DPO Radio

Law 71/2025/QH15 is Vietnam's active law for the digital technology industry. Most provisions took effect on 1 January 2026; Articles 11, 28 and 29 on financing, investment support and incentives, and innovative start-up support took effect earlier, on 1 July 2025, under Article 50(2). Article 2 applies to domestic and foreign agencies, organizations and individuals participating in or related to the digital technology industry in Vietnam.
ComplianceOne's applicability assessment groups activity into digital technology enterprises, product and service providers, semiconductor participants, AI system providers and digital-asset service actors. These are operational categories used by the platform, rather than five statutory classes defined by Article 2.
ComplianceOne models it as a sector overlay: an optional installation that cross-links existing frameworks rather than replacing them. Teams confirm applicability before enabling direct-scope reporting workflows; others can use a reference-only installation. This product gate does not narrow the law's scope: Article 35(1)(a) requires quarterly or authority-requested database updates from bodies with related activity, including research institutes, universities and vocational education institutions. Teams must assess that duty separately from the platform's installation category.
Decision 1946/QĐ-TTg is the official implementation roadmap for the law, a planning and coordination reference rather than the main compliance law.
Active law, generally effective 1 January 2026; Articles 11, 28 and 29 effective 1 July 2025 under Article 50(2)
Domestic and foreign agencies, organizations and individuals participating in or related to the digital technology industry in Vietnam (Article 2)
Digital technology enterprises; product/service providers; semiconductor participants; AI system providers; digital-asset service actors — operational categories rather than a statutory list
Direct-scope or reference-only use; reporting requires platform scope confirmation, which does not determine or limit the statutory duty
Quarterly or authority-requested updates under Article 35(1)(a), including related research and education activity
The law establishes obligations for digital technology industry actors, covering products and services, quality and standards, sandboxes, and a national digital technology industry database.
Decision 1946/QĐ-TTg (Prime Minister, 9 September 2025) is the official implementation plan; used for implementation-plan tracking, guidance review, training, coordination, and future child-instrument review. It is a planning reference rather than a standalone compliance framework.

ComplianceOne starts with a sector applicability assessment that determines direct scope versus reference-only installation and identifies the applicable industry role. In-scope actors maintain a digital technology product and service inventory with category, owner, market role, quality requirements, data and AI use, cybersecurity controls, and applicable standards.
Cybersecurity, data, and personal-data compliance is cross-linked to PDPL, the Data Law, the Data Security Draft, and cybersecurity evidence. Quality and standards readiness tracks conformity evidence and technical documentation. Regulatory sandbox readiness captures scope, risk boundaries, eligibility, and outcomes.
National database readiness prepares quarterly and ad-hoc update evidence after the platform's applicability confirmation. Article 35's wider legal scope must be reviewed even where the installation is reference-only. AI activity links to Law 134/2025/QH15, Decree 142/2026/NĐ-CP and Decision 33/2026/QĐ-TTg. Digital-asset and semiconductor activity retains its own inventory and applicability evidence. Human review remains required before formal evidence or submission.
Coordinates scope assessment, standards, sandboxes, and database readiness.
Explore Program GovernanceMaps products/services, data and AI dependencies, and cross-framework links.
Explore Data MappingProvides internal inventory, assessment, and reporting templates.
Explore Compliance FormsTracks quality/standards and recurring database updates.
Explore Monitoring Programs


Assess whether your organization falls directly within scope and identify the relevant digital technology industry role. National database reporting is only applied where direct scope is confirmed.

Keep product and service, quality and standards, cybersecurity, personal data, sandbox, AI, digital asset, and semiconductor evidence connected across related compliance work.

Record authority requests and responses alongside reporting evidence, reviews, and approvals, creating a clear history of what was required, what was provided, and who reviewed it.
See how ComplianceOne scopes the overlay, inventories products and services, and cross-links cyber, data, AI, and semiconductor evidence.

Yes. Most of Law 71/2025/QH15 took effect on 1 January 2026. Articles 11, 28 and 29 on financing, investment support and incentives, and innovative start-up support took effect on 1 July 2025 under Article 50(2). Its original AI chapter was repealed from 1 March 2026 by AI Law 134/2025/QH15; current AI work follows that law and its implementing instruments.
It is an optional, opt-in pack for digital technology industry actors that overlays and cross-links existing frameworks rather than replacing them. Organizations in direct scope install it directly; others can install it reference-only.
Article 2 reaches domestic and foreign agencies, organizations and individuals participating in or related to the digital technology industry in Vietnam. ComplianceOne groups activity into enterprise, product/service, semiconductor, AI and digital-asset roles for its applicability workflow. Those groups do not replace the statutory scope, and Article 35's database duty also includes related research and education bodies.
No. Decision 1946 is the official implementation roadmap – a planning and coordination reference. The substantive framework is the law itself.
No. No official form IDs or fine amounts are presented until verified. Internal templates support readiness, and the platform enables reporting templates after scope confirmation. This workflow gate does not exempt reference-only users from any applicable statutory reporting duty.

Test scoped workflows, evidence, and review with your compliance team.

Review whether you are in direct scope and what evidence your products and services require.