//
AI / Technology

Vietnam Proposes Up to 1.5 Billion VND Fine for Individual Data Leaks in New Draft Law

Q
qnews24h
Pham Van Quynh
July 25, 2026 Updated July 25, 2026 0 views· 9 min read
Vietnam Proposes Up to 1.5 Billion VND Fine for Individual Data Leaks in New Draft Law
Vietnam's draft Data Security Law introduces strict individual liability and heavy administrative fines for critical data breaches. Source: Znews.vn / Pexels / NCS
Quick summary
  • Individual fines reach up to 1.5 billion VND while organizations face up to 3 billion VND for severe data security violations.
  • Personal legal liability applies to IT administrators, system engineers, public officials, and managers with data access rights.
  • Core national data transfers outside Vietnam are prohibited without explicit Government approval.
  • Data security and cybersecurity appraisals will be integrated into a single procedure, with compliance waivers for non-sensitive SMEs.

As Vietnam rapidly accelerates its national digital transformation, data has officially emerged as a critical strategic asset. However, with the exponential expansion of digital networks, public databases, and enterprise cloud infrastructure, the unauthorized exposure and exploitation of sensitive personal and national information have become pressing national security risks. To tackle these vulnerabilities head-on, the Ministry of Public Security has drafted the landmark Data Security Law, proposing unprecedented administrative fines of up to 1.5 billion VND for individuals and 3 billion VND for organizations that compromise vital data infrastructure. This statutory push signals a decisive transition toward uncompromising personal and enterprise accountability across the nation's technology ecosystem.

Quick summary

  • Record financial penalties: Individual violators face administrative fines of up to 1.5 billion VND, while organizations face up to 3 billion VND for severe data security infractions.
  • Expanded legal scope: Personal liability applies not only to data brokers or hackers, but also to IT administrators, system engineers, public officials, and corporate managers holding data access rights.
  • Strict cross-border transfers: Transferring core or critical national data outside Vietnam without explicit approval from the Government is strictly prohibited.
  • Streamlined compliance and SME relief: The draft integrates data security and cybersecurity appraisals into a single procedure while granting compliance waivers to non-sensitive small and medium enterprises.

Why it matters

For years, digital enterprises operating across emerging markets have often treated administrative fines for data breaches as a manageable cost of doing business—budgeting for occasional regulatory penalties rather than investing heavily in robust security architectures. The proposed Data Security Law fundamentally dismantles this calculation. By raising financial sanctions to 1.5 billion VND ($60,000 USD) for individuals and 3 billion VND ($120,000 USD) for legal entities, the Vietnamese government is making data negligence prohibitively expensive.

Furthermore, extending legal liability to system administrators, IT engineers, and corporate managers means that internal mismanagement carries direct personal consequences. Technical operators can no longer hide behind corporate immunity or institutional oversight failures. For domestic tech firms and multinational corporations alike, cross-border data residency protocols require immediate auditing, as unauthorized external transfers of core national data could trigger severe financial and legal penalties. Conversely, small and medium enterprises (SMEs) gain clear operational relief through targeted exemptions, ensuring that stringent compliance burdens do not stifle startup innovation or smaller commercial endeavors.

Background

Vietnam's regulatory landscape regarding cyber defense and digital assets has evolved rapidly over the past decade. Following the enactment of the Law on Cybersecurity in 2018 and the implementation of Decree 13/2023/ND-CP on Personal Data Protection, authorities have steadily tightened controls over how public and private entities collect, process, and retain digital information. However, systemic data leaks and cyber incidents targeting critical databases highlighted persistent gaps in operational security and individual liability.

In response, the Ministry of Public Security (MPS) spearheaded the drafting of the dedicated Law on Data Security. The draft legislation was placed under public consultation through August 9, with plans for formal submission to the National Assembly for review during its October session. A key aspect of this statutory evolution is the alignment of data safety regulations with broader national security frameworks, framing critical data breaches not merely as privacy infringements, but as threats to national defense and public infrastructure.

Sweeping Liability: Who Is Affected by the 1.5 Billion VND Fine?

Under the proposed draft, individual liability reaches far beyond criminal cybercriminals who trade or sell stolen datasets. The law explicitly encompasses IT engineers, system administrators, cloud architects, public sector officers, and corporate managers entrusted with data access or stewardship rights.

Specifically, heavy financial penalties will apply to several categories of misconduct:

  • Unauthorized exfiltration or transfer of core and critical data assets out of Vietnamese territory without prior approval from competent authorities.
  • Deployment of malicious code, malware installation, cyber espionage, or unlawful interference with national data centers and critical public databases.
  • Gross negligence or intentional bypass of standard data security protocols leading to high-impact data exposures.

