TL;DR: Vietnam e-commerce compliance does not require replacing the systems that run sellers, orders, payments, refunds, invoices, complaints or content operations.
It requires being able to prove what those systems did and how the organization met its regulatory obligations. ComplianceOne connects evidence from existing commerce, payment, tax, e-invoice and regulatory systems to the obligations, controls, attestations, exceptions, prescribed forms and authority responses that govern them.
For the workflow examined here, Decrees 117/2025/NĐ-CP and 70/2025/NĐ-CP provide the tax and e-invoice context. They sit inside a wider regulatory stack that can include the E-Commerce Law 122/2025/QH15 and Decree 248/2026/NĐ-CP, consumer-protection requirements, PDPL and Decree 356, the Data Law, cybersecurity and online-information rules, electronic-transactions and trust-service requirements, and other role-dependent frameworks.
The operational systems remain the systems of record and action. ComplianceOne provides the governance and evidence layer needed to demonstrate compliance, identify gaps, manage exceptions and respond to regulatory review.
It does not replace tax engines, e-invoice systems, payment systems or professional legal and tax judgement.
An e-commerce platform closes a reporting period. The order system shows one amount. The payment provider shows another. A refund was recorded after the order export. The seller’s invoice reflects an adjustment that the reconciliation spreadsheet does not contain.
The tax team asks which figure is right.
That is the moment many platforms ask their software to cross a line. Comparing two stated figures is an evidence operation. Declaring which figure is legally correct is a tax position.
The distinction matters because platform data rarely comes from one system. Seller registration, marketplace orders, payment settlements, refunds, adjustments, e-invoices, and authority correspondence may have different owners, identifiers, periods, and retention rules. A spreadsheet can combine the columns, but it rarely preserves who ran the comparison, which source version was used, what exceptions were resolved, and what evidence supported the final human decision.
Vietnam’s Decree 70/2025/NĐ-CP has applied since 1 June 2025 to the amended invoice and document framework. Decree 117/2025/NĐ-CP has applied since 1 July 2025 to tax administration for household and individual businesses on e-commerce and digital platforms.
The operational challenge is not to turn a governance platform into a tax engine. It is to make seller, transaction, invoice, artifact, reconciliation, and authority evidence traceable without spreading merchant and consumer data beyond its purpose.
“A reconciliation should tell you where statements disagree. Accountable people and their advisers decide what the disagreement means.”
Place Tax Evidence in the Wider E-Commerce Stack
Vietnam's core e-commerce framework includes the E-Commerce Law 122/2025/QH15 and Decree 248/2026/NĐ-CP, together with the implementation roadmap and prescribed regulatory forms. Decrees 117/2025/NĐ-CP and 70/2025/NĐ-CP sit alongside this framework for the tax-administration and e-invoice evidence examined in this article. Each layer retains its own scope and obligations.
Decree 248 has staged commencement. Its general effective date is 1 July 2026, while the platform owner's electronic verification duty for sellers and livestream sellers starts on 1 January 2027. An active framework does not mean every duty is already live. A seller-registration record is not proof of electronic identity verification, and ComplianceOne does not itself perform national electronic identification.
The connected regulatory baseline can also include the Consumer Rights Law 19/2023/QH15 and Decree 55/2024/NĐ-CP; the Personal Data Protection Law 91/2025/QH15 and Decree 356/2025/NĐ-CP; the Data Law 60/2024/QH15 and Decree 165/2025/NĐ-CP; Cybersecurity Law 116/2025/QH15 and applicable implementing instruments; and the Electronic Transactions Law 20/2023/QH15 with applicable trust-services instruments. These requirements remain distinct. Retaining transaction, invoice or seller evidence does not by itself establish compliance with them.
Additional obligations depend on what the platform actually does. Where the platform provides online-information, content, livestream or takedown functions, Decree 147/2024/NĐ-CP and applicable cybersecurity and online-information instruments may enter scope. Where seller electronic identification or authentication is required, the applicable Vietnamese identity and e-ID framework, including Decrees 69/2024/NĐ-CP and 320/2026/NĐ-CP where applicable, must be considered separately.
Where regulated AI supports seller, content, ranking, risk or other platform decisions, Vietnam's AI Law and applicable implementing instruments form another distinct compliance layer.
