DPO Radio

Decree 326/2026/NĐ-CP was signed on 19 August 2026, taking effect on 1 September 2026. Its 18 articles establish location identification for objects across the territory of Vietnam; land parcels, structures, transport works, place names and more, outside the State-secrets list. An annex enumerates 71 numbered object classes across 18 groups, three of them open or group-level categories.
Each identified location receives a single, stable 12-digit identification code established by the Location Identification Database, a national, centralized database built and managed under the Ministry of Public Security. The decree does not break the 12 digits into named segments; the code structure's technical detail is delegated to follow-on ministerial instruments. Public location data is surfaced to organizations and individuals through the national identification application VNeID.
The duty structure is unusual and worth stating plainly. Nearly every affirmative obligation (collecting, synchronizing, updating, guiding) falls on state bodies. Location owners and lawful managers are passive subjects: the decree imposes no filing, registration or declaration duty on them, because data about their sites flows from existing state databases. The substantive private-sector duties attach to those who exploit the data or connect to the database.

Decree 326 is a Government decree issued on seven legal bases, and its data-governance anchors are the ones that matter operationally: the Data Law is where its database, sharing and exploitation machinery takes root, and the Personal Data Protection Law governs every touch of the database's non-public information; land-certificate details, structural and three-dimensional geospatial data, custodian identity and owner or user identity.
It is carried in the Data Law family rather than as an implementing decree of any single parent, because that is how it behaves: a national-database instrument whose exploitation rules hand off to personal-data-protection and State-secret law the moment non-public information is involved.
| Provision | What It Requires | Operational Implication |
|---|---|---|
| Điều 2, Phụ lục | Identified objects: land parcels, architectural and construction works, built structures, place names and any physical structure – 71 numbered classes in 18 annex groups. | Facility-heavy organizations should expect their sites to carry codes under the decree. |
| Điều 4 | The identification code is a sequence of 12 natural digits, distinct, non-duplicated and stable; no segment breakdown is prescribed in the text. | Do not build against an assumed segment encoding – the technical standard is delegated to later instruments. |
| Điều 5 | The Location Identification Database with 16 information fields, from code and address through coordinates to owner or user identity. | The field set defines what the state will hold about each site. |
| Điều 7 khoản 2 | Exploitation channels: public data via VNeID; state bodies via national platforms; everyone else via electronic authentication service providers, against an exploitation-and-use fee. | Channel selection is prescribed, and the fee applies on the general channel. |
| Điều 7 khoản 3 | Ten of the 16 field families are public; six are non-public – land-certificate information, structure, three-dimensional geospatial data, data custodian, owner or user, and connected other information. | Non-public exploitation runs under personal-data-protection and State-secret law. |
| Điều 7 khoản 2 điểm đ | Exploiting information beyond the public set requires the consent of the location's owner or lawful manager. | Consent capture is a precondition, not a courtesy. |
| Điều 8 khoản 1 | Connection requires an information system meeting security assurance at minimum level 3. | A concrete, auditable technical precondition. |
| Điều 8 khoản 5 | Connected and exploiting organizations retain and produce exploitation and usage history on the management authority's request. | Exploitation logging is a standing duty, not an incident response. |
| Điều 8 khoản 6 | Purpose limitation and a flat ban on onward transfer, sharing or supply of exploited information, save on data-subject request or consent under personal data protection law. | Downstream re-use of exploited location data is closed by default. |
| Điều 6 khoản 3 điểm c | Anyone may report errors in recorded location data; the receiving agency forwards the report immediately to the source-database manager. | A right worth operationalizing – owners can correct the state's record of their sites. |
| Điều 17 | Transitional roadmap: objects already holding the minimum data set are synchronized by the effective date; incomplete objects follow a ministry-built roadmap with no fixed calendar deadline. | Coverage of the annex classes will phase in after 1 September 2026. |
| Obligation | Timeline | Reference |
|---|---|---|
| Decree in effect | 1 September 2026 | Điều 18 khoản 1 |
| Ministries synchronize objects holding the minimum data set | By the effective date | Điều 17 khoản 1 |
| Security inspection of a connection requester's system | No more than 30 days from receipt of the request | Điều 8 khoản 3 |
| Connection effected after inspection | No more than 5 working days | Điều 8 khoản 4 |
| Roadmap for objects lacking the minimum data set | Ministry-built with the Ministry of Public Security; no fixed calendar deadline stated. | Điều 17 khoản 2 |
The two connection clocks bind the state side, not the requester, but a requester who tracks them knows when a pending connection has left its window.
The decree prescribes no official forms. Its only attachment is the annex listing the objects subject to identification, and the connection request under Điều 8 khoản 2 is a free-form written document stating the scope and purpose of connection. Everything ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.
The decree also contains no sanctioning provisions and no penalty schedule. The only monetary element anywhere in the text is the exploitation-and-use fee on the general exploitation channel; a fee, not a fine. No exposure figure should be quoted for this instrument.

The passive and active roles are held apart. A location owner sees what the decree does to their sites (codes assigned from state data, an error-reporting right, no filing duty) while an exploiter or connector sees the duty set that actually binds them: channel, fee, consent, logging, purpose limitation and the onward-sharing ban.
Facility inventories can be connected to the annex object classes, so an organization knows which of its sites (plants, warehouses, ports, farms, land parcels) sit in scope as codes appear in state-facing registries.
Connection readiness runs as dated preparation: the security level 3 precondition, the written request's scope and purpose, and the 30-day and 5-working-day windows on the authority side, each held as evidence a programme can be measured against.
Holds the facility and system inventory that annex object classes are screened against.
Explore Data MappingAssigns the standing exploiter duties – consent, logging, purpose limitation – to accountable owners.
Explore Program GovernanceOrganizes the internal preparation templates for connection requests, consent records and exploitation logs.
Explore Compliance FormsPreserves exploitation history, consent evidence and error-report records.
Explore Audit TrailOrganizations implementing Decree 326 compliance should confirm:
See how ComplianceOne screens a facility footprint against the annex classes, prepares connection evidence, and manages the applicable compliance requirements.

Yes. Decree 326 took effect on 1 September 2026 under Điều 18 khoản 1.
No. The decree imposes no filing, registration or declaration duty on owners or lawful managers of locations. Codes are assigned from data already held in national and specialized state databases. Owners hold rights rather than duties: exploiting their own information via VNeID, reporting errors in the recorded data, and relief from re-submitting dossier components the database already holds.
Organizations that exploit location identification data or connect to the database. Outside VNeID and the state channels, exploitation runs through electronic authentication service providers against an exploitation-and-use fee, non-public information needs the location owner's or manager's consent, and connected organizations carry security level 3, exploitation-log retention, purpose limitation and an onward-sharing ban.
The decree contains no sanctioning provisions and no fine amounts, it is an organizational and data-governance instrument. The only monetary element is the exploitation-and-use fee, which is a fee, not a fine. Any exposure discussion for related conduct runs through other frameworks, such as personal data protection law for non-public data handling.
The signed text does not say. Điều 4 establishes a sequence of 12 natural digits – distinct, non-duplicated, stable and extensible – and leaves the technical standard for the data structure to follow-on ministerial instruments. Component addresses within a location get a separate randomly generated address code, distinct from the 12-digit location code.
No. Codes are established by the state's Location Identification Database under the Ministry of Public Security. ComplianceOne tracks readiness and duties; scope screening, consent, logging, connection evidence and the follow-on instruments, and does not perform any state function.

Test facility scope screening, exploiter duty controls and connection requirements.

Review which of your sites the annex reaches, whether you exploit location data, and what the requirements mean for you.