TL;DR: The proposed data security fine Vietnam businesses now face comes from Vietnam's Ministry of Public Security (Bo Cong An - MPS), which has proposed a new data security decree that would impose maximum fines of up to 5% of total annual revenue for serious violations involving specially protected data categories.
A companion draft amendment to Decree 147/2024/ND-CP would require all social media and online gaming accounts in Vietnam to be identity-verified against a phone number or national ID card (CCCD/CMND). Together, these proposals raise the financial stakes of data non-compliance to GDPR-equivalent levels and directly increase the value of investing in compliant identity verification infrastructure. DataCore's eKYC Service and People Data Service are built to help Vietnamese businesses meet exactly these requirements.
Table of Contents
- What exactly is Vietnam proposing?
- Which businesses are most at risk?
- Which data categories trigger the harshest penalties?
- Background: how the proposal took shape
- How does this compare to GDPR in Europe?
- What does the social media and gaming account verification rule mean?
- How can DataCore help your business comply?
- What should businesses do right now?
- Frequently Asked Questions

What exactly is the data security fine Vietnam is proposing?
Two interrelated regulatory proposals behind the data security fine Vietnam is drafting are advancing through Vietnam's drafting process in 2026, and both have direct implications for any business that handles personal data.
The first is a comprehensive data security decree led by the Ministry of Public Security (Bo Cong An - MPS), Vietnam's top law enforcement authority. The draft introduces a tiered penalty framework with a headline provision: a maximum fine of 5% of total annual revenue for serious violations involving two specially protected data categories - "critical data" (du lieu quan trong) and "core data" (du lieu cot loi). Smaller fixed fines apply to less severe violations involving ordinary personal data.
The second proposal is a draft amendment to Decree 147/2024/ND-CP, which governs internet services and online information in Vietnam. This amendment would require social media platforms and online gaming operators to verify every Vietnamese user account against a phone number or a national identity card (Can Cuoc Cong Dan - CCCD, or the older Chung Minh Nhan Dan - CMND). Platforms that allow unverified accounts to continue operating face penalties themselves.
Both proposals build on top of the existing baseline: Decree 13/2023/ND-CP, Vietnam's Personal Data Protection Decree (PDPD), which took effect in 2023. The new proposals significantly raise the enforcement stakes for non-compliance.
Which businesses face the highest data security fine Vietnam risk?
- Banks and financial institutions: Already subject to mandatory Know-Your-Customer (KYC) requirements from the State Bank of Vietnam (SBV), these organizations hold large volumes of financial, biometric, and identity data.
- Fintech companies: Digital lenders, neobanks, payment service providers, and securities platforms handle high volumes of transactions tied to verified personal identities. Any gap in identity verification creates simultaneous regulatory and fraud risk.
- Insurance companies: Underwriting requires detailed personal and health data. Failure to protect this data adequately falls squarely within the harshest penalty tier.
- E-commerce and marketplace platforms: These businesses collect purchase histories, home addresses, financial account details, and in some cases biometric verification data.
- Social media platforms and online games: Directly targeted by the Decree 147 amendment, which mandates verified phone or CCCD registration for every user account.
- HR and payroll processors: Handle full government ID data, tax codes, and bank account numbers for large employee populations.
Which data categories trigger the harshest data security fine Vietnam penalties?
Core data (du lieu cot loi): The most protected tier. This covers data relating to national sovereignty, defense secrets, classified state information, and the functioning of critical state systems. Most private-sector businesses will not routinely handle true core data.
Critical data (du lieu quan trong): The tier most relevant to financial services, healthcare, and telecom. This covers data whose unauthorized disclosure or destruction would seriously disrupt economic activity, public safety, or national security. A serious violation involving critical data carries the 5% of annual revenue penalty. This is where most regulated businesses need to anchor their compliance planning.
Personal data (du lieu ca nhan): Already regulated under Decree 13/2023/ND-CP. The proposed new decree adds higher, revenue-based penalties specifically for the two more sensitive categories above.
The data security fine Vietnam applies scales with severity, so practical guidance matters: if your organization holds or processes biometric data, bulk financial records, health data, or any data volume large enough to characterize as critical to economic infrastructure, treat yourself as a potential 5% fine candidate and plan your compliance investment at that risk level.
Background: how the proposal took shape
Vietnam's data protection framework has developed in stages rather than as a single law. Decree 13/2023/ND-CP, which took effect in July 2023, established the country's first comprehensive personal data protection regime, defining categories such as personal data and sensitive personal data and setting out consent, cross-border transfer, and breach-notification obligations. The Ministry of Public Security (Bo Cong An - MPS), which drafted and administers Decree 13/2023, is the same body now drafting the new data security decree described above. That continuity matters for compliance planning: businesses that already built a Decree 13/2023 compliance program have a head start, because the new decree layers additional categories and penalties on top of the existing structure rather than replacing it.
The methodology behind this article draws on the publicly circulated draft decree text and the companion draft amendment to Decree 147/2024/ND-CP, both of which were released for public and inter-agency comment as part of Vietnam's standard legislative drafting process. Draft decrees in Vietnam typically go through several rounds of revision between initial publication and the version submitted to the Government for signature, so specific figures such as the 5% revenue cap should be treated as the current draft position rather than a guaranteed final figure.
Businesses should monitor the official Vietnam Government Portal and MPS announcements for the finalized text and its effective date, and should not wait for finalization before starting internal compliance assessments, since the direction of travel toward higher, revenue-based penalties is consistent with regional and global trends already visible in frameworks like GDPR.
For context on how Vietnam's broader digital economy is scaling alongside these new compliance obligations, see DataCore's coverage of the household business digital data shift, which illustrates how quickly the pool of businesses handling digitized personal and transactional data is growing.
How does this compare to GDPR in Europe?
The parallel is deliberate and structurally sound. Europe's General Data Protection Regulation (GDPR), enforced since 2018, established maximum fines of up to 4% of global annual turnover for serious violations. Vietnam's proposed 5% cap on annual revenue is structurally identical - and in percentage terms, slightly more aggressive than the GDPR headline figure.
For context: a Vietnamese company with VND 500 billion in annual revenue (approximately USD 20 million) faces a potential fine of VND 25 billion (roughly USD 1 million) for a serious violation - before reputational damage, business disruption, or civil liability is considered.
What does the social media and gaming account verification rule mean?
The draft amendment to Decree 147/2024 creates specific obligations for platform operators in Vietnam. Every Vietnamese user account on a social media platform or online game must be linked to a verified phone number or national ID card (CCCD/CMND). Platforms that allow unverified accounts to persist would be in breach and face their own penalties.
Platform operators need a compliant, scalable identity verification flow at account creation - and potentially for retroactive verification of existing accounts at scale. A platform with millions of Vietnamese users cannot manually process each case; it needs an automated eKYC solution. All platforms collecting verification data must simultaneously comply with Decree 13/2023, creating a layered obligation.

