DPO Radio

AesirX ComplianceOne | Vietnam Data Platforms Decree 314/2026/NĐ-CP

Overview Image

Decree 314/2026/NĐ-CP: Scope and Current Status

Decree 314/2026/NĐ-CP was issued by the Government on 8 August 2026, taking effect on 25 September 2026. It is a child instrument beneath Law 60/2024/QH15, by the Minister of Public Security, and issued on the basis of the Data Law, the Personal Data Protection Law, the Electronic Transactions Law and the Cybersecurity Law. It is promulgated, not a draft.

The decree regulates the operation of data platforms; data-platform service businesses, data testing on a platform, the conditions for participating in transactions, the conditions for the data itself, valuation support, the transaction process, risk management and dispute support, and the responsibilities of sellers, buyers and intermediary data-service providers. It runs to 38 articles across nine chapters, with one form in its appendix.

This instrument promulgates the earlier Data Exchanges Draft 2026. Historical draft references are preserved as aliases, but Decree 314 is now the canonical implementation layer, and readiness work built against draft article numbers needs re-checking rather than carrying forward unchanged.

Overview Image

How Decree 314 Relates to the Vietnam Data Law

The Data Law remains the parent framework. Decree 165/2025/NĐ-CP supplies the general implementing procedures and Decree 169/2025/NĐ-CP the data-products and data-services layer; Decree 314 sits alongside them and governs the venue where that data is traded.

The three interlock rather than repeat. Decree 314 imports the platform operator's duties from Article 35 of Decree 169 and the intermediary's from its Article 26, then adds what is specific to a trading venue: listing review, controlled testing, transaction records and dispute support. Where listed data is core or important, the classification obligations under Decree 165 and Decision 20/2025/QĐ-TTg still apply to it.

A practitioner therefore needs all three. Decree 314 alone will not tell you whether the data you are listing is classified, and Decree 165 alone will not tell you what a platform must check before it publishes your listing.

Technical Provisions and Compliance Obligations

ProvisionWhat It RequiresOperational Implication
Điều 5Two platform classes – the National Data Platform, built and operated by the National Data Centre, and other platforms; every platform holds information-system security level 3 or higher.Record the class, hold the security-level approval, and evidence connection readiness with the National Data Platform.
Điều 4 khoản 6Personal data may not be traded; data derived from personal data may be traded only where de-identification and personal-data requirements are met.Hold de-identification evidence, a re-identification risk assessment and a lawful-basis record before listing.
Điều 16, Điều 17Conditions on who may transact and on the data itself – lawful origin, disclosed restrictions, machine-readable format, connection documentation, published quality and limitations.Verify participant eligibility before issuing an account; hold a provenance record with every listing.
Điều 18 khoản 5Five cumulative conditions before data formed from a national or specialised database may be traded.Hold the permission document and the evidence of the right to supply, exploit, use and trade.
Điều 19, Điều 20, Điều 21Listing dossier, intermediary appraisal, platform review, listing, suspension and delisting.Separate appraisal from the listing decision, and from anyone with a related interest.
Điều 23Electronic contract with prescribed minimum content, accepted by digital signature or another method that identifies the subject, records the moment and preserves integrity.Hold the contract, the acceptance evidence and the timestamp together.
Điều 25Delivery only on an effective contract and completed payment; a data-message confirmation of exploitation and use rights that expressly does not confer ownership.Gate delivery on both conditions; do not describe the confirmation as a certificate of ownership.
Điều 24Settlement through a published payment provider, in Vietnamese dong.Publish the provider list; route every transaction through registered accounts.

ObligationTimelineReference
Decree takes effect25 September 2026Điều 37
Controlled test window30 days from the grant of accessĐiều 13 khoản 4
Test window extensionOne extension of up to 30 days, total not exceeding 60Điều 13 khoản 4
Erase test data after expiry24 hoursĐiều 13 khoản 4
Suspend a transaction after a ground arises24 hoursĐiều 22 khoản 5
Complete verification after suspension5 working days, extendable once by 5Điều 22 khoản 5
Ask for missing information on a support request24 hoursĐiều 29 khoản 4
Acknowledge a complete support request3 working daysĐiều 29 khoản 4
Handle a support request15 working days, extendable once by 15Điều 29 khoản 4
Retain transaction traceability recordsat least 10 years from completionĐiều 25 khoản 3

FormOfficial IDPurposeRequired For
Request to open a transaction account on a data platform.Mẫu ĐK01Applies to open a transaction account, selecting the role – seller, buyer, intermediary data service, analysis and aggregation service, or valuation support.A foreign organisation or individual without a level-2 electronic identification account, and any applicant the platform routes through written verification.