AI-enabled commerce decisions require their own scope assessment. If AI is used for regulated platform decisions, for example seller risk, automated content decisions, fraud or eligibility decisions, or another use falling within Vietnam's AI framework, the applicable AI Law obligations should be mapped separately. Evidence that a transaction was reconciled does not establish that an AI-supported decision complied with its own governance requirements.
Payment, logistics, postal, data-platform and data-service obligations likewise depend on the organization's actual regulated role. Decree 314/2026/NĐ-CP concerns the operation of data platforms, while Decrees 169/2025/NĐ-CP and 347/2026/NĐ-CP address data products and services. These instruments should be assigned only where the organization's actual activities fall within their respective scopes.
Keep enforcement context separate from operating duties. Decree 330/2026/NĐ-CP provides the supported cybersecurity and personal-data enforcement layer. Decree 363/2026/NĐ-CP on data-sector penalties is supported as upcoming, with commencement on 11 November 2026.
Start With the Platform’s Actual Role
Not every online seller, marketplace, payment provider, e-invoice operator, or digital platform has the same responsibilities.
Before building the evidence process, teams should identify:
- The legal entity operating the platform.
- Its relationship with sellers and customers.
- Whether it manages a marketplace, transaction environment, payment flow, invoicing function, or supporting technology.
- The sellers and transaction types included in the review.
- The source systems that state each figure.
- The tax, invoicing, privacy, consumer, security, and contractual rules confirmed for the role.
- The accountable tax advisers and operational owners.
ComplianceOne supports direct operational use where the organization confirms relevant platform tax-administration or e-invoice scope. Other organizations can retain the regulatory content for reference without treating research records as accepted obligations.
The platform does not determine scope. Legal and tax specialists remain responsible for deciding which entity, seller population, period, artifact, and filing duty applies.
Keep Seller Registration and Regulatory Standing Separate
A platform makes its own operational decision about whether a seller may register, remain active, become suspended, or withdraw. A regulatory instrument may describe a different status or standing.
Those facts should not be collapsed into one field.
ComplianceOne records the seller’s identity and the platform’s registration decision separately from the state declared by the applicable regulatory content. This preserves discrepancies that may matter during review. A seller can be operationally active while a separate compliance issue remains unresolved, or operationally suspended for a reason unrelated to tax standing.
Suspension carries its reason on the live seller record so that another team can understand the current state. When suspension is lifted, that reason no longer remains as a stale explanation of an active seller. Withdrawal is terminal history.
These records do not decide tax residence, liability, registration status with an authority, or the seller’s legal classification. They preserve the platform’s own decisions and the evidence that informed them.
Merchant privacy begins here. Seller identity data should be limited to what the platform needs for onboarding, operations, compliance, support, and evidence. Teams should avoid copying complete identity files into every reconciliation or authority package when a governed reference and supporting evidence link will answer the question.
Carry Every Figure With Its Source
An amount without provenance is a future dispute.
ComplianceOne records transactions and associated documents with the source that stated each figure. A source may be the marketplace order system, payment system, seller document, refund record, adjustment record, or e-invoice evidence.
The platform does not rewrite one source to match another. If two systems state different values, both remain visible. The record should make it possible to answer:
- Which seller and transaction are involved?
- What amount and currency did each source state?
- When was each record created or adjusted?
- Which document was associated with the transaction?
- Which system supplied the evidence?
- Who reviewed the discrepancy?
This provenance supports tax review and also improves privacy governance. Teams can identify which system holds merchant and consumer data, which copy entered the evidence process, and which exported packages contain it.
ComplianceOne performs no arithmetic to create a tax position. It has no tax rate, taxable base, period aggregate, liability total, payment amount, or refund computation. Figures remain statements made by identified sources.
Make Reconciliation a Governed Period Record
Spreadsheets often treat reconciliation as a temporary calculation. A defensible process treats it as a record with a period, owner, inputs, run history, exceptions, review, and closure.
ComplianceOne can run a comparison over a stated period and record what it examined. The comparison checks for defined evidence conditions such as a transaction without a corresponding document, a document without a transaction, an amount disagreement, or a currency disagreement.
