A PDPL & cybersecurity penalty decree is coming: compliance gets urgent

Photo: Albert Stoynov / Unsplash
PDPL sets duties, but the teeth — concrete penalties — live in a penalty decree. In Q1 2026, the Ministry of Public Security consulted on a draft decree on administrative penalties for cybersecurity and personal data protection. When issued, the specific fines will be clear.
What this means
- So far, the headline figure is a ceiling up to 5% of revenue for serious violations (see what "fines up to 5%" means).
- The penalty decree will set brackets per violation type — turning abstract risk into numbers.
- Once penalties are clear, "we hadn't gotten to it" is no longer an accepted excuse.
What businesses should do now
Don't wait for the decree to start. Complete the foundational duties first — see the PDPL checklist and PDPL review season. Keeping data under control reduces violation risk.
Tetra eOffice and Manta Security support data and access control. For advice, book a consultation.
Note: this article is for reference only; follow the official text once issued.
Related articles

Transferring personal data abroad under the PDPL: records, process and penalties
The 2026 PDPL sets strict obligations for transferring personal data abroad, with the highest penalty of up to 5% of revenue. When it applies, what to file, and how to reduce risk with on-premise.
Read ↗
Deploying eOffice on-premise: data sovereignty seen from the architecture
Data sovereignty is more than servers located in Vietnam. A look at the architecture, infrastructure, integration and staffing behind an on-premise eOffice.
Read ↗
PDPL review season: impact assessment records and the DPO role
After PDPL took effect, businesses enter a review season: impact assessment records, the DPO role, and reviewing data transfers out.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.