Vietnam August 2026 Decrees | Compliance Guide

Aug 26, 202609 minute read

Vietnam's August 2026 Decree Wave: What Compliance Teams Need to Track Now

blogdetail image
Vietnam's August 2026 Decree Wave: What Compliance Teams Need to Track Now

TL;DR: In the second half of August 2026, Vietnam's Government issued a wave of decrees touching almost every compliance program in the country: penalties for the cybersecurity and personal data protection stack, the implementation layer for the Cybersecurity Law, a national location-identification system, journey-monitoring devices for road transport, and a full replacement of the National Single Window decree.

The instruments arrived close together, but they do not start together, effective dates run from 19 August 2026 to 1 July 2027 and beyond. For a compliance lead, the real work is not reading the headlines. It is sorting the wave into a calendar of duties, owners, and evidence.

The penalty layer arrived first: Decree 330

Decree 330/2026/NĐ-CP, issued and effective on 19 August 2026, is the administrative-penalty decree for the cybersecurity and personal data protection stack. It replaces the draft enforcement decree that teams had been watching, and it is where sanction questions for both regimes now resolve.

Two things matter operationally. First, the decree carries an attribution rule that determines how a stated amount applies: cybersecurity amounts are stated per individual and doubled for organizations, while personal-data-protection amounts are stated per organization and halved for individuals. Reading a schedule without that rule produces the wrong number, in either direction. Second, none of the new cybersecurity implementing decrees carries fines of its own, they all route sanctions to Decree 330. We deliberately quote no amounts here: schedules belong to the decree's own text, read with counsel.

The Cybersecurity Law got its implementation layer

The Cybersecurity Law 116/2025/QH15 has been in force since 1 July 2026, but its operating detail arrived on 19 August 2026, when four implementing decrees were promulgated with immediate effect, joined by a fifth with a later date:

  • Decree 333/2026/NĐ-CP: the general implementation decree: protection-measure procedures, service-provider duties with short information and removal clocks, minimum log-retention and data-localization periods, and a phased training rollout.
  • Decree 331/2026/NĐ-CP: five-level classification for information systems, with data-subject-count thresholds between levels, dossier-review clocks, an incident ladder that tightens with system level, and an annual review cycle. The predecessor security-level decree from 2016 is not repealed; it remains a transitional regime.
  • Decree 327/2026/NĐ-CP: the procedures for handling violating information and acts in cyberspace: seven families of measures, a 24-hour attack report, and short data-provision and removal clocks.
  • Decree 332/2026/NĐ-CP: business conditions for cybersecurity products and services, with a licensing regime and defined product and service categories.
  • Decree 328/2026/NĐ-CP: prevention of fake and false information, issued 19 August 2026 but effective later, on 5 October 2026: an umbrella definition with sub-types, a six-step handling process, authority labeling clocks, and an always-on provider contact point.

The pattern to notice: classification questions, provider duties, licensing, and information-handling now each have their own instrument, and all of them point at Decree 330 for sanctions. A program that mapped its duties to the law alone should re-map them to the decree that now details each area.

the cybersecurity law got its implementation layer

Location codes and journey monitoring: data infrastructure with privacy consequences

Two more instruments extend the wave beyond classic cybersecurity.

Decree 326/2026/NĐ-CP, issued 19 August 2026 and effective 1 September 2026, establishes location identification: one stable 12-digit code per location, maintained in a national database with defined public and non-public fields, and exploitation channels that include VNeID. It creates no filing duty for location owners and prescribes no fines and no official forms, but organizations consuming the codes take on purpose-limitation, logging, and onward-sharing constraints.

Decree 319/2026/NĐ-CP, signed 13 August 2026, requires journey-monitoring, driver-image, and passenger-compartment-image devices on commercial road vehicles, including the own-account fleets of manufacturers and traders. Nothing is due yet: the first installation date is 1 July 2027, and the phase-in runs by vehicle class to 1 January 2030. The decree itself routes all processing of the recorded surveillance data to the Data Law and the personal data protection law, which means fleet operators inherit a privacy program obligation alongside a hardware one. The right response in 2026 is planning against the dates, not urgency.

