescribed in the Appendix to Decree No. 356/2025/ND-CP) to the Department of Cybersecurity and High-Tech Crime Prevention (the Ministry of Public Security) within 60 days from the first day of conducting personal data processing;
c) Intentionally failing to finalize impact assessment dossiers at the request of specialized agencies in case the dossiers are incomplete or inconsistent with regulations;
d) Failing to update Dossiers for personal data processing impact assessment on a 06-month periodic basis when there are changes in accordance with law;
dd) Failing to update dossiers within 10 days when falling under one of the cases subject to mandatory updates as specified by law.
2. A fine from VND 50,000,000 to VND 100,000,000 shall be imposed for intentionally falsifying data, providing misleading information in the Dossier for personal data processing impact assessment, or refusing to rectify or complete the dossier upon receiving a written request for remediation from the Department of Cybersecurity and High-Tech Crime Prevention (the Ministry of Public Security).
3. Remedial measure(s):
a) Forcible compilation, finalization and submission of dossiers for personal data processing impact assessment in accordance with regulations, and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article;
b) Forcible cessation of personal data processing activities until the completion of obligations to submit dossiers for personal data processing impact assessment and confirmation is made by a specialized personal data protection agency, for the act of violation specified at Point a, Clause 1 of this Article.
Article 56. Violations of regulations on cross-border personal data transfer
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to make dossiers for cross-border personal data transfer impact assessment before or during the time of conducting the data transfer;
b) Failing to submit 01 original copy of the dossier for cross-border personal data transfer impact assessment to the specialized personal data protection agency within 60 days from the first day of conducting the data transfer;
c) Failing to finalize the dossier for cross-border personal data transfer impact assessment within 30 days from receiving the request of the specialized personal data protection agency;
d) Failing to update periodically or failing to update the dossier for cross-border personal data transfer impact assessment when there are changes in accordance with law;
dd) Failing to maintain the dossier for cross-border personal data transfer impact assessment in a state of readiness to serve the inspection activities of the specialized personal data protection agency;
e) Failing to notify the information and contact details of the organizations or individuals in charge of personal data protection on the side of the data recipients after completing the cross-border personal data transfer;
g) Lacking control mechanisms or failing to request cross-border data recipients to comply with processes when forwarding personal data to other third parties, leading to the fact that personal data of Vietnamese citizens are processed beyond the scope declared in the impact assessment dossiers.
2. A fine from VND 50,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Failing to establish a contract or transfer document binding personal data protection responsibilities between the transferor and the cross-border data recipient, or failing to clearly define responsibilities for fulfilling the rights of personal data subjects after data transfer;
b) Failing to ensure the consent of personal data subjects regarding the purpose of cross-border data transfer, or failing to notify personal data subjects of the transfer of their data abroad, the receiving organization, and the purpose of processing;
c) Failing to apply appropriate security measures during the process of cross-border personal data transfer, or failing to have a plan to ensure personal data safety after transfer;
d) Failing to cooperate with or obstructing the inspection of cross-border data transfer activities by the specialized personal data protection agency;
dd) Continuing cross-border transfer of personal data after the issuance of a decision requesting the cessation of data transfer by the specialized personal data protection agency;
e) Failing to notify the specialized personal data protection agency and failing to request the cross-border data recipient to cease processing and prevent damage upon detecting that the recipient has committed a violation of personal data protection regulations or experienced a personal data leakage or loss incident.
3. A fine calculated as a percentage of the total revenue generated in the Vietnamese market in the immediately preceding financial year shall be imposed on an organization that transfers personal data across borders without preparing an impact assessment dossier, conceals or misdeclares data flows resulting in personal data leakage or loss, or continues to transfer personal data after the specialized personal data protection agency has issued a decision requesting cessation of such transfer, specifically as follows:
a) A fine from 1% to 2% of total revenue shall be imposed for acts leading to the disclosure or loss of personal data of between 10,000 and under 100,000 personal data subjects who are Vietnamese citizens;
b) A fine from 2% to 3% of total revenue shall be imposed for acts leading to the disclosure or loss of personal data of between 100,000 and under 1,000,000 personal data subjects who are Vietnamese citizens;
c) A fine from 3% to 5% of total revenue shall be imposed for acts leading to the disclosure or loss of personal data of 1,000,000 personal data subjects who are Vietnamese citizens or more, or the cross-border transfer of personal data after a decision requesting the cessation of transfer is issued by a specialized agency in charge of personal data protection, causing harm to national defense or national security.
4. In case an organization violating the provisions of Clause 3 of this Article has no revenue generated in the Vietnamese market in the immediately preceding financial year or the fine level calculated based on the percentage of revenue at each point is lower than VND 3,000,000,000, the following fine levels shall apply:
a) A fine from VND 200,000,000 to VND 500,000,000 shall be imposed for acts leading to the disclosure or loss of personal data of between 10,000 and under 100,000 personal data subjects who are Vietnamese citizens;
b) A fine from VND 500,000,000 to VND 1,000,000,000 shall be imposed for acts leading to the disclosure or loss of personal data of between 100,000 and under 1,000,000 personal data subjects who are Vietnamese citizens;
c) A fine from VND 1,000,000,000 to VND 3,000,000,000 shall be imposed for acts leading to the disclosure or loss of personal data of 1,000,000 personal data subjects who are Vietnamese citizens or more, or the cross-border transfer of personal data after a decision requesting the cessation of transfer is issued by a specialized agency in charge of personal data protection, causing harm to national defense or national security.
5. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means for the acts of violation specified in Clause 2 and Clause 3 of this Article;
b) Suspension of cross-border transfer of personal data for a definite term of between 06 months and 12 months, for the acts of violation specified in Clause 3 of this Article.
6. Remedial measure(s):
a) Forcible compilation, finalization and submission of dossiers for cross-border personal data transfer impact assessment in accordance with regulations, for the acts of violation specified in Clause 1 of this Article;
b) Forcible cessation of cross-border personal data transfer until the full completion of dossier obligations and confirmation is made by a specialized personal data protection agency, for the acts of violation specified at Points a and b, Clause 1, and Points a and b, Clause 2 of this Article;
c) Forcible requirement to request the cross-border data recipient to destroy and irrecoverably delete all unlawfully transferred personal data, and to provide evidence of such destruction and erasure by the recipient to the competent agency, for the acts of violation specified in Clause 2 and Clause 3 of this Article;
d) Forcible disgorgement of proceeds from the act of violation specified in Clause 3 of this Article.
