These regulations are outlined in Article 65 of Decree 330/2026/ND-CP on administrative penalties for cybersecurity and personal data protection violations, effective from 19/8.
According to point b, clause 2, Article 65, OTT applications and social networks that use non-public technological features to eavesdrop, record calls, read text messages, or automatically extract contacts and media files from devices without the consent of the personal data subject are subject to fines of 70-150 million dong.
This fine applies to organizations. Individuals committing the same offense face half the penalty.
Therefore, a user installing an OTT application or using a social network does not grant platforms silent permission to employ unknown features for accessing calls, messages, contacts, or files on their devices.
For instance, a messaging application that uses a non-public feature to automatically read message content without user consent could face penalties.
Similarly, using hidden features to eavesdrop, record calls, or automatically collect contacts, images, videos, and other media files from a device may also be penalized if it falls under the provisions of Article 65.
Beyond monetary fines, organizations violating clause 2, Article 65 may also face suspension of service provision in Vietnam for three to six months. Illegally collected personal data, identification documents, contacts, and files, as specified, may be ordered to be destroyed or deleted to an unrecoverable state.
![]() |
Applications must clearly disclose the collection and use of users' personal data. Photo: Hai Pham
Platforms must disclose what data they are collecting
Article 65 also stipulates responsibilities for organizations providing social network services, online communication, and digital content platforms.
Organizations that fail to clearly inform users about the personal data collected during the installation and use of social networks and online communication services may be fined 50-70 million dong.
The same fine applies to several actions: failing to provide users with an option to refuse cookie collection and sharing; not offering a "do not track" option; not publishing a transparent privacy policy; or lacking a mechanism for users to access, modify, or delete their personal data as required.
These regulations mandate greater transparency from platforms regarding data collection, empowering users with options to control the tracking, sharing, and management of their data.
How to detect applications that are 'eavesdropping'?
For average users, detecting if an application is secretly reading messages, recording calls, or accessing contacts is difficult, as Article 65 primarily targets the use of "non-public technological features"—functions not clearly disclosed to users.
Decree 330 does not require users to independently discover or prove an application is "eavesdropping." When there are signs of violation, competent authorities can verify using electronic evidence, including data from electronic devices, information systems, accounts, images, audio, and other relevant data.
In other words, whether an application secretly accesses or collects data can be clarified through the electronic footprints left by such activity, rather than solely relying on whether users see or recognize it.
Enforcement authority under Decree 330 is assigned to several agencies, including the Police, Chairpersons of People's Committees, and Inspectors, each within their respective functions and duties. Specifically, the Police force has specialized cybersecurity units from the provincial level up to the Ministry of Public Security.
Therefore, users do not need to "catch an application in the act" of eavesdropping to report it. Whether a violation exists must be investigated, verified, and concluded by competent authorities based on evidence.
Decree 330 comprises four chapters and 82 articles, stipulating penalties in cybersecurity and personal data protection. Penalties related to personal data range from obtaining consent, collection, processing, and storage to public disclosure, location tracking, and data usage on digital platforms.
Among these, organizations that consider user silence as consent to process data could face fines up to 70 million dong; individuals who publicly disclose others' data without consent, unless otherwise stipulated by law, could be fined up to 25 million dong; and using location tracking technology unlawfully could result in fines up to 150 million dong.
Hai Pham
