DPO Radio
AESIRX COMPLIANCEONE REGULATORY FRAMEWORKS
Understand how Vietnam's active laws, implementing decrees, temporary procedures, and draft instruments fit together, and how ComplianceOne turns regulatory obligations into structured workflows and audit trails.


Vietnam has enacted several overlapping regulatory frameworks covering personal data protection, cybersecurity, telecommunications, e-commerce, data governance, and AI. Each framework is administered by a different authority, for example, the Ministry of Public Security (MPS) for personal data or the Ministry of Industry and Trade (MOIT) for e-commerce; each imposes distinct obligations, formats, and response deadlines.
Organizations operating across sectors must comply with multiple frameworks simultaneously, providing operational proof through dossiers, official form labels (Mau so, Phu luc), submission packages, statutory notifications, and other evidence that matches each framework's legal and procedural requirements.
The legal stack is also dynamic. Active parent laws sit alongside implementing decrees, administrative decisions, temporary procedural overlays, and drafts. Good regulatory operations depend on knowing which layer is in force, which is temporary, and which remains preparatory.
When departments work in isolation using disconnected tools, sections get missed, contributor accountability is lost, and the organization cannot demonstrate to regulators who did what or when. Teams across legal, IT, security, HR, marketing, and procurement must coordinate evidence, reviews, approvals, and submissions while maintaining a complete audit history.
ComplianceOne reflects how Vietnam's regulatory system operates and turns those distinctions into governed work. Teams can assign owners, prepare forms and dossiers, collect evidence, review decisions, track authority interactions, and preserve an audit history, while distinguishing active legal requirements from draft and future obligations.
ComplianceOne regulatory frameworks are structured to reflect how Vietnam’s obligations are enforced, so teams can move from high-level requirements to the exact filings, workflows, and evidence needed.
Comprehensive personal data protection framework with a multi-layer operating stack.
Vietnam's primary personal data protection law (91/2025/QH15) establishes obligations for data controllers and processors.
Manage processing and transfer impact assessments, responsible personnel, rights, consent, incidents, evidence packs, and authority interactions. The stack includes Implementation Decree 356, Decision 778, temporary NQ22 procedures, and a separate shared enforcement draft.
Data governance, inventory, classification, sharing, and cross-border data management.
The Vietnam Data Law (60/2024/QH15) establishes enterprise-wide data governance obligations including data inventory and classification, sharing agreements, cross-border data governance, and annual attestation cycles.
Manage data inventory, classification, sharing, transfer governance, data products and services, important/core data screening, official forms, and clearly separated draft data-exchange readiness.
Telecommunications sector overlay, confidentiality, disclosure controls, and authority cooperation.
Vietnam’s Telecommunications Law (24/2023/QH15) regulates the country's telecom sector, expanding its scope to include modern digital infrastructure. Governed alongside implementation guidance like Decree 163, it brings data centers, cloud computing, and OTT services (e.g., messaging and calls) within the regulatory framework under proportionate obligations.
Maintain sector-specific records for subscriber data, disclosures, authority requests, and responsible handling.
Consolidated cybersecurity obligations, incident response, authority cooperation, and data localization.
The Law on Cybersecurity (LoCS - 116/2025/QH15) effective 1 July 2026, consolidates cybersecurity obligations including incident response and authority cooperation, in-scope system determination, data localization requirements, and security assessment obligations.
Manage incident evidence, authority cooperation, localization readiness, and transition records across the parent law and its implementing, protection, and enforcement instruments.
Risk-based AI governance, system classification, high-risk controls, transparency, and conformity.
Vietnam's AI Law (134/2025/QH15) effective May 1 2026, its Implementing Decree (142/2026/NĐ-CP), and Decision 33/2026/QĐ-TTg establish Vietnam's risk-based AI governance framework.
Manage AI system classification, high-risk controls, conformity evidence, transparency, incidents, monitoring, controlled testing, and the decree’s official forms.
E-commerce governance, marketplace compliance, consumer protection, and digital transaction oversight.
The Law on Electronic Commerce (122/2025/QH15) establishes Vietnam's e-commerce framework. Decree 248/2026/NĐ-CP details certain provisions of the Law, while Decision 776/2026/QĐ-TTg sets the implementation plan.
Together, they cover platform classification, marketplace governance, consumer protection, transaction transparency, cross-border obligations, and digital commerce compliance.
Manage registration, seller and livestreamer verification, livestream selling, takedowns, complaints, reporting, and accountable marketplace operations.
Digital transformation governance, digital infrastructure, technology industries, and cross-regulatory coordination.
Vietnam's Law on Digital Transformation (148/2025/QH15) establishes Vietnam's digital transformation framework. It coordinates implementation across data, AI, cybersecurity, telecommunications, electronic transactions, and e-commerce while replacing the 2006 Law on Information Technology.
Manage digital transformation initiatives, governance records, implementation evidence, and cross-regulatory obligations across the parent law and its supporting framework.
Electronic identity, authentication, trust services, attestations, and digital identity readiness.
The Draft Law on Electronic Identification and Authentication proposes a framework for digital identity, authentication, electronic attestations, and trust services. It remains consultation material until enacted.
Prepare identity governance, authentication assurance, provider oversight, cross-border readiness, and supporting evidence while keeping draft obligations clearly separated from active law.
Data security, sovereignty, lifecycle governance, classification, and cross-border data readiness.
The Draft Law on Data Security proposes a framework for data security, sovereignty, classification, lifecycle governance, and cross-border data management. It remains legislative-program material until enacted.
Prepare data classification, lifecycle governance, cross-border controls, monitoring, personnel responsibilities, and incident evidence while keeping draft obligations clearly separated from active law.
e-signatures, trust services, audit, and data-message certification.
identity Law 2023, Decree 69, and Project 06 as a program reference.
optional digital-services overlay with direct or reference mode.
cross-sector HR process overlay for e-contract evidence and traceability.
optional sector overlays.
scope-triggered security overlays.
official subordinate guidance beneath the AI Law, not a sanctions instrument.
These optional overlays add focused operating evidence without replacing their related parent laws. Public-sector packs are reference-first outside confirmed government-facing scope; consumer and platform overlays activate by relevant business process.

