Nghị định 330/2026 về việc siết chặt quyền tiếp cận thông tin tại Việt Nam

Tino Cao 

Chặn trang, gỡ bài, khóa tài khoản và xử phạt cả người hướng dẫn cách vượt qua biện pháp ngăn chặn không làm xã hội an toàn hơn; chúng chỉ làm nghèo đi môi trường thông tin, hạn chế năng lực tự kiểm chứng và đẩy công dân vào trạng thái lệ thuộc ngày càng lớn vào phần thông tin được chính quyền tùy thích cho phép lưu hành.

Ngày 19 tháng 8 năm 2026, Chính phủ Việt Nam ban hành Nghị định 330/2026/NĐ-CP về xử phạt vi phạm hành chính trong lĩnh vực an ninh mạng và bảo vệ dữ liệu cá nhân, có hiệu lực ngay trong ngày. Trong 82 điều của nghị định, Điểm p Khoản 1 Điều 15 đáng chú ý đặc biệt. Cá nhân có thể bị phạt từ 10 đến 20 triệu đồng nếu hướng dẫn hoặc chia sẻ phương thức truy cập một trang mạng, ứng dụng hay nền tảng số đã bị giới hạn truy cập theo pháp luật. Tang vật, phương tiện có thể bị tịch thu, nội dung hướng dẫn phải gỡ hoặc xóa. Tổ chức nếu thực hiện cùng hành vi nói trên thì phải chịu mức phạt gấp đôi.



Quy định này đẩy chính sách kiểm soát Internet tại Việt Nam leo thang lên một mức độ hà khắc hơn, xâm phạm trực tiếp quyền tiếp cận thông tin của người dân. Trước đây, nhà nước chủ yếu nhắm vào nội dung và nơi phát hành nội dung. Trang bị chặn, bài bị gỡ, tài khoản bị hạn chế, nền tảng bị buộc tuân thủ. Nay chế tài tiến thêm đến người đọc và người chỉ cho người khác cách tiếp cận nguồn tin. Quyền lực kiểm duyệt không dừng ở việc đóng một cánh cửa. Người chỉ cách mở cánh cửa ấy cũng có thể bị xử phạt.

Nghị định 330, và Nghị định 333/2026/NĐ-CP quy định chi tiết và biện pháp thi hành Luật An ninh mạng, cùng được ban hành trong đợt này, cho thấy rõ cách nhà nước Việt Nam đang siết việc kiểm soát Internet từ cả phía doanh nghiệp cung cấp hạ tầng lẫn người sử dụng. Theo Nghị định 330, doanh nghiệp viễn thông có thể bị phạt từ 60 đến 100 triệu đồng nếu không triển khai, duy trì hoặc nâng cấp các biện pháp kĩ thuật theo yêu cầu của cơ quan có thẩm quyền nhằm ngăn người dùng tiếp tục truy cập nội dung bị xác định là vi phạm. Trong một số trường hợp, doanh nghiệp còn có thể bị đình chỉ hoạt động từ một đến ba tháng. Nghị định 333 quy định nhà cung cấp dịch vụ phải hạn chế hoặc chặn truy cập, gỡ thông tin, ứng dụng hay dịch vụ tại Việt Nam trong vòng 24 giờ kể từ khi nhận yêu cầu của lực lượng chuyên trách Bộ Công an. Với trường hợp được xác định là khẩn cấp về an ninh quốc gia, thời hạn rút xuống còn sáu giờ.

Cơ chế kiểm soát khá rõ ràng. Cơ quan công an xác định nội dung cần ngăn chặn, doanh nghiệp viễn thông hoặc nền tảng phải thi hành trong thời gian rất ngắn, còn người dân có thể bị xử phạt nếu chia sẻ cách tiếp cận phần nội dung ấy. Điều đáng lo nằm ở chỗ công dân lại không được cung cấp đầy đủ thông tin để biết mình đang đứng trước một lệnh chặn nào. Nghị định 330 không buộc nhà nước công bố danh sách các trang, tên miền, ứng dụng hay nội dung đang bị hạn chế. Nghị định 333 cũng chỉ quy định lực lượng chuyên trách gửi yêu cầu cho doanh nghiệp cung cấp dịch vụ, mà không kèm nghĩa vụ công khai tương ứng với xã hội. Khi gặp một trang trắng, lỗi DNS, kết nối bị cắt hoặc thông báo chung chung về “quy định địa phương”, người sử dụng Internet khó biết đó là lỗi kỹ thuật, chính sách riêng của nền tảng hay một quyết định của cơ quan nhà nước. Trong khi trách nhiệm pháp lý có thể rơi xuống doanh nghiệp và từng cá nhân, thông tin cần thiết để nhận biết giới hạn ấy lại nằm trong tay cơ quan ban hành lệnh chặn.