Article 57. Violations of regulations on designation of personnel and departments in charge of personal data protection
1. A caution or a fine from VND 10,000,000 to VND 20,000,000 shall be imposed on an agency or organization for committing any of the following acts:
a) Failing to sign a confidentiality agreement with the personal data protection officer;
b) Failing to organize training and professional enhancement in personal data protection knowledge and skills for personal data protection officers;
c) Issuing official documents designating personal data protection officers or decisions establishing a personal data protection department without specifying functions, tasks, powers, and requirements for personal data protection work in accordance with law.
2. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed on an agency or organization for committing any of the following acts:
a) Designating personal data protection personnel who fail to satisfy qualification requirements of a college degree or higher, or fail to have at least 02 years of working experience related to one of the fields of legal affairs, information technology, cybersecurity, data security, risk management, compliance control, or personnel management;
b) Designating personal data protection officers who have not been trained or fostered in legal knowledge and professional skills on personal data protection;
c) Failing to promulgate official documents designating personal data protection officers, or failing to promulgate decisions on establishing personal data protection departments.
3. Remedial measure(s):
a) Forcible replacement with personnel satisfying all conditions prescribed by law and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 2 of this Article;
b) Forcible promulgation of designation documents and formulation of full functions and tasks in accordance with regulations, and forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article.
Article 58. Violations of regulations on provision of personal data protection services
1. A fine from VND 10,000,000 to VND 30,000,000 shall be imposed on an individual providing personal data protection services for committing any of the following acts:
a) Failing to satisfy qualification requirements of a college degree or higher, or failing to have at least 03 years of working experience related to one of the fields of legal affairs, personal data processing, cybersecurity, data security, risk management, or compliance control, or having not received in-depth training in personal data protection, while still providing services;
b) Performing services exceeding the scope and tasks agreed upon in the contract;
c) Failing to delete or destroy personal data processed during service provision after completing the contract.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed on an organization providing personal data protection services for committing any of the following acts:
a) Failing to formulate a capacity dossier or providing a capacity dossier that fails to fully contain the required contents in accordance with regulations;
b) Failing to have at least 03 personnel satisfying capacity qualification conditions in accordance with regulations;
c) Failing to enter into a service usage contract and a personal data processing agreement with the service-using agency or organization prior to providing services;
d) Failing to publicly disclose information about the service-providing organization to personal data subjects and relevant parties.
3. A fine from VND 50,000,000 to VND 100,000,000 shall be imposed for taking advantage of service provision to access, collect, use, disclose, or process personal data beyond the contractual scope, or committing other acts of law violation.
4. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means, for the acts of violation specified in Clause 3 of this Article;
b) Suspension of operations of personal data protection service provision for a definite term of between 06 months and 12 months for the acts of violation specified at Points a and b, Clause 2 and Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of all personal data unlawfully collected or processed in the course of service provision, for the acts of violation specified at Point c, Clause 1, and Clause 3 of this Article;
b) Forcible disgorgement of proceeds from the acts of violation specified in Clause 3 of this Article;
c) Forcible notification to agencies or organizations using services of the fact that organizations or individuals providing services no longer satisfy prescribed conditions, so that such agencies or organizations can promptly implement substitute measures to ensure continuous personal data protection activities, for the acts of violation specified at Points a and b, Clause 2 of this Article.
Article 59. Violations of regulations on provision of personal data processing services
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed on an organization doing business in personal data processing services that has been granted a Certificate, for committing any of the following acts:
a) Failing to formulate a personal data protection risk management framework appropriate to the services provided;
b) Failing to formulate regulations on the responsibilities and powers of the organization in personal data processing;
c) Failing to apply standards and technical regulations related to data security, personal data protection, and cybersecurity;
d) Failing to perform organization identity verification in accordance with regulations of law on electronic identification and authentication.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed on an organization doing business in personal data processing services that has been granted a Certificate, for committing any of the following acts:
a) In case of being a personal data processor, failing to request the personal data controller to obtain the consent of the personal data subject prior to providing services, or failing to ensure that the personal data subject is informed of the category of data processed, processing purpose, and the service provider;
b) Failing to ensure personal data processing for proper purposes, failing to limit collection, transfer, and storage appropriately in accordance with regulations, or failing to apply measures to prevent unauthorized access, collection, use, or disclosure of personal data in service provision activities;
c) Failing to conduct periodic evaluations of personal data protection compliance status and credibility level once every 01 year.
3. A fine from VND 50,000,000 to VND 80,000,000 shall be imposed on an organization providing personal data processing services for committing any of the following acts:
a) Conducting business activities in personal data processing services without having been granted a Certificate of eligibility for personal data processing service business;
b) Assigning personal data protection personnel who fail to satisfy qualification requirements of a college degree or higher, or fail to have at least 03 years of working experience related to one of the fields of legal affairs, personal data processing, cybersecurity, data security, risk management, or compliance control, or have not received in-depth training in personal data protection;
c) Failing to have at least 03 personnel satisfying capacity conditions in accordance with regulations.
4. A fine from VND 80,000,000 to VND 100,000,000 shall be imposed for continuing to provide personal data processing services after the Certificate of eligibility for personal data processing services has been revoked.
5. Remedial measure(s):
a) Forcible formulation, promulgation and implementation of risk governance frameworks, regulations on responsibilities, technical standards, and identity authentication mechanisms in accordance with regulations; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article;
b) Forcible destruction or irrecoverable deletion of all personal data unlawfully collected or processed in the course of service provision, for the acts of violation specified in Clause 2 and Clause 3 of this Article;
c) Forcible disgorgement of proceeds from the violations specified in Clause 3 of this Article.
Article 60. Violations of regulations on personal data protection of children, persons losing or restricted in civil act capacity, and persons with difficulties in awareness and behavior control
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to implement a child age verification process prior to processing children’s personal data;
b) Processing personal data of children under 07 years of age, persons who have lost or have limited civil act capacity, or persons with difficulties in cognition or behavior control without the consent of their legal representatives, unless otherwise specified in Clause 1, Article 19 of the Law on Personal Data Protection;
c) Processing personal data of children aged full 07 years or older without the simultaneous consent of the child and his/her legal representative, unless otherwise specified in Clause 1, Article 19 of the Law on Personal Data Protection.