How can DataCore help your business comply?
DataCore eKYC Service is an electronic Know-Your-Customer identity verification service built for regulated industries - banks, fintechs, insurers, and any business that must verify customer identity before onboarding or account creation. The service automates the verification of Vietnamese national ID documents (CCCD/CMND) against authoritative government data sources, producing an auditable verification record that can withstand regulatory scrutiny. Learn more at datacore.vn/en/services.
DataCore People Data Service is a person-verification and credit-signal layer built on public Vietnamese government data sources. It allows businesses to verify that a stated identity matches authoritative public records - directly relevant to onboarding, fraud detection, and ongoing monitoring of customer data quality.
Explore both at datacore.vn/en/services or read more at blog.datacore.vn.

What does a realistic data security fine Vietnam compliance timeline look like?
Businesses evaluating exposure to the data security fine Vietnam has proposed should plan compliance work in three phases rather than waiting for the decree's final effective date.
Phase one, data mapping (weeks 1 to 4): Inventory every system that stores or processes personal data, sensitive personal data, core data, or critical data as defined under Decree 13/2023/ND-CP and the proposed new decree. Most Vietnamese businesses have not completed a full data map, and this step alone typically surfaces unexpected exposure, such as marketing databases or legacy systems holding identity documents without adequate access controls.
Phase two, gap remediation (weeks 4 to 12): Compare current identity verification, consent capture, and data security practices against both decrees. This is where automated eKYC infrastructure, encryption at rest, and access logging typically need to be introduced or upgraded. Businesses relying on manual or paper-based verification face the largest remediation gap and the highest risk of falling under the 5% revenue fine tier if a serious violation involving critical data occurs.
Phase three, ongoing monitoring (continuous): Data security compliance is not a one-time project. Regulatory text can still shift before final enactment, and businesses should maintain a standing process to monitor MPS announcements, re-test verification flows, and refresh staff training on data handling obligations.
What should businesses do about the data security fine Vietnam right now?
- Data mapping: Identify every personal data category your organization holds. Flag any data that could qualify as critical or core under the proposed framework.
- Identity verification audit: Review your current customer onboarding and KYC processes. Are they documented? Backed by authoritative data sources? Capable of producing an audit trail?
- Vendor assessment: If your verification process is manual, paper-based, or self-declaration-only, evaluate automated eKYC solutions now - before a compliance deadline forces a rushed and expensive procurement.
- Legal review: Have counsel map your data processing activities against both Decree 13/2023 and the proposed new framework. Identify gaps before regulators do.
Preparing now for the data security fine Vietnam regulators are proposing is far less costly than reacting after enforcement begins.
Ready to assess your eKYC readiness? Contact DataCore at datacore.vn/en/services to learn how the eKYC Service and People Data Service can be integrated into your compliance stack before the deadline arrives.