Mẫu ĐK01 is the only form the decree prescribes. Everything else supplied for this instrument is an internal preparation template and is labelled as one.

Overview Image

How ComplianceOne Supports Decree 314 Compliance

The instrument is carried as a promulgated child framework with an effective date, so it reads as upcoming until 25 September 2026 and as active after it, without anyone editing copy on the day. Its 36 requirements each carry the article they came from, which is what makes a readiness record traceable back to the source rather than to a summary of it.

Mẫu ĐK01 is held as an official form with its role selection and undertaking, distinguishable in the catalogue from the preparation templates around it. The 32 templates authored during the draft period were re-pointed to this instrument rather than duplicated, so evidence collected before promulgation keeps its identifiers and its history.

Five templates were added where the promulgated text asks for something the draft-era set did not cover: de-identification evidence, auction refusal for personal data, intermediary conflict of interest, level 3 security evidence, and authority request and response. One draft-era template was renamed: what it called a certificate of property rights over data is, under Điều 25 khoản 5, a confirmation that expressly does not confer ownership.

The timed obligations are held as deadlines rather than as prose, so the 24-hour suspension, the 5-working-day verification, the 3-and-15-working-day support windows and the 10-year retention are things a programme can be measured against.

Related Modules

Data MappingData Mapping

Holds the provenance, technical description and rights scope a listing dossier must carry.

Explore Data Mapping

Data ClassificationData Classification

Screens listed data for core or important status before it reaches a listing.

Explore Data Classification

Compliance FormsCompliance Forms

Keeps Mẫu ĐK01 distinguishable from the preparation templates around it.

Explore Compliance Forms

Program GovernanceProgram Governance

Assigns the operator readiness, listing review and pricing publication work.

Explore Program Governance

Risk AssessmentRisk Assessment

Tracks the twelve risk areas, each recording that no penalty figure is stated in the source.

Explore Risk Assessment

Audit TrailAudit Trail

Preserves the transaction, suspension and dispute history the decree requires be retained.

Explore Audit Trail

Compliance Readiness Checklist

Organizations implementing Decree 314 compliance should confirm:

The platform class is recorded, and the permitted data sources and service scope follow from it.

Information-system security level 3 or higher is approved and current for the platform system.

Connection and data-sharing requirements with the National Data Platform is evidenced.

Any listing derived from personal data carries de-identification evidence and a lawful-basis record.

Appraisal is separated from the listing decision, and from anyone with a related interest.

Controlled testing runs in an isolated environment, within 30 days, with erasure inside 24 hours of expiry.

Electronic contracts carry the prescribed minimum content and a recorded acceptance method.

Delivery is gated on both an effective contract and completed payment.

Transaction traceability records are retained for at least ten years and connect to the national lookup.

Records describing a confirmation of ownership over data have been corrected.

Mẫu ĐK01 is the only artefact presented as an official form.

No penalty amount is presented as a statutory fine under this decree.

Background Image

See Decree 314 Compliance in Action

See how ComplianceOne manages the applicable requirements, official form, and supporting compliance evidence.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

Yes, in the sense that it is the promulgated form of it. The draft is retained as a historical reference and its earlier codes still resolve, but the article numbering and several operative periods changed between the two, so readiness records keyed to draft article numbers need re-checking rather than carrying forward.

No. Điều 25 provides a confirmation of the right to exploit and use data, issued as a data message. Khoản 5 states in terms that it neither confirms nor gives rise to ownership, does not change the rights of the data owner, and does not replace the contract or the payment and handover records.

Only where the de-identification condition and the other requirements of personal-data protection law are met. Personal data itself may not be bought or sold on a platform, and may not be auctioned at all, an auction provider must refuse.

Information-system security level 3 or higher, for every platform. A platform other than the National Data Platform must additionally be able to connect and share data with it through the data sharing and coordination platform, following the National Data Centre's guidance.

No. It sets obligations without prescribing penalty figures. Risk areas are tracked with a fine-amount status of not specified in source, so the absence is recorded rather than an amount estimated.

Yes. Related records can be cross-linked while preserving their original framework ownership and audit history.

 

Next Steps

Icon Image

Start a Compliance Pilot

Test operator requirements, listing review, controlled testing and transaction evidence.

Icon Image

Discuss Your Compliance Needs

Review your platform role, compliance records, and applicable requirements.