mask
Cross-border telecom providers could face fines of up to 5 per cent of global revenue
Foreign enterprises providing cross-border telecommunications and Internet services in Vietnam could face fines of up to 5 per cent of their global revenue for serious violations related to data security, according to a draft Law on Data Security proposed by the Ministry of Public Security.
The working space at the Cybersecurity Monitoring Centre, the Department of Cybersecurity and Hi-tech Crime Prevention (A05) under the Ministry of Public Security. — Photo: Pham Kien/VNA

Under the draft Law on Data Security, proposed by the Ministry of Public Security (MPS), the maximum fine would generally be capped at 5 per cent of the violating organisation’s total revenue generated in Vietnam in the preceding financial year.

However, for an organisation belonging to a multinational group, if its revenue generated in Vietnam is considered disproportionate to the scale and severity of the violation, the competent authority may calculate the fine based on the group’s global revenue. In such cases, the fine would still be capped at 5 per cent of the applicable revenue.

The proposed revenue-based penalty regime would apply to foreign enterprises providing cross-border telecommunications and Internet services that process data of users in Vietnam or whose activities affect national data security.

The proposed mechanism is linked to a four-tier data classification system comprising ordinary data (Level 1), internal data (Level 2), important data (Level 3) and core data (Level 4).

Fines of up to 5 per cent of revenue would apply only to serious violations involving the two highest-risk categories: important data and core data.

Important data is defined as data in key sectors and fields whose disclosure, misuse or misappropriation are likely to seriously affect national security, macroeconomic security or the public interest.

Core data refers to data directly related to national defence, national security, digital sovereignty and other paramount strategic interests, where its compromise might pose a threat to the country’s survival.

In addition to financial penalties, the draft proposes technical enforcement measures against violations. These include restricting bandwidth and suspending or terminating access to data flows associated with violations within Vietnam in order to promptly prevent the dissemination of harmful data.

According to the MPS, the revenue-based penalty mechanism draws on advanced international legal frameworks, including the European Union’s General Data Protection Regulation, and is intended to strengthen deterrence, particularly for violations committed by large cross-border technology groups.

The draft law is scheduled to be submitted to the National Assembly for passage in October.- (VLLF) 

back to top