This regulation is stipulated in Article 37 of Decree 330/2026/ND-CP concerning administrative penalties in cybersecurity and personal data protection, effective from 19/8.
Accordingly, advertising messages can only be sent from 7h to 22h, and advertising calls from 8h to 17h daily, unless a different agreement with the user exists.
Without a different agreement, each advertiser may not send more than three messages to a phone number, three emails to an email address, or make more than one advertising call to a phone number within 24 hours.
Individuals violating regulations on advertising timeframes and frequencies can be fined 30-50 million dong; organizations face double the penalty, corresponding to 60-100 million dong.
Advertising timeframes and frequencies are not new regulations, but Decree 330 significantly increases sanctions: for the same offense, organizations previously fined 20-30 million dong now face 60-100 million dong, increasing deterrence against bothersome advertising calls and messages.
The decree also penalizes sending advertising emails or messages without recipient consent; making advertising calls without explicit user consent; or continuing to send advertising messages after the user has opted out. Individuals committing these acts can be fined 10-20 million dong, with organizations facing double the amount.
Higher penalties apply to sending advertising messages or making calls to phone numbers on the Do Not Call List. Individuals violating this face fines of 80-90 million dong, while organizations are fined 160-180 million dong.
In addition to monetary fines, depending on the specific act, offenders may also have their right to use identifying names suspended or be prohibited from providing services to new customers for one to three months.
![]() |
Calling or texting advertisements at improper times could lead to a fine of 100 million dong. Photo: Xuan Minh
Network providers must block spam calls and messages
Article 38 of Decree 330 specifically outlines the responsibilities of service providers in preventing and combating spam emails, spam messages, and spam calls.
Actions such as failing to provide tools for users to report issues; not implementing prevention and handling measures; or not meeting requirements for managing and monitoring dissemination sources can all be penalized on a case-by-case basis.
Telecommunications enterprises providing voice over internet protocol (VoIP) and SIP Trunk services can be fined 50-70 million dong if they fail to implement or maintain automatic technical mechanisms to block call traffic without valid identifying names; fail to monitor, analyze, or detect unusual call traffic; or fail to warn, restrict, temporarily suspend, or terminate services for customers showing signs of generating spam, fraudulent, or impersonation calls as regulated.
For some actions in this category, businesses may also have their VoIP and SIP Trunk services suspended for one to three months.
Decree 330 comprises 4 chapters and 82 articles, stipulating penalties in cybersecurity and personal data protection. In addition to spam messages, emails, and calls, the document also sets out sanctions for various acts of collecting, processing, storing, and disclosing personal data contrary to regulations.
Specifically, organizations that unilaterally consider user silence or non-response as consent for data processing can be fined up to 70 million dong; storing data longer than necessary can result in a 40 million dong fine. Individuals who disclose others' data without consent, unless otherwise stipulated by law, can be fined a maximum of 25 million dong.
Hai Pham
