DPO Radio

The Law on Electronic Transactions 20/2023/QH15 is Vietnam's active parent framework governing transactions conducted by electronic means, including the legal validity of data messages, electronic signatures, electronic contracts, trust services, and electronic transactions involving state agencies. It was passed by the National Assembly on 22 June 2023 and took effect on 1 July 2024. The Law governs how a transaction is conducted electronically; it does not determine the substantive content, conditions, or permissible form of the underlying transaction itself.
Beneath the Law sits an active implementing and technical stack. Decree 23/2025/NĐ-CP is the implementing decree for electronic signatures and trust services; certificates, public digital-signature certification, timestamp services, data-message certification services, licensing, and regulatory oversight. Circular 19/2025/TT-BKHCN adds technical-audit requirements for the information systems and service-delivery processes behind secure signatures and trust services. Circular 53/2025/TT-BKHCN issues QCVN 139:2025/BKHCN, the national technical regulation for data-message certification. A further cluster of seven active technical instruments, covering signing software, certification practice, NEAC interoperability, certificate formats, two more QCVNs, and foreign e-signature recognition, sits alongside them as a technical-reference layer rather than seven separate headline frameworks.
ComplianceOne keeps the parent law, its active implementing decree, its technical-audit and technical-regulation circulars, and the technical-reference cluster connected without flattening their different legal roles or forms status.
Law 20/2023/QH15 on Electronic Transactions, passed 22 June 2023, effective 1 July 2024, data messages, electronic signatures, electronic contracts, trust services, and electronic transactions with state agencies.
Decree 23/2025/NĐ-CP on E-Signatures and Trust Services – effective 10 April 2025.
Circular 19/2025/TT-BKHCN – effective 1 January 2026.
Circular 53/2025/TT-BKHCN issuing QCVN 139:2025/BKHCN – effective 1 July 2026.
Seven instruments covering signing software, certification practice, NEAC interoperability, certificate formats, public digital-signature and timestamp QCVNs, and foreign e-signature recognition.
Organizations conducting electronic transactions, and trust-service providers, software teams, certificate operators, and relying parties supporting them.
Signature and certificate validation; trust-service provider readiness; data-message certification and integrity; authority submission evidence; technical and interoperability control mapping.
Signature and certificate records, provider readiness and licensing evidence, data-message certification records, audit-readiness records, submission proof.
Three verified Decree 23 Forms (Mẫu số) No. 01, 03, and 08. No verified official form is currently seeded for Circular 19, Circular 53, or the technical cluster; QCVNs are official technical regulations, not fillable forms.
Active stack managed as parent law, implementing decree, technical-audit and technical-regulation circulars, and a technical-reference cluster.
The Law on Electronic Transactions is the active parent framework governing transactions conducted by electronic means in Vietnam, including the legal validity of data messages, electronic signatures, electronic contracts, trust services, and electronic transactions involving state agencies.
The operational layer beneath the Law, implementing electronic-signature and trust-service requirements: certificates, public digital-signature certification, timestamp services, data-message certification services, licensing, operational conditions, and regulatory oversight. It has verified official Forms (Mẫu số) No. 01 (application for certification of a secure specialised electronic signature), No. 03 (evidence of creation of a secure specialised electronic signature), and No. 08 (certificate implementation report).
processes supporting secure electronic signatures, digital signatures, electronic-signature certificates, digital-signature certificates, and trust services.
Issues QCVN 139:2025/BKHCN, establishing technical, operational, and control requirements for data-message certification services, including evidence of sending and receipt, sending and receipt times, integrity, origin, participant identity, and long-term verification.
Additional active instruments cover digital-signing and signature-checking software, NEAC interoperability, certification practice, digital-certificate formats, two further QCVNs, and recognition of foreign electronic-signature certificates.