The installed regulatory content supplies the reader-facing labels. The platform detects the structural condition and does not invent legal terminology.
Where figures disagree, the exception preserves both figures and both sources. There is deliberately no field for a corrected value. A named person records the resolution in their own words.
That design prevents a subtle but serious overreach. If the system selected or generated the “correct” amount, the record could be read as a tax conclusion. By stopping at the disagreement, it gives tax professionals a complete evidence question without answering it on their behalf.
The human resolution should describe the evidence reviewed and the operational action taken. It should not be treated as tax advice merely because it appears in a compliance record.
Connect E-Invoice Events to Their Source Transactions
E-invoice evidence can include issuance, codes, parties, status, transmission evidence, retention, adjustment, and replacement context. The compliance problem is often not the absence of a document. It is the inability to connect the document’s lifecycle to the order, payment, refund, or adjustment that explains it.
ComplianceOne links transaction records and documents so reviewers can follow that relationship. A replacement or adjustment does not need to erase the earlier evidence. The history can show which source event led to the change and which acknowledgement was retained.
The platform does not create, issue, transmit, validate, or file an e-invoice. It does not connect live to an e-invoice service or tax-authority system. E-invoicing software remains the system of action. ComplianceOne holds the organization’s governance and evidence position around what those systems reported.
This distinction should be explicit in procurement. “E-invoice evidence” is not an e-invoice engine.
Preserve Verified Artifact Context
Decree 117 materials include seven verified declarations, schedules, certificates, and refund-request artifacts. Their audiences and purposes differ, including two similarly numbered documents.
ComplianceOne associates a verified artifact with the relevant audience, period, seller population, supporting records, channel evidence, and acknowledgement. This helps teams select the right artifact and avoid treating similar numbering as interchangeable.
Decree 70 forms that still require exact-source implementation are not reproduced incompletely. Organization-prepared working records should remain distinguishable from authority-issued artifacts.
Even where a refund-request artifact is available, the platform does not request a refund, calculate an amount, determine eligibility, or send the document. It organizes the evidence for accountable people to prepare and act through the proper process.
Govern Decree 248 Regulatory Forms and Reporting
Decree 248 adds platform reporting and prescribed-form obligations to the wider e-commerce evidence model. ComplianceOne treats these regulatory outputs as governed records rather than isolated documents.
The evidence process should establish which requirement and reporting population applies, which approved source data populated the form, who reviewed and approved it, which version was submitted, and what acknowledgement or authority response followed.
The form itself is therefore only one part of the evidence package. The defensible record also preserves its source population, completeness checks, exceptions, approvals, submission evidence and subsequent amendments.
Commerce systems remain the source of operational facts. ComplianceOne governs whether the evidence supporting the regulatory output is complete, attributable and reviewable.

Protect Merchant and Consumer Data During Reconciliation
Platform reconciliation can expose seller identities, customer details, order contents, payment references, addresses, refunds, disputes, and invoice information. The easiest workflow is to export everything and send the spreadsheet to every reviewer. It is also the least controlled.
A stronger process separates identifiers needed to match records from data needed to decide the exception. Many amount or currency disagreements can be reviewed without exposing a customer’s full profile or delivery details.
Teams should define:
- Which seller and transaction identifiers are required for matching.
- Which fields tax, finance, privacy, support, and audit reviewers may see.
- How evidence from payment and invoicing providers is referenced.
- Which attachments contain personal or confidential data.
- How long reconciliation exports and authority packages remain available.
- How corrected source records propagate into the evidence history.
- How rights and deletion requests interact with legally retained transaction evidence.
ComplianceOne can structure permissions, references, assignments, and history. It cannot prevent an authorized person from exporting data and sharing it through an unapproved channel. Secure transfer, role design, training, and monitoring remain part of the control.
Answer Authority Questions From a Connected Evidence Set
Authority correspondence often begins with a request covering a seller, period, transaction population, invoice set, or discrepancy. Without a connected record, teams rebuild the evidence from scratch and risk producing a different answer each time.
ComplianceOne annotates the organization’s existing authority-request record with the sellers, exceptions, and documents involved and the evidence set used for the response. The underlying request retains the broader correspondence lifecycle.