Decree 137 Compliance Operations
State-agency systems, electronic record exchange, integrations, safeguards, incidents, and audit evidence.

Data Sharing and Open Data
Public-sector database connections, shared data, open-data releases, architecture, quality, and portal evidence.

Consumer Protection & E-Commerce Risk
Disclosures, terms, complaints, refunds, remedies, consumer data, and authority-response evidence.

E-Invoicing Platform Evidence
Narrow seller, transaction, reconciliation, e-invoice, and artifact evidence support; not tax advice or a tax-calculation product.
These optional vertical overlays support direct installation after confirming the relevant payment, logistics, customs, postal, courier, or delivery scope. Other organizations can install them reference-only.

Banking, Fintech and Payments Expansion
AML links, payment services, accounts, eKYC, biometrics, cards, transaction logs, incidents, and authority evidence beyond Circular 83.

Logistics, Cross-Border Trade and Customs Data
Shipment, cargo, customs, manifest, warehouse, electronic submission, customer, vendor, and international data evidence.

Postal, Courier and Parcel Data
Activity notifications, parcels, tracking, sender and recipient data, delivery proof, returns, claims, and international transfers.
These optional overlays support direct installation after confirming the relevant manufacturing, product, producer/importer, chemical, technical-regulation, or smart-factory scope. Organizations outside direct scope can install them reference-only.

Manufacturing Product Quality and Traceability
Product inventory, risk screening, QCVN mapping, traceability, conformity, and corrective-action evidence across the Product and Goods Quality Law, Decree 37, and Circulars 31, 33, and 34.

Manufacturing EPR for Producers and Importers
Product and packaging inventory, recycling execution, provider oversight, contribution evidence, annual declarations, and payment records under Decree 110.

Manufacturing Chemicals and Hazardous Products
Chemical inventory, product composition, supplier declarations, testing, safety, incident, and recall evidence.

Manufacturing Product Technical Regulations
Affected-product screening and evidence for Circular 37’s textile, fluorescent-lamp, and paint QCVN amendments.

Smart Factory OT and IIoT Data Security
An AesirX evidence overlay, not a law, for connecting industrial assets and data to privacy, cybersecurity, AI, vendor, cloud, and incident records.
Ready to see how ComplianceOne handles Vietnamese regulatory obligations operationally? Request a demo tailored to your regulatory landscape.

Operational regulatory packs for Vietnam’s key laws, decrees, and draft instruments.
Status Legend
In force and applicable
Published, not yet in force
Consultation or proposal only






Organizations can explore ComplianceOne by regulatory framework or by operational modules. This allows teams to understand what each regulation requires and how those requirements are executed in practice.
Explore the regulatory frameworks, then speak with us about the obligations your organization needs to operationalize first

Test ComplianceOne with your applicable Vietnamese frameworks - PDPL, Data Law, Cybersecurity, or all seven configured together.

Walk through your Vietnamese regulatory obligations with our team and identify which frameworks and workflows apply to your organization.
Yes. Organizations can coordinate obligations across personal data protection, data governance, cybersecurity, telecommunications, e-commerce, and AI while each framework keeps its own status, ownership, and evidence context.
Each instrument is presented according to its current status. Active obligations drive current work, temporary procedures carry review dates, and draft instruments remain in separate readiness tracks until promulgated.
ComplianceOne supports official forms associated with implemented Vietnam frameworks, including Decree 165, Decree 356, Decision 778, and Decree 142. Form preparation remains connected to evidence and human approval.
Yes. Teams can assemble supporting records, review completeness, approve packages, retain sending proof, record authority responses, and track required hard-copy follow-up.
No. ComplianceOne structures work, evidence, and accountability. Legal interpretation, approval, and submission decisions remain with the organization and its advisers.