DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

AesirX ComplianceOne | Vietnam Compliance

Feature IconAESIRX COMPLIANCEONE REGULATORY FRAMEWORKS

Operate Vietnam's Overlapping Regulatory Requirements Without Losing Legal Status or Evidence Context

Understand how Vietnam's active laws, implementing decrees, temporary procedures, and draft instruments fit together, and how ComplianceOne turns regulatory obligations into structured workflows and audit trails.

Icon Image
Overview Image

Why Compliance Operations Matter in Vietnam

Vietnam has enacted several overlapping regulatory frameworks covering personal data protection, cybersecurity, telecommunications, e-commerce, data governance, and AI. Each framework is administered by a different authority, for example, the Ministry of Public Security (MPS) for personal data or the Ministry of Industry and Trade (MOIT) for e-commerce; each imposes distinct obligations, formats, and response deadlines. 

Organizations operating across sectors must comply with multiple frameworks simultaneously, providing operational proof through dossiers, official form labels (Mau so, Phu luc), submission packages, statutory notifications, and other evidence that matches each framework's legal and procedural requirements.

The legal stack is also dynamic. Active parent laws sit alongside implementing decrees, administrative decisions, temporary procedural overlays, and drafts. Good regulatory operations depend on knowing which layer is in force, which is temporary, and which remains preparatory.

When departments work in isolation using disconnected tools, sections get missed, contributor accountability is lost, and the organization cannot demonstrate to regulators who did what or when. Teams across legal, IT, security, HR, marketing, and procurement must coordinate evidence, reviews, approvals, and submissions while maintaining a complete audit history.

ComplianceOne reflects how Vietnam's regulatory system operates and turns those distinctions into governed work. Teams can assign owners, prepare forms and dossiers, collect evidence, review decisions, track authority interactions, and preserve an audit history, while distinguishing active legal requirements from draft and future obligations.

Regulatory Frameworks

ComplianceOne regulatory frameworks are structured to reflect how Vietnam’s obligations are enforced, so teams can move from high-level requirements to the exact filings, workflows, and evidence needed.

Vietnam Personal Data Protection Law (PDPL)

Comprehensive personal data protection framework with a multi-layer operating stack.

Vietnam's primary personal data protection law (91/2025/QH15) establishes obligations for data controllers and processors.

Manage processing and transfer impact assessments, responsible personnel, rights, consent, incidents, evidence packs, and authority interactions. The stack includes Implementation Decree 356, Decision 778, temporary NQ22 procedures, and a separate shared enforcement draft.

Vietnam Data Law

Data governance, inventory, classification, sharing, and cross-border data management.

The Vietnam Data Law (60/2024/QH15) establishes enterprise-wide data governance obligations including data inventory and classification, sharing agreements, cross-border data governance, and annual attestation cycles. 

Manage data inventory, classification, sharing, transfer governance, data products and services, important/core data screening, official forms, and clearly separated draft data-exchange readiness.

Vietnam Telecom Law

Telecommunications sector overlay, confidentiality, disclosure controls, and authority cooperation.

Vietnam’s Telecommunications Law (24/2023/QH15) regulates the country's telecom sector, expanding its scope to include modern digital infrastructure. Governed alongside implementation guidance like Decree 163, it brings data centers, cloud computing, and OTT services (e.g., messaging and calls) within the regulatory framework under proportionate obligations.

Maintain sector-specific records for subscriber data, disclosures, authority requests, and responsible handling.

Vietnam Law on Cybersecurity

Consolidated cybersecurity obligations, incident response, authority cooperation, and data localization.

The Law on Cybersecurity (LoCS - 116/2025/QH15) effective 1 July 2026, consolidates cybersecurity obligations including incident response and authority cooperation, in-scope system determination, data localization requirements, and security assessment obligations. 

Manage incident evidence, authority cooperation, localization readiness, and transition records across the parent law and its implementing, protection, and enforcement instruments.

Vietnam AI Law

Risk-based AI governance, system classification, high-risk controls, transparency, and conformity.

Vietnam's AI Law (134/2025/QH15) effective May 1 2026, its Implementing Decree (142/2026/NĐ-CP), and Decision 33/2026/QĐ-TTg establish Vietnam's risk-based AI governance framework. 

Manage AI system classification, high-risk controls, conformity evidence, transparency, incidents, monitoring, controlled testing, and the decree’s official forms.

Vietnam E-Commerce Law

E-commerce governance, marketplace compliance, consumer protection, and digital transaction oversight.