Sự thiếu minh bạch ở đây đưa đến một vấn đề pháp lý căn bản. Công dân có thể bị xử phạt vì hướng dẫn cách truy cập một địa chỉ bị giới hạn, nhưng lại không được cung cấp một danh sách công khai để biết địa chỉ nào đang thuộc diện đó. Một chế tài chỉ có tính dự liệu khi người dân có khả năng nhận biết trước hành vi nào có thể dẫn đến xử phạt. Nếu đối tượng của lệnh chặn được giữ kín, người dân bị buộc tự gánh rủi ro từ chính sự thiếu thông tin do cơ quan công quyền tạo ra. Sự bất hợp lý ấy còn rõ hơn khi đối chiếu Nghị định 330 với Luật An ninh mạng năm 2025. Điểm i Khoản 4 Điều 13 của luật đề cập hành vi hướng dẫn người khác thực hiện hành vi vi phạm pháp luật, trong khi Điểm p Khoản 1 Điều 15 của nghị định xử phạt cả việc hướng dẫn hoặc chia sẻ phương thức truy cập một địa chỉ đã bị hạn chế. Đây là hai hành vi khác nhau về bản chất. Việc đọc một tài liệu để nghiên cứu, kiểm chứng, lưu trữ, làm báo hay phản biện tự nó không đồng nghĩa với hành vi trái pháp luật. Nếu luật chỉ quy định chế tài đối với việc hướng dẫn người khác thực hiện hành vi vi phạm, còn nghị định mở rộng sang hành vi hướng dẫn tiếp cận thông tin, thì vấn đề thẩm quyền của văn bản dưới luật và giới hạn của chế tài này cần được xem xét nghiêm túc.

Khía cạnh hiến định còn đặt ra vấn đề về tính thống nhất giữa Hiến pháp và các quy định pháp luật liên quan. Điều 14 Hiến pháp năm 2013 xác định quyền con người và quyền công dân chỉ có thể bị hạn chế theo luật, trong những trường hợp thật sự cần thiết vì các lý do do chính Hiến pháp quy định. Điều 25 của Hiến pháp đồng thời ghi nhận tự do ngôn luận, tự do báo chí và quyền tiếp cận thông tin. Trong bối cảnh đó, việc một nghị định của Chính phủ bổ sung chế tài trực tiếp đối với hành vi tiếp cận và truyền đạt thông tin đặt ra nghi vấn về căn cứ pháp lí, mức độ dự liệu của quy định và tính tương xứng giữa biện pháp hạn chế với mục tiêu mà nhà nước viện dẫn.

Nghị định 330 không đồng nghĩa với việc VPN, proxy hay DNS thay thế bị cấm nói chung. Đây đều là những công cụ kỹ thuật có nhiều công dụng hợp pháp, từ bảo vệ dữ liệu khi sử dụng Wi-Fi công cộng, kết nối với hệ thống nội bộ của doanh nghiệp, làm việc từ xa đến hạn chế theo dõi thương mại. Điều đáng ngại nằm ở phạm vi áp dụng quá rộng và cách diễn giải mơ hồ của Điểm p. Quy định này không đòi hỏi người vi phạm có mục đích thu lợi, gây thiệt hại, thực hiện hành vi phạm tội hay tạo ra một hậu quả cụ thể. Chỉ riêng việc “hướng dẫn” hoặc “chia sẻ phương thức truy cập” đã có thể dẫn đến xử phạt. Trong khi danh sách nội dung bị giới hạn lại không được công khai đầy đủ, một bài viết thuần túy giải thích kĩ thuật cũng có thể bị chụp mũ và cưỡng ép vào diện xử phạt nếu người khác sử dụng kiến thức ấy để truy cập một địa chỉ đang bị chặn.

