DPO Radio

AesirX ComplianceOne | Vietnam Electronic Transactions Law 20/2023/QH15

Overview Image

Why the Vietnam Electronic Transactions Law Matters

The Law on Electronic Transactions 20/2023/QH15 is Vietnam's active parent framework governing transactions conducted by electronic means, including the legal validity of data messages, electronic signatures, electronic contracts, trust services, and electronic transactions involving state agencies. It was passed by the National Assembly on 22 June 2023 and took effect on 1 July 2024. The Law governs how a transaction is conducted electronically; it does not determine the substantive content, conditions, or permissible form of the underlying transaction itself.

Beneath the Law sits an active implementing and technical stack. Decree 23/2025/NĐ-CP is the implementing decree for electronic signatures and trust services; certificates, public digital-signature certification, timestamp services, data-message certification services, licensing, and regulatory oversight. Circular 19/2025/TT-BKHCN adds technical-audit requirements for the information systems and service-delivery processes behind secure signatures and trust services. Circular 53/2025/TT-BKHCN issues QCVN 139:2025/BKHCN, the national technical regulation for data-message certification. A further cluster of seven active technical instruments, covering signing software, certification practice, NEAC interoperability, certificate formats, two more QCVNs, and foreign e-signature recognition, sits alongside them as a technical-reference layer rather than seven separate headline frameworks.

ComplianceOne keeps the parent law, its active implementing decree, its technical-audit and technical-regulation circulars, and the technical-reference cluster connected without flattening their different legal roles or forms status.

What the Vietnam Electronic Transactions Law Covers

Dimension

Coverage

Parent framework

Law 20/2023/QH15 on Electronic Transactions, passed 22 June 2023, effective 1 July 2024, data messages, electronic signatures, electronic contracts, trust services, and electronic transactions with state agencies.

Active implementing decree

Decree 23/2025/NĐ-CP on E-Signatures and Trust Services – effective 10 April 2025.

Active technical-audit circular

Circular 19/2025/TT-BKHCN – effective 1 January 2026.

Active national technical regulation

Circular 53/2025/TT-BKHCN issuing QCVN 139:2025/BKHCN – effective 1 July 2026.

Active technical-reference cluster

Seven instruments covering signing software, certification practice, NEAC interoperability, certificate formats, public digital-signature and timestamp QCVNs, and foreign e-signature recognition.

Scope

Organizations conducting electronic transactions, and trust-service providers, software teams, certificate operators, and relying parties supporting them.

Operational themes

Signature and certificate validation; trust-service provider readiness; data-message certification and integrity; authority submission evidence; technical and interoperability control mapping.

Evidence

Signature and certificate records, provider readiness and licensing evidence, data-message certification records, audit-readiness records, submission proof.

Official forms

Three verified Decree 23 Forms (Mẫu số) No. 01, 03, and 08. No verified official form is currently seeded for Circular 19, Circular 53, or the technical cluster; QCVNs are official technical regulations, not fillable forms.

Status handling

Active stack managed as parent law, implementing decree, technical-audit and technical-regulation circulars, and a technical-reference cluster.

The Electronic Transactions Instrument Stack

Law on Electronic Transactions 20/2023/QH15 – Parent Law

Active

The Law on Electronic Transactions is the active parent framework governing transactions conducted by electronic means in Vietnam, including the legal validity of data messages, electronic signatures, electronic contracts, trust services, and electronic transactions involving state agencies.

Decree 23/2025/NĐ-CP – Implementing Decree

Active

The operational layer beneath the Law, implementing electronic-signature and trust-service requirements: certificates, public digital-signature certification, timestamp services, data-message certification services, licensing, operational conditions, and regulatory oversight. It has verified official Forms (Mẫu số) No. 01 (application for certification of a secure specialised electronic signature), No. 03 (evidence of creation of a secure specialised electronic signature), and No. 08 (certificate implementation report).

Circular 19/2025/TT-BKHCN – Technical-Audit Circular

Active

processes supporting secure electronic signatures, digital signatures, electronic-signature certificates, digital-signature certificates, and trust services.

Circular 53/2025/TT-BKHCN – National Technical Regulation

Active

Issues QCVN 139:2025/BKHCN, establishing technical, operational, and control requirements for data-message certification services, including evidence of sending and receipt, sending and receipt times, integrity, origin, participant identity, and long-term verification.

Additional Trust Services Technical Standards – Active Technical Reference Cluster

Additional active instruments cover digital-signing and signature-checking software, NEAC interoperability, certification practice, digital-certificate formats, two further QCVNs, and recognition of foreign electronic-signature certificates.

  • Circular 15/2025/TT-BKHCN: signing and signature-checking software and the public certification service gateway.
  • Circular 16/2025/TT-BKHCN: model certification practice.
  • Circular 17/2025/TT-BKHCN: NEAC interoperability requirements.
  • Circular 28/2025/TT-BKHCN: digital-signature certificate information formats.
  • Circular 50/2025/TT-BKHCN: QCVN 137 for public digital-signature certification services.
  • Circular 51/2025/TT-BKHCN: QCVN 138 for timestamp services.
  • Circular 06/2024/TT-BTTTT: foreign electronic-signature and certificate recognition in Vietnam.
Overview Image

How ComplianceOne Supports the Vietnam Electronic Transactions Law

readiness, and data-message certification records so teams can maintain a governed evidence trail rather than disconnected spreadsheets. Review and approval records show how eligibility, licensing, and certification decisions were made.