The Law on Electronic Commerce (122/2025/QH15) establishes Vietnam's e-commerce framework. Decree 248/2026/NĐ-CP details certain provisions of the Law, while Decision 776/2026/QĐ-TTg sets the implementation plan.

Together, they cover platform classification, marketplace governance, consumer protection, transaction transparency, cross-border obligations, and digital commerce compliance.

Manage registration, seller and livestreamer verification, livestream selling, takedowns, complaints, reporting, and accountable marketplace operations.

Vietnam Digital Transformation Law

Digital transformation governance, digital infrastructure, technology industries, and cross-regulatory coordination.

Vietnam's Law on Digital Transformation (148/2025/QH15) establishes Vietnam's digital transformation framework. It coordinates implementation across data, AI, cybersecurity, telecommunications, electronic transactions, and e-commerce while replacing the 2006 Law on Information Technology.

Manage digital transformation initiatives, governance records, implementation evidence, and cross-regulatory obligations across the parent law and its supporting framework.

Vietnam eID & Authentication Law (Draft)

Electronic identity, authentication, trust services, attestations, and digital identity readiness.

The Draft Law on Electronic Identification and Authentication proposes a framework for digital identity, authentication, electronic attestations, and trust services. It remains consultation material until enacted.

Prepare identity governance, authentication assurance, provider oversight, cross-border readiness, and supporting evidence while keeping draft obligations clearly separated from active law.

Vietnam Data Security Law (Draft)

Data security, sovereignty, lifecycle governance, classification, and cross-border data readiness.

The Draft Law on Data Security proposes a framework for data security, sovereignty, classification, lifecycle governance, and cross-border data management. It remains legislative-program material until enacted.

Prepare data classification, lifecycle governance, cross-border controls, monitoring, personnel responsibilities, and incident evidence while keeping draft obligations clearly separated from active law.

Additional Active Stacks and Scoped Overlays

Icon Image

Electronic Transactions and Trust Services

e-signatures, trust services, audit, and data-message certification.

Icon Image

Current Identity and E-ID

identity Law 2023, Decree 69, and Project 06 as a program reference.

Icon Image

Internet Services and Online Platforms

optional digital-services overlay with direct or reference mode.

Icon Image

Electronic Labor Contracts

cross-sector HR process overlay for e-contract evidence and traceability.

Icon Image

Health Data and Education Data

optional sector overlays.

Icon Image

State Secrets and Civil Cryptography

scope-triggered security overlays.

Icon Image

AI Ethics Framework

official subordinate guidance beneath the AI Law, not a sanctions instrument.

Public-Sector and Consumer Process Overlays

These optional overlays add focused operating evidence without replacing their related parent laws. Public-sector packs are reference-first outside confirmed government-facing scope; consumer and platform overlays activate by relevant business process.

State E-Transactions

State E-Transactions

Decree 137 Compliance Operations

State-agency systems, electronic record exchange, integrations, safeguards, incidents, and audit evidence.

National Databases

National Databases

Data Sharing and Open Data

Public-sector database connections, shared data, open-data releases, architecture, quality, and portal evidence.

Consumer Rights

Consumer Rights

Consumer Protection & E-Commerce Risk

Disclosures, terms, complaints, refunds, remedies, consumer data, and authority-response evidence.

E-Commerce Tax

E-Commerce Tax

E-Invoicing Platform Evidence

Narrow seller, transaction, reconciliation, e-invoice, and artifact evidence support; not tax advice or a tax-calculation product.

Payments, Logistics and Delivery Verticals

These optional vertical overlays support direct installation after confirming the relevant payment, logistics, customs, postal, courier, or delivery scope. Other organizations can install them reference-only.

Banking & FinTech

Banking & FinTech

Banking, Fintech and Payments Expansion

AML links, payment services, accounts, eKYC, biometrics, cards, transaction logs, incidents, and authority evidence beyond Circular 83.

Logistics

Logistics

Logistics, Cross-Border Trade and Customs Data

Shipment, cargo, customs, manifest, warehouse, electronic submission, customer, vendor, and international data evidence.

Postal & Courier

Postal & Courier

Postal, Courier and Parcel Data

Activity notifications, parcels, tracking, sender and recipient data, delivery proof, returns, claims, and international transfers.

Manufacturing Sector and Process Overlays

These optional overlays support direct installation after confirming the relevant manufacturing, product, producer/importer, chemical, technical-regulation, or smart-factory scope. Organizations outside direct scope can install them reference-only.

