Skip to content
Blog

What "fines up to 5% of revenue" under PDPL really means

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··6 min read
What "fines up to 5% of revenue" under PDPL really means

Photo: Tingey Injury Law Firm / Unsplash

The phrase "fines up to 5% of revenue" comes up almost every time someone discusses Vietnam's Personal Data Protection Law (PDPL). It makes a strong impression, which is exactly why it is so often misread. The most common misreading, and the most damaging one, is to assume that any personal-data violation is fined at 5% of revenue. That is not how the law works. The 5% ceiling applies to one specific category of violation only. Getting this right lets a business put its resources where they matter, instead of being alarmed and mistargeted at the same time.

The framework here is the Personal Data Protection Law No. 91/2025/QH15, effective 1 January 2026, with the maximum administrative penalties set out in Article 8 of the Law, and Decree 356/2025/ND-CP providing implementation guidance. The key point to grasp from the start: Article 8 does not set a single penalty for every act. It splits the maximum penalty into several categories depending on the nature of the violation.

What the 5% actually applies to

The maximum fine of 5% of an organization's prior-year revenue applies only to violations of the rules on transferring personal data abroad, that is, cross-border data transfers. This is the only category where the penalty is calculated as a percentage of revenue. Every other category of violation is calculated in a completely different way, and most of them never touch the 5% figure at all.

Why cross-border transfer? Because this is the category the state assesses as carrying the highest risk. Once the personal data of people in Vietnam leaves the country, the ability of both the business and the regulator to control, recover and protect that data drops sharply. Tying the penalty to revenue is how the fine stays meaningful even for large companies, echoing the logic of Europe's GDPR. A fixed fine of a few billion dong may be trivial to a large group, but 5% of revenue is always significant.

How the penalty tiers really work

To see where the 5% figure actually sits, you have to look at the whole structure of maximum penalties under Article 8. The law distinguishes at least three categories.

Buying or selling personal data. This is treated as inherently serious, and the maximum penalty is calculated as up to 10 times the illicit gains from the violation. This approach targets the profit motive directly: the more you make from trading data, the larger the fine.

Transferring personal data abroad. This category, as noted, carries a maximum of 5% of the organization's prior-year revenue. It is the only category tied to revenue.

All other violations. Everything else, for example a missing impact-assessment record, improperly obtained consent, slow responses to data-subject requests, or failing to appoint data protection personnel, carries a fixed maximum of VND 3 billion, not a percentage of revenue.

On top of this, an individual committing the same act faces a maximum of half the amount applied to an organization. It is worth stressing that these are ceilings set by the Law, that is, the highest possible limits. The specific fine for each act will be detailed in the decree on administrative sanctions, and businesses should follow the official text once issued to know the actual bracket for a given breach.

In other words, most day-to-day compliance mistakes do not fall into the 5% category. They fall under the VND 3 billion ceiling. The 5% figure gets talked about not because it is common, but because it is the heaviest and the most attention-grabbing.

Why cross-border transfer is treated most severely

What makes this striking is how many businesses are already transferring data abroad without realizing it. A cross-border transfer is not only the act of sending a file out. Storing and processing the personal data of people in Vietnam on systems located outside the country also counts as a transfer abroad. That means when you use SaaS software, a cloud service or an AI tool hosted overseas to process the data of customers, employees or partners, you have already triggered cross-border transfer obligations, even if you never actively "sent" anything.

This is why the category is both the most severely penalized and the most easily triggered in practice. The risk usually hides inside third-party software a business already relies on. The details of the record-keeping obligations, the filing process, and how to spot outbound data flows are set out in transferring personal data abroad under the PDPL.

Why this is a board issue

When the heaviest penalty scales with revenue, compliance risk no longer sits inside the IT department. A decision that looks purely technical, such as choosing a foreign cloud platform because it is convenient and cheap, can carry a legal obligation tied directly to business results. And the administrative fine is only one part: there are also remedial measures, incident-handling costs, and the effect on brand trust. That is why PDPL compliance belongs at the governance level, connected to infrastructure decisions and vendor choices, rather than being handed off entirely to engineering as a technical task.

What a business should do

Because the heaviest penalty attaches to transferring data abroad, the most effective way to reduce risk is to shrink that exposure.

Map where your data actually lives. Inventory the systems that process personal data and mark which run in-country and which use platforms located abroad. This is the hardest step but also the most important, because many outbound flows hide inside third-party software.

Limit transfers you do not truly need. Every system you bring back onto in-country infrastructure is one transfer impact assessment you do not have to file and one risk category you do not have to manage.

Prefer on-premise or in-country storage for sensitive data. When software and data run on-premise or on in-country infrastructure, that part creates no cross-border obligation, and it is also easier to prove control during an inspection.

Complete the foundational steps. Tasks like building a data inventory, standardizing how you collect consent, appointing data protection personnel, and setting up a data-subject response process are laid out in the PDPL compliance checklist.

On the tooling side, Tetra eOffice and Manta Security run on-premise, support role-based access, access logging, and keeping data inside your own systems, which reduces the share of data that must leave the country and makes control easier to demonstrate.

The takeaway

The 5% figure is real, but it does not apply to every violation. It is a ceiling reserved for violations of the cross-border transfer rules, the largest financial-risk category under Article 8. Most everyday compliance mistakes fall under the VND 3 billion ceiling, while buying and selling data is calculated as a multiple of illicit gains. Understanding this structure lets a business work in the right order: control outbound data flows first, then address the rest. To review your current status and build a roadmap, book a consultation.

Note: this article is for reference only and is not a substitute for legal advice; businesses should check the current legal texts and consult legal experts.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist