Skip to content
Blog

A PDPL & cybersecurity penalty decree is coming: compliance gets urgent

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··1 min read
A PDPL & cybersecurity penalty decree is coming: compliance gets urgent

Photo: Albert Stoynov / Unsplash

PDPL sets duties, but the teeth — concrete penalties — live in a penalty decree. In Q1 2026, the Ministry of Public Security consulted on a draft decree on administrative penalties for cybersecurity and personal data protection. When issued, the specific fines will be clear.

What this means

  • So far, the headline figure is a ceiling up to 5% of revenue for serious violations (see what "fines up to 5%" means).
  • The penalty decree will set brackets per violation type — turning abstract risk into numbers.
  • Once penalties are clear, "we hadn't gotten to it" is no longer an accepted excuse.

What businesses should do now

Don't wait for the decree to start. Complete the foundational duties first — see the PDPL checklist and PDPL review season. Keeping data under control reduces violation risk.

Tetra eOffice and Manta Security support data and access control. For advice, book a consultation.

Note: this article is for reference only; follow the official text once issued.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist