Key Concerns In Draft Cyber & PDP Sanctions Decree On Personal Data Protection
On 16 March 2026, the Ministry of Public Security (MPS) issued the draft decree on administrative sanctions in the fields of cybersecurity and personal data protection (the Draft Decree) for public consultation. It is the first step to put concrete penalties behind the PDPL 2025, which took effect on 1 January 2026 but left the enforcement details to the Government. The Draft covers a wide range of sectors, such as cybersecurity, personal data, AI, telecommunications, and digital signatures. This post focuses on the personal data provisions (Articles 57 to 69 of the Draft Decree), which raise potential concerns for businesses.
The Draft Decree states its fines at the rate applicable to individuals; organisations pay double (Article 6.1 of the Draft Decree). Unless stated otherwise, the amounts in this post are the organisation-level fines.
1. The DPIA/TIA mismatch - Filing penalties scaled by breach size
Articles 67 and 68 of the Draft Decree penalize failures relating to the data processing impact assessment (DPIA) and the cross-border transfer impact assessment (TIA) - both of which are procedural filing duties. Both then scale the penalty by the number of Vietnamese citizens whose data is leaked or lost. Article 68 makes the link to the filing duty explicit: Articles 68.2 to 68.3 apply to "conduct specified in clause 1 of this Article which results in" a leak or transfer at the relevant threshold, so a transferor that has complied is not exposed. Article 67 omits that link. On their face, Articles 67.2 to 67.4 impose fines on the act of leaking or losing data as a standalone violation.
We do not think that is what was intended. Article 67 is headed "Violations of regulations on personal data processing impact assessment"; the penalty in each of Articles 67.2 to 67.4 is expressed as a multiple of the fine under Article 67.1; and the additional sanctions and remedial measures in Articles 67.5 and 67.6 are attached exclusively to the conduct under Article 67.1. On a standalone reading, a leak affecting five million citizens would carry no licence suspension, no forced deletion and no disgorgement, while a missed filing deadline carries all three. That reading would also overlap with Article 57.2(h), which already penalises the intentional disclosure or loss of personal data, leaving two provisions to punish the same conduct. Read purposively, Articles 67.2 to 67.4 must be about the aggravated forms of the violation under Article 67.1.
The express formula "conduct specified in clause 1 of this Article" appears a dozen times elsewhere in the Draft Decree, which makes its absence from Article 67 conspicuous. It is not clear whether the standalone reading is what the drafter intends to convey in Article 67. If the final draft is still left as is, a data controller that has fully complied with its DPIA obligations is left to argue construction against the plain words of the provision it is charged under - and to do so before an enforcement officer working from the text.
2. Penalizing data subjects - Turning victims into violators
Article 58.1(a) of the Draft Decree proposes fines of VND 50 million to VND 70 million for individuals who "fail to protect their own personal data". The duty itself is not new: PDPL 2025 Article 4.2(a) already obliges data subjects to protect their own personal data, and Article 58.1 of the Draft Decree reproduces the four data subject obligations in Article 4.2 point for point. What is new is the sanction - the PDPL created the duty without attaching a penalty to it, and the Draft Decree now prices it at up to VND 70 million. Still, this provision shifts data subjects from victims of data theft into violators who are penalized for their own losses. While the rule may aim to increase public awareness of data security, it is overly severe and unrealistic for vulnerable groups, such as the elderly, who are frequent targets for scams and often lack technical knowledge. Crucially, neither the PDPL 2025 nor the Draft Decree provides a clear legal test for what "failing to protect" actually means, leaving significant scope for arbitrary enforcement. Notably, this is also not consistent with international framework like the GDPR since such regulations focus on protecting data subject and do not impose administrative penalties on individuals for failing to protect themselves.