Key data security fine Vietnam definitions businesses need to know
Understanding the proposed data security fine in Vietnam requires understanding four data tiers used across Decree 13/2023/ND-CP and the new draft decree:
- Personal data (du lieu ca nhan): Any information that identifies or can identify a specific individual, such as name, address, or ID number. Regulated under Decree 13/2023.
- Sensitive personal data (du lieu ca nhan nhay cam): A subset of personal data requiring stronger protection, including biometric data, health records, financial account data, and location data.
- Core data (du lieu cot loi): Data tied directly to national security, defense, or foreign affairs interests. Subject to the strictest handling rules.
- Critical data (du lieu quan trong): Data whose loss, alteration, or unauthorized disclosure would seriously affect economic activity, social order, or public safety. This is the tier most relevant to banks, fintechs, telecoms, and large platforms, and the tier most likely to trigger the 5% revenue fine.
Businesses that are unsure which tier applies to their data holdings should treat the classification exercise itself as the first compliance task, since the applicable penalty tier and required safeguards both depend on it.
Frequently Asked Questions
What is the maximum data security fine Vietnam has proposed?
The Ministry of Public Security (Bo Cong An) proposes a maximum fine of 5% of a company's total annual revenue for serious violations involving critical data (du lieu quan trong) or core data (du lieu cot loi). This is structurally similar to the GDPR's maximum 4% of global turnover and represents one of the highest data penalty regimes in Asia.
Which Vietnamese businesses face the greatest data security fine Vietnam exposure?
Banks, fintech companies, insurance providers, e-commerce platforms, healthcare organizations, social media platforms, online gaming operators, and any business that collects or processes Vietnamese citizens' personal data at scale all carry meaningful data security fine Vietnam exposure. The greater the sensitivity and volume of the data you hold, the higher your regulatory exposure.
What is the difference between critical data and core data in Vietnam's framework?
Critical data (du lieu quan trong) covers information whose unauthorized disclosure would seriously disrupt economic activity, public safety, or national security. Core data (du lieu cot loi) is even more sensitive, covering data relating to national sovereignty, defense, and critical state systems. Both categories attract the maximum 5% revenue penalty for serious violations.
How does DataCore's eKYC Service help with compliance?
DataCore's eKYC Service automates electronic identity verification for customer onboarding using authoritative Vietnamese government data sources, producing auditable records that address the core obligations under Decree 13/2023 and the proposed new decree. It is purpose-built for banks, fintechs, and insurers already subject to mandatory KYC requirements from the State Bank of Vietnam.
When will Vietnam's new data security decree take effect?
As of mid-2026, the decree is in the proposal and public comment stage. Given Vietnam's pattern of short implementation windows after enactment, businesses should begin compliance preparations now. Building compliant identity verification infrastructure before a regulatory deadline is significantly faster and less expensive than doing so under time pressure.
How is the data security fine Vietnam imposes calculated in practice?
Under the draft decree, the data security fine is calculated as a percentage of the violating company's total annual revenue, capped at 5% for the most serious violations involving critical data or core data. Regulators are expected to assess the severity of the violation, the volume and sensitivity of data affected, and whether the company had reasonable safeguards in place before determining the exact percentage applied within that ceiling. This revenue-based approach for the data security fine Vietnam is proposing mirrors GDPR's turnover-based penalty structure rather than Vietnam's older practice of fixed-amount fines.
Where can businesses track the official status of the data security fine Vietnam is proposing?
The Ministry of Public Security publishes draft decrees and amendments for public comment through the Vietnam Government Portal and the MPS's own legal document channels. Businesses working with legal counsel or compliance advisors in Vietnam should ask their advisors to monitor these channels directly, since draft text can change between the public comment period and the final signed decree.
Related reading
For more on how Vietnam's regulatory and data landscape is evolving, see DataCore's analysis of the VN-Index rally alongside Vietnam's GDP growth and the 2026 Vietnam AI Week wrap-up, both of which touch on the data infrastructure decisions driving compliance and technology investment across Vietnamese businesses this year.
Does the data security fine Vietnam is proposing apply to foreign companies operating there?
Yes. Decree 13/2023/ND-CP and the proposed new data security decree apply to any organization that processes the personal data of individuals in Vietnam, regardless of where the organization is headquartered. Foreign companies operating in Vietnam through a local entity, branch, or representative office, as well as foreign companies that process Vietnamese users' data remotely, fall within scope and face the same revenue-based penalty exposure as domestic businesses.
What should a Vietnam data security fine compliance checklist include?
At minimum, a practical checklist should cover: a completed data inventory classifying holdings by personal, sensitive personal, core, and critical data tiers; documented consent flows for personal data collection; an automated, auditable identity verification process for any account or customer onboarding flow; encryption and access controls for data at rest and in transit; a designated internal owner for data protection compliance; and a documented incident response plan for suspected breaches. Businesses that can check all six items are in a materially stronger position against data security fine Vietnam enforcement if regulators review their practices after the new decree takes effect.
Want data like this on your own watchlist? DataCore's Company Intelligence Service gives you verified financial, ownership, and registry data on over 2.3 million Vietnamese companies, one click away.




Để lại một bình luận
You must be logged in to post a comment.