DPO Radio

AesirX ComplianceOne | Vietnam Data Law Decree 326/2026/NĐ-CP

Overview Image

Decree 165/2025/ND-CP: Scope and Current Status

Decree 326/2026/NĐ-CP was signed on 19 August 2026, taking effect on 1 September 2026. Its 18 articles establish location identification for objects across the territory of Vietnam; land parcels, structures, transport works, place names and more, outside the State-secrets list. An annex enumerates 71 numbered object classes across 18 groups, three of them open or group-level categories.

Each identified location receives a single, stable 12-digit identification code established by the Location Identification Database, a national, centralized database built and managed under the Ministry of Public Security. The decree does not break the 12 digits into named segments; the code structure's technical detail is delegated to follow-on ministerial instruments. Public location data is surfaced to organizations and individuals through the national identification application VNeID.

The duty structure is unusual and worth stating plainly. Nearly every affirmative obligation (collecting, synchronizing, updating, guiding) falls on state bodies. Location owners and lawful managers are passive subjects: the decree imposes no filing, registration or declaration duty on them, because data about their sites flows from existing state databases. The substantive private-sector duties attach to those who exploit the data or connect to the database.

Overview Image

How Decree 326 Relates to the Vietnam Data Law

Decree 326 is a Government decree issued on seven legal bases, and its data-governance anchors are the ones that matter operationally: the Data Law is where its database, sharing and exploitation machinery takes root, and the Personal Data Protection Law governs every touch of the database's non-public information; land-certificate details, structural and three-dimensional geospatial data, custodian identity and owner or user identity.

It is carried in the Data Law family rather than as an implementing decree of any single parent, because that is how it behaves: a national-database instrument whose exploitation rules hand off to personal-data-protection and State-secret law the moment non-public information is involved.

Technical Provisions and Compliance Obligations

ProvisionWhat It RequiresOperational Implication
Điều 2, Phụ lụcIdentified objects: land parcels, architectural and construction works, built structures, place names and any physical structure – 71 numbered classes in 18 annex groups.Facility-heavy organizations should expect their sites to carry codes under the decree.
Điều 4The identification code is a sequence of 12 natural digits, distinct, non-duplicated and stable; no segment breakdown is prescribed in the text.Do not build against an assumed segment encoding – the technical standard is delegated to later instruments.
Điều 5The Location Identification Database with 16 information fields, from code and address through coordinates to owner or user identity.The field set defines what the state will hold about each site.
Điều 7 khoản 2Exploitation channels: public data via VNeID; state bodies via national platforms; everyone else via electronic authentication service providers, against an exploitation-and-use fee.Channel selection is prescribed, and the fee applies on the general channel.
Điều 7 khoản 3Ten of the 16 field families are public; six are non-public – land-certificate information, structure, three-dimensional geospatial data, data custodian, owner or user, and connected other information.Non-public exploitation runs under personal-data-protection and State-secret law.
Điều 7 khoản 2 điểm đExploiting information beyond the public set requires the consent of the location's owner or lawful manager.Consent capture is a precondition, not a courtesy.
Điều 8 khoản 1Connection requires an information system meeting security assurance at minimum level 3.A concrete, auditable technical precondition.
Điều 8 khoản 5Connected and exploiting organizations retain and produce exploitation and usage history on the management authority's request.Exploitation logging is a standing duty, not an incident response.
Điều 8 khoản 6Purpose limitation and a flat ban on onward transfer, sharing or supply of exploited information, save on data-subject request or consent under personal data protection law.Downstream re-use of exploited location data is closed by default.
Điều 6 khoản 3 điểm cAnyone may report errors in recorded location data; the receiving agency forwards the report immediately to the source-database manager.A right worth operationalizing – owners can correct the state's record of their sites.
Điều 17Transitional roadmap: objects already holding the minimum data set are synchronized by the effective date; incomplete objects follow a ministry-built roadmap with no fixed calendar deadline.Coverage of the annex classes will phase in after 1 September 2026.

ObligationTimelineReference
Decree in effect1 September 2026Điều 18 khoản 1
Ministries synchronize objects holding the minimum data setBy the effective dateĐiều 17 khoản 1
Security inspection of a connection requester's systemNo more than 30 days from receipt of the requestĐiều 8 khoản 3
Connection effected after inspectionNo more than 5 working daysĐiều 8 khoản 4
Roadmap for objects lacking the minimum data setMinistry-built with the Ministry of Public Security; no fixed calendar deadline stated.Điều 17 khoản 2

The two connection clocks bind the state side, not the requester, but a requester who tracks them knows when a pending connection has left its window.

