A new regulation, effective from 19/8, will penalize organizations that assume customer consent for personal data processing based on silence or non-response, with fines ranging from 50-70 million dong. Individuals committing the same offense face half the penalty, 25-35 million dong. This provision is detailed in Article 43 of Decree 330/2026/ND-CP, which addresses violations related to personal data subject consent.
For instance, if a business sends a notification seeking permission to use customer data and receives no reply, it cannot automatically assume consent.
Article 43 also differentiates this offense from processing collected data without prior consent, which carries a lower penalty of 30-50 million dong for organizations.
No pre-checked 'agree' options
The decree further imposes fines of 30-50 million dong on organizations that set up default consent mechanisms or create ambiguous instructions that confuse agreement and disagreement regarding data processing.
For example, if a customer registers for an online service and the data processing consent box is pre-checked, requiring the user to manually deselect it to decline, this design might be considered 'default consent' under the regulations.
Businesses also face penalties if they impose mandatory conditions or refuse service when customers decline data processing for purposes unrelated to the service agreement.
Consent requests must ensure users agree to each specific data processing purpose. The decree mandates that consent requests be clear, specific, and verifiable, confirming the data subject, time, and content of their agreement. Before providing consent, data subjects must receive transparent information about the type of data processed, its purpose, and related rights and obligations. Consequently, offering only an "I agree" button without clarifying what the user is consenting to may create legal risks.
![]() |
Businesses must not assume customer silence implies consent for data processing. *Xuan Minh*
Decree 330/2026/ND-CP, issued by the Government at the request of the Minister of Public Security, outlines administrative penalties for violations in cybersecurity and personal data protection. Comprising four chapters and 82 articles, the sanctions apply to all stages of data handling: collection, processing, storage, provision, disclosure, transfer, sale, deletion, and cross-border data transfers.
Under Article 39, organizations storing personal data beyond the necessary duration may face fines of up to 40 million dong. Article 50 stipulates that organizations disclosing personal data without consent face fines of 30-50 million dong, while individuals incur half that amount. This regulation also restricts the online publication of others' data for complaints, disputes, or "boc phot" (exposing wrongdoing). The decree also penalizes collecting data outside its specified scope, using it for unauthorized purposes, failing to delete data, illegal trading, or unauthorized cross-border data transfers.
Data protection extends beyond preventing information leaks; it begins with verifying whether users consent to others using their data and the specific methods by which they have provided that consent.
Pham Hai
Trading over 50 million personal data records of officials, students, business owners
10th grade male student hacked national vaccination system, stole data
Risk of personal information exposure when parents share children's photos online