For Decree 23, the platform brings the three verified official forms, provider licensing and readiness evidence, and certificate and signature lifecycle records into one controlled workspace. For Circular 19, teams maintain technical-audit scope, control records, findings, and remediation evidence. For Circular 53, the platform supports data-message certification and integrity evidence without claiming unverified forms or certification outcomes. For the technical-reference cluster, each circular carries one internal working template — applicability, the two software inventories, interoperability, certificate-format evidence, QCVN readiness, and foreign e-signature recognition — filled and reviewed as records rather than run as registers. Recognition itself is not a dossier the platform assembles: what it holds is the position your organization has recorded about a provider on that provider's own record, with the date it was checked and the source it was checked against, and not established available as an answer rather than a default in either direction.

Evidence packs and audit history provide a reviewable record of completed work. Where Electronic Transactions Law activity overlaps identity, data governance, or labor-contract obligations, the same underlying evidence can be linked to the relevant framework without losing its original context.

Trust Service Evidence Under Decree 23's Regime

Decree 23 declares a trust regime, and ComplianceOne reads it from the frameworks an organization has installed. The decree recognises four trust service types – timestamp issuance, data message certification, and public digital signature certification, each requiring a licensed provider, plus the safe specialised electronic signature, which the decree states is not a licensed trust service. The mechanism is not specific to Vietnam: any framework whose pack declares a trust regime is read the same way, so a new instrument arrives as a content update rather than a product change.

Providers are held as records of what the organization has established about each one's standing under the regime. ComplianceOne does not determine whether a provider holds a licence (the supervising authority's published register is the source of truth ) and "not established" is a legitimate recorded answer for an organization that has not yet checked.

A credential carries a lifecycle rather than a status field: issue, activation, suspension, revocation, expiry, and renewal are recorded events with a reason, a time, an actor, and evidence. Revocation and expiry are terminal, so a renewal produces a successor record linked to its predecessor. Signature, seal, timestamp, and data-message checks are recorded as verification events with the algorithm metadata exactly as the verifying tool reported it.

A dossier filed to an authority is recorded as an electronic submission – the channel that carried it, the hash of the payload sent, the receipt that came back, and any later amendment, which never overwrites the original. ComplianceOne records that a filing was made; it does not transmit one, issue any certificate, hold key material, sign anything, or verify a signature itself.

Related Modules

Compliance FormsCompliance Forms

Organizes relevant records, ownership, review, and evidence for this framework.

Explore Compliance Forms

Audit TrailAudit Trail

Preserves contributor, reviewer, approval, decision, and change history across signatures, certificates, and related evidence.

Explore Audit Trail

Program GovernanceProgram Governance

Assigns ownership and recurring review across the implementing decree, technical circulars, and reference cluster.

Explore Program Governance

Data MappingData Mapping

Maintains trust-service provider inventories and data-message certification records.

Explore Data Mapping

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconSignature evidence is scattered across systems.
IconConnect signatures to source records and approvals.
IconCertificate changes lose their approval history.
IconTrack certificate lifecycle evidence and responsible owners.
IconTrust-service audits become manual document hunts.
IconPrepare reviewable audit and authority evidence packages.
IconData-message certification and long-term verification evidence goes unrecorded.
IconCross-link evidence while preserving each framework's legal context.
IconCertificate status lives in an inbox; nobody can say which credential was valid on the day a transaction was signed.
IconMaintain complete ownership, review, and audit history from one location.

Built for Electronic Transactions Compliance Operations

Build For Image

Status and legal scope remain visible throughout every workflow, helping teams distinguish parent laws, decrees, and circulars while preserving their individual legal roles.

Build For Image

Authority-issued artifacts and ComplianceOne operational templates retain clear source labels, reducing confusion between official records and internally prepared documentation.

Build For Image

Contributor, reviewer, approval, decision, and evidence history stay connected across signatures, certificates, trust services, and certified data messages.

Background Image

See Electronic Transactions Compliance in Action

See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

Yes. Law 20/2023/QH15 took effect on 1 July 2024 and is the active parent framework represented by this page, together with its active implementing decree and technical circulars.

No. Identity and eID are related, but this stack governs electronic transactions, signatures, trust services, and certified data messages.

Yes. The law and the three child instruments represented here are active, with their own effective dates and roles.

No. It governs how a transaction is conducted by electronic means; data messages, signatures, contracts, and trust services. It does not determine the substantive content, conditions, or permissible form of the underlying transaction.

No. It helps manage governance records, evidence, reviews, and audit readiness around certificate and trust-service processes.

No. Three verified official forms – Mẫu số 01, 03, and 08 – are seeded for Decree 23. No verified official form is currently seeded for Circular 19, Circular 53, or the technical cluster; QCVNs are official technical regulations, not fillable forms.

They are highly technical, supporting instruments – software requirements, interoperability rules, certificate formats, and two QCVNs – rather than headline obligations in their own right, so ComplianceOne presents them as one traceable technical-reference layer.

nothing, performs no signature verification of its own, and transmits no filing. It records the evidence about all of those, which is what an organization is asked to produce.

 

No. It helps teams assess applicability, assign owners, track controls, connect supporting evidence, manage review, and preserve audit history. It does not provide legal advice, certify trust services, or guarantee authority acceptance. The same boundary runs through the trust records themselves: ComplianceOne issues no certificate, holds no key material, signs.

 

Next Steps

Icon Image

Start a Compliance Pilot

Test scoped workflows, evidence, and review with your compliance team.

Icon Image

Discuss Your Compliance Needs

Review applicability, evidence sources, and operating-model requirements.