Forms and Data Requirements

The decree prescribes no official forms. Its only attachment is the annex listing the objects subject to identification, and the connection request under Điều 8 khoản 2 is a free-form written document stating the scope and purpose of connection. Everything ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

The decree also contains no sanctioning provisions and no penalty schedule. The only monetary element anywhere in the text is the exploitation-and-use fee on the general exploitation channel; a fee, not a fine. No exposure figure should be quoted for this instrument.

Overview Image

How ComplianceOne Supports Decree 326 Compliance

The passive and active roles are held apart. A location owner sees what the decree does to their sites (codes assigned from state data, an error-reporting right, no filing duty) while an exploiter or connector sees the duty set that actually binds them: channel, fee, consent, logging, purpose limitation and the onward-sharing ban.

Facility inventories can be connected to the annex object classes, so an organization knows which of its sites (plants, warehouses, ports, farms, land parcels) sit in scope as codes appear in state-facing registries.

Connection readiness runs as dated preparation: the security level 3 precondition, the written request's scope and purpose, and the 30-day and 5-working-day windows on the authority side, each held as evidence a programme can be measured against.

Related Modules

Data MappingData Mapping

Holds the facility and system inventory that annex object classes are screened against.

Explore Data Mapping

Program GovernanceProgram Governance

Assigns the standing exploiter duties – consent, logging, purpose limitation – to accountable owners.

Explore Program Governance

Compliance FormsCompliance Forms

Organizes the internal preparation templates for connection requests, consent records and exploitation logs.

Explore Compliance Forms

Audit TrailAudit Trail

Preserves exploitation history, consent evidence and error-report records.

Explore Audit Trail

Compliance Readiness Checklist

Organizations implementing Decree 326 compliance should confirm:

The facility footprint is screened against the annex's 71 object classes, so in-scope sites are known as codes are assigned.

No self-registration workstream has been stood up, the decree imposes none, and effort spent inventing one is effort misdirected.

Any planned exploitation of location data is mapped to its lawful channel: VNeID for public and own data, or an electronic authentication service provider with the fee.

Consent capture from location owners or managers is in place before any non-public information is exploited.

Exploitation and usage logging can be retained and produced on the management authority's request.

Purpose limitation is enforced, and no exploited information is transferred or shared onward without data-subject request or consent.

A planned database connection has security level 3 evidence and a written request stating scope and purpose.

The 30-day inspection and 5-working-day connection windows are tracked once a request is lodged.

The error-reporting right is operationalized, so wrong data about owned sites gets corrected at the source database.

Regulatory monitoring watches the delegated follow-on instruments, the identification process, the technical standards, and the ministry roadmaps for incomplete objects.

Background Image

See Decree 326 Compliance in Action

See how ComplianceOne screens a facility footprint against the annex classes, prepares connection evidence, and manages the applicable compliance requirements.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

Yes. Decree 326 took effect on 1 September 2026 under Điều 18 khoản 1.

No. The decree imposes no filing, registration or declaration duty on owners or lawful managers of locations. Codes are assigned from data already held in national and specialized state databases. Owners hold rights rather than duties: exploiting their own information via VNeID, reporting errors in the recorded data, and relief from re-submitting dossier components the database already holds.

Organizations that exploit location identification data or connect to the database. Outside VNeID and the state channels, exploitation runs through electronic authentication service providers against an exploitation-and-use fee, non-public information needs the location owner's or manager's consent, and connected organizations carry security level 3, exploitation-log retention, purpose limitation and an onward-sharing ban.

The decree contains no sanctioning provisions and no fine amounts, it is an organizational and data-governance instrument. The only monetary element is the exploitation-and-use fee, which is a fee, not a fine. Any exposure discussion for related conduct runs through other frameworks, such as personal data protection law for non-public data handling.

The signed text does not say. Điều 4 establishes a sequence of 12 natural digits – distinct, non-duplicated, stable and extensible – and leaves the technical standard for the data structure to follow-on ministerial instruments. Component addresses within a location get a separate randomly generated address code, distinct from the 12-digit location code.

No. Codes are established by the state's Location Identification Database under the Ministry of Public Security. ComplianceOne tracks readiness and duties; scope screening, consent, logging, connection evidence and the follow-on instruments, and does not perform any state function.

Next Steps

Icon Image

Start a Compliance Pilot

Test facility scope screening, exploiter duty controls and connection requirements.

Icon Image

Discuss Your Compliance Needs

Review which of your sites the annex reaches, whether you exploit location data, and what the requirements mean for you.