The single window changes hands on 15 October

Decree 336/2026/NĐ-CP, signed 22 August 2026, replaces the 2019 National Single Window decree in full from 15 October 2026. Until 14 October 2026, the old decree remains the in-force basis. The new regime sets a declarant account lifecycle in which VNeID electronic identification becomes an access path alongside digital signatures, statutory information-indicator sets replace printed form templates, and ministries may keep legacy result formats for up to one year.

For importers, exporters, brokers, and forwarders, this is a continuity task with a dated switchover: re-check portal accounts and signature currency before the handover, move procedure citations to the new decree from 15 October, and expect acknowledgement evidence in both new and legacy formats during the transition year. Evidence recorded under the old decree stays valid history, the succession just needs to be recorded beside it. The logistics and customs overlay carries this succession with its dates.

And one vertical that is not a new law at all

Alongside the decree wave, ComplianceOne's Vietnam coverage gained a securities and capital-markets vertical, built on the Securities Law 54/2019/QH14 and Decree 155/2020/NĐ-CP, both in force since 1 January 2021. Nothing changed in the law in August; what changed is that public companies, securities firms, fund managers, and market-infrastructure banks can now run their disclosure calendars, reporting clocks, retention duties – led by the payment-bank pairing of ten-year settlement-data retention with 48-hour production – and inspection responses as structured, owned evidence. Securities fine schedules live in their own decree, outside the covered instruments, and the coverage says so rather than quoting them. Details are on the securities and capital markets overlay page.

The lesson generalizes: new instruments and a five-year-old stack come down to the same operating question, which duties apply to us, on what dates, with what evidence.

How ComplianceOne supports this

ComplianceOne carries each of these instruments with its real status and dates: in force from 19 August, effective 1 September or 5 October or 15 October 2026, or phasing in from 1 July 2027. Teams map obligations to owners, run the clocks as monitored tasks, and keep authority-facing evidence – reports, submissions, acknowledgements, and responses – connected to the duty that produced it.

Two boundaries are worth stating plainly. ComplianceOne connects to no government system – not the single-window portal, not any authority server – and files nothing on anyone's behalf; it structures the duties, readiness, and evidence around the channels your organization uses. And it does not make you compliant: it helps you prepare, track, and prove the work, while legal interpretation stays with your team and counsel.

Explore the full picture on the Vietnam regulatory frameworks page.

Key takeaways

  1. Sort the wave by effective date, not by publication date: 19 August 2026 (Decrees 330, 333, 331, 327, 332), 1 September 2026 (Decree 326), 5 October 2026 (Decree 328), 15 October 2026 (Decree 336), 1 July 2027 with a phase-in to 2030 (Decree 319).
  2. Sanction questions across the cybersecurity and personal-data stack now resolve to Decree 330 – and its attribution rule changes what any stated amount means for your organization, so never read a schedule without it.
  3. Re-map cybersecurity duties from the law to the implementing decree that now details each area: classification, provider duties, information handling, and licensing each have their own instrument.
  4. The journey-monitoring decree is a 2027-2030 program with a privacy program inside it – plan against the dates rather than reacting to the headline.
  5. Prepare for the single-window handover as a dated continuity task: accounts, citations, and dual result formats through the transition year.

Next steps

Request Pilot Access

See how ComplianceOne tracks Vietnam's August 2026 instruments – statuses, dates, duties, and evidence – in your environment.

Book a Consultation

Discuss which of the new decrees touch your operations and how to sequence readiness against their dates.