Thẩm quyền xử phạt được giao xuống tận cấp xã. Theo Điều 72 và Điều 73, trưởng công an cấp xã và chủ tịch ủy ban nhân dân cấp xã có thể phạt cá nhân đến 50 triệu đồng, phạt tổ chức đến 100 triệu đồng trong lĩnh vực an ninh mạng, đồng thời tịch thu tang vật và áp dụng các biện pháp khắc phục hậu quả. Mức thẩm quyền này đủ để xử lí toàn bộ khung phạt đối với hành vi hướng dẫn hoặc chia sẻ cách truy cập. Trong khi các khái niệm như “hướng dẫn” và “chia sẻ phương thức” còn thiếu giới hạn rõ ràng, việc để hàng nghìn đơn vị cấp cơ sở cùng áp dụng một điều khoản rộng như vậy chắc chắn sẽ dẫn đến tình trạng mỗi nơi hiểu và xử lí theo một cách khác nhau.

Nghị định 330 cũng không mở đầu cho việc chặn mạng tại Việt Nam. Hoạt động này đã diễn ra từ nhiều năm trước và từng được ghi nhận qua các nghiên cứu đo lường Internet. Nhiều trang báo, trang nhân quyền và nguồn tin chính trị bị nghi chặn bằng các biện pháp như can thiệp DNS, chặn địa chỉ IP hoặc cắt kết nối TCP và TLS. Chỉ trong sáu tháng đầu năm 2022, hơn 301.000 phép đo trên 2054 địa chỉ tại 10 mạng ở Việt Nam ghi nhận hơn 1000 trường hợp website không thể truy cập. Tỷ lệ nghi bị chặn tập trung cao ở các trang phê phán chính trị, báo chí và nhân quyền. Nghị định 330 không tạo ra một cơ chế kiểm duyệt mới từ con số 0 mà bổ sung thêm một loạt biện pháp chế tài đối với người sử dụng can thiệp vào hệ thống chặn truy cập đã tồn tại từ trước.

Sức ép đối với các nền tảng quốc tế từng bộc lộ khá rõ qua chính hạ tầng mạng. Năm 2020, Reuters điều tra việc các máy chủ Facebook tại Việt Nam bị gián đoạn hoặc làm chậm trong nhiều tuần, và dịch vụ chỉ được khôi phục đầy đủ sau khi Facebook tăng mức hạn chế đối với những nội dung mà nhà chức trách coi là chống nhà nước. Đến tháng 5 năm 2025, Telegram bị chặn trên diện rộng, với dấu hiệu được ghi nhận trên các mạng lớn như FPT, VNPT và Viettel. Những trường hợp này cho thấy việc kiểm soát nội dung không chỉ diễn ra qua yêu cầu gỡ bài hay khóa tài khoản mà còn có thể được thực hiện ngay ở tầng hạ tầng truy cập.

Trong cùng giai đoạn, Bộ Công an tiếp nhận MobiFone và phần vốn nhà nước chi phối tại FPT Telecom, qua đó gia tăng vai trò trực tiếp trong lĩnh vực viễn thông. Khi cơ quan yêu cầu áp dụng các biện pháp an ninh mạng đồng thời có ảnh hưởng ngày càng lớn đối với hạ tầng truyền dẫn, yêu cầu về minh bạch, giám sát tư pháp và cơ chế khiếu nại càng trở nên cấp thiết. Nếu thiếu những bảo đảm này, việc kiểm soát Internet dễ rơi vào tình trạng “vừa đá bóng vừa thổi còi”, khi cùng một hệ thống vừa xác định nội dung cần ngăn chặn, vừa có khả năng chi phối cách lệnh chặn được thực hiện.

Quy mô can thiệp vào nội dung trực tuyến cũng được phản ánh qua số liệu chính thức. Riêng quý III năm 2025, Facebook, YouTube và TikTok đã xử lí hơn 12.000 nội dung theo yêu cầu hoặc trong khuôn khổ phối hợp với các cơ quan Việt Nam. Sang quý I năm 2026, hàng nghìn bài viết, video, kênh và tài khoản tiếp tục bị gỡ hoặc khóa. Các nguồn thống kê sử dụng thời k và cách đếm khác nhau nên không thể cộng trực tiếp, nhưng các con số này vẫn cho thấy mức độ can thiệp vào nội dung trên mạng đã đạt quy mô lớn và diễn ra thường xuyên.

