This regulation is outlined in point c, clause 1, Article 39 of Decree 330/2026/ND-CP, which concerns administrative penalties in cybersecurity and personal data protection. The decree takes effect on 19/8.
Accordingly, organizations found storing personal data beyond the period necessary for processing purposes, unless otherwise stipulated by law, will be fined 20-40 million dong.
The regulation sets limits on how long data can be retained after collection. Continued storage must remain necessary, align with the processing purpose, or fall under other legal provisions.
For instance, regarding employee data after resignation, businesses are not automatically required to immediately delete all collected information. However, continued retention must meet the requirement of being necessary for the processing purpose.
Article 39 also stipulates fines of 20-40 million dong for organizations that process personal data outside the defined scope, for unsuitable purposes, or beyond what is necessary. Penalties also apply for failing to ensure data accuracy or not promptly correcting and updating incorrect data.
Thus, data protection responsibility extends beyond collection and use to include storage. Organizations must determine which data remains necessary, for how long it can be stored, and the purpose of its continued retention.
![]() |
Employee data after resignation should not be stored indefinitely. Photo: Xuan Minh
Penalties span from data collection to trading
Decree 330 comprises four chapters and 82 articles, outlining penalties in two areas: cybersecurity and personal data protection. The personal data protection group is a separate section, covering acts from collection, processing, storage, provision, disclosure, deletion, transfer, to trading and cross-border data transfer.
In a regulation directly impacting social media users, Article 50 states that organizations disclosing personal data without the subject's consent, unless otherwise provided by law, face fines of 30-50 million dong. Individuals are subject to half of this amount, with a maximum of 25 million dong. This provision forms the basis for addressing cases where individuals' data is posted online for accusations, disputes, or "exposing" others.
The decree also outlines penalties for collecting data beyond scope, misusing it, failing to delete data when required, illegal trading, or improper cross-border transfer of personal data. For some serious violations, fines can reach billions of dong or be calculated as a percentage of revenue.
These regulations demonstrate that data protection penalties target not only data leaks or trading but also encompass the entire process of data collection, use, retention, and sharing.
Pham Hai