This avoids creating a second authority inbox inside platform evidence. One request has one governed context, while the platform-specific annotation explains which commercial records it covers.
The system does not draft an automatic legal or tax response, submit correspondence, choose the channel, promise acceptance, or close the matter without a person’s action. Concluding an authority matter is a separately controlled organizational decision.
An evidence set should let reviewers reconstruct:
- What the authority asked.
- Which seller population and period were in scope.
- Which transactions, documents, and exceptions were reviewed.
- Which source systems stated each figure.
- Who resolved each disagreement and on what evidence.
- Which artifact or response the organization prepared.
- What acknowledgement or follow-up came back.
That history improves consistency without pretending the platform answered the authority.
Maintain Human Accountability and Practical Role Separation
Seller decisions, reconciliation, exception resolution, artifact preparation, submission, and authority response are different responsibilities. ComplianceOne provides distinct permissions so organizations can separate them.
The separation is available, not guaranteed by default. A customer must assign roles to match its tax, finance, legal, privacy, and operational governance. A small organization may place several responsibilities with one person, while a large platform may require independent review.
Certain decisions use controlled state transitions so two concurrent actions cannot both appear to be the final decision. That protects record integrity but does not replace organizational oversight.
Teams should review role assignments regularly and ask:
- Can the person registering a seller also suspend or withdraw that seller?
- Can the person running a reconciliation resolve every exception?
- Who may prepare a response, and who may conclude an authority matter?
- Who can access merchant and consumer attachments?
- Who can export seller, transaction, and invoice evidence?
- Does the configured separation match the policy represented to auditors?
The platform can enforce assigned permissions. It cannot make an unconfigured separation exist.
Use Exports as Evidence Packages, Not Working Databases

Seller, transaction, document, reconciliation, exception, and correspondence records may need to be exported for review. The package should answer a defined question rather than replicate the platform database.
Before exporting, confirm:
- The relevant legal entity, seller population, and period.
- The source systems and cut-off times included.
- Whether open exceptions remain.
- Whether the reviewer needs consumer-level details.
- Whether similar artifact numbers are correctly distinguished.
- Whether the package includes the acknowledgement and amendment history.
- Who may retain the file and for how long.
Every figure should retain its provenance. Every disagreement should retain both statements. Every human resolution should remain attributable. The package should never insert a corrected value that the evidence process did not hold.
Where a tax or e-invoice system already calculates or files, retain its output as source evidence. Do not reproduce its logic in the governance layer or imply that an exported evidence package is itself a filing.
A Practical Platform-Evidence Sequence
E-commerce organizations can establish the process one reporting period at a time.
1. Confirm the operating role. Identify the platform manager, seller relationship, e-invoice operator, payment providers, advisers, and accountable legal entity.
2. Define the seller population. Record seller identity, platform status, applicable regulatory standing, source systems, and ownership without turning the platform status into a tax conclusion.
3. Map transaction and document sources. Identify orders, payments, refunds, adjustments, invoices, replacements, acknowledgements, and the identifiers that connect them.
4. Establish provenance rules. Require each figure to retain its source system or document. Prevent manual normalization from erasing disagreements.
5. Run one period reconciliation. Record the period, owner, inputs, run history, and structural exceptions.
6. Resolve exceptions through people. Preserve both figures and both sources. Document the evidence and operational action without adding a platform-generated corrected value.
7. Associate the correct artifacts. Verify audience, purpose, period, seller type, supporting records, and numbering before preparation.
8. Apply privacy minimization. Limit customer, merchant, payment, and delivery data to what each review needs. Control attachments and exported copies.
9. Connect one authority request. Link the relevant sellers, exceptions, documents, evidence set, response work, and acknowledgement without automating the response.
10. Rehearse the review. Ask a team independent of the period run to reconstruct one disagreement from source records through resolution and authority evidence.
The rehearsal should expose orphaned sellers, unmatched documents, unexplained adjustments, missing provenance, overbroad exports, confused artifacts, and conclusions that lack accountable human ownership.
What This Gives the Organization
The result is not another operational commerce database. It is a defensible compliance record showing which obligations applied, which controls addressed them, which systems supplied the evidence, whether evidence was complete, which exceptions remained open, who approved the outcome and what was submitted or provided to an authority.