Không thể viện dẫn an ninh mạng để hợp thức hóa mọi biện pháp kiểm soát thông tin. Nhà nước có trách nhiệm ngăn lừa đảo, mã độc, bóc lột tình dục trẻ em, ma túy, kích động bạo lực và các hành vi phạm tội trên mạng. Nhưng Luật An ninh mạng năm 2025 lại gom cả những khái niệm chính trị rất mơ hồ như “tuyên truyền chống nhà nước”, “xuyên tạc lịch sử”, “phủ nhận thành tựu cách mạng”, “gây chia rẽ giữa nhân dân với chính quyền” hay “gây phương hại đến uy tín quốc gia” vào cùng phạm vi xử lí. Khoản 2 Điều 4 xác định công tác bảo vệ an ninh mạng nằm dưới sự lãnh đạo của đảng cộng sản Việt Nam. Quy định này khiến toàn bộ hoạt động quản lý không gian mạng gắn trực tiếp với định hướng chính trị của đảng cầm quyền. Khái niệm “an ninh” theo đó có thể mở rộng từ phòng chống tội phạm, bảo vệ hạ tầng và dữ liệu sang bảo vệ uy tín chế độ, kiểm soát các diễn giải bất lợi về lịch sử, chính sách và trách nhiệm của quan chức, đồng thời hạn chế sự lưu hành của những quan điểm đối nghịch với diễn ngôn chính thức. Khi đảng cầm quyền chi phối định hướng chính trị, cơ quan hành pháp nắm quyền áp dụng các biện pháp cưỡng chế, còn tư pháp độc lập gần như bị vô hiệu hóa, thì sự khác biệt giữa bảo vệ an ninh quốc gia và bảo vệ lợi ích chính trị của đảng cầm quyền trên thực tế bị xóa bỏ. Những trường hợp hạn chế các bài viết sự thật về Làng Vân hay Nguyễn Sỹ Cương trong thời gian qua cho thấy nguy cơ ấy đang hiện diện trong thực tế kiểm soát thông tin.

Việt Nam là thành viên Công ước quốc tế về các quyền dân sự và chính trị. Điều 19 bảo vệ quyền tìm kiếm, tiếp nhận và truyền đạt thông tin. Bình luận chung số 34 của Ủy ban Nhân quyền Liên Hiệp Quốc yêu cầu mọi hạn chế đối với quyền này phải có căn cứ rõ ràng, cần thiết và tương xứng. Năm 2025, Ủy ban đã bày tỏ quan ngại về việc gián đoạn Internet, gỡ nội dung phê phán chính quyền và những quy định an ninh mạng quá rộng tại Việt Nam. Nghị định 330 không những không sửa chữa những khiếm khuyết đó mà còn tăng cường tính độc tài bằng việc đưa ra những chế tài mới, nhắm vào người truyền đạt kiến thức giúp người khác tiếp cận thông tin. Điểm p Khoản 1 Điều 15 vì thế cần phải bị bãi bỏ.

Chính sách này cần bị chỉ trích vì trên thực tế, nó đang biến pháp luật an ninh mạng thành công cụ để chính quyền Việt Nam tiếp tục kiểm soát và bóp nghẹt khả năng tiếp cận thông tin độc lập của người dân. Chặn trang, gỡ bài, khóa tài khoản và xử phạt cả người hướng dẫn cách vượt qua biện pháp ngăn chặn không làm xã hội an toàn hơn; chúng chỉ làm nghèo đi môi trường thông tin, hạn chế năng lực tự kiểm chứng và đẩy công dân vào trạng thái lệ thuộc ngày càng lớn vào phần thông tin được chính quyền tùy thích cho phép lưu hành. Xét về bản chất, đây là một chính sách ngu dân, bởi nó cản trở chính khả năng tìm kiếm, đối chiếu và hình thành phán đoán độc lập của người dân. Một chính quyền có đủ niềm tin vào tính chính danh của mình không cần phải đối xử với một đường dẫn, một tài liệu bất đồng quan điểm hay một hướng dẫn kĩ thuật như một mối đe dọa. Việc một người dùng Internet chỉ cho người khác cách tiếp cận nguồn tin bị nhà nước cấm đoán cũng có thể bị xử phạt, tự nó đã biến không gian mạng thành một cơ chế giam cầm tự do trí tuệ, nơi mà pháp luật bị lạm dụng để duy trì chính sách kiểm soát hà khắc, ấu trĩ và phản tiến bộ.