2. A fine from VND 50,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Processing children’s personal data to publicize or disclose information about the private life or personal secrets of children aged full 07 years or older without the simultaneous consent of the child and his/her legal representative;
b) Failing to cease processing personal data of children, persons who have lost or have limited civil act capacity, or persons with difficulties in cognition or behavior control when their legal representative withdraws consent, unless otherwise specified by law;
c) Failing to cease processing personal data of children, persons who have lost or have limited civil act capacity, or persons with difficulties in cognition or behavior control when a competent agency has sufficient grounds to prove that data processing may infringe upon the lawful rights and interests of the protected subjects and requests cessation, unless otherwise specified by law.
3. A fine from VND 100,000,000 to VND 200,000,000 shall be imposed for failing to irrecoverably delete or destroy personal data of children in the following cases: the data is processed for an improper purpose or the processing purpose has been fulfilled; the parent or guardian withdraws consent; at the request of a competent agency.
4. Additional sanction(s): Suspension of personal data processing operations directly related to the act of violation from 01 month to 03 months, for the act of violation specified in Clause 2 of this Article; and from 03 months to 06 months, for the act of violation specified in Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible cessation of personal data processing activities and forcible written notification to legal representatives of the cessation of processing, for the acts of violation specified at Points b and c, Clause 2 of this Article;
b) Forcible destruction or irrecoverable deletion of all personal data processed in contravention of regulations, for the acts of violation specified in Clause 1, Clause 2 and Clause 3 of this Article;
c) Forcible removal of information about private life or personal secrets disclosed in contravention of regulations, and forcible notification to legal representatives of the removal, for the act of violation specified at Point a, Clause 2 of this Article.
Article 61. Violations of regulations on personal data protection in recruitment, management and use of labor
1. A fine from VND 20,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Requiring candidates to provide personal data not serving recruitment purposes or in contravention of law;
b) Using candidates’ personal data for purposes other than recruitment purposes without agreements with candidates;
c) Processing candidates’ personal data without consent or processing beyond the scope and purposes consented to by candidates;
d) Failing to delete or destroy personal data of job applicants in case of non-recruitment, unless otherwise agreed with the applicant.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Storing employees’ personal data beyond the time limit prescribed by law or beyond the agreed time limit;
b) Failing to delete or destroy employees’ personal data upon termination of labor contracts, unless otherwise agreed or specified by law;
c) Applying technological or technical measures to collect employees’ personal data without ensuring that employees are clearly aware of such measures, including installing device-tracking software, surveillance cameras, or other data collection equipment in the working environment without notifying employees;
d) Applying technological and technical measures to collect employees’ personal data in contravention of law or failing to ensure the lawful rights and interests of employees.
3. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for processing or using personal data of employees collected through technological and technical measures in contravention of law.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data collected or processed in contravention of regulations, for the acts of violation specified at Points c and d, Clause 1, Points c and d, Clause 2, and Clause 3 of this Article;
b) Forcible disgorgement of proceeds from the acts of violation specified in Clause 3 of this Article;
Article 62. Violations of regulations on personal data protection concerning health information and in insurance business
1. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Transferring customers’ personal data to partners without clear and transparent provisions in the contracts entered into with customers during the business of insurance, reinsurance, and retrocession;
b) Collecting sensitive personal data without establishing regulations on access-limiting decentralization and security measures as specified by regulations during the development and operation of medical applications or online healthcare platforms.
2. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for providing or sharing personal data of patients to third parties being other healthcare service providers, or health insurance or life insurance enterprises without receiving written requests from personal data subjects.
3. Additional sanction(s): Suspension of personal data processing operations directly related to the act of violation from 01 month to 03 months, for the act of violation specified in Clause 1 of this Article; and from 03 months to 06 months, for the act of violation specified in Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible establishment and application of security measures and access decentralization in accordance with technical regulations for systems of collecting health or biometric data; forcible provision of implementation evidence to competent agencies, for the act of violation specified at Point b, Clause 1 of this Article;
b) Forcible requirement to request the third party to destroy and irrecoverably delete all unlawfully received personal data, and to provide evidence of such implementation to the competent agency, for the act of violation specified in Clause 2 of this Article;
c) Forcible disgorgement of illegal proceeds from the commission of the violations specified in Clause 2 of this Article.
Article 63. Violations of regulations on personal data protection in advertising service business
1. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Collecting and using basic personal data for advertising delivery without the consent of personal data subjects;
b) Organizations and individuals doing business in advertising services failing to provide transparent and accessible technical mechanisms and methods for personal data subjects to exercise the right to refuse to receive advertisements or withdraw consent to share personal data for advertising purposes;
c) Establishing default methods of consent to provide personal data of personal data subjects to affiliate advertising networks;
d) Intentionally sharing user profiles with third parties for the purpose of doing business in advertising services when users have performed refusal operations.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Collecting and using sensitive personal data for advertising delivery without the consent of personal data subjects;
b) Conducting advertising services based on personal data of children under 16 years of age without the consent of their legal representatives;
c) Collecting personal data by tracking websites, portals, or applications for behavioral, targeted, or personalized advertising without the consent of personal data subjects;
d) Failing to establish a mechanism allowing personal data subjects to opt out of sharing personal data for behavioral, targeted, or personalized advertising;
dd) Intentionally storing, or failing to delete or destroy personal data when such data are no longer necessary for processing purposes in accordance with law.
3. Additional sanction(s): Suspension of operations of advertising service provision directly related to the violations from 01 month to 03 months for the acts of violation specified in Clause 1; from 03 months to 06 months for the acts of violation specified in Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal data unlawfully collected or used for advertising distribution, for the acts of violation specified in Clause 1 and Clause 2 of this Article;
b) Forcible disgorgement of proceeds from the commission of the acts of violation specified in Clause 1 and Clause 2 of this Article;
c) Forcible establishment and provision for users of a mechanism to refuse to receive advertisements and withdraw consent for data sharing in accordance with regulations, and forcible provision of implementation evidence to competent agencies, for the act of violation specified at Point b, Clause 1 of this Article.
