DPO Radio

Decree 147/2024/NĐ-CP on Internet Services and Online Information was issued by the Government of Vietnam and took effect on 25 December 2024. It is modeled as a shared platform overlay rather than a child of a single law, because online platforms, social networks, and internet services sit at the intersection of Telecommunications, Cybersecurity, E-Commerce, personal data protection, and Data Law obligations. Direct scope covers online-platform operators, social-network service providers, internet-service providers, online-game service providers, and foreign digital-service providers serving Vietnam.
Within that scope, the decree asks organizations to inventory their internet, platform, social-network, game, and content services; maintain risk-appropriate user-account verification evidence; preserve content-moderation, restriction, takedown, notification, and review records; run an accountable authority-request intake, validation, response, and evidence process; cross-link user data to PDPL, Data Law, and cybersecurity controls; and map foreign-provider applicability, contacts, records, and operational obligations where a provider serves Vietnam from abroad.
Six of the decree's official Mẫu số forms are verified and seeded here — social-network service notification (Mẫu số 20) and the amendment and extension forms for aggregated-information-website and social-network licences and notifications (Mẫu số 22 through 26) — scoped specifically to the implemented online-platform and social-network content. Gaming, domain/IP, mobile-content, and e-commerce forms under the same decree are excluded pending reconciliation against Decree 116/2026/NĐ-CP amendments, and are not represented here as available.
Direct mode is for organizations within the declared digital-services scope; others install it for reference, which produces no deadlines, score contribution, or automated workflows. ComplianceOne coordinates this shared-overlay evidence without duplicating the parent Telecommunications, Cybersecurity, E-Commerce, PDPL, or Data Law obligations it cross-links.
Decree 147/2024/NĐ-CP on Internet Services and Online Information, effective 25 December 2024, issued by the Government of Vietnam.
Online-platform operators, social-network service providers, internet-service providers, online-game service providers, and foreign digital-service providers serving Vietnam.
Service inventory; user-account verification; content moderation and takedown; authority-request response; user-data cross-linking; foreign-provider readiness.
User-account records, moderation decisions, platform logs, and authority-request packages across 6 tracked obligations.
6 verified Mẫu số forms (Mẫu số 20, 22, 23, 24, 25, 26) scoped to online-platform and social-network notifications, licence amendments, and extensions; gaming, domain/IP, mobile-content, and e-commerce forms under the same decree remain unverified and are not included.
ComplianceOne does not record monetary fine amounts for this instrument; five risk areas are tracked as risk-only findings with no monetary figure attached.
Active, optional sector overlay, direct mode for in-scope organizations, reference mode for others.

ComplianceOne brings the six verified Mẫu số forms (social-network service notification and the licence/notification amendment and extension forms) into the same controlled workspace as the platform's internal working records, with official identifiers kept visibly distinct from platform-prepared templates.
User-account verification records and content-moderation/takedown records carry their detection, impact, and response detail with evidence attached, so a moderation decision can be reconstructed from the record rather than after the fact. Authority-request records track the submitting entity, the receiving authority, submission content, and the authority's response with an accountable owner assigned throughout.
Because platform obligations intersect user data, the platform cross-links user-data records to PDPL and Data Law evidence, and foreign-provider readiness records document applicability, contacts, and operational obligations for providers serving Vietnam from abroad, all without duplicating the Telecommunications, Cybersecurity, E-Commerce, PDPL, or Data Law obligations this overlay cross-references.
Assigns ownership and recurring review across service inventory, account verification, and foreign-provider readiness.
Explore Program GovernanceTracks content-moderation and takedown records with detection, impact, and response detail.
Explore Incident OperationsPreserves contributor, review, approval, and evidence history across moderation and authority-request records.
Explore Audit TrailSupports the six verified Mẫu số notification, amendment, and extension forms alongside internal working templates.
Explore Compliance Forms


Status and scope remain visible throughout the workflow, helping teams distinguish active obligations, draft readiness, ownership, and review progress.

Authority-issued and platform-prepared artifacts retain clear source labels, keeping official forms and internal records distinct throughout every process.

Contributor, reviewer, approval, and evidence history stays connected, preserving a complete audit trail across every decision, update, and compliance activity.
See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Organizations within the pack’s declared digital-services scope can use direct mode; other organizations can install it for reference.
No. It is a shared platform overlay and cross-links e-commerce without duplicating Decree 248.
It follows the implemented platform and social-network scope; other areas remain outside this page’s claims.
The pack includes six verified forms for the implemented scope and does not claim unverified forms outside it.
No final monetary fines are marketed without a verified sanctions source.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.