Ronni K. Gothard Christiansen
Technical Privacy Engineer and CEO, AesirX.io

Laws and standards referenced

  • Cybersecurity Law 116/2025/QH15
  • Personal Data Protection Law
  • Data Law
  • Decree 330/2026/NĐ-CP: Administrative penalties for cybersecurity and personal data protection
  • Decree 333/2026/NĐ-CP: Cybersecurity Law implementation
  • Decree 331/2026/NĐ-CP: Information-system classification
  • Decree 327/2026/NĐ-CP: Handling violating information and acts in cyberspace
  • Decree 332/2026/NĐ-CP: Cybersecurity products and services
  • Decree 328/2026/NĐ-CP: Prevention of fake and false information
  • Decree 326/2026/NĐ-CP: Location identification
  • Decree 319/2026/NĐ-CP: Journey-monitoring and image-recording devices
  • Decree 336/2026/NĐ-CP: National Single Window
  • Securities Law 54/2019/QH14
  • Decree 155/2020/NĐ-CP: Securities Law implementation

Disclaimer

This article is for general information only and does not constitute legal advice. Regulatory requirements, effective dates, scope, and obligations may vary depending on an organisation’s activities and circumstances. Organisations should review the official legal texts and seek qualified legal advice when determining their specific obligations. AesirX ComplianceOne supports compliance management, tracking, and evidence management but does not provide legal advice, connect to government systems, submit filings on an organisation’s behalf, or guarantee compliance.

Frequently Asked Questions About Vietnam's August 2026 Decrees

Answer: Five instruments were issued and took effect on 19 August 2026: Decree 330/2026/NĐ-CP on administrative penalties for cybersecurity and personal data protection, and four decrees implementing the Cybersecurity Law – Decree 333/2026/NĐ-CP (general implementation), Decree 331/2026/NĐ-CP (five-level information-system classification), Decree 327/2026/NĐ-CP (handling violating information and acts), and Decree 332/2026/NĐ-CP (cybersecurity products and services business). Three more from the same wave start later: Decree 326/2026/NĐ-CP on location identification on 1 September 2026, Decree 328/2026/NĐ-CP on fake and false information on 5 October 2026, and Decree 336/2026/NĐ-CP on the National Single Window on 15 October 2026.

Answer: Decree 330/2026/NĐ-CP carries the administrative fine schedules for both the cybersecurity and personal data protection regimes, in force since 19 August 2026. The amounts are set per violation in the decree's own articles and are governed by an attribution rule: cybersecurity amounts are stated per individual and doubled for organizations, while personal-data amounts are stated per organization and halved for individuals. Because the applicable figure depends on the violation, the actor, and that rule, organizations should read the schedules in the decree's text with counsel rather than rely on summarized amounts.

Answer: Decree 336/2026/NĐ-CP replaces the 2019 single-window decree in full from 15 October 2026, and the old decree remains the in-force basis until 14 October 2026. The new regime defines the declarant account lifecycle – including VNeID electronic identification as an access path alongside digital signatures – and uses statutory information-indicator sets instead of printed form templates, with ministries allowed to keep legacy result formats for up to one year. Organizations should re-check portal accounts and signatures before the handover and expect acknowledgements in both formats during the transition.

Answer: Decree 319/2026/NĐ-CP, signed 13 August 2026, phases in journey-monitoring, driver-image, and passenger-compartment-image devices on commercial road vehicles starting 1 July 2027, with later dates by vehicle class running to 1 January 2030 and a window for legacy devices to the end of 2029. Own-account fleets operated by manufacturers and traders are in scope, not only licensed transport businesses. The decree routes all processing of the recorded surveillance data to Vietnam's Data Law and personal data protection law, so operators should plan the privacy work alongside the installation calendar.

Answer: Mostly yes. The penalty decree and the cybersecurity implementing decrees reach any organization operating information systems or processing personal data in Vietnam, not only technology providers. The journey-monitoring decree reaches any company running its own commercial vehicle fleet, and the single-window decree affects anyone declaring imports, exports, or transit goods. The practical first step for a compliance lead is a scoping pass: which instruments name duties your operations actually trigger, and on which dates.

Enjoyed this read? Share the blog!