DPO Radio

Decree 137/2024/NĐ-CP has applied since 23 October 2024 to electronic transactions of state agencies and the information systems that support them. It sits beneath Vietnam’s Electronic Transactions Law.
This is a scoped public-sector overlay. Direct use is relevant to state agencies, public-service portal operators, state electronic-transaction system operators, and suppliers operating those systems. Other organizations can retain it for reference.
Operational readiness depends on more than a policy. Teams need an accountable inventory of systems and integrations, evidence of electronic record exchange, security and continuity records, and reviewable audit trails.
Decree 137/2024/NĐ-CP, issued by the Government of Vietnam and effective 23 October 2024, implementing the Law on Electronic Transactions for the public sector.
State agencies, state e-transaction systems, public-service portals, integration operators, and relevant suppliers.
Ownership, purpose, users, connected databases, exchanged records, classification, and safeguards.
Creation, sending, receipt, processing, integrity, timestamps, signatures, and status evidence.
Authority, purpose, interfaces, authentication, data fields, transmission, and reconciliation.
Six organization-prepared assessments, inventories, exchange, integration, audit, and dossier records.
Optional; direct after public-sector scope confirmation, or reference-only.

Teams can assign ownership for each state e-transaction system and connect system, data, integration, security, incident, and continuity evidence. Transaction records preserve accountable creation-to-processing history.
Cross-links reuse applicable Electronic Transactions, trust-services, Data Law, cybersecurity, digital-transformation, identity, and state-database evidence without duplicating specialist obligations.
Decree 137 declares no trust regime of its own. Where a state e-transaction depends on a certificate, a signature check, or a filing to an authority, that evidence is held under the regime an installed instrument declares (Decree 23 for trust services, Decree 69 for regulated electronic identity) and cross-linked to the system record here. A credential carries its issue, suspension, revocation, and expiry history as events, so the question of what was valid on the day a transaction was signed is read from a timeline. ComplianceOne records that a filing was made, with the payload hash and the receipt returned; it transmits nothing and signs nothing.
Maps systems, exchanged records, databases, interfaces, and accountable owners.
Explore Data MappingStructures supporting system, exchange, integration, and audit records.
Explore Compliance FormsAssigns reviews, exceptions, remediation, and evidence collection.
Explore Task Management


System ownership, integration details, and record-exchange evidence for a state e-transaction system live in the same workspace, so an audit or incident review starts from one accountable source instead of being reconstructed after the fact.

Evidence gathered for Decree 137 cross-links to Electronic Transactions, trust-services, Data Law, and cybersecurity work already on the platform, so public-sector teams don't duplicate proof they've already produced elsewhere.

Supporting records are presented as ComplianceOne working documents rather than government forms, keeping teams from submitting an internal template as if it carried official appendix-form status.