The Defensible Platform-Evidence Standard
The standard is not automated tax compliance. It is traceable evidence under human control.
A compliance claim should not pass merely because an evidence record exists. Missing required evidence, evidence outside the review period, incomplete reporting populations, failed connector runs, source/report mismatches, missed regulatory deadlines, missing submission acknowledgements and unresolved material exceptions should remain visible as compliance gaps until they are resolved or formally accepted.
- Confirm platform role and scope before activating direct operational use.
- Keep the platform’s seller decision distinct from regulatory standing.
- Carry every figure with the source that stated it.
- Preserve orders, payments, refunds, adjustments, and invoice events as connected evidence.
- Make reconciliation a period record with an owner and history.
- Record both disagreeing figures and never generate a corrected value.
- Keep tax liability, advice, calculations, payments, refunds, and filings outside the governance layer.
- Associate verified artifacts with the correct audience and purpose.
- Protect merchant and consumer data through scoped access and exports.
- Connect authority correspondence to the existing request and evidence set.
- Keep every decision attributable to a person.
This model lets tax and finance teams use specialist calculation and filing systems for the work those systems are built to perform. ComplianceOne preserves the organization’s independent evidence position: which records were compared, where they came from, who resolved the difference, and what was provided when an authority asked.
Map Your E-Commerce Systems to Vietnam's Regulatory Stack
You do not need to replace the systems running your marketplace.
Map seller management, listings, transactions, payments, complaints, takedowns, tax and e-invoice systems to the applicable obligations under Law 122, Decree 248 and the connected Vietnam regulatory framework.
Then run one reporting period through ComplianceOne and test whether the organization can prove:
who supplied the evidence, which obligation it supports, whether it was complete, who resolved the exceptions, who approved the regulatory output, and what the authority ultimately received.
AesirX ComplianceOne turns existing commerce-system evidence into an auditable regulatory record.
Ronni K. Gothard Christiansen
Technical Privacy Engineer and CEO, AesirX.io
Laws and instruments referenced
Vietnam’s E-Commerce Law 122/2025/QH15 and Decree 248/2026/NĐ-CP both became effective on 1 July 2026 and form the core e-commerce framework discussed in this article. Decision 776/QĐ-TTg provides the Government’s implementation plan for the Law.
Decree 117/2025/NĐ-CP governs tax administration for household and individual businesses conducting business through e-commerce and digital platforms. Decree 70/2025/NĐ-CP amends the invoice and document framework.
Personal-data considerations may engage the Personal Data Protection Law 91/2025/QH15, Decree 356/2025/NĐ-CP and relevant procedures under Decision 778/QĐ-BCA. Related operational requirements may also arise under the Consumer Rights Law 19/2023/QH15, Decree 55/2024/NĐ-CP, the Electronic Transactions Law, and Decree 23/2025/NĐ-CP.
The wider data and cybersecurity context includes the Data Law 60/2024/QH15, Decree 165/2025/NĐ-CP, Decision 20/2025/QĐ-TTg, and Cybersecurity Law 116/2025/QH15 with its applicable implementing instruments.
Decree 169/2025/NĐ-CP, as amended by Decree 347/2026/NĐ-CP, concerns certain data products and services. Decree 347 became effective on 15 September 2026 and is relevant only where an organization's activities fall within its scope. Decree 314/2026/NĐ-CP concerns the operation of data platforms and should likewise be considered only where the organization's activities fall within its scope.
Decree 330/2026/NĐ-CP provides the applicable cybersecurity and personal-data enforcement context. Decree 363/2026/NĐ-CP concerns data-sector penalties and takes effect on 11 November 2026.
Disclaimer
This article provides general operational and compliance information from a platform vendor and does not constitute legal, tax, accounting or other professional advice. The laws and instruments referenced may apply differently depending on the legal entity, platform model, activity, data processing, seller population, transaction model and jurisdiction. Inclusion of a law or instrument does not mean that every obligation applies to every e-commerce business or platform. Organizations should confirm their applicable obligations, commencement dates and regulatory scope with qualified Vietnamese legal, tax and compliance professionals.
Frequently Asked Questions