3. Heavy penalties for minor or procedural breaches
Many violations in the Draft Decree are minor or purely procedural, yet the fines applicable to enterprises are very severe. For instance,
- a missed deadline for handling a data subject request can trigger a fine of up to VND 200 million (Article 58.2(b));
- a late or incomplete breach notification is subject to an administrative penalty of up to VND 100 million (Article 66); or
- failing to keep a dossier triggers penalties of up to VND 140 million (for DPIA dossier) to 200 million (for TIA dossier) (Article 67 and 68).
Beyond monetary fines, several articles authorize additional sanctions for these violations, including suspension of the business licence for one to three months and and suspension of all personal data processing activities for one to three months. For a data-driven business, those consequences may effectively amount to a shutdown. This may be inconsistent with the general principle that administrative penalties should be proportionate to the seriousness of the violation.
4. The Draft Decree overlooks the PDPL's own exemptions
The PDPL 2025 does not apply the DPIA, dossier-update and data protection officer duties to everyone. Household businesses and micro-enterprises are outside them altogether (Article 38.3). Small enterprises and startups may elect not to comply until 1 January 2031 (Article 38.2). Both carve-outs fall away if the business provides personal data processing services, directly processes sensitive personal data, or processes the data of a large number of data subjects. Separately, competent state agencies need not carry out a DPIA at all (Article 21.6), and several categories of cross-border transfer sit outside the TIA regime, including transfers by state agencies and an organisation's storage of its own employees' data on cloud services (Article 20.6).
Articles 67, 68 and 69 of the Draft Decree are drafted with no such carve-outs. On the face of the Draft Decree, a micro-enterprise that is permanently exempt from the DPIA duty, or a startup that has lawfully elected out of it, is still exposed to a fine of VND 100 million to VND 140 million under Article 67.1 for not having done the thing the statute excused it from.
We expect this to be addressed, since a decree should not impose a penalty for failing to discharge a duty the parent law does not impose.
5. Obligations that enterprises are not in a position to comply with
Article 57 of the Draft Decree converts the PDPL's statements of principle directly into conducts subject to fine. Article 57.1(g) of the Draft Decree penalizes a party whose data protection is "not associated with the protection of national and ethnic interests, service to socio-economic development, and the assurance of national defence, security and foreign relations" - language taken from the principles in Article 3 of the PDPL. Article 57.1(e) penalizes a failure to "proactively prevent, detect, stop, combat and promptly and strictly handle" every violation of personal data protection law.
Principles of this kind should be read to guide the construction of the law and the conduct of the State. They are not capable of objective proof, and an enterprise cannot audit itself against them. It is also unclear whether limbs (e) and (g) are directed at enterprises at all. Read literally they apply to any organisation processing personal data, yet neither describes something a private business should be expected to be in a position to do. For example, (i) proactively detecting and strictly handling every violation of personal data protection law is a function of the State, not of a data controller, and (ii) aligning one's data protection arrangements with national defence and foreign relations objectives is not a compliance standard a company can meaningfully be measured against. If these limbs are intended to apply to the specialised State agencies, they should say so.
6. Several inconsistencies with the PDPL 2025
The Draft Decree has several inconsistencies with the PDPL 2025, particularly:
· DPO appointment: PDPL 2025 requires every agency and organisation to designate a qualified data protection function or personnel, or to outsource the role to a personal data protection service provider (Article 33.2 of PDPL 2025). That duty is not framed by data category - it applies regardless of whether the data is basic or sensitive. The Draft Decree, however, sanctions only the failure to designate for sensitive personal data (Article 69.2 of the Draft Decree), and makes no allowance for the outsourcing option the PDPL 2025 expressly permits;
· Breach notification: While the PDPL 2025 only requires notification of a breach that "may harm national defense, national security, social order or safety, or infringe upon the life, health, honor, dignity or property of the data subject," within a 72-hour deadline (Article 23 of PDPL 2025), the Draft Decree penalizes all breaches and sets a shorter deadline of two working days (Article 66 of the Draft Decree).