DPO Radio

AesirX ComplianceOne | Vietnam eID & e-Authentication Law

Overview Image

Why the Draft Law Matters

Vietnam's Ministry of Public Security opened consultation on the Draft Law on Electronic Identification and Authentication from 13 July to 2 August 2026. The draft has no assigned law number or final effective date and may change before promulgation.

Its proposed scope reaches beyond identifying people and organizations. It also covers physical objects, products, data, digital resources, applications, software, services, digital assets, intellectual property rights, events, transactions, interactions, and physical or virtual spaces.

That breadth creates a cross-functional readiness challenge. Identity owners, privacy teams, cybersecurity teams, AI governance leads, service operators, and vendor managers may need a shared view of identifiers, lifecycle events, authentication decisions, evidence, incidents, and provider dependencies.

ComplianceOne keeps this work in a draft-readiness track. Teams can prepare and review evidence while preserving the distinction between consultation proposals and requirements that are legally in force.

What the Draft Covers

Dimension

Coverage

Electronic identity scope

People, organizations, objects, data, digital resources, software, services, assets, events, transactions, interactions, and spaces.

Identity governance

Unique identifiers, registration, verification, issuance, updating, suspension, termination, linking, and traceability.

Authentication models

Centralized, intermediary, and self-sovereign authentication.

Assurance levels

Three risk-based levels using knowledge, possession, and inherent-characteristic factors.

Data handling

Purpose limitation, factor minimization, consent, temporary factor retention, authentication logs, and Vietnam storage readiness.

Electronic attestations

Independently verifiable certificates, subject-controlled sharing, combined presentation, and selective disclosure.

Providers

Proposed conditions for domestic providers and foreign providers serving Vietnam.

AI and security

Anti-spoofing, independent evaluation, bias and reliability review, adversarial resistance, monitoring, explainability, decision logs, and incident response.

The draft also proposes synchronization and retention rules and an 18-month transition measured from a future effective date. These are readiness markers, not current compliance deadlines.

Overview Image

How ComplianceOne Supports Draft Readiness

Teams can build an electronic identity inventory covering each proposed object category, assign accountable owners, and connect identifiers to lifecycle, source, assurance, and linkage evidence. Records can show how an object relates to its lawful owner or manager and how a transaction relates to its participants, time, location, and context.

Authentication assessments help teams document transaction risk, the selected authentication model, the proposed assurance level, and the factors used. Privacy review can record necessity, consent, minimization, and temporary retention decisions alongside authentication evidence.

Readiness records support electronic attestations and selective disclosure, domestic and cross-border provider assessment, controlled testing, AI identity-system controls, and incident handling. Each record remains clearly marked as preparatory work based on a consultation draft.

Related duties can be linked to Vietnam's personal data protection, Data Law, Cybersecurity Law, AI Law, Electronic Transactions Law, E-Commerce Law, and Telecommunications Law without duplicating evidence or merging their legal status.

Related Modules

Program GovernanceProgram Governance

Assigns ownership, review, approval, and recurring change checks.

Explore Program Governance

Data MappingData Mapping

Connects identity sources, systems, providers, storage, and data flows.

Explore Data Mapping

Vendor RiskVendor Risk

Connects lifecycle stages, storage, recipients, systems, and cross-border flows.

Explore Vendor Risk

Incident OperationsIncident Operations

Preserves investigation, notification, remediation, and closure evidence.

Explore Incident Operations

Audit TrailAudit Trail

Retains contributor, reviewer, decision, and change history.

Explore Audit Trail

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconIdentity objects and owners are scattered across system and vendor inventories.
IconIdentity scope, identifiers, owners, lifecycle, and linkages stay connected.
IconAuthentication levels are selected without a consistent risk rationale.
IconAuthentication model, assurance, factors, minimization, and evidence are reviewed together.
IconPrivacy, security, AI, and provider reviews produce disconnected evidence.
IconProvider, AI, privacy, security, and incident work shares a governed evidence chain.
IconDraft synchronization, retention, and transition proposals are mistaken for current deadlines.
IconDraft proposals remain visibly separate from active legal requirements.
IconConsultation changes are difficult to compare against earlier readiness decisions.
IconPromulgation review can compare the final instrument with the readiness baseline.

Built for Compliance Operations

Build For Image

ComplianceOne records the official consultation window and links readiness work to the uploaded draft and Ministry of Public Security consultation dossier.

Build For Image

The readiness set uses organization-created working records. It does not present government forms, final fines, a final effective date, or final administrative procedures.

Build For Image

Human review remains central to legal interpretation, provider decisions, evidence approval, and any future authority interaction.

Background Image

See Compliance in Action

See how ComplianceOne organizes electronic identity, authentication, provider, AI, and incident readiness without overstating the draft's legal status.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

No. The source is a 2026 consultation draft with no assigned law number or final effective date. ComplianceOne presents it as preparatory material until an official promulgated instrument is verified.

The proposed scope includes people and organizations as well as physical objects, data, digital resources, applications, software, services, assets, rights, events, transactions, interactions, and physical or virtual spaces.

The draft proposes three risk-based levels using combinations of knowledge, possession, and inherent-characteristic factors. Readiness assessments can record the rationale without treating the levels as final law.

Yes. It describes a self-sovereign authentication model and electronic attestations that can support subject-controlled sharing and selective disclosure, subject to the final text and implementing rules.

It structures reviews of establishment, infrastructure, security, personnel, process integrity, continuity, Vietnam presence, data storage, national-system connectivity, AI controls, and incident readiness.

Next Steps

Icon Image

Start a Compliance Pilot

Test identity inventory, authentication assessment, and provider-readiness workflows with your team.

Icon Image

Discuss Your Compliance Needs

Map the draft's proposed scope to your identity systems, providers, data, and existing Vietnam duties.