— tino 

 𝙏𝙝𝙖𝙢 𝙠𝙝𝙤:

* Nghị định 330/2026/NĐ-CP ngày 19 tháng 8 năm 2026 của Chính phủ về xử phạt vi phạm hành chính trong lĩnh vực an ninh mạng và bảo vệ dữ liệu cá nhân.

* Nghị định 333/2026/NĐ-CP của Chính phủ về các biện pháp thi hành pháp luật an ninh mạng.

* Luật An ninh mạng số 116/2025/QH15.

* Hiến pháp nước Cộng hòa Xã hội Chủ nghĩa Việt Nam năm 2013, Điều 14 và Điều 25.

* Công ước quốc tế về các quyền dân sự và chính trị, Điều 19.

* Ủy ban Nhân quyền Liên Hiệp Quốc, Bình luận chung số 34 về Điều 19 ICCPR.

* Ủy ban Nhân quyền Liên Hiệp Quốc, Concluding observations on the fourth periodic report of Viet Nam, CCPR/C/VNM/CO/4, 2025.

* OONI và iMAP, các báo cáo kĩ thuật về kiểm duyệt Internet tại Việt Nam, đặc biệt dữ liệu đo lường năm 2022 và việc chặn Telegram năm 2025.

* Reuters, các điều tra và tường thuật về Facebook tại Việt Nam năm 2020, việc chặn Telegram năm 2025 và thay đổi quyền quản lí đối với các doanh nghiệp viễn thông.

* Các báo cáo minh bạch của Meta về yêu cầu hạn chế nội dung tại Việt Nam.

* Số liệu của cơ quan quản lý Việt Nam về việc Facebook, YouTube, TikTok và các nền tảng khác gỡ hoặc hạn chế nội dung trong năm 2025 và 2026.

•••••

𝐃𝐞𝐜𝐫𝐞𝐞 𝟑𝟑𝟎/𝟐𝟎𝟐𝟔 𝐚𝐧𝐝 𝐕𝐢𝐞𝐭𝐧𝐚𝐦𝐬 𝐞𝐬𝐜𝐚𝐥𝐚𝐭𝐢𝐧𝐠 𝐫𝐞𝐬𝐭𝐫𝐢𝐜𝐭𝐢𝐨𝐧𝐬 𝐨𝐧 𝐚𝐜𝐜𝐞𝐬𝐬 𝐭𝐨 𝐢𝐧𝐟𝐨𝐫𝐦𝐚𝐭𝐢𝐨𝐧

On 19 August 2026, the Vietnamese government issued Decree No. 330/2026/NĐ-CP on administrative penalties for violations in the fields of cybersecurity and personal data protection. The decree took effect on the same day. Among its 82 articles, Article 15(1)(p) warrants particular scrutiny. It provides for a fine of between VND 10 million and VND 20 million for an individual who “instructs or shares methods for accessing websites, applications, or digital platforms to which access has been restricted in accordance with law”. Instruments or means used in committing the violation may be confiscated, and the relevant instructional content may be ordered removed or deleted. An organization committing the same violation is subject to twice the fine applicable to an individual.

This provision marks a significant escalation in Vietnam’s system of Internet control because it extends coercive regulation directly to the public’s ability to obtain information. Earlier forms of Internet censorship focused primarily on content and the infrastructure through which it was distributed. Websites were blocked, posts removed, accounts restricted, and online platforms compelled to comply with government orders. Decree 330 extends enforcement beyond content providers and platforms to readers themselves and to those who help others locate or reach restricted sources. The state’s censorship power no longer ends with closing a door. A person who explains how that door can be opened may now also face punishment.

Decree 330, and Decree No. 333/2026/NĐ-CP, detailing provisions and measures for the implementation of the Cybersecurity Law, issued on the same date, demonstrate how the Vietnamese state is tightening Internet control simultaneously across communications infrastructure, service providers, digital platforms, and individual users. Under Decree 330, telecommunications companies may face substantial penalties for failing to implement, maintain, or upgrade technical measures required by competent authorities to prevent continued access to content deemed unlawful. Certain violations may also result in the temporary suspension of operations. Decree 333 requires providers of telecommunications, Internet, and related digital services in Vietnam to restrict or block access, remove information, or disable services and applications when directed by the Ministry of Public Security’s specialized cybersecurity force. Such orders must ordinarily be carried out within 24 hours. Where the authorities classify a case as an emergency involving national security, the deadline is reduced to six hours.

