Decree 330/2026/ND-CP, effective from 19 August 2026, sets out specific administrative violations, penalties and remedial measures in the areas of cybersecurity and personal data protection. For businesses, this marks a shift from simply having policies in place to demonstrating effective controls and evidence of compliance.
Which businesses should pay attention?
Decree 330 has a broad scope of application, covering private enterprises, joint stock companies, limited liability companies, partnerships and their dependent units, as well as various other organizations and foreign entities falling within its scope.
In practice, organizations should conduct an immediate review if they engage in:
- Large-scale recruitment and workforce management.
- Direct retail, digital marketing, and customer relationship management (CRM).
- Cloud computing services or Software-as-a-Service (SaaS) platforms.
- Cross-border transfers of personal data (via overseas servers, parent entities, or international partners).
Compliance obligations vary based on the specific business activities, data categories handled, and processing practices of each entity.
3 key areas businesses should review
01 – Human Resources: Employee Data
Recruitment and employee records contain significant amounts of personal data and are often shared with recruitment agencies, payroll providers, insurers and other service providers. Businesses should review the legal basis for processing, purposes of use, access rights and the responsibilities of relevant parties. Certain violations in recruitment and employee management may be subject to fines of VND 50–70 million.
02 – Sales & Marketing: Collecting and Using Personal Data
Businesses should review the source of customer data, the purposes for which it is used, how consent is recorded and whether data is shared with third parties. Notably, Decree 330 provides for fines of VND 30–50 million for establishing a default mechanism whereby data subjects are deemed to have consented to the processing of personal data.
03 – Information Technology: Is Personal Data Being Transferred Overseas?
The use of cloud platforms, Software as a Service solutions and international technology platforms requires businesses to understand where personal data is stored, accessed and transferred. Where cross-border transfers of personal data are involved, businesses should review the applicable requirements concerning impact assessment documentation and other related obligations.
For certain serious violations, fines may reach 1%–5% of the total revenue generated in Vietnam in the preceding financial year.
4 actions management should take now
01 – Map data flows: Review the personal data lifecycle – collection → storage → use → sharing → transfer → deletion/destruction — and identify who has access to the data.
02 – Review the legal basis: Assess the legal basis for data processing, mechanisms for recording consent and agreements with data processors or third parties.
03 – Review impact assessment documentation: Determine whether the business is required to prepare a Personal Data Processing Impact Assessment (DPIA) and/or a Cross-Border Personal Data Transfer Impact Assessment.
04 – Prepare an incident response plan: Establish procedures for detecting, responding to, documenting and reporting data breaches. For cases subject to the notification requirements, businesses should note the 72-hour deadline from the time the violation is detected.
KTC Perspective: Data Compliance Is a Management Issue
Personal data protection is no longer solely an IT or legal matter. It is closely connected to internal controls, risk management, business continuity and management information.
Businesses need more than policies on paper. They need to be able to demonstrate: Where is the data collected from, who has access to it, who is it shared with, and how can the business demonstrate that these controls are actually working?
KTC can support businesses in reviewing internal control systems, identifying compliance gaps and assessing risks associated with data management processes, helping organizations proactively respond to evolving cybersecurity and personal data protection requirements.
Disclaimer: This article is for general information purposes only and does not constitute legal advice for any specific case.