Article 64. Violations of regulations on personal data protection in financial, banking, and credit information activities
1. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for the following acts:
a) Failing to notify or late notifying beyond the 72-hour time limit the specialized personal data protection agency and personal data subjects from the time of detecting a sensitive personal data leakage or loss incident;
b) Failing to ensure that all minimum details as specified by law are included in the personal data protection breach incident notification;
c) Failing to record system logs of all personal data processing activities or failing to conduct annual periodic compliance evaluations in accordance with regulations;
d) Failing to establish personal data recovery solutions upon the occurrence of a personal data loss incident;
dd) Failing to apply technical standards and regulations on personal data protection, or technical regulations on personal data de-identification and anonymization in accordance with regulations;
e) Failing to clearly specify required information specified in Clause 2, Article 9 of the Law on Personal Data Protection in the requests for consent from personal data subjects.
2. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Using personal data subjects’ personal data to conduct credit scoring, credit rating, or creditworthiness evaluation activities without the consent of personal data subjects, unless the personal data processing does not require such consent;
b) Organizations conducting credit information activities without deploying managerial and technical measures to prevent unauthorized access, use, disclosure, or alteration of customers’ personal data;
c) Collecting personal data beyond the scope necessary to serve credit information activities, or collecting data from sources not permitted by law.
3. Additional sanction(s): Suspension of operations of provision of credit information, credit scoring, credit rating, and credit trustworthiness assessment services from 01 month to 03 months for the acts of violation specified in Clause 1; from 03 months to 06 months for the acts of violation specified in Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of credit scoring and rating results unlawfully created, for the act of violation specified at Point a, Clause 2 of this Article;
b) Forcible requirement to request partners and affiliates to destroy and irrecoverably delete unlawfully shared or transferred sensitive personal data, for the act of violation specified at Point b, Clause 2 of this Article;
Article 65. Violations of regulations on personal data protection concerning social network platforms and online communication services
1. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed on an organization providing social network services, online media services, and digital content platforms for committing any of the following acts:
a) Failing to clearly notify the contents of personal data collected when personal data subjects install and use social networks or online media services;
b) Failing to provide an option allowing users to reject the collection and sharing of data files (known as cookies);
c) Failing to provide a “do not track” option, or tracking activities on social networks and online media services only upon obtaining user consent;
d) Failing to publicly disclose a privacy policy, or failing to clearly and comprehensibly explain how personal data is collected, used, stored, and shared;
dd) Failing to provide users with mechanisms to access, rectify, or delete personal data, configure privacy settings for their personal accounts, and report security and privacy violations;
e) Failing to clearly notify contents of personal data to be collected when the data subject installs and uses the application;
2. A fine from VND 70,000,000 to VND 150,000,000 shall be imposed for any of the following acts:
a) Compelling users to provide images or videos containing full or partial identity documents as a mandatory condition to authenticate ordinary accounts in case specialized laws do not require identification;
b) Using undisclosed technological features of OTT applications or social networks to eavesdrop, record calls, read text messages, or automatically extract contacts or media files from devices without the consent of personal data subjects, unless otherwise specified by law;
c) Unlawfully collecting personal data beyond the scope agreed upon with users when installing the service.
3. Additional sanction(s): Suspension of operations of service provision of digital applications and platforms in Vietnam from 01 month to 03 months for the acts of violation specified in Clause 1; from 03 months to 06 months for the acts of violation specified in Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible establishment and provision for users of features to refuse tracking and sharing cookies; forcible provision of implementation evidence to competent agencies, for the acts of violation specified at Points b and c, Clause 1 of this Article;
b) Forcible destruction or irrecoverable deletion of personal data, identity papers, contacts or files unlawfully collected or extracted, for the acts of violation specified in Clause 2 of this Article.
Article 66. Violations of regulations on personal data protection in big data processing
1. A fine from VND 20,000,000 to VND 30,000,000 shall be imposed for any of the following acts:
a) Processing big data containing personal data without formulating an appropriate policy on personal data storage, erasure, and destruction in accordance with the law;
b) Failing to have a written agreement with third parties, partners, and service providers to ensure full compliance with regulations on personal data protection;
c) Failing to organize periodic training, dissemination, and awareness raising on personal data security for personnel, especially personnel directly processing data.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Failing to have a notification mechanism or failing to properly explain to personal data subjects regarding the incorporation of their data into big data analytics systems;
b) Failing to use strong authentication methods (at least multi-factor authentication) or failing to segregate access rights to ensure that only authorized persons can access data;
c) Failing to conduct continuous monitoring or failing to use monitoring tools to track access activities and detect abnormal behaviors;
d) Failing to conduct periodic cybersecurity and data protection inspections and assessments to detect, prevent, and fix security vulnerabilities;
dd) Failing to encrypt or anonymize personal data during data transfer and provision, unless otherwise specified by specialized law.
3. A fine from VND 50,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Operating big data systems that make automated decisions affecting security, order, or the lawful rights and interests of organizations or individuals without establishing an oversight mechanism or without permitting requests for human re-evaluation;
b) Using or developing big data systems processing personal data for the purpose of harming security and order, or infringing upon the honor, dignity, or property of other individuals.
4. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means directly used to commit the acts of violation specified in Clause 2 and Clause 3 of this Article;
b) Suspension of the operation of big data analysis systems and application platforms related to personal data processing from 03 months to 06 months for the act of violation specified in Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible establishment, promulgation and disclosure of policies on archiving, deleting and destroying personal data and personal data protection measures in organizations in accordance with law; forcible supplementation and modification of agreements with third parties, partners and service providers to assure compliance with regulations on personal data protection; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article;
b) Forcible application of appropriate technical and organizational security measures, including multi-factor authentication, access decentralization, encryption and anonymization of personal data in the course of data transfer and provision; forcible provision of full and transparent information to personal data subjects on the inclusion of their data in big data analysis systems; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 2 of this Article;
c) Forcible cessation of personal data processing activities in contravention of regulations until the violations are remedied and confirmed by competent agencies; forcible destruction or irrecoverable deletion of personal data unlawfully processed; forcible full implementation of rights of personal data subjects, including the right to request a reassessment of automated decisions;
d) Forcible disgorgement of proceeds from the act of violation specified in Clause 3 of this Article.