The regulatory structure is relatively straightforward. Security authorities identify information, services, or applications to be restricted. Telecommunications companies and digital platforms must implement the restriction within a short statutory period. Individuals may then be penalized for explaining how the restricted material can still be accessed.

The central problem is that citizens are not provided with a corresponding level of information about the restrictions they are expected to obey. Decree 330 does not require the government to maintain a comprehensive public list of websites, domains, applications, platforms, or categories of content currently subject to access restrictions. Decree 333 provides for orders to be transmitted to service providers but establishes no corresponding general obligation to disclose those orders to the public. When a user encounters a blank page, a DNS error, an interrupted connection, or a generic notice referring to “local regulations,” there may be no practical means of determining whether the cause is a technical failure, a private decision by the platform, or an access restriction imposed by a state authority.

This asymmetry has serious consequences. Legal liability may attach to companies and individuals, while the information necessary to determine where the legal boundary lies remains concentrated in the hands of the authority that imposed the restriction.

This raises a fundamental rule-of-law problem. A person may be punished for explaining how to access a restricted digital resource while having no reliable public mechanism for determining which resources are subject to such restrictions. A sanction can be considered reasonably foreseeable only when those subject to it can determine, with sufficient clarity, what conduct exposes them to liability. Where the subject of a blocking order is undisclosed, citizens are effectively required to bear the legal risk created by the state’s own lack of transparency.

The issue becomes more serious when Decree 330 is compared with the 2025 Cybersecurity Law, Law No. 116/2025/QH15. Article 13(4)(i) of that law addresses conduct involving the instruction of others to engage in unlawful acts. Article 15(1)(p) of Decree 330, however, penalizes instruction or the sharing of methods for accessing a resource to which access has been restricted. These are not necessarily equivalent forms of conduct. Reading a document for research, verification, archival purposes, journalism, academic analysis, or public criticism does not in itself constitute an unlawful act.

If the statute authorizes sanctions against instructing others to commit an unlawful act, while an implementing decree extends liability to instruction on how to obtain access to information, a legitimate question arises as to whether the executive regulation has expanded the scope of liability beyond that authorized by the legislation from which it derives its authority. This is more than a technical question of statutory interpretation. It concerns the fundamental principle that subordinate legislation should implement a statute rather than create additional restrictions on fundamental rights without a sufficiently clear legislative basis.

There is also a constitutional issue. Article 14 of Vietnam’s 2013 Constitution states that human rights and citizens’ rights may be restricted only by law and only where necessary for reasons specified by the Constitution. Article 25 recognizes freedom of speech, freedom of the press, the right of access to information, and the freedoms of assembly, association, and demonstration. Against this constitutional framework, the use of a government decree to impose direct sanctions on the transmission of knowledge concerning access to information raises serious questions about legal authority, foreseeability, necessity, and proportionality.

Decree 330 should not be understood as imposing a general prohibition on virtual private networks, proxy services, alternative DNS services, or comparable technologies. Such tools have numerous legitimate uses. They are routinely employed to secure communications over public Wi-Fi, connect employees to corporate networks, facilitate remote work, protect commercially sensitive information, and reduce certain forms of commercial tracking.

The concern lies instead in the breadth and ambiguity of Article 15(1)(p). The provision does not appear to require proof that a person acted for financial gain, intended to cause harm, facilitated a criminal offense, or produced any demonstrable harmful consequence. The acts of “instructing” or “sharing methods of access” may themselves be sufficient to trigger administrative liability. Combined with the absence of a comprehensive and readily accessible public registry of blocked resources, this wording creates a substantial risk that technically neutral information could be treated as unlawful when another person uses that knowledge to access a resource currently subject to government restriction.

That ambiguity is particularly serious because enforcement authority extends to the local level. Under Articles 72 and 73 of Decree 330, senior commune-level police officials and chairpersons of commune-level People’s Committees have sufficient administrative enforcement authority to deal with the Article 15 offense, including powers to impose fines, confiscate relevant items, and order remedial measures. Although the decree sets different maximum sanctioning powers for organizations and individuals under its general penalty structure, local authorities nevertheless possess sufficient jurisdiction to impose the full range of penalties applicable to an individual accused of sharing methods of access.

