DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

AesirX ComplianceOne | Decree 69/2024/NĐ-CP on eID and Authentication

Overview Image

Decree 69/2024/NĐ-CP: Scope and Current Status

Decree 69/2024/NĐ-CP on Electronic Identification and Authentication was issued by the Government on 25 June 2024 and took effect on 1 July 2024, the same day as the Identity Law 26/2023/QH15 it implements. It replaces Decree 59/2022/NĐ-CP of 5 September 2022. It governs electronic identity accounts, the levels of authentication attaching to them, and the eligibility regime for electronic authentication services. Decree 69 is represented according to its implemented legal role and is not promoted into a broader or more binding framework.

Operational themes include eID account lifecycle, identity attributes, verification, authentication events, state-data reuse, and accountable evidence. Teams should confirm applicability and legal interpretation with qualified advisers.

Overview Image

How Decree 69 Relates to the Vietnam Data Law

This instrument sits beneath the Vietnam Identity Law 26/2023/QH15. The parent law establishes the identity baseline: identity information, the identity card, and the identity database, and is the legal basis for electronic identification. Decree 69 supplies the narrower operational layer beneath it and is the only instrument in the stack that carries verified official forms.

Project 06 (Đề án 06), approved by Decision 06/QĐ-TTg of 6 January 2022, sits alongside this decree as a national programme reference under the same parent. It shapes population-database and VNeID integration but prescribes no official forms, so it is covered on the parent page rather than on an instrument page of its own.

Cross-links preserve related evidence without duplicating parent obligations or changing the status of neighboring active, draft, guidance, or reference layers.

Technical Provisions and Operational Baseline Components

Operational AreaComplianceOne Support
ApplicabilityRecord scope decisions, owners, and review history.
Operational workAssign tasks, connect supporting evidence, and manage approvals.
Official formsSeven verified official forms: TK01 (electronic identity account application), TK03 (request to lock or unlock an electronic identity account or card), and XT01–XT05 (electronic authentication service eligibility confirmation, amendment, issued confirmation, revocation decision, and activity report).
Internal recordsSeven platform-prepared lifecycle and evidence templates, labelled as internal working documents and kept separate from the official forms.
Audit readinessPreserve contributor, reviewer, decision, and change history.
Overview Image

How ComplianceOne Supports Decree 69 Compliance

ComplianceOne connects structured records, supporting evidence, assigned owners, and human review. Authority-issued artifacts retain source labels; platform-prepared templates remain clearly identified as operational aids.

The platform helps prepare authority-ready or audit-ready packages where the implemented pack supports them. It does not guarantee compliance, legal validity, certification, or acceptance by an authority.

Related Modules

Data MappingData Mapping

Maintains electronic identity data inventories, identity attributes, processing flows, and VNeID integration records across systems.

Explore Data Mapping

Data ClassificationData Classification

Classifies electronic identity and authentication information, with documented handling rules, ownership, and review history.

Explore Data Classification

Program GovernanceProgram Governance

Assigns accountable owners, manages recurring reviews, and tracks governance activities for electronic identity operations.

Explore Program Governance

Compliance FormsCompliance Forms

Supports the seven official Decree 69 forms and keeps internal lifecycle records clearly separate.

Explore Compliance Forms

Audit TrailAudit Trail

Preserves contributor, review, approval, evidence, and change history across electronic identity and authentication records.

Explore Audit Trail

Compliance Readiness Checklist

Confirm applicability and current instrument status.

Assign accountable owners and reviewers.

Select official artifacts only where source-verified.

Link supporting evidence and related framework records.

Record human review and approval.

Retain audit history for later inspection.

Background Image

See Decree 69 Compliance in Action

See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

It is active. Decree 69/2024/NĐ-CP was issued on 25 June 2024, took effect on 1 July 2024, and replaced Decree 59/2022/NĐ-CP. It is represented separately from draft, roadmap, or neighboring framework layers.

It implements the Identity Law 26/2023/QH15, adding a narrower operational layer beneath it while retaining its own code, status, evidence, and review context.

Seven, all source-verified: TK01, TK03, and XT01 through XT05. They cover electronic identity account application, account or card lock and unlock, and the electronic authentication service eligibility lifecycle including amendment, revocation, and activity reporting.

Authority-issued forms keep their official identifiers and source labels. Platform-prepared templates and internal lifecycle records are labelled as operational working documents and are never presented as prescribed forms.

No. It structures evidence, ownership, workflow, and review; organizations remain responsible for legal interpretation.

Yes. Related records can be cross-linked while preserving their original framework ownership and audit history.

Next Steps

Icon Image

Start a Compliance Pilot

Test scoped workflows, evidence, and review with your compliance team.

Icon Image

Discuss Your Compliance Needs

Review applicability, evidence sources, and operating-model requirements.