Decree 330/2026/ND-CP: Key sanctions with significant implications for enterprises in cybersecurity and personal data protection

Ngày đăng: Monday, 07/09/26 Người đăng: Admin
Decree 330/2026/ND-CP: Key sanctions with significant implications for enterprises in cybersecurity and personal data protection

INTRODUCTION

On 19 August 2026, the Government issued Decree No. 330/2026/ND-CP on administrative sanctions for violations in the fields of cybersecurity and personal data protection (“Decree 330”), which took effect on the date of issuance. Decree 330 specifies the violations, forms and levels of sanctions, remedial measures, sanctioning authority, and enforcement of sanctioning decisions in these two fields.

As an instrument necessarily issued following the Law on Cybersecurity 2025 and the Law on Personal Data Protection 2025, Decree 330 specifies the sanctions applicable to violations provided for under those laws, thereby reinforcing compliance obligations and establishing an administrative enforcement mechanism for such violations.

Of direct relevance to enterprises, the sanctions under Decree 330 are not limited to fines. Depending on the violation, enterprises may also be subject to supplementary penalties and remedial measures that can materially affect their business operations, such as suspension of business activities, revocation of licences or permits, orders to cease processing or transferring data, or orders to destroy or delete data.

Accordingly, CNC has prepared this article to focus on the groups of provisions that have significant implications for enterprises, together with the practical recommendations set out below.

1. Impact of the scope of application and effective date

1.1. Scope of application includes foreign-related organizations

Decree 330 has a broad scope of application, covering Vietnamese and foreign individuals and organizations. Under Article 2.1, foreign individuals and organizations fall within the scope of Decree 330 when they commit administrative violations in the fields of cybersecurity or personal data protection “within the territory, internal waters, territorial waters, contiguous zone, exclusive economic zone and continental shelf of the Socialist Republic of Viet Nam; on aircraft bearing Vietnamese nationality or seagoing ships flying the Vietnamese flag”.

The scope of application to foreign-related organizations is specifically provided in Article 2.2(dd) of Decree 330. Accordingly, “organizations” falling within the scope of Decree 330 include, among other entities, “foreign agencies and organizations that directly participate in or are involved in the processing of personal data of Vietnamese citizens and persons of Vietnamese origin whose nationality has not been determined, who are residing in Viet Nam and have been issued an identity certificate”.

This provision removes nationality, place of establishment and physical presence in Viet Nam as determining factors when identifying violations of personal data protection laws by agencies and organizations. Instead, the scope of application depends solely on the relationship between the foreign agency or organization and the processing of personal data relating to data subjects falling within the prescribed scope.

Accordingly, an agency or organization established and operating overseas, with no branch, representative office, business location or operational establishment in Viet Nam, may still fall within the scope of Decree 330 if it directly participates in or is involved in the processing of personal data of Vietnamese citizens or persons of Vietnamese origin falling within the circumstances specified in Article 2.2(dd). Foreign agencies and organizations should therefore assess the applicability of Decree 330 by reference to the nationality of the data subjects whose personal data they process.

1.2. Effective date and transitional provisions

Decree 330 took effect on 19 August 2026. Enterprises should therefore treat the date on which the violation was committed, or the date on which the administrative violation record was made, as the first factor when assessing the applicability of sanctions. [1]

For conduct occurring before 19 August 2026 but discovered or being considered and resolved thereafter, the general rule is that the sanctioning provisions in force at the time the conduct was committed apply, unless Decree 330 does not impose legal liability or imposes lighter legal liability, in which case Decree 330 applies. [2]

For administrative violations for which an administrative violation record was made before Decree 330 took effect but no sanctioning decision had yet been issued, the application of the more lenient legal liability may still be available after the provisions of Article 80.2 are considered.

This point should be incorporated into incident review and internal investigation procedures. For a matter spanning 19 August 2026, the business should establish a timeline of the conduct, the date of discovery, the date on which the administrative violation record was made, and the status of any sanctioning decision in order to determine the applicable transitional regime and assess whether the more lenient legal liability provisions may apply.

2. Compliance risks differentiated by business activities

2.1. Group 1 – Enterprises that process personal data as part of ordinary business activities

This group comprises enterprises that do not provide personal data processing services but collect and process data relating to employees, customers, suppliers or business partners for operational purposes, as violations concerning processing principles, consent, data subject rights, Personal Data Processing Impact Assessment (“DPIA”), data transfers and security may arise in virtually any ordinary business activity.