This decentralization matters. Expressions such as “instructing” and “sharing methods” leave substantial room for interpretation. When a broadly worded restriction can be enforced by a large number of administrative authorities across the country, inconsistent application becomes highly likely. One local authority may regard a general explanation of VPN technology as legitimate technical information, while another may treat the same explanation as a method of accessing prohibited material. Such variability is difficult to reconcile with the degree of legal certainty required when a rule directly affects freedom of expression and access to information.

Decree 330 did not introduce Internet blocking in Vietnam. Restrictions on online access have been documented for years through independent technical measurements. News organizations, human rights websites, and politically sensitive sources have reportedly been affected through techniques including DNS interference, IP blocking, and disruption of TCP or TLS connections. Measurements conducted in 2022 across thousands of URLs and multiple Vietnamese networks recorded numerous instances in which websites could not be reached, with suspected blocking disproportionately affecting political criticism, independent journalism, and human rights material.

Decree 330 therefore does not create a censorship system from the ground up. Its significance lies in adding another layer of legal liability for users to an access-control infrastructure that already existed.

Pressure on international platforms has also been exerted through communications infrastructure itself. In 2020, Reuters reported that Facebook’s local servers in Vietnam were taken offline or severely disrupted for approximately seven weeks. According to sources cited by Reuters, full service was restored after Facebook agreed to increase restrictions on content that Vietnamese authorities considered “anti-state.” Whatever terminology is used to characterize that episode, it demonstrated that control over telecommunications infrastructure could be used as leverage in disputes over online speech.

A more recent example occurred in May 2025, when Vietnamese authorities ordered telecommunications providers to block Telegram. Independent network measurements subsequently found strong evidence of blocking on major networks including VNPT, Viettel, and FPT. OONI reported that the restrictions began on 25 May 2025 and were lifted in July. The Telegram episode demonstrated that the state’s capacity to control online content extends beyond requests to delete posts or suspend accounts. Access to an entire communications service can be disrupted at the network level.

The institutional context has also changed. The Ministry of Public Security assumed control of MobiFone and, in 2025, received the state’s 50.17% stake in FPT Telecom, one of Vietnam’s major Internet service providers. The transfer significantly expanded the ministry’s presence in the telecommunications sector at the same time that its specialized cybersecurity authorities were receiving extensive regulatory and enforcement powers.

This concentration creates an important governance concern. When the agency responsible for ordering cybersecurity restrictions also exercises growing influence over the communications infrastructure through which those restrictions may be implemented, transparency, independent oversight, and meaningful avenues of appeal become especially important. Without such safeguards, the same state apparatus may identify material for restriction, direct the implementation of that restriction, and exercise influence over major components of the infrastructure through which access is controlled.

The scale of state involvement in online content is also reflected in official figures. In the third quarter of 2025 alone, Vietnamese authorities reported that Facebook blocked or removed 10,713 pieces of content, YouTube removed 705 videos, and TikTok blocked or removed 798 items following regulatory action or cooperation with government agencies. During the first quarter of 2026, authorities reported the removal or restriction of thousands of additional posts, videos, pages, channels, and accounts. Later official figures covering the first half of 2026 likewise reported large numbers of removals across Meta platforms, YouTube, and TikTok.

The reporting periods and counting methodologies differ, so these figures should not simply be added together. They nevertheless demonstrate a broader pattern. State intervention in online content has become routine, institutionalized, and extensive rather than exceptional.

Cybersecurity cannot legitimately serve as a blanket justification for information control. Every government has a responsibility to combat online fraud, malware, child sexual exploitation, illegal drug trafficking, incitement to violence, cyberattacks, and other genuine criminal activity. Effective cybersecurity law is necessary in any modern society.

The difficulty in Vietnam lies in the breadth with which national security and cybersecurity are defined and applied. The 2025 Cybersecurity Law encompasses politically charged categories such as propaganda against the state, distortion of history, denial of revolutionary achievements, conduct said to cause division between the population and public authorities, and information considered harmful to the nation’s reputation. Such formulations are capable of reaching expression far beyond conventional cybersecurity threats.

