Vietnam proposes a 5% revenue fine for serious data security violations
- Evelyn Carter

- 5 hours ago
- 4 min read
Vietnam’s Ministry of Public Security is seeking public feedback on the draft Data Security Law, which proposes fines of up to 5% of the previous financial year’s revenue for organizations committing particularly serious violations involving important or core data. For certain multinational groups, the fine may be calculated based on global revenue.
A future data security violation in Vietnam may no longer be addressed only through a fixed administrative penalty, particularly when the offending organization has substantial revenue. The draft Data Security Law, which the Ministry of Public Security is collecting feedback on until August 9, 2026, proposes a revenue-based penalty mechanism intended to strengthen deterrence.
The proposal is not yet legally effective. However, the method used to calculate penalties indicates that data security is increasingly being treated as an enterprise-level financial, legal and governance risk, rather than solely as a technical responsibility of the IT department.
Why does Vietnam need stronger data security protection?
Vietnam is home to nearly 80 million Internet users, generating, storing and exchanging vast amounts of personal and sector-specific data every day. At the same time, data governance remains fragmented across different systems, while a comprehensive and unified data protection framework has yet to be fully established.

On average, the Ministry of Public Security detects more than 2,600 Vietnamese websites and online portals using the “.vn” domain each year that have been compromised by hackers through website defacement or the insertion of malicious files.
The illegal trade of personal data also continues to expand across online forums and communities. Authorities have identified 300 cases involving the sale of more than 1.7 million data records spanning multiple sectors, including healthcare, education, public services, banking, electricity, insurance, securities, citizen identification, transportation and telecommunications.
In one notable case, the Ministry of Public Security reported that hackers had stolen and offered for sale more than 160 million customer records belonging to the National Application Information Center under the State Bank of Vietnam.
What penalty mechanism is the Ministry of Public Security proposing?
The proposed maximum penalty would not exceed 5% of the violating organization’s total revenue in Vietnam during the immediately preceding financial year. For organizations that belong to multinational groups, if revenue generated in Vietnam is not proportionate to the scale and seriousness of the violation, the fine may be considered based on the group’s global revenue, although it would still be capped at 5%.
The draft also proposes technical enforcement measures, including bandwidth restrictions and the temporary suspension or termination of access to violating data flows within Vietnamese territory. These measures are intended to reduce the risk of continued data dissemination while the case is being handled.
Area | Proposal in the draft law |
Applicable entities | Organizations committing particularly serious violations |
Relevant data categories | Important data and core data |
Standard penalty basis | Revenue generated in Vietnam during the previous financial year |
Maximum fine | No more than 5% of revenue |
Multinational groups | Global revenue may be considered if Vietnam revenue is not proportionate |
Additional measures | Bandwidth restriction, temporary suspension or termination of access to violating data flows |
Legal status | Draft under public consultation and not yet effective |
Why should businesses prepare before the law is adopted?
The background information presented by the Ministry of Public Security indicates that data-related risks in Vietnam are increasing. In 2025, Vietnamese information systems reportedly faced approximately 552,000 cyberattacks, while 5,230 agencies and businesses were recorded as being affected.
Authorities also identified 300 data sale cases involving more than 1.7 million records from sectors including healthcare, education, banking, insurance, securities, logistics and telecommunications. Inspections conducted across seven ministries, sectors and local authorities reportedly uncovered more than 1,300 critical vulnerabilities and over 4,000 high-severity vulnerabilities in servers and information systems.

An employee with legitimate access may still transfer data through personal email, USB drives, cloud services, messaging applications or public AI tools.
IPSIP Vietnam has examined these data exfiltration channels and relevant controls in its article on preventing data leakage when employees leave an organization.
What should businesses do now?
Because the draft law has not yet been adopted, businesses cannot build a final compliance program based solely on the current consultation text. However, foundational data governance measures can be implemented immediately and will remain valuable even if the draft is revised.
Priority preparation checklist
Create an inventory of systems, databases, cloud storage environments and devices processing company data.
Assign a business owner to each major data category.
Classify data according to sensitivity and the impact of unauthorized disclosure, alteration or destruction.
Review access rights based on job roles and the principle of least privilege.
Enable multi-factor authentication for administrative accounts, cloud platforms, VPNs and critical systems.
Log downloads, file sharing, data exports, permission changes and deletion activities.
Configure alerts for unusual access patterns or large-scale data exports.
Control the use of personal email, USB drives, messaging applications and unapproved AI platforms.
Encrypt sensitive data both at rest and in transit.
Establish incident response, evidence preservation and breach-scope assessment procedures.
Organizations using Microsoft 365, CRM platforms or employee-owned devices should pay particular attention to the risk of data being synchronized to unmanaged applications or devices.
IPSIP Vietnam’s article on protecting data against leakage through Zalo PC and endpoint devices provides additional context on Endpoint DLP and device management.
What does IPSIP Vietnam’s expert perspective indicate?
Data can be compromised through vulnerability exploitation, credential theft, cloud misconfiguration, lost devices or insider activity. In some cases, attackers do not need to break into a system because authorized users can copy and transfer data outside the organization.
In addition to regulatory penalties, organizations may face operational disruption, forensic investigation costs, compensation obligations, customer complaints, intellectual property loss and reputational damage.
Which IPSIP Vietnam solutions are relevant?
Security Operations Center - SOC 24/7: Relevant for organizations that lack the resources to continuously monitor logs and respond to alerts. A SOC can centralize events from identities, endpoints, servers, cloud platforms and security systems to help identify unusual behavior.

Security Awareness Training: Appropriate where risk arises from user error or improper data-handling practices. IPSIP Vietnam’s enterprise cybersecurity training services can address data protection, phishing, AI usage, cloud platforms and mobile devices according to employee roles.









Comments