DPO Radio

Decree 88/2026/NĐ-CP was issued by the Government of Vietnam on 28 March 2026 and took effect on 15 May 2026. The Ministry of Education and Training is the lead authority. It is an active education-sector overlay for education and training data governance, learner records, credentials, sharing, and interoperability, binding schools, universities, education and training institutions, education-data platforms, EdTech providers, and certification and diploma systems.
Within that scope, the decree asks organizations to inventory education and training data together with its systems, owners, sources, and recipients; assign accountable ownership, quality, update, access, and lifecycle controls for education databases; maintain provenance, authenticity, and verification evidence for diplomas, certificates, transcripts, and learning records; and record lawful sharing, interconnection, authentication, and reuse controls where education data moves between systems.
Two obligations point directly at the sensitivity of this population. Learner, student, staff, and minor personal-data processing must be cross-linked to the applicable Personal Data Protection Law safeguards rather than governed twice. And where an organization uses AI systems to assess, rank, monitor, or profile learners, that use must be mapped to AI Law and high-risk-system controls; the pack's cross-references reach as far as the AI High-Risk Systems Decision. A further obligation addresses the legal-equivalence readiness of electronic education records where applicable.
This overlay is opt-in: organizations outside its declared scope can install it in reference mode, which produces no deadlines, score contribution, or automated workflows. ComplianceOne keeps its education-specific obligations connected to the Data Law, PDPL, cybersecurity, identity, and AI frameworks they depend on, without duplicating those parent obligations or blurring which instrument owns which requirement.
Decree 88/2026/NĐ-CP, issued 28 March 2026, effective 15 May 2026, Ministry of Education and Training as lead authority.
Schools, universities, education and training institutions, education-data platforms, EdTech providers, and certification/diploma systems.
Education-data inventory; education database governance; learner/staff/minor data safeguards; credential and learning-record integrity; data sharing and interconnection; electronic-record legal-equivalence readiness; AI learner-system risk cross-link.
Learner-record inventories, credential and verification records, sharing/interconnection records, and AI-risk cross-link assessments across 8 tracked obligations.
No official form has been verified against the checked Decree 88 Gazette text, appendices, or linked Ministry of Education and Training procedure references; the pack's 8 templates are internal working documents.
ComplianceOne does not record monetary fine amounts for this instrument.
Active, optional education sector overlay, direct mode for in-scope organizations, reference mode for others.

ComplianceOne maintains the education and training data inventory as a governed register (systems, owners, sources, and recipients tied to accountable review rather than a static spreadsheet) alongside education-database governance records covering control description, implementation, and ownership for each database in scope.
For credentials, the platform tracks diploma, certificate, transcript, and learning-record verification as its own evidence type, separate from general data records, so provenance and authenticity checks are traceable on demand. Data-sharing and interconnection records capture recipients, storage locations, and cross-references to the frameworks each transfer also touches.
Because learner, student, staff, and minor data is personal data, the platform links this overlay's evidence to the relevant PDPL safeguards without duplicating them, and where AI systems assess, rank, monitor, or profile learners, the AI education-system risk cross-link record connects that use to AI Law and high-risk-system evidence. Contributor, review, and approval history stays attached to every record as work progresses.
Maps learner records, credential data, verification activities, and education-data flows across connected systems.
Explore Data MappingDistinguishes sensitive health and patient data from general operational data for downstream handling decisions.
Explore Compliance FormsConnects learner records, credential verification, and data access to accountable owners and reviewers.
Explore Access & AccountabilityPreserves contributor, review, approval, credential, and evidence history across education-data governance records.
Explore Audit Trail


Status and scope remain visible throughout the workflow.

Authority-issued and platform-prepared artifacts retain clear source labels.

Contributor, reviewer, approval, and evidence history stays connected.
See how ComplianceOne helps structure evidence, ownership, and review for this framework.

No. It is an optional sector overlay; organizations outside education can use it as reference.
No official forms were verified in the checked decree, appendices, or linked procedure sources.
It supports evidence and cross-links for student and child-data protection where relevant, without replacing PDPL.
No. It helps manage evidence around credentials and verification; it does not claim credential issuance.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.