DPO Radio

The Draft Decree on Data Exchange Operations is a proposed child instrument under the Vietnam Data Law. It remains in draft status, has no final decree number, and must not be presented as promulgated law.
The public-facing name reflects data exchange operations. An earlier “Data Platforms Draft” name remains only as a legacy reference in platform metadata.
The draft can be monitored and prepared for now, but workflows, dates, and obligations must be reviewed again when a final instrument is issued.

The Vietnam Data Law is the parent framework. The draft would add detailed governance for the National Data Exchange, other data exchanges, operators, participants, listings, testing, and transactions.
It is separate from active Decree 165. Organizations should continue current Decree 165 work while maintaining the data-exchange proposal as a distinct regulatory-change track.
| Operational Area | Data Exchange Draft Role | Evidence to Maintain |
|---|---|---|
| Exchange classification | Distinguishes the National Data Exchange from other exchanges | Operator scope and governance assessment |
| Security and interoperability | Other exchanges are expected to meet Level 3 information-system security and connect with the National Data Exchange | Security assessment, architecture, test results, and connection readiness |
| Controlled testing | Supports segregated testing environments with controls against unauthorized extraction | Access rules, test logs, approvals, and extraction records |
| Product and service listings | Requires review of source, lawfulness, technical quality, pricing, and usage restrictions before listing | Listing dossier, review decision, and supporting evidence |
| Transactions | Uses electronic contracts and connected order, payment, delivery, and rights records | Contract, timestamp, payment, delivery, and rights-confirmation evidence |
| Complaints and risks | Expects risk controls, early warning, and complaint or dispute handling | Risk register, complaint case, actions, and resolution evidence |
The uploaded draft includes one official draft form, Mẫu ĐK01 in Appendix II, for transaction-account requests in the circumstances described by the proposal. Other operational templates are internal preparation aids and must not be presented as official forms.
The draft does not specify administrative fine amounts. ComplianceOne can track risk areas and remediation, but it does not present estimated or invented amounts as statutory fines.

Preparing for the Draft
Organizations can assess operator governance, Level 3 security readiness, interoperability, participant verification, listing review, controlled testing, electronic contracting, and transaction evidence without assuming the final text will remain unchanged.
Preparation records should be reusable even if the draft changes: system inventories, security assessments, approval records, contract evidence, listing review criteria, and complaint-handling procedures all strengthen operational control.
Regulatory-change ownership should include a review of the final decree number, issue date, effective date, forms, procedures, and any changed obligations before the draft is promoted into active work.
ComplianceOne keeps the draft in a separate readiness workspace with clear status labeling. Teams can assign gap reviews, collect evidence, record assumptions, and track changes without mixing draft tasks into active Decree 165 obligations.
Listing, controlled-testing, security, contracting, and complaint records can be linked to responsible owners and review gates. Mẫu ĐK01 can be handled as a draft official form while internal preparation templates remain clearly distinguished.
When a final instrument is promulgated, the draft lineage and readiness evidence can be reviewed and adapted rather than discarded or silently treated as current law.
Records data sources, flows, participants, and transaction context.
Explore Data MappingTracks security, listing, transaction, extraction, and dispute risks.
Explore AssessmentsAssigns regulatory-change reviews, owners, assumptions, and decisions.
Explore Program GovernanceDistinguishes draft Mẫu ĐK01 from internal preparation templates.
Explore Compliance FormsOrganizations preparing for the draft should confirm:
See how ComplianceOne separates draft preparation from active Data Law work while preserving reusable evidence.

No. It remains a draft, has no final decree number, and may change before promulgation. ComplianceOne presents it as a preparation and regulatory-change track.
The canonical public-facing name is “Draft Decree on Data Exchange Operations.” The earlier “Data Platforms Draft” name is retained only as a legacy reference.
The draft indicates that non-national data exchanges should meet Level 3 information-system security and be capable of connecting and sharing data with the National Data Exchange.
The uploaded draft includes one official draft form, Mẫu ĐK01. Other ComplianceOne preparation templates are internal and are not presented as authority-issued forms.
No. The source does not specify final fine amounts. ComplianceOne can track risk areas and remediation without fabricating monetary penalties.

Test security, listing, controlled-testing, and transaction-evidence readiness.

Review your data-exchange role, readiness assumptions, and regulatory-change plan.