Quick answer: Organizations and enterprises providing online services are responsible for cooperating and participating in ensuring information security under the law on network information security and Decree No. 147/2024/ND-CP (effective 25/12/2024, replacing Decree No. 72/2013/ND-CP). The Vietnam Cybersecurity Emergency Response Teams/Coordination Center (VNCERT/CC) is the national focal point for coordinating network information security incident response.
Responsibility to cooperate in ensuring network information security
Under the Law on Network Information Security 2015 and Decree No. 147/2024/ND-CP, organizations providing online services are responsible for: applying measures to ensure information security for their systems; cooperating with competent agencies when incidents occur; and promptly reporting serious network information security incidents as required.
Related services
M&A, Equity Transfer and Project Transfer
If you are preparing an equity transfer, M&A transaction, project transfer or restructuring, ANT Legal can help review legal risks and transaction structure.
What are the functions of VNCERT/CC?
The Vietnam Cybersecurity Emergency Response Teams/Coordination Center (VNCERT/CC), under the Authority of Information Security — Ministry of Science and Technology (after the merger of the Ministry of Information and Communications in 2025), is the focal point coordinating national network information security incident response activities.
Penalties for network information security violations
Violations of regulations on ensuring network information security are subject to administrative penalties under Decree No. 15/2020/ND-CP (amended and supplemented by Decree No. 14/2022/ND-CP). Fine levels depend on each violation; cases causing serious consequences may be subject to criminal liability.
Applicable legal basis
- Law on Network Information Security 2015 (86/2015/QH13).
- Decree No. 147/2024/ND-CP (effective 25/12/2024, replacing Decree No. 72/2013/ND-CP).
- Decree No. 15/2020/ND-CP (amended by Decree No. 14/2022/ND-CP) on administrative penalties in posts, telecommunications, radio frequencies, information technology, and electronic transactions.
Note on Applying Current Legal Regulations
This article is part of the Business & M&A Knowledge series and is presented for reference purposes, helping readers understand the legal issue at a general level before preparing documents or entering into transactions.
Legal regulations may change depending on timing, locality, document type, and specific circumstances. If you need to determine the exact legal basis applicable to your file, please contact ANT Legal’s lawyers at 0966.475.966 for verification and advice before proceeding.
Common Risks to Note
- Applying an outdated, amended, or replaced legal instrument.
- Preparing incomplete dossiers, documents, or evidence.
- Misunderstanding the conditions, procedures, time limits, or competent authorities.
- Signing, filing, or entering into transactions without fully assessing legal risks.
How Can ANT Legal Help?
ANT Legal supports reviewing specific situations, checking dossiers, identifying the applicable legal basis, advising on handling options, and representing clients in dealings with individuals, organizations, or competent authorities when necessary.
For prompt advice, please contact our lawyers at 0966.475.966.
Related Articles
- Can an Enterprise Sign Business Contracts Before Completing Enterprise Registration?
- Must a Joint-Stock Company Publish Unrejected Meeting Agenda Proposals and Meeting Content on Its Website?
- When an Eligibility Certificate’s Contents Change, How Long Does a Credit Rating Enterprise Have to Adjust?
- Are Global Minimum Tax Information-Return Violations Administratively Penalized During the Transition Period?
- Can an Asset Auction Enterprise Be Established and Operate as a Partnership?