Article 67. Violations of regulations on personal data protection in artificial intelligence systems and metaverses
1. A fine from VND 20,000,000 to VND 50,000,000 shall be imposed for processing personal data in artificial intelligence systems or metaverses but failing to conduct compliance assessments of regulations on personal data protection periodically once a year.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Failing to notify or explain the operating principles of automated algorithms and their impact on the lawful rights and interests of personal data subjects;
b) Failing to provide tools or mechanisms for personal data subjects to exercise the right to opt out of automated data processing;
c) Failing to ensure personal data subjects the rights to rectify, anonymize, or delete identification profiles;
d) Failing to classify artificial intelligence systems according to risk levels to establish appropriate personal data protection measures;
dd) Failing to apply personal data protection measures when using artificial intelligence inference results to identify or assist in identifying a specific individual;
e) Developing or deploying artificial intelligence or metaverse systems without building systems that meet comprehensive cybersecurity and data protection standards, or without establishing early warning and monitoring systems for cybersecurity risks;
g) Failing to apply appropriate authentication and identification methods or failing to segregate access rights for processing personal data in the system.
3. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for any of the following acts:
a) Failing to establish mechanisms to control and prevent the abuse of artificial intelligence or the metaverse for activities infringing upon national security or social order and safety;
b) Developing or operating artificial intelligence or metaverse systems that make automated decisions affecting security, order, or the lawful rights and interests of organizations or individuals without establishing an oversight mechanism or without permitting requests for human re-evaluation;
c) Using or developing artificial intelligence or metaverse systems for the purpose of harming security and order, or infringing upon the honor, dignity, or property of other individuals.
4. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means including those directly used to commit the acts of violation specified in Clause 2 and Clause 3 of this Article;
b) Suspension of the operation of artificial intelligence and metaverse systems and application platforms related to personal data processing from 03 months to 06 months for the act of violation specified in Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible establishment, promulgation and full implementation of mechanisms to notify and explain algorithms’ operating principles to personal data subjects; forcible provision of tools and mechanisms for personal data subjects to exercise the right to refuse automated processing, and the right to rectify, anonymize and delete identification profiles; forcible application of appropriate technical and organizational security measures, including risk classification, identity authentication, access decentralization, and protection of personal identification inference results; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 2 of this Article;
b) Forcible cessation of personal data processing activities in contravention of regulations until the violations are remedied and confirmed by competent agencies; forcible destruction or irrecoverable deletion of personal data unlawfully processed; forcible full implementation of rights of personal data subjects, including the right to request a reassessment of automated decisions;
c) Forcible disgorgement of proceeds from the acts of violation specified in Clause 3 of this Article.
Article 68. Violations of regulations on personal data protection in blockchain technology
1. A fine from VND 20,000,000 to VND 50,000,000 shall be imposed for processing personal data in blockchain technology but failing to conduct compliance assessments of regulations on personal data protection periodically once a year.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Failing to apply encryption algorithms, hashing algorithms, or digital signature algorithms to ensure safety when processing personal data on blockchains;
b) Failing to apply appropriate authentication and identification methods or failing to segregate access rights for processing personal data.
3. A fine from VND 70,000,000 to VND 150,000,000 shall be imposed for using blockchain technology to directly store personal data (plaintext) on blockchain networks without implementing de-identification processes or using data hashing algorithms.
4. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means directly used to commit the acts of violation specified in Clause 2 and Clause 3 of this Article;
b) Suspension of the operation of blockchain systems and application platforms related to personal data processing from 03 months to 06 months for the act of violation specified in Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible application of appropriate technical and organizational security measures, including the application of encryption algorithms, hashing and digital signatures to assure safety; forcible establishment of identity authentication and access decentralization methods in accordance with regulations; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 2 of this Article;
b) Forcible cessation of plaintext personal data storage activities on blockchain networks until the violations are remedied and confirmed by competent agencies;
c) Forcible application of technical measures to eliminate unlawfully and originally stored personal data on blockchains to the extent of unidentifiability;
d) Forcible disgorgement of proceeds from the act of violation specified in Clause 3 of this Article.
Article 69. Violations of regulations on personal data protection in cloud computing
1. A fine from VND 20,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Providing cloud computing services without providing information on personal data protection departments and officers to partners and relevant parties;
b) Organizations using cloud computing services failing to clearly define personal data processing flows, roles, and responsibilities of the parties in contracts with service providers, or failing to include technical and organizational security measure requirements in contracts;
c) Cloud computing service providers failing to require or bind subcontractors to perform personal data protection regulations and obligations;
d) Failing to formulate appropriate policies on personal data storage, erasure, and destruction;
dd) Cloud computing service providers failing to conduct compliance assessments regarding personal data protection regulations once every 01 year.
2. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Providing or using cloud computing services without applying technical and organizational measures to prevent unauthorized access to personal data;
b) Providing or using cloud computing services without encrypting customers’ personal data at rest (in storage) and in transit;
c) Failing to apply appropriate authentication and identification methods or failing to strictly segregate access rights for processing personal data on cloud computing;
d) Organizations using cloud computing services failing to notify relevant parties when system or infrastructure changes occur that may affect personal data safety.
3. A fine from VND 70,000,000 to VND 100,000,000 shall be imposed for using or developing cloud computing systems for the purpose of causing harm to security and order, or infringing upon the honor, dignity, and property of other individuals.
4. Additional sanction(s):
a) Confiscation of administrative violation material evidence or means directly used to commit the acts of violation specified in Clause 2 and Clause 3 of this Article;
b) Suspension of the operation of cloud computing systems and application platforms related to personal data processing from 03 months to 06 months for the act of violation specified in Clause 3 of this Article.
5. Remedial measure(s):
a) Forcible establishment, promulgation and disclosure of policies on archiving, deleting and destroying personal data in accordance with law; forcible supplementation and modification of contracts with cloud computing service providers, and requests for subcontractors to fully implement personal data protection regulations and obligations in accordance with law; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 1 of this Article;
b) Forcible application of appropriate technical and organizational security measures, including personal data encryption at rest and in transit, identity authentication, strict access decentralization, and measures to prevent unlawful access; forcible provision of implementation evidence to competent agencies, for the acts of violation specified in Clause 2 of this Article;
c) Forcible cessation of personal data processing activities in contravention of regulations until the violations are remedied and confirmed by competent agencies; forcible destruction or irrecoverable deletion of personal data unlawfully processed;
d) Forcible disgorgement of proceeds from the acts of violation specified in Clause 3 of this Article.