Product Quality & Traceability

Product Quality & Traceability

Manufacturing Product Quality and Traceability

Product inventory, risk screening, QCVN mapping, traceability, conformity, and corrective-action evidence across the Product and Goods Quality Law, Decree 37, and Circulars 31, 33, and 34.

Extended Producer Responsibility

Extended Producer Responsibility

Manufacturing EPR for Producers and Importers

Product and packaging inventory, recycling execution, provider oversight, contribution evidence, annual declarations, and payment records under Decree 110.

Chemicals & Hazardous Products

Chemicals & Hazardous Products

Manufacturing Chemicals and Hazardous Products

Chemical inventory, product composition, supplier declarations, testing, safety, incident, and recall evidence.

 Product Technical Regs

Product Technical Regs

Manufacturing Product Technical Regulations

Affected-product screening and evidence for Circular 37’s textile, fluorescent-lamp, and paint QCVN amendments.

Smart Factory Security

Smart Factory Security

Smart Factory OT and IIoT Data Security

An AesirX evidence overlay, not a law, for connecting industrial assets and data to privacy, cybersecurity, AI, vendor, cloud, and incident records.

Background Image

See Vietnam Compliance in Action

Ready to see how ComplianceOne handles Vietnamese regulatory obligations operationally? Request a demo tailored to your regulatory landscape.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

ComplianceOne Regulatory Frameworks

Operational regulatory packs for Vietnam’s key laws, decrees, and draft instruments.

Status Legend

Active

In force and applicable

Upcoming

Published, not yet in force

Draft

Consultation or proposal only

Personal Data Protection

Personal Data Protection

activePersonal Data Protection Law 91/2025/QH15
activeDecree 356/2025/ND-CP
activeDecision 778/QD-BCA-A05
activeResolution 22/2026/NQ-CP
draftShared Draft Enforcement Decree 2026
Data

Data

activeData Law 60/2024/QH15
activeDecree 165/2025/ND-CP
activeDecree 169/2025/NĐ-CP
activeDecision 20/2025/QĐ-TTg
draftDraft Data-Exchanges Decree 2026
Telecommunications

Telecommunications

activeTelecoms Law 24/2023/QH15
activeDecree 163/2024/NĐ-CP
Cybersecurity

Cybersecurity

activeCybersecurity Law 116/2025/QH15
draftDraft Implementing Decree 2026
draftDraft Info-Protection Decree 2026
draftShared Draft Enforcement Decree 2026
Artificial Intelligence

Artificial Intelligence

activeAI Law 134/2025/QH15
activeDecree 142/2026/ND-CP
upcomingDecision 33/2026/QD-TTg
E-Commerce

E-Commerce

activeE-Commerce Law 122/2025/QH15
activeDecree 248/2026/ND-CP
activeDecision 776/QD-TTg
Digital Transformation

Digital Transformation

activeLaw 148/2025/QH15
activeDecision 268/QĐ-TTg
activeDecree 224/2026/NĐ-CP
Electronic ID & Authentication

Electronic ID & Authentication

drafteID & Auth Law 2026
Data Security

Data Security

draftData Security Law 2026

Modules Included

Organizations can explore ComplianceOne by regulatory framework or by operational modules. This allows teams to understand what each regulation requires and how those requirements are executed in practice.

Explore the Modules

Explore the regulatory frameworks, then speak with us about the obligations your organization needs to operationalize first

Icon Image

Start a Compliance Pilot

Test ComplianceOne with your applicable Vietnamese frameworks - PDPL, Data Law, Cybersecurity, or all seven configured together.

Icon Image

Discuss Your Compliance Needs

Walk through your Vietnamese regulatory obligations with our team and identify which frameworks and workflows apply to your organization.

Frequently Asked Questions

Yes. Organizations can coordinate obligations across personal data protection, data governance, cybersecurity, telecommunications, e-commerce, and AI while each framework keeps its own status, ownership, and evidence context.

Each instrument is presented according to its current status. Active obligations drive current work, temporary procedures carry review dates, and draft instruments remain in separate readiness tracks until promulgated.

ComplianceOne supports official forms associated with implemented Vietnam frameworks, including Decree 165, Decree 356, Decision 778, and Decree 142. Form preparation remains connected to evidence and human approval.

Yes. Teams can assemble supporting records, review completeness, approve packages, retain sending proof, record authority responses, and track required hard-copy follow-up.

No. ComplianceOne structures work, evidence, and accountability. Legal interpretation, approval, and submission decisions remain with the organization and its advisers.