March 7, 2025
The Government has issued Decree No. 24/2025/ND-CP, amending Decree No. 98/2020/ND-CP, which takes effect on February 21, 2025. This decree introduces significant updates on administrative sanctions for violations related to consumer information protection.

Notably, Decree 24/2025/ND-CP increases penalties for certain violations compared to Decree 98/2020/ND-CP and expands the list of offenses subject to administrative sanctions. Key updates include:
Fines ranging from VND 20,000,000 – 30,000,000 for the following violations:
Fines of VND 30,000,000 – 40,000,000 for the following violations:
Note: If the violation is committed by an organization or involves sensitive personal data, the fine is doubled. If the violation is committed by a large-scale digital platform operator, the fine is quadrupled.
Decree 24/2025/ND-CP also introduces new penalties for violations in online transactions, particularly those involving consumer information, including:
To minimize legal risks, particularly the risk of administrative sanctions, it is recommended to:
1/ Conduct a comprehensive review of all consumer personal data processing activities to identify potential compliance gaps, with a focus on obligations under the 2023 Law on Protection of Consumer Rights.
2/ Implement necessary compliance measures, remediate any gaps, and strengthen data protection safeguards to enhance security and ensure the organization’s data processing practices meet regulatory standards.
PrivacyCompliance prides itself on its team of experts having achieved numerous internationally recognized certifications such as CIPM, CIPP/E, CISA, CISM, CRISC®, ISO27001 Lead Auditor, etc. With tried-and-tested knowledge and capacity, PrivacyCompliance is confident in being able to provide in-depth and comprehensive solutions on personal data compliance and protection.
Draft Decree on Data Exchanges: Proposed Legal Framework for Data Transactions in Vietnam The draft Decree on data exchange operations is currently open for consultation and proposes a framework for organizing, operating, and governing data transactions in Vietnam in a more transparent, controlled, and secure manner. A notable feature of the draft is the proposed […]
Learn more
🔐 𝗥𝗘𝗗𝗗𝗜𝗧 𝗙𝗜𝗡𝗘𝗗 £14.47 𝗠𝗜𝗟𝗟𝗜𝗢𝗡 𝗙𝗢𝗥 𝗖𝗛𝗜𝗟𝗗𝗥𝗘𝗡’𝗦 𝗣𝗥𝗜𝗩𝗔𝗖𝗬 𝗙𝗔𝗜𝗟𝗨𝗥𝗘𝗦 — 𝗔 𝗟𝗔𝗡𝗗𝗠𝗔𝗥𝗞 𝗨𝗞 𝗘𝗡𝗙𝗢𝗥𝗖𝗘𝗠𝗘𝗡𝗧 𝗔𝗖𝗧𝗜𝗢𝗡 Recently, the Information Commissioner’s Office (ICO) imposed a fine of approximately £14.47 million (~USD 19.5 million) on Reddit for processing the personal data of users under 13 without implementing appropriate age verification measures. This is reported to be the largest […]
Learn more
Privacy Compliance Joint Stock Company is recruiting a Marketing Intern to support communication and brand development activities in the field of personal data protection and privacy. Job Description Assist in developing and implementing communication plans and content (website, LinkedIn, Facebook, email marketing, etc.). Coordinate in editing articles on data protection, compliance, and risk management (under […]
Learn more