DPO Radio

Decree 314/2026/NĐ-CP was issued by the Government on 8 August 2026, taking effect on 25 September 2026. It is a child instrument beneath Law 60/2024/QH15, by the Minister of Public Security, and issued on the basis of the Data Law, the Personal Data Protection Law, the Electronic Transactions Law and the Cybersecurity Law. It is promulgated, not a draft.
The decree regulates the operation of data platforms; data-platform service businesses, data testing on a platform, the conditions for participating in transactions, the conditions for the data itself, valuation support, the transaction process, risk management and dispute support, and the responsibilities of sellers, buyers and intermediary data-service providers. It runs to 38 articles across nine chapters, with one form in its appendix.
This instrument promulgates the earlier Data Exchanges Draft 2026. Historical draft references are preserved as aliases, but Decree 314 is now the canonical implementation layer, and readiness work built against draft article numbers needs re-checking rather than carrying forward unchanged.

The Data Law remains the parent framework. Decree 165/2025/NĐ-CP supplies the general implementing procedures and Decree 169/2025/NĐ-CP the data-products and data-services layer; Decree 314 sits alongside them and governs the venue where that data is traded.
The three interlock rather than repeat. Decree 314 imports the platform operator's duties from Article 35 of Decree 169 and the intermediary's from its Article 26, then adds what is specific to a trading venue: listing review, controlled testing, transaction records and dispute support. Where listed data is core or important, the classification obligations under Decree 165 and Decision 20/2025/QĐ-TTg still apply to it.
A practitioner therefore needs all three. Decree 314 alone will not tell you whether the data you are listing is classified, and Decree 165 alone will not tell you what a platform must check before it publishes your listing.
| Provision | What It Requires | Operational Implication |
|---|---|---|
| Điều 5 | Two platform classes – the National Data Platform, built and operated by the National Data Centre, and other platforms; every platform holds information-system security level 3 or higher. | Record the class, hold the security-level approval, and evidence connection readiness with the National Data Platform. |
| Điều 4 khoản 6 | Personal data may not be traded; data derived from personal data may be traded only where de-identification and personal-data requirements are met. | Hold de-identification evidence, a re-identification risk assessment and a lawful-basis record before listing. |
| Điều 16, Điều 17 | Conditions on who may transact and on the data itself – lawful origin, disclosed restrictions, machine-readable format, connection documentation, published quality and limitations. | Verify participant eligibility before issuing an account; hold a provenance record with every listing. |
| Điều 18 khoản 5 | Five cumulative conditions before data formed from a national or specialised database may be traded. | Hold the permission document and the evidence of the right to supply, exploit, use and trade. |
| Điều 19, Điều 20, Điều 21 | Listing dossier, intermediary appraisal, platform review, listing, suspension and delisting. | Separate appraisal from the listing decision, and from anyone with a related interest. |
| Điều 23 | Electronic contract with prescribed minimum content, accepted by digital signature or another method that identifies the subject, records the moment and preserves integrity. | Hold the contract, the acceptance evidence and the timestamp together. |
| Điều 25 | Delivery only on an effective contract and completed payment; a data-message confirmation of exploitation and use rights that expressly does not confer ownership. | Gate delivery on both conditions; do not describe the confirmation as a certificate of ownership. |
| Điều 24 | Settlement through a published payment provider, in Vietnamese dong. | Publish the provider list; route every transaction through registered accounts. |
| Obligation | Timeline | Reference |
|---|---|---|
| Decree takes effect | 25 September 2026 | Điều 37 |
| Controlled test window | 30 days from the grant of access | Điều 13 khoản 4 |
| Test window extension | One extension of up to 30 days, total not exceeding 60 | Điều 13 khoản 4 |
| Erase test data after expiry | 24 hours | Điều 13 khoản 4 |
| Suspend a transaction after a ground arises | 24 hours | Điều 22 khoản 5 |
| Complete verification after suspension | 5 working days, extendable once by 5 | Điều 22 khoản 5 |
| Ask for missing information on a support request | 24 hours | Điều 29 khoản 4 |
| Acknowledge a complete support request | 3 working days | Điều 29 khoản 4 |
| Handle a support request | 15 working days, extendable once by 15 | Điều 29 khoản 4 |
| Retain transaction traceability records | at least 10 years from completion | Điều 25 khoản 3 |
| Form | Official ID | Purpose | Required For |
|---|---|---|---|
| Request to open a transaction account on a data platform. | Mẫu ĐK01 | Applies to open a transaction account, selecting the role – seller, buyer, intermediary data service, analysis and aggregation service, or valuation support. | A foreign organisation or individual without a level-2 electronic identification account, and any applicant the platform routes through written verification. |
Mẫu ĐK01 is the only form the decree prescribes. Everything else supplied for this instrument is an internal preparation template and is labelled as one.

The instrument is carried as a promulgated child framework with an effective date, so it reads as upcoming until 25 September 2026 and as active after it, without anyone editing copy on the day. Its 36 requirements each carry the article they came from, which is what makes a readiness record traceable back to the source rather than to a summary of it.
Mẫu ĐK01 is held as an official form with its role selection and undertaking, distinguishable in the catalogue from the preparation templates around it. The 32 templates authored during the draft period were re-pointed to this instrument rather than duplicated, so evidence collected before promulgation keeps its identifiers and its history.
Five templates were added where the promulgated text asks for something the draft-era set did not cover: de-identification evidence, auction refusal for personal data, intermediary conflict of interest, level 3 security evidence, and authority request and response. One draft-era template was renamed: what it called a certificate of property rights over data is, under Điều 25 khoản 5, a confirmation that expressly does not confer ownership.
The timed obligations are held as deadlines rather than as prose, so the 24-hour suspension, the 5-working-day verification, the 3-and-15-working-day support windows and the 10-year retention are things a programme can be measured against.
Holds the provenance, technical description and rights scope a listing dossier must carry.
Explore Data MappingScreens listed data for core or important status before it reaches a listing.
Explore Data ClassificationKeeps Mẫu ĐK01 distinguishable from the preparation templates around it.
Explore Compliance FormsAssigns the operator readiness, listing review and pricing publication work.
Explore Program GovernanceTracks the twelve risk areas, each recording that no penalty figure is stated in the source.
Explore Risk AssessmentPreserves the transaction, suspension and dispute history the decree requires be retained.
Explore Audit TrailOrganizations implementing Decree 314 compliance should confirm:
See how ComplianceOne manages the applicable requirements, official form, and supporting compliance evidence.

Yes, in the sense that it is the promulgated form of it. The draft is retained as a historical reference and its earlier codes still resolve, but the article numbering and several operative periods changed between the two, so readiness records keyed to draft article numbers need re-checking rather than carrying forward.
No. Điều 25 provides a confirmation of the right to exploit and use data, issued as a data message. Khoản 5 states in terms that it neither confirms nor gives rise to ownership, does not change the rights of the data owner, and does not replace the contract or the payment and handover records.
Only where the de-identification condition and the other requirements of personal-data protection law are met. Personal data itself may not be bought or sold on a platform, and may not be auctioned at all, an auction provider must refuse.
Information-system security level 3 or higher, for every platform. A platform other than the National Data Platform must additionally be able to connect and share data with it through the data sharing and coordination platform, following the National Data Centre's guidance.
No. It sets obligations without prescribing penalty figures. Risk areas are tracked with a fine-amount status of not specified in source, so the absence is recorded rather than an amount estimated.
Yes. Related records can be cross-linked while preserving their original framework ownership and audit history.

Test operator requirements, listing review, controlled testing and transaction evidence.

Review your platform role, compliance records, and applicable requirements.