readiness, and data-message certification records so teams can maintain a governed evidence trail rather than disconnected spreadsheets. Review and approval records show how eligibility, licensing, and certification decisions were made.
For Decree 23, the platform brings the three verified official forms, provider licensing and readiness evidence, and certificate and signature lifecycle records into one controlled workspace. For Circular 19, teams maintain technical-audit scope, control records, findings, and remediation evidence. For Circular 53, the platform supports data-message certification and integrity evidence without claiming unverified forms or certification outcomes. For the technical-reference cluster, each circular carries one internal working template — applicability, the two software inventories, interoperability, certificate-format evidence, QCVN readiness, and foreign e-signature recognition — filled and reviewed as records rather than run as registers. Recognition itself is not a dossier the platform assembles: what it holds is the position your organization has recorded about a provider on that provider's own record, with the date it was checked and the source it was checked against, and not established available as an answer rather than a default in either direction.
Evidence packs and audit history provide a reviewable record of completed work. Where Electronic Transactions Law activity overlaps identity, data governance, or labor-contract obligations, the same underlying evidence can be linked to the relevant framework without losing its original context.
Decree 23 declares a trust regime, and ComplianceOne reads it from the frameworks an organization has installed. The decree recognises four trust service types – timestamp issuance, data message certification, and public digital signature certification, each requiring a licensed provider, plus the safe specialised electronic signature, which the decree states is not a licensed trust service. The mechanism is not specific to Vietnam: any framework whose pack declares a trust regime is read the same way, so a new instrument arrives as a content update rather than a product change.
Providers are held as records of what the organization has established about each one's standing under the regime. ComplianceOne does not determine whether a provider holds a licence (the supervising authority's published register is the source of truth ) and "not established" is a legitimate recorded answer for an organization that has not yet checked.
A credential carries a lifecycle rather than a status field: issue, activation, suspension, revocation, expiry, and renewal are recorded events with a reason, a time, an actor, and evidence. Revocation and expiry are terminal, so a renewal produces a successor record linked to its predecessor. Signature, seal, timestamp, and data-message checks are recorded as verification events with the algorithm metadata exactly as the verifying tool reported it.
A dossier filed to an authority is recorded as an electronic submission – the channel that carried it, the hash of the payload sent, the receipt that came back, and any later amendment, which never overwrites the original. ComplianceOne records that a filing was made; it does not transmit one, issue any certificate, hold key material, sign anything, or verify a signature itself.
Organizes relevant records, ownership, review, and evidence for this framework.
Explore Compliance FormsPreserves contributor, reviewer, approval, decision, and change history across signatures, certificates, and related evidence.
Explore Audit TrailAssigns ownership and recurring review across the implementing decree, technical circulars, and reference cluster.
Explore Program GovernanceMaintains trust-service provider inventories and data-message certification records.
Explore Data Mapping


Status and legal scope remain visible throughout every workflow, helping teams distinguish parent laws, decrees, and circulars while preserving their individual legal roles.

Authority-issued artifacts and ComplianceOne operational templates retain clear source labels, reducing confusion between official records and internally prepared documentation.

Contributor, reviewer, approval, decision, and evidence history stay connected across signatures, certificates, trust services, and certified data messages.
See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Yes. Law 20/2023/QH15 took effect on 1 July 2024 and is the active parent framework represented by this page, together with its active implementing decree and technical circulars.
No. Identity and eID are related, but this stack governs electronic transactions, signatures, trust services, and certified data messages.
Yes. The law and the three child instruments represented here are active, with their own effective dates and roles.
No. It governs how a transaction is conducted by electronic means; data messages, signatures, contracts, and trust services. It does not determine the substantive content, conditions, or permissible form of the underlying transaction.
No. It helps manage governance records, evidence, reviews, and audit readiness around certificate and trust-service processes.
No. Three verified official forms – Mẫu số 01, 03, and 08 – are seeded for Decree 23. No verified official form is currently seeded for Circular 19, Circular 53, or the technical cluster; QCVNs are official technical regulations, not fillable forms.
They are highly technical, supporting instruments – software requirements, interoperability rules, certificate formats, and two QCVNs – rather than headline obligations in their own right, so ComplianceOne presents them as one traceable technical-reference layer.
nothing, performs no signature verification of its own, and transmits no filing. It records the evidence about all of those, which is what an organization is asked to produce.
No. It helps teams assess applicability, assign owners, track controls, connect supporting evidence, manage review, and preserve audit history. It does not provide legal advice, certify trust services, or guarantee authority acceptance. The same boundary runs through the trust records themselves: ComplianceOne issues no certificate, holds no key material, signs.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.