
General articles are free for 24 hours after publish.
Vietnam Proposes Fines Up to 5% of Revenue for Data Security Violations
Vietnam's Ministry of Public Security has proposed a significant increase in penalties for data security breaches, suggesting fines of up to 5% of a violating company's revenue. This move comes in response to estimated annual losses of $15-20 billion from cybercrime and the inadequacy of current fixed fines.
Vietnam's Ministry of Public Security has proposed a significant overhaul of penalties for data security breaches, suggesting fines up to 5% of a violating company's total revenue. The current fixed fine system is deemed "outdated," particularly for large multinational corporations, where fines are often treated as operational costs rather than incentives for robust security investments. The proposed Data Security Law aims to transition to a revenue-based penalty mechanism. For severe violations, organizations could face fines equivalent to up to 5% of their total revenue in the preceding fiscal year. In cases where a subsidiary's revenue in Vietnam does not reflect the scale of the violation, authorities may consider applying the fine based on the parent group's global revenue, capped at 5%. This penalty structure is tied to a four-tiered data classification system based on risk levels: Normal (Level 1), Internal (Level 2), Important (Level 3), and Core (Level 4). The maximum 5% revenue fine would apply only to violations involving "Important Data" and "Core Data." Important Data is defined as information in critical sectors whose leakage or theft could seriously harm national security, macro-economic stability, or public interests. Core Data refers to information directly related to national defense, security, digital sovereignty, and supreme strategic interests, the compromise of which could threaten national existence. Beyond financial penalties, the draft law also proposes technical enforcement measures such as bandwidth limitations and the temporary suspension or termination of access to violating data streams within Vietnamese territory. These measures are intended to promptly prevent the spread of malicious data. The Ministry of Public Security stated that the revenue-based fine model is inspired by advanced global legal frameworks like the EU's General Data Protection Regulation (GDPR), aiming to enhance deterrence against cross-border technology firms. These proposals come amid rising cyber threats in Vietnam. In 2025, the country's information systems faced over 552,000 cyberattacks, affecting more than 5,230 agencies and businesses. Authorities have also uncovered hundreds of incidents involving the sale of sensitive data, including over 1.7 million records from sectors like healthcare, education, banking, and telecommunications. Online fraud alone is estimated to cause losses of $15-20 billion annually, nearly 4% of Vietnam's GDP. Internal breaches or negligence by staff are identified as the source of 60-70% of data leaks. The draft law is expected to be submitted to the National Assembly for consideration and approval in October.
Original source
VnExpress