Key risks for this group may include processing beyond the permitted scope or purposes, retaining data beyond the applicable retention period, failing to ensure data accuracy, failing to prevent, detect or coordinate the timely handling of violations; processing data without valid consent; establishing consent by default or treating silence as consent; and failing to prepare, maintain or submit a DPIA as required.

In particular, consent mechanisms should be reviewed across the entire website, applications, electronic forms, support centres and other data collection channels. Decree 330 sanctions, among other things, the establishment of default consent mechanisms, failure to ensure that consent can be verified, failure to obtain separate consent for each processing purpose, failure to provide transparent information, and treating silence or non-response as consent. For certain violations, the applicable remedial measure is the compulsory destruction or deletion of data to the extent that it cannot be recovered. [3]

A DPIA is an independent compliance control mechanism. An enterprise that commences personal data processing without preparing or maintaining a DPIA, or fails to submit the original DPIA within 60 days from the date on which processing first commences, may be sanctioned and may also be required to cease processing until all obligations have been fully satisfied and confirmation has been obtained from the competent specialized authority. [4]

2.2. Group 2 – Enterprises providing personal data processing services

This group presents a higher level of structural risk because providing personal data processing services requires compliance with specific business conditions. Typical affected enterprises may include SaaS providers, data analytics platforms, storage service providers and data processors providing processing services to customers.

Decree 330 specifically establishes sanctions for providing personal data processing services without a Certificate of Eligibility; appointing personal data protection personnel who do not meet the required qualifications, experience or training requirements; and failing to have at least three personnel meeting the competency requirements. A separate penalty framework also applies where an enterprise continues operating after its Certificate of Eligibility has been revoked. [5]

Even after obtaining the Certificate of Eligibility, an enterprise must maintain a risk management framework, rules on responsibilities and authority, and standards and technical regulations relating to data security, personal data protection and cybersecurity; ensure processing for proper purposes and comply with requirements on collection limits, transfer and storage; and conduct an annual assessment of its compliance status and level of trustworthiness. Violations may result in obligations to destroy or delete data and surrender proceeds obtained. [6]

Accordingly, the risks faced by Group 2 are twofold. On the one hand, there is administrative sanction risk arising from the violation itself; on the other, there is business interruption risk and contractual risk in relation to customers if the business is suspended or ceases to satisfy the conditions for providing its services.

3. Violations subject to notable financial penalties for enterprises

Decree 330 establishes substantially higher monetary penalty thresholds for certain serious violations of personal data protection regulations, reflecting the increasingly stringent approach of Vietnamese law to privacy rights in general and individuals’ control over their personal data in particular — rights that are intrinsically linked to individuals’ fundamental personality rights. For certain violations, fines are not determined solely by a fixed amount but are instead linked to revenue or proceeds obtained from the violation. This approach draws on global legislative and enforcement trends in personal data protection, notably the European Union’s General Data Protection Regulation (GDPR), under which fines may reach up to 4% of the total worldwide annual turnover of the preceding financial year, China’s Personal Information Protection Law (PIPL), under which fines may reach up to 5% of the preceding year’s turnover, and Brazil’s General Data Protection Law (LGPD), under which fines may reach up to 2% of revenue in Brazil, as applicable.

Violation Legal basis Fine applicable to organizations
Cross-border transfer of personal data resulting in disclosure or loss of personal data of a large number of data subjects, or continuing to transfer data after a decision requiring cessation of the transfer has been issued Article 56.3 to 56.6 1% to 5% of the total revenue in the Vietnamese market in the preceding financial year, depending on the circumstances. If the organization has no revenue in the Vietnamese market in the preceding financial year, or the percentage-based fine is less than VND 3 billion, a fine of VND 200 million to VND 3 billion applies, depending on the scale and nature of the violation.
Unlawful purchase or sale of personal data Article 53.1 to 53.5 A fine of 2 times to a maximum of 10 times the proceeds obtained from the violation. Where there are no proceeds, or the fine calculated by reference to proceeds is lower than the fine under the alternative mechanism, the fine based on the scale and nature of the violation applies.
Unlawful purchase or sale of personal data where the proceeds cannot be determined – large scale Article 53.3(c), 53.4 and 53.5 VND 500 million to VND 1 billion for basic personal data of at least 10,000 data subjects or sensitive personal data of at least 2,000 data subjects.
Unlawful collection of personal data by technological or technical means on a large scale Article 48.3(d), 48.5 and 48.6 VND 500 million to VND 800 million for basic personal data of at least 5,000 data subjects or sensitive personal data of at least 1,000 data subjects.
Unlawful collection of personal data by technological or technical means on a medium to large scale Article 48.3(c), 48.5 and 48.6 VND 300 million to VND 500 million for basic personal data of 1,000 to fewer than 5,000 data subjects or sensitive personal data of 200 to 1,000 data subjects.