Article 70. Violations of regulations on personal data protection concerning personal location data and biometric data
1. A fine from VND 50,000,000 to VND 70,000,000 shall be imposed for any of the following acts:
a) Providing platforms or mobile applications that collect personal location data without notifying users of the use of personal location data;
b) Failing to have technical measures to prevent the collection of personal location data by unrelated third parties, or failing to provide users with personal location tracking options;
c) Collecting or processing biometric data without establishing physical security measures for systems and devices storing and transmitting biometric data;
d) Failing to restrict access rights or failing to have a monitoring system to prevent infringing acts against personal location data and biometric data;
dd) Failing to notify the specialized personal data protection agency and affected data subjects within 72 hours from the time of detecting a personal data breach incident involving location data or biometric data;
e) Notifications to affected data subjects failing to include the minimum required contents in accordance with the law;
g) Failing to record, store, and update violation dossiers to serve inspection, examination, and handling activities; failing to ensure the retention of violation dossiers for a minimum period of 05 years from the date the incident is fully remedied;
h) Failing to publicly announce via the organization’s official electronic channels on websites or applications, or failing to send notifications to relevant personal data subjects when technical conditions permit in case it is impossible to notify all affected personal data subjects within the prescribed time limit due to technical or emergency reasons.
2. A fine from VND 70,000,000 to VND 150,000,000 shall be imposed for any of the following acts:
a) Installing or using location tracking technologies via radio frequency identification (RFID) tags and other technologies without the consent of personal data subjects or without a request from competent agencies as provided by law, unless otherwise specified by law;
b) Exploiting or using biometric data of personal data subjects beyond the original purpose without obtaining consent.
3. Additional sanction(s):
a) Confiscation of transmitting devices, RFID tags, collection devices, and biometric storage servers used to commit the acts of violation specified in Clause 2 of this Article;
b) Suspension of the operation of location tracking systems and application platforms related to personal data processing from 03 months to 06 months for the act of violation specified in Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of personal location data and biometric data unlawfully collected or tracked, for the acts of violation specified in Clause 2 of this Article;
b) Forcible provision for users of options to enable/disable personal location data collection; forcible provision of implementation evidence to competent agencies, for the act of violation specified at Point b, Clause 1 of this Article.
Article 71. Violations of regulations on personal data protection collected from audio and video recording activities in public places
1. A fine from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following acts:
a) Installing or using audio and video recording equipment in public spaces or customer service areas without applying notification or warning forms via physical signs or electronic means in easily recognizable locations so that personal data subjects understand they are being recorded;
b) Failing to provide contact information of the Personal Data Controller or Personal Data Controller and Processor upon the request of personal data subjects to retrieve their images, unless otherwise specified by law.
2. A fine from VND 30,000,000 to VND 50,000,000 shall be imposed for any of the following acts:
a) Using personal data, images, or voices obtained from public camera surveillance systems for commercial purposes, behavioral analysis, or automated facial recognition for personal profiling without the lawful consent of personal data subjects;
b) Unlawfully extracting, sharing, or publicly disclosing audio or video recording data, unless provided upon the written request of competent agencies.
3. Additional sanction(s): Confiscation of administrative violation material evidence or means, for the acts of violation specified in Clause 2 of this Article.
4. Remedial measure(s):
a) Forcible destruction or irrecoverable deletion of audio or image data collected in contravention of regulations, for the acts of violation specified in Clause 1 and Clause 2 of this Article;
b) Forcible establishment and disclosure of contact information of Personal Data Controllers so that personal data subjects can request image retrieval; forcible provision of implementation evidence to competent agencies, for the act of violation specified at Point b, Clause 1 of this Article.
Chapter III
COMPETENCE TO MAKE RECORDS OF ADMINISTRATIVE VIOLATIONS AND SANCTION ADMINISTRATIVE VIOLATIONS
Article 72. Competence to sanction administrative violations of the People’s Public Security
1. People’s Public Security officers on duty have the competence to:
a) Issue cautions;
b) Impose fines up to VND 20,000,000 for administrative violations in the field of cybersecurity, and up to 10% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause.
2. Chiefs of Commune-level Police have the competence to:
a) Issue cautions;
b) Impose fines up to VND 100,000,000 for administrative violations in the field of cybersecurity, and up to 50% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
3. Heads of professional divisions under the Department of Foreign Security, the Department of Internal Security, the Department of Internal Political Security, the Department of Economic Security, the Department of Cybersecurity and Hi-tech Crimes, the Immigration Department, the Office of the Investigation Police Agency, the Police Department for Investigation of Social Order-Related Crimes, the Police Department for Administrative Management of Social Order, the Police Department for Investigation of Corruption, Economic and Smuggling Crimes, the National Data Center; Heads of divisions under provincial-level Police Departments, including: Heads of the Foreign Security Divisions, Heads of the Internal Security Divisions, Heads of the Internal Political Security Divisions, Heads of the Economic Security Divisions, Heads of the Cybersecurity and Hi-tech Crime Divisions, Chiefs of the Offices of the Investigation Police Agencies, Heads of the Police Divisions for Investigation of Social Order-Related Crimes, Heads of the Police Divisions for Investigation of Corruption, Economic and Smuggling Crimes, Heads of the Police Divisions for Administrative Management of Social Order, Heads of the Criminal Police Divisions have the competence to:
a) Issue cautions;
b) Impose fines up to VND 160,000,000 for administrative violations in the field of cybersecurity, and up to 80% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
4. Heads of the Immigration Management Divisions under the provincial-level Public Security Departments have the competence to impose sanctions as specified in Clause 3 of this Article and have the right to decide on the application of the sanctioning form of expulsion.
5. Directors of the provincial-level Public Security Departments have the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the sanctioning form of expulsion;
e) Apply the remedial measures specified in Article 5 of this Decree.
