Hanoi (VNA) – The Government has issued Decree No. 327/2026/ND-CP, detailing measures to prevent and handle information and activities involving information technology, computer networks, telecommunications networks and electronic devices that threaten national security, social order and safety in cyberspace.
The decree, which took effect on August 19, provides detailed regulations for Article 14 of the Law on Cybersecurity, covering preventive and handling measures, the authority of specialised cybersecurity forces and competent agencies, and the responsibilities of domestic and foreign businesses providing telecommunications, Internet and other online services.
It also establishes a coordination mechanism among relevant agencies, service providers, information system operators, organisations and individuals in preventing and handling violations in cyberspace.
Under the decree, information system operators and service providers must take measures to prevent, detect, block and remove information that threatens national security, social order and safety.
These measures include electronically identifying and authenticating organisations and individuals before and during the provision of services, detecting and blocking the operation of accounts that are not registered to their actual users, and managing Internet addresses in accordance with the law.
They must also comply with regulations on the protection of state secrets and requirements concerning the retention, storage and provision of information and electronic data for the prevention and handling of violations in cyberspace.
When receiving cybersecurity warnings concerning violations, service providers must immediately take necessary measures as instructed by competent authorities. They are also required to report within 24 hours any cyberattack that infringes upon or threatens national sovereignty, interests or security, or seriously harms social order and safety.
Payment and payment-intermediary service providers, as well as digital-asset service providers, must comply with relevant regulations when continuing to provide services to digital accounts placed on warning lists by specialised cybersecurity forces or competent agencies.
Organisations and individuals that create, post or disseminate information online must also cooperate with cybersecurity forces, competent agencies and information system operators in handling information that threatens national security, social order and safety.
The decree requires information system operators and service providers to proactively deploy technical and management measures to monitor information on their systems and promptly notify and coordinate with specialised cybersecurity forces and competent agencies when they detect information falling into categories specified under Article 13 of the Law on Cybersecurity.
They must review and assess potential risks, signs, methods, tools, digital accounts, groups, channels, websites, applications, platforms, information systems, domain names, network addresses, links and electronic data that may be exploited for illegal activities online.
They must also establish mechanisms for inspection, monitoring, warnings, early detection and receiving reports, denunciations and recommendations from organisations and individuals concerning violations. Measures must be taken to prevent the misuse of digital accounts, electronic identities, electronic devices, technical infrastructure and digital services for illegal activities.
Particular attention is given to protecting children, minors, older people, people with disabilities and others at risk of being harmed or exploited online. Service providers are required to proactively warn users about risks such as fraud, asset appropriation, humiliation, defamation, violations of privacy and the dissemination of illegal content.
They must also raise users' awareness and skills in preventing, detecting and responding to violations in cyberspace.
When signs of an online violation are detected, relevant organisations and individuals must immediately take necessary measures within their authority to limit its consequences and preserve electronic evidence, ensuring that such evidence is not lost, altered, damaged or compromised. They must also promptly notify specialised cybersecurity forces and competent authorities.
Depending on the nature, severity and consequences of violations, specialised cybersecurity forces may apply one or more measures prescribed by the Law on Cybersecurity.
Violators may face measures including blocking or requiring the temporary or permanent suspension of online information services; requiring the removal of unlawful, false or fabricated information that threatens national security, social order and safety or infringes upon the legitimate rights and interests of organisations and individuals.
Authorities may also block or restrict the operation of information systems, suspend or terminate their operation, or revoke domain names. Other measures include requiring content-control mechanisms to prevent repeat violations and blocking access from Vietnamese territory to violating information systems.
Service providers and information system operators must provide electronic information and data at the request of specialised cybersecurity forces and competent agencies. The deadline is no later than 24 hours for ordinary requests and three hours in emergency situations./.