* For cross-border transfers of personal data falling within the cases where the fine is calculated by reference to revenue, the fine ranges from 3% to 5% of the total revenue in the Vietnamese market in the preceding financial year. If the organization has no revenue in the Vietnamese market in the preceding financial year, or the percentage-based fine is less than VND 3 billion, the fine is instead determined within the range of VND 1 billion to VND 3 billion under the corresponding provisions of Article 56. For particularly serious violations, applying a percentage of revenue causes the sanction to increase with the scale of the business, thereby limiting the possibility that the fine becomes immaterial for enterprises with high revenue.

** For unlawful purchase or sale of personal data, the proceeds obtained from the violation constitute a direct basis for determining the fine and are calculated without deducting costs associated with carrying out the transaction. Where the proceeds cannot be determined, Decree 330 applies an alternative fine mechanism based on the scale of the data or the nature of the violation. This approach indicates that the sanction does not depend on whether the enterprise actually made a profit; costs incurred in carrying out the violation do not reduce the proceeds used as the basis for calculating the fine.

*** For unlawful collection of personal data by technological or technical means, the fine is differentiated according to the number of data subjects and the type of data collected. For large-scale cases, a fine of VND 500 million to VND 800 million applies where the conduct involves basic personal data of at least 5,000 data subjects or sensitive personal data of at least 1,000 data subjects. Quantifying violation thresholds by reference to the number of data subjects indicates that the level of sanction is directly linked to the scale of the unlawful collection activity.

The minimum fines established by Decree 330 where there is no revenue, no proceeds, or the revenue or proceeds are below the threshold of the applicable fine range are significant for enterprises. Accordingly, the absence of, or a low level of, revenue or proceeds does not automatically result in a low sanction. Once the conduct falls within a particular fine range, the fine must still be determined within that range, including its applicable minimum.

This mechanism shows that the severity of the sanction is determined not only by the actual loss or economic benefit obtained by the business from the violation, but also by the nature and severity of the conduct, as quantified under Decree 330 by reference to data volume, the number of data subjects or other legal criteria. Accordingly, in certain cases, revenue or proceeds are not the sole determinant of the fine. [7]

It is important to reiterate that, when assessing sanctioning risk, enterprises should not rely solely on the economic value of the transaction or the revenue generated by the violation. Even where the revenue or proceeds are immaterial, a business may still face a substantial fine if the conduct satisfies the conditions for application of the relevant fine range. This factor should be taken into account when assessing the severity of personal data violations.

4. Supplementary penalties and remedial measures that may directly affect business operations

In addition to fines, Decree 330 provides for various supplementary penalties and remedial measures that may directly affect an enterprise’s ability to continue its business activities, provide services, or process personal data.

Importantly, the economic consequences of a sanctioning decision are not limited to the amount of the fine. Depending on the nature of the violation, an enterprise may be restricted from, or become unable to, continue a business activity, be required to cease a particular data processing flow, delete accumulated data, or implement technical and governance measures that may materially alter its operating model. [8]

4.1. Suspension of cross-border transfers of personal data

Under Article 56.5, an organization may be subject to suspension of cross-border transfers of personal data for a period of 6 to 12 months in the circumstances specified in Article 56.3.

This penalty directly affects enterprises whose data processing systems are distributed between Viet Nam and overseas jurisdictions. A suspension may require the enterprise to temporarily cease transferring data to overseas systems, service providers or data recipients during the suspension period.

The practical consequences will depend on the structure of the enterprise’s systems and data flows. If an enterprise relies on customer, employee or user data being transferred to overseas systems for storage, administration, analytics or service delivery, it may need to suspend or modify its product or service delivery model, migrate systems to alternative processing arrangements, or restructure data flows to continue operating in compliance with the sanctioning decision.

The key risk is therefore that the enterprise may be unable to maintain its existing data processing model throughout the suspension period. For enterprises that are highly dependent on overseas infrastructure or data processing systems, this may entail system migration costs, changes of service providers, process restructuring or service disruption.