6. The Director of the Department of Foreign Security; the Director of the Department of Internal Security; the Director of the Internal Political Security Department; the Director of the Economic Security Department; the Director of the Department of Cybersecurity and Hi-tech Crimes; the Chief of the Office of the Investigation Police Agency; the Director of the Police Department for Investigation of Social Order-Related Crimes; the Director of the Police Department for Investigation of Corruption, Economic and Smuggling Crimes; the Director of the Police Department for Administrative Management of Social Order; the Director of the Criminal Police Department; the Director of the National Data Center have the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
7. The Director of the Immigration Department has the competence to impose sanctions as specified in Clause 6 of this Article and decide on the application of the sanctioning form of expulsion.
Article 73. Competence to sanction administrative violations of Chairpersons of People’s Committees at all levels
1. Chairpersons of the Commune-level People’s Committees have the competence to:
a) Issue cautions;
b) Impose fines up to VND 100,000,000 for administrative violations in the field of cybersecurity, and up to 50% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
2. Chairpersons of the provincial-level People’s Committees have the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
Article 74. Competence to sanction administrative violations of Inspectorates
1. Inspectors of the ministries including: The Ministry of National Defence, the Ministry of Public Security, have the competence to:
a) Issue cautions;
b) Impose fines up to VND 20,000,000 for administrative violations in the field of cybersecurity, and up to 10% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause.
2. Heads of inspection teams at the military region level, the Hanoi Capital High Command, and provincial-level Public Security Departments have the competence to:
a) Issue cautions;
b) Impose fines up to VND 100,000,000 for administrative violations in the field of cybersecurity, and up to 50% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause.
3. Chief national defense inspectors of military regions; Chief national defense inspector of the Hanoi Capital High Command, Provincial-level chief public security inspectors assigned to perform inspection and examination tasks within the state management scope of ministries and ministerial-level agencies have the competence to:
a) Issue cautions;
b) Impose fines up to VND 160,000,000 for administrative violations in the field of cybersecurity, and up to 80% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
4. Chief Inspectors of the Ministry of National Defence, the Ministry of Public Security, and the State Bank of Vietnam; heads of inspection teams established by the Chief Inspectors of the Ministry of National Defence and the Ministry of Public Security have the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
Article 75. Competence to sanction administrative violations of the Border Guard
1. Border Guard officers on duty have the competence to:
a) Issue cautions;
b) Impose fines up to VND 10,000,000 for administrative violations in the field of cybersecurity, and up to 5% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause.
2. Station chiefs and team commanders of the Border Guard have the competence to:
a) Issue cautions;
b) Impose fines up to VND 20,000,000 for administrative violations in the field of cybersecurity, and up to 10% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
d) Apply the remedial measures specified at Points a and e, Clause 1, Article 28 of the Law on Handling of Administrative Violations.
3. Captains of the Drug Crime Prevention and Control Task Force Teams under the Drug Crime Prevention and Control Task Force Units have the competence to:
a) Issue cautions;
b) Impose fines up to VND 30,000,000 for administrative violations in the field of cybersecurity, and up to 15% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
d) Apply the remedial measures specified at Points a and e, Clause 1, Article 28 of the Law on Handling of Administrative Violations.
4. Chiefs of the Border Guard stations, Commanders of the Border Guard naval divisions, Commanders of the Guard Commands of port border gates have the competence to:
a) Issue cautions;
b) Impose fines up to VND 60,000,000 for administrative violations in the field of cybersecurity, and up to 30% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
d) Apply the remedial measures specified in Article 5 of this Decree.
5. Commanders of the Drug Crime Prevention and Control Task Force Units under the Drug and Crime Prevention and Control Department under the Border Guard High Command has the competence to:
a) Issue cautions;
b) Impose fines up to VND 100,000,000 for administrative violations in the field of cybersecurity, and up to 50% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
dd) Apply the remedial measures specified in Article 5 of this Decree.
6. Commanders of Border Guard Commands; Commanders of Border Guard naval units; the Director of the Drug and Crime Prevention and Control Department under the Border Guard High Command have the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
dd) Apply the remedial measures specified in Article 5 of this Decree.
Article 76. Competence to sanction administrative violations of the Coast Guard
1. Coast Guard officers on duty have the competence to:
a) Issue cautions;
b) Impose fines up to VND 10,000,000 for administrative violations in the field of cybersecurity, and up to 5% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause.
2. Leaders of the Coast Guard Professional Groups have the competence to:
a) Issue cautions;
b) Impose fines up to VND 20,000,000 for administrative violations in the field of cybersecurity, and up to 10% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause.
3. Captains of the Coast Guard Professional Teams, Heads of the Coast Guard Stations have the competence to:
a) Issue cautions;
b) Impose fines up to VND 40,000,000 for administrative violations in the field of cybersecurity, and up to 20% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
d) Apply the remedial measures specified at Points a and e, Clause 1, Article 28 of the Law on Handling of Administrative Violations.
4. Commanders of the Coast Guard Flotillas have the competence to:
a) Issue cautions;
b) Impose fines up to VND 60,000,000 for administrative violations in the field of cybersecurity, and up to 30% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Confiscate administrative violation material evidence or means with a value of not exceeding 02 times the fine level specified at Point b of this Clause;
d) Apply the remedial measures specified in Article 5 of this Decree.
5. Commanders of the Coast Guard Squadrons; Commanders of the Reconnaissance Units, Commanders of the Anti-Drug Special Task Units under the Vietnam Coast Guard have the competence to:
a) Issue cautions;
b) Impose fines up to VND 100,000,000 for administrative violations in the field of cybersecurity, and up to 50% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
6. Commanders of the Coast Guard Region Commands, the Director of the Professional and Legal Department under the Vietnam Coast Guard have the competence to:
a) Issue cautions;
b) Impose fines up to VND 160,000,000 for administrative violations in the field of cybersecurity, and up to 80% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
7. The Commander of the Vietnam Coast Guard has the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
Article 77. Competence of agencies performing state management tasks by specialized fields and sectors, and certain other titles
1. Directors of the provincial-level Departments of Culture, Sports and Tourism; Directors of the provincial-level Departments of Science and Technology; Directors of the provincial-level Departments of Industry and Trade; heads of inspection teams established by the Director of the Authority of Broadcasting and Electronic Information have the competence to:
a) Issue cautions;
b) Impose fines up to VND 160,000,000 for administrative violations in the field of cybersecurity, and up to 80% of the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
2. Chief of Office of the Ministry of Science and Technology; Heads of inspection teams assigned by the Minister of Science and Technology; Chief of Office of the Ministry of Culture, Sports and Tourism; Chief of Office of the Ministry of Industry and Trade; Director General of the Vietnam Telecommunications Authority; Director General of the E-Commerce and Digital Economy Agency; Director General of the Authority of Press; Director General of the Authority of Broadcasting and Electronic Information have the competence to:
a) Issue cautions;
b) Impose fines up to VND 200,000,000 for administrative violations in the field of cybersecurity, and up to the maximum fine level for the field of personal data protection specified in Chapter II;
c) Deprive the right to use licenses for a definite term or suspension of operations for a definite term;
d) Confiscate administrative violation material evidence or means;
dd) Apply the remedial measures specified in Article 5 of this Decree.