Article 4(2) of the 2025 Cybersecurity Law further provides that cybersecurity protection is to be conducted under the leadership of the Communist Party of Vietnam and the unified management of the state. This provision is significant both politically and legally. It formally places cybersecurity governance within the political leadership structure of the ruling party.

Under such a framework, the concept of “security” can expand from preventing cybercrime and protecting infrastructure, networks, and data to protecting the political standing of the regime itself. It can encompass efforts to control unfavorable interpretations of history, government policy, public controversies, or the conduct of officials, while limiting the circulation of political arguments inconsistent with officially approved narratives.

The institutional problem becomes particularly acute where political leadership determines the governing orientation, executive agencies possess broad coercive powers, and opportunities for independent judicial review are limited. In such an environment, the distinction between protecting national security and protecting the political interests of the ruling party becomes difficult to maintain. Recent controversies involving restrictions on politically sensitive reporting illustrate why that distinction is not merely theoretical.

Vietnam is a state party to the International Covenant on Civil and Political Rights. Article 19 of the Covenant protects the freedom to seek, receive, and impart information and ideas of all kinds. The UN Human Rights Committee’s General Comment No. 34 makes clear that restrictions on freedom of expression must satisfy stringent requirements of legality, necessity, and proportionality. Restrictions cannot rest merely on broad invocations of national security. The state must be able to demonstrate why a particular interference is necessary and why a less restrictive measure would be insufficient.

In its 2025 concluding observations on Vietnam’s fourth periodic report, the Human Rights Committee expressed concern about restrictions affecting freedom of expression, including disruptions of Internet access, the removal of content critical of the authorities, and broadly formulated cybersecurity provisions.

Decree 330 does not address those concerns. Article 15(1)(p) compounds them by extending administrative liability to the dissemination of knowledge that may enable another person to obtain information. The provision should therefore be repealed.

The deeper objection to this policy lies in the continued use of cybersecurity law to control and suppress the public’s ability to seek and verify information independently. Blocking websites, removing posts, suspending accounts, and punishing people who explain how restricted sources can be reached do not, by themselves, make a society safer. When applied to lawful journalism, political criticism, historical inquiry, academic research, or dissenting opinion, such measures impoverish the information environment and weaken the public’s capacity for independent verification.

They also foster a culture of anticipatory compliance. Citizens need not know with certainty that an article, website, or technical instruction is prohibited. The possibility of punishment may itself be sufficient to discourage people from reading, sharing, discussing, or explaining it. This is the familiar chilling effect produced by vague and overbroad restrictions on expression. Its reach extends far beyond those who are actually fined, because legal uncertainty encourages many others to censor themselves.

At that point, censorship ceases to be merely a mechanism for suppressing particular pieces of information. It begins to affect the conditions under which knowledge itself is acquired and exchanged.

That is what makes Article 15(1)(p) particularly regressive. A state that blocks an online source already limits what its citizens may encounter. A state that also punishes citizens for teaching one another how information can be reached interferes with a more fundamental social capacity: the ability to investigate, compare competing accounts, test official claims against independent evidence, and form an autonomous judgment.

In political terms, this is an obscurantist policy. It fosters informational dependency by restricting the means through which citizens can examine claims outside state-approved channels. It assumes that the public should encounter only information that the authorities have permitted to circulate, and that attempts to circumvent this hierarchy of information may themselves constitute punishable conduct.

A government confident in the legitimacy of its institutions should not need to treat a hyperlink, a dissenting document, an independent news source, or a piece of technical knowledge as a threat merely because citizens may use it to obtain information that the authorities would prefer them not to see.

Once an Internet user can be punished simply for showing another person how to reach a source of information that the state has chosen to suppress, cyberspace is being transformed from a medium for the exchange of knowledge into a system of intellectual confinement. In such circumstances, law ceases to function primarily as a safeguard against demonstrable harm and is instead used to sustain an increasingly intrusive, paternalistic, and politically regressive system of information control.

   tino 

Nguồn: FB Tino Cao

 

 

Sáng lập:

Nguyễn Huệ Chi - Phạm Toàn - Nguyễn Thế Hùng

Điều hành:

Nguyễn Huệ Chi [trước] - Phạm Xuân Yêm [nay]

Liên lạc: bauxitevn@gmail.com

boxitvn.online

boxitvn.blogspot.com

FB Bauxite Việt Nam


Bài đã đăng

Được tạo bởi Blogger.

Nhãn