4.2. Order to cease personal data processing for violations relating to impact assessment requirements

For certain violations concerning DPIA dossiers, Decree 330 provides for the remedial measure of requiring the business to cease personal data processing until all obligations have been fully satisfied and confirmation has been obtained from the specialized personal data protection authority. [9]

This measure should first be distinguished from the supplementary penalty of “suspension of cross-border transfers”. A remedial measure is intended to eliminate the underlying violation and permits the activity to resume once the remediation conditions have been satisfied. [10]

For an enterprise for which data processing is an integral part of its business operations, an order to cease processing may have consequences extending beyond the data processing activity itself. For example, if the business requires data to perform services, maintain customer accounts, manage customer relationships or carry out a particular business process, being prohibited from continuing to process the data may prevent the business from fully or timely performing its corresponding service obligations.

Accordingly, the impact of this measure depends heavily on the extent to which the business model relies on personal data processing, but will generally include disruption or interruption of activities involving personal data, temporary suspension of certain business functions or processing activities, remediation and documentation costs, and potential disputes if the enterprise cannot perform its obligations to customers or business partners during the period in which processing is suspended.

4.3. Mandatory destruction or deletion of data to the extent that it cannot be recovered

In various circumstances, Decree 330 provides for the remedial measure of mandatory destruction or deletion of data to the extent that it cannot be recovered, where the data has been unlawfully collected, processed, purchased, sold or transferred.

This is one of the measures capable of having the most far-reaching impact on enterprises because the affected subject matter is not limited to a future processing activity and may extend to an entire dataset that has been accumulated and is currently used for business purposes.

For data collected and accumulated over a long period, mandatory deletion to the point of irrecoverability may prevent a business from continuing to use that data for other lawful purposes. The business must also identify and address the data across all storage systems and copies that have been provided or transferred, to the extent required by the decision and applicable regulations.

This consequence is particularly significant for business models in which data has substantial commercial or operational value. Once data is required to be deleted, an enterprise cannot assume that internal backups will permit continued use of that data; instead, the enterprise must be able to demonstrate that data falling within the deletion requirement has been handled appropriately.

Potential serious consequences include loss of data resources supporting business operations; costs of rebuilding databases; loss of the ability to derive value from accumulated data; obligations to delete data or request deletion by third parties that have received the data; and costs of demonstrating completion of the remedial measure.

4.4. Confiscation and suspension of activities relating to the provision of personal data protection or processing services

For the provision of personal data protection services, Decree 330 provides that, in the relevant circumstances, exhibits and means used to commit administrative violations may be confiscated and the provision of personal data protection services may be suspended for a specified period.

For the business of providing personal data processing services, Decree 330 also establishes requirements concerning the Certificate of Eligibility, personnel and governance systems. Operating without satisfying the applicable conditions, or continuing to operate where the Certificate of Eligibility is no longer valid, may result in corresponding sanctions, including suspension of activities and remedial measures relating to data and proceeds. [11]

In substance, this is no longer merely an internal compliance obligation. Where a licence or business condition is affected, the business’s right to continue providing services may be directly restricted.

For enterprises providing services to multiple customers, the consequences may also extend to existing contractual relationships: the business may no longer be able to perform certain committed services during the suspension period or while it is remedying the conditions for conducting the business. However, whether liability for damages or breach of contract arises must be assessed on a contract-by-contract basis and under the applicable law; it is not an automatic consequence of a sanctioning decision.

5. Sanctioning organizations with no physical presence in Vietnam

As discussed in Section 1 of this article, the absence of a registered office or operational establishment in Viet Nam does not mean that the competent authority cannot establish a violation and issue a sanctioning decision, provided that the foreign organization falls within the scope of Article 2 and the relevant conduct constitutes an administrative violation under Chapter II of Decree 330.

5.1. A sanctioning decision may still be served on an overseas organization

Under Article 70.1 and 70.2 of the Law on Handling of Administrative Violations currently in force, within 3 working days from the date of issuance of a sanctioning decision, the person who issued the decision must send it to the sanctioned individual or organization and the relevant authorities for enforcement. Service may be effected by personal delivery, by registered postal service, or electronically; where these methods cannot be used, the law also provides for a mechanism for public posting.

This is relevant where a foreign organization has no office or permanent representative in Viet Nam: geographical absence does not, in itself, prevent a sanctioning decision from being served. However, the method of service and the conditions for the decision to be deemed duly served must comply with the Law on Handling of Administrative Violations and its implementing regulations.

Once the decision has been duly served, the sanctioned organization must comply within the period specified in the decision. The sanctioning decision must also specify the time limit and place of enforcement, the place where the fine is to be paid, the responsibilities for enforcement, and the coercive measures applicable in the event of non-voluntary compliance.