For civil servants, public officers, and state enterprise employees, administrative fines will be accompanied by severe internal disciplinary actions. Penalties range from official reprimands and wage downgrades to immediate dismissal and permanent termination of employment, ensuring that both individual and structural deterrence are enforced within government bodies.

Data security and IT administration

Strict Cross-Border Data Transfers and Quantum Cyber Preparedness

One of the most consequential chapters of the draft law governs the residency and cross-border flow of critical digital assets. Under the proposed provisions, data classified as "core data" or "important data"—which includes key national infrastructure metrics, sovereign statistics, and defense-related assets—cannot be exported or hosted outside Vietnam’s borders without explicit sanction from the Government. Overseas transfers will only be allowed under exceptional circumstances serving paramount national interests.

Simultaneously, regulators are looking ahead to future cyber threats, specifically the long-term risk posed by developments in quantum computing. As quantum processing capabilities threaten to break existing encryption standards, the draft legislation creates a framework for mandating post-quantum cryptographic standards to keep critical databases resilient against next-generation decryption techniques.

To prevent unnecessary administrative delays for businesses, the draft unifies data security appraisals with existing cybersecurity review procedures. Rather than navigating separate regulatory approvals, enterprises will undergo a single streamlined appraisal process overseen by state security authorities.

Security Operations Center

Targeted Relief for Small and Medium Enterprises (SMEs)

Recognizing that overly rigid compliance mandates could overburden smaller businesses, the draft law introduces a proportional relief mechanism for micro, small, and medium enterprises (MSMEs).

SMEs that do not process large-scale data volumes and do not manage core or important national data will benefit from reduced regulatory burdens. Specifically, these enterprises will be exempted from mandatory lifecycle risk assessments and complex third-party data security audits. This proportional approach aims to prevent excessive financial stress on early-stage startups while focusing state enforcement resources strictly on high-risk, data-intensive industries such as banking, telecommunications, healthcare, and public administration.

Qnews24h insight

The draft Data Security Law marks a significant maturation of Vietnam's digital sovereignty and cybersecurity policy. By capping individual administrative fines at 1.5 billion VND and corporate fines at 3 billion VND, the Ministry of Public Security is addressing the widespread tendency among organizations to view security compliance as a secondary priority. However, the long-term success of this legislation will depend on clear operational guidelines and balanced administrative enforcement.

Key issues to watch include:

  • Clear definitions of "Core" and "Important" Data: Explicit technical criteria are necessary so that international cloud providers and domestic tech firms can determine compliance requirements without disrupting normal digital trade.
  • Proportional personal liability: Holding IT administrators personally liable requires a clear distinction between deliberate malpractice and security incidents resulting from inadequate corporate security budgets.
  • Administrative efficiency: Merging data security and cybersecurity appraisals into a single procedure is a positive step, provided regulatory reviews match the fast pace of technological innovation.

Ultimately, while compliance stakes are rising significantly, this legislative initiative provides a clear framework for Vietnam to establish a secure and resilient digital economy.

Sources

Frequently Asked Questions (FAQ)

What is the maximum fine for individuals under Vietnam's draft Data Security Law?

Individuals violating data security regulations face administrative fines of up to 1.5 billion VND (approximately $60,000 USD), alongside potential internal disciplinary actions such as wage reductions or dismissal for public sector employees.

Who can be held personally liable for critical data breaches under this law?

Liability extends beyond external hackers to include IT engineers, system administrators, corporate managers, state officials, and any authorized personnel managing critical data systems.

Are small businesses required to perform full data security audits under the draft law?

No. Micro, small, and medium enterprises (MSMEs) that do not handle core or important national data and do not process data on a large scale are exempted from complex risk assessments and mandatory third-party audits.

Why it matters

The draft law removes the ability for enterprises to treat data breach fines as a standard cost of doing business. By establishing high financial penalties and personal accountability for IT administrators and managers, it incentivizes immediate investment in secure data architectures while protecting non-sensitive SMEs from heavy compliance costs.

Background

Following the enactment of the 2018 Law on Cybersecurity and Decree 13/2023/ND-CP on Personal Data Protection, Vietnam has continuously reinforced its digital regulatory framework. The Ministry of Public Security introduced this dedicated draft Data Security Law after recent cyber threats demonstrated the need for stricter operational oversight and clearer individual liability regarding critical public and enterprise databases.

Qnews24h perspective

The proposed law represents a firm step toward digital sovereignty and cyber resilience. Success will depend on clear technical classifications for 'core data' and ensuring that personal liability for IT staff distinguishes between intentional negligence and systemic corporate underfunding.

References

Editorial information

XH
Qnews24h Editorial Team
Editorial desk

The editorial team reviews sources, adds context, and structures stories so readers can understand the news more clearly.

Article from QNEWS24H

Share:

Comments

(0)
User
You need to sign in to comment.
0/500

No comments yet. Be the first to share your thoughts.