Cybersecurity Law 2025, Decrees 330 and 332: Compliance Requirements and Business Risks
*Vietnam’s cybersecurity framework: key compliance priorities and potential exposures*
DN Legal’s latest legal update examines the *Cybersecurity Law 2025 and Decrees 330 and 332*, covering data security, AI and deepfakes, information system protection, responses to authority requests, and cybersecurity licensing.
For businesses, the financial and operational consequences deserve particular attention. Potential exposure includes:
* Fines of up to *10 times the receipts from unlawful personal data trading*.
* Fines of up to *5% of the preceding financial year’s Vietnam-market turnover* for specified cross-border personal data transfer breaches.
* A statutory ceiling of *VND 3 billion* for other personal data protection violations.
* Suspension of services or data processing, licence-related sanctions, mandatory data deletion and surrender of unlawful receipts.
These ceilings depend on the specific offence and statutory conditions. They are not automatic fines, and financial penalties are only one part of the potential business impact.
Our update includes *Schedule 1—a guide to key penalties and maximum exposures*, with statutory references and the principal operational consequences.
Businesses should review their data practices, AI use, incident-response arrangements and licensing position, and identify the obligations most relevant to their operations.



Comments