5.2. Enforcement mechanism under the Law on Handling of Administrative Violations

Article 6 of Decree 330 expressly provides that, upon expiry of the enforcement period, if the violating individual or organization has not voluntarily complied, coercive enforcement will be carried out in accordance with the Law on Handling of Administrative Violations.

Under Article 86.2 of the Law on Handling of Administrative Violations, coercive measures for enforcement of a sanctioning decision may, depending on the circumstances, include deduction of money from bank accounts; distraint of assets of equivalent value for auction; collection of money or assets belonging to the subject of coercive enforcement that are held by another organization or individual; compulsory implementation of remedial measures; and other coercive measures prescribed by law.

Notably, for accounts of an organization subject to coercive enforcement held at a credit institution, the State Treasury or a foreign bank branch, the law requires information to be provided on the conditions for enforcement of the decision, the corresponding amount to be frozen, and the amount payable to be transferred at the request of the competent enforcement officer, subject to the statutory conditions.

Accordingly, if a foreign organization has no presence in Viet Nam but has accounts, assets or proprietary interests within the scope to which Vietnamese law permits coercive measures to be applied, the competent authority may, in principle, still use the corresponding enforcement mechanisms under the Law on Handling of Administrative Violations.

6. Action recommendations

Step 1: Identify and determine the data processing model

Enterprises should conduct an overall review of their personal data processing activities to determine the scope of data, processing purposes, legal bases for processing, the roles of the parties and the relevant data flows. The review should cover the type and nature of the data, the number of data subjects, processing purposes and retention periods, storage locations, parties to whom data is provided or who have access to it, cross-border data transfers, and the role of each party in the processing activity.

In addition, enterprises should determine whether their actual activities constitute the provision of personal data processing services or other conditional business activities under Decree 330, and identify the corresponding legal obligations applicable to each processing model.

Step 2: Complete the legal documentation and compliance governance framework

Once the processing model has been identified, enterprises should review and complete their documentation, records and procedures to demonstrate compliance with applicable legal requirements. Depending on the circumstances, this framework may include the Personal Data Processing Impact Assessment dossier, the Personal Data Transfer Impact Assessment dossier, records evidencing consent, data inventories and data management records, procedures for exercising data subject rights, incident response procedures and records, data processing agreements with service providers, and records relating to personnel or the function responsible for personal data protection.

The documentation should be developed in parallel with mechanisms for allocation of responsibilities, approval, updating and retention to ensure that the business can demonstrate its compliance status at the time of an inspection or when requested by a competent authority.

Step 3: Translate legal requirements into practical controls

Personal data protection requirements should be translated into managerial, organizational and technical measures that can be implemented and tested in practice. Depending on the nature of the activities, enterprises should consider appropriate measures such as encryption, access controls, multi-factor authentication, logging, mechanisms for recording and managing consent, data deletion procedures, segregation of backup and deletion mechanisms, vendor controls, and controls over cross-border data transfers.

These measures should not only prevent and mitigate violations, but also ensure that the business can detect, respond to, remediate and demonstrate compliance with legal obligations within the applicable time limits when an incident occurs or a request is made by a competent authority.

7. Conclusion

Decree 330 materially changes how enterprises should view compliance risk in the fields of cybersecurity and personal data protection. Risk is no longer limited to a fixed monetary fine. For certain violations, fines are calculated by reference to revenue or proceeds, while the competent authority may also impose measures that directly affect data, systems and the ability to continue conducting business.

Three categories of risk should be prioritized at the corporate governance level: (i) financial exposure, particularly in relation to cross-border transfers of personal data and data trading; (ii) loss of digital assets resulting from obligations to destroy or delete data to the point of irrecoverability; and (iii) business disruption resulting from orders to cease processing or transferring data, suspension of activities, or loss of eligibility to provide services.

For ordinary enterprises, immediate priorities are to establish lawful bases for processing and valid consent, complete DPIAs, control data transfers, and establish procedures for exercising data subject rights and responding to incidents. For personal data processing service providers, a separate workstream should be added covering business conditions, the Certificate of Eligibility, personnel and the risk management framework.

From a governance perspective, enterprises should treat Decree 330 as a business operating requirement. An effective compliance programme must answer not only the question of “whether the business is in violation”, but also whether “the business can detect, prevent, remediate and continue operating in a controlled manner if an incident occurs or the competent authority takes enforcement action”.