Article 78. Determination of sanctioning competence
1. The competent persons of the People’s Public Security Forces have the competence to sanction administrative violations and apply remedial measures for the administrative violations specified in Chapter II of this Decree in accordance with the competence specified in Article 72, Article 74 of this Decree and their assigned functions, tasks and powers within the sectors and localities under their management.
2. Chairpersons of the People’s Committees at all levels have the competence to sanction administrative violations and apply remedial measures for the administrative violations specified in Chapter II of this Decree in accordance with the competence specified in Article 73 of this Decree and their assigned functions, tasks and powers within the sectors and localities under their management.
3. The National Defense Inspectorate, the Inspectorate of the State Bank of Vietnam; the Border Guard High Command; the High Command of the Vietnam Coast Guard have the competence to sanction administrative violations and apply remedial measures for the administrative violations specified in Chapter II of this Decree within the scope of their assigned tasks and public duties in accordance with the competence specified in Articles 74, 75, 76 of this Decree and their assigned functions, tasks and powers within the sectors and localities under their management.
4. Heads of agencies performing state management tasks by specialized fields and sectors shall have the competence to sanction administrative violations and apply remedial measures for the administrative violations specified in Chapter II of this Decree, in accordance with the competence specified in Article 77 of this Decree and the assigned functions, tasks, and powers within the fields and localities under their management.
Article 79. Competence to make records of administrative violations
1. Persons having the competence to sanction administrative violations specified in Article 72, Article 73, Article 74, Article 75, Article 76, Article 77 of this Decree.
2. Inspectors when performing inspections in the fields under the scope of regulation of this Decree; civil servants, public employees, personnel of the People’s Army, the People’s Public Security Forces, and agencies performing state management tasks specified in Article 77 of this Decree who are on official duty or performing tasks in the fields of cybersecurity and personal data protection shall have the competence to make written records of administrative violations for administrative violations in accordance with their assigned functions, tasks, and powers.
Chapter IV
IMPLEMENTATION PROVISIONS
Article 80. Effect
This Decree takes effect from August 19, 2026.
Article 81. Transitional provisions
1. For administrative violations in the fields of cybersecurity and personal data protection committed before the effective date of this Decree, which are subsequently detected or currently being considered and resolved, the Government’s Decrees on sanctioning of administrative violations in force at the time of commission of such violations shall apply; in case this Decree does not prescribe legal liability or prescribes a lighter legal liability for such violations, this Decree shall apply.
2. Administrative violations for which administrative violation records were made prior to the effective date of this Decree but sanctioning decisions have not been issued shall be handled as follows:
a) In case the time limit for issuing sanctioning decisions has not expired, the sanctioning and application of remedial measures shall be carried out on the principles specified in Clause 1 of this Article;
b) In case the statute of limitations for sanctioning administrative violations has expired or the time limit for issuing a sanctioning decision has expired in accordance with Point c, Clause 1, Article 65 of the Law on Handling of Administrative Violations, no sanctioning decision shall be issued, but the competent person must issue a decision on confiscation of administrative violation material evidence or means if such administrative violation material evidence or means are prohibited from possession or circulation, or are those for which the sanctioning form of confiscation is prescribed by law, and apply the remedial measures prescribed for such administrative violation; the application of the sanctioning form of confiscation of administrative violation material evidence or means and the application of remedial measures shall comply with the principles specified in Clause 1 of this Article.
3. Administrative sanctioning decisions issued prior to the effective date of this Decree that have not been fully executed shall continue to be executed.
4. For decisions on sanctioning administrative violations that have been promulgated or fully executed before the effective date of this Decree but the sanctioned individuals or organizations still lodge complaints, the regulations of the Law on Handling of Administrative Violations, the Government’s decrees on sanctioning of administrative violations, and relevant legal documents effective at the time of promulgating the sanctioning decisions shall be applied for settlement.
5. Sanctioning competence in transitional cases shall be determined as follows:
a) Administrative violation cases being handled and settled by competent persons prior to the effective date of this Decree where such persons remain competent to sanction under this Decree shall continue to be settled; in case handling persons no longer have competence or cases exceed sanctioning competence under this Decree, case files shall be transferred to competent sanctioning persons under this Decree for settlement. Written records of administrative violations, verification results, documents, and evidence made and collected in accordance with former regulations of law shall remain legally valid;
b) In case an agency or title holder with sanctioning competence specified in this Decree undergoes changes in name, functions, tasks, or powers due to organizational restructuring, the agency or title holder inheriting the corresponding functions, tasks, and powers shall exercise sanctioning competence in accordance with the provisions of this Decree.
Article 82. Responsibilities for implementation
1. The Minister of Public Security shall be responsible for monitoring, guiding and organizing the implementation of this Decree.
2. Ministers, Heads of ministerial-level agencies, Chairpersons of People’s Committees of provinces and centrally-governed cities, and relevant organizations and individuals shall be responsible for the implementation of this Decree./.
| ON BEHALF OF THE GOVERNMENT FOR THE PRIME MINISTER DEPUTY PRIME MINISTER
Pham Gia Tuc |
You are not logged in.
This feature is available to Advanced account holders. Please log in to access detailed information on Related documents.
If you do not have an account, please register here!
VIETNAMESE DOCUMENTS
This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here
This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here
ENGLISH DOCUMENTS
This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here
This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here