As a final recommendation, enterprises should conduct a documented compliance gap assessment within the first 90 days after Decree 330 takes effect, prioritizing cross-border data flows, automated collection activities, paid purchase, sale or transfer of data, SaaS/cloud computing models, and enterprises providing personal data processing services.

What CNC can support?

  • Inbound/Outbound Investment: Company Establishment, Investment Registration and Post-registration Services in relation to tax, accounting, labor, insurance, salary, and outsourced legal department;
  • Operation Licenses: We could provide support in the application for operation licenses for business activities in fields such as manufacturing, commerce, services, e-commerce, healthcare, education, or food & beverage (restaurants);
  • M&A Services: Conduct legal due diligence, structure transactions, draft and negotiate transaction documents, provide advice on competition law compliance (including merger control filings and related approvals), obtain necessary regulatory approvals and licenses, and provide post-closing support;
  • Personal Data Protection: Provide support in compliance with the data protection regulations, including the drafting and reviewing of Data Protection Impact Assessment (DPIAs), Data Processing/Transfer Agreement, Privacy Policies, and other necessary documents under the Personal Data Protection Decree (PDPD);
  • Dispute Resolution: Litigation and Commercial Arbitration (VIAC SIAC ICC); and
  • Legal Retainer Services per the clients’ requests.

Please contact Mr. Chris Luong – Partner through the email address of chris.luong@cnccounsel.com through the email address of ngan.nguyen@cnccousel.com for prompt and timely support.

Managed by

Luong Van Chuong I Partner

Phone: (84) 938 04 7969

Email: chris.luong@cnccounsel.com

Tran Anh Thy | Associate

Phone: (84) 28 6276-9900

Email: thy.tran@cnccounsel.com

Contact Us

For further information, please contact:

CNC Vietnam Law Firm

Address: The Rise Building, 2A1 Nguyen Thi Minh Khai, Sai Gon Ward, Ho Chi Minh City, Vietnam

Phone: (84) 28-6276 9900 – 081 235 3839

Hotline: (84) 916-545-618

Email: contact@cnccounsel.com

Website:cnccounsel

We would be delighted to welcome you at CNC’s office, where you’ll have the opportunity to consult with the lawyer best suited to your circumstances. Of course, if you are unable to meet in person, simply email us via contact@cnccounsel.com or call us via (+84-28) 6276 9900.

It would be a pleasure for CNC’s lawyers to help you build a solid legal foundation, thus ensuring the success and sustainable development of your project!

————————————

Copyright © CNC Counsel. All rights reserved. Ownership: This documentation and content (Content) is a proprietary resource owned exclusively by CNC Counsel. Use of this Content does not of itself create a contractual relationship, nor any attorney/client relationship, between CNC Counsel and any person. Disclaimers: The Content provided is for informational purposes only and may not reflect the latest legal or regulatory developments. Summaries of laws, regulations, and practices are subject to change. This Content does not constitute legal or professional advice for any specific situation and should not be relied upon as a substitute for reviewing and complying with applicable laws, rules, regulations, or official forms. Always seek legal counsel before making any decisions or taking any action based on this Content. CNC Counsel, along with its editors and contributing authors, make no guarantees regarding the accuracy of the Content and explicitly disclaim any liability for any consequences resulting from actions taken, allowed, or omitted, whether fully or partially based on any part of the Content. The Content may include links to external websites, and external sites may also link to it. CNC Counsel is not responsible for the content or functionality of any such external websites and disclaims all liability for any issues arising from their content or operation. Please note: Past results do not guarantee similar outcomes.

————————————

[1] Article 80 of Decree No. 330/2026/ND-CP.

[2] Article 81.1 of Decree No. 330/2026/ND-CP.

[3] Article 43 of Decree No. 330/2026/ND-CP.

[4] Article 55 of Decree No. 330/2026/ND-CP.

[5] Article 59 of Decree No. 330/2026/ND-CP.

[6] Article 59 of Decree No. 330/2026/ND-CP.

[7] Articles 48, 53 and 56 of Decree No. 330/2026/ND-CP.

[8] Articles 4 and 5 of Decree No. 330/2026/ND-CP.

[9] Articles 56.5 and 56.6 of Decree No. 330/2026/ND-CP.

[10] Articles 4 and 55 of Decree No. 330/2026/ND-CP.

[11] Articles 7, 48, 53, 55, 56 and 59 of Decree No. 330/2026/ND-CP.

Content Protection by DMCA.com

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.