DPO Radio

Decree 137/2024/NĐ-CP has applied since 23 October 2024 to electronic transactions of state agencies and the information systems that support them. It sits beneath Vietnam’s Electronic Transactions Law.
This is a scoped public-sector overlay. Direct use is relevant to state agencies, public-service portal operators, state electronic-transaction system operators, and suppliers operating those systems. Other organizations can retain it for reference.
Operational readiness depends on more than a policy. Teams need an accountable inventory of systems and integrations, evidence of electronic record exchange, security and continuity records, and reviewable audit trails.
Decree 137/2024/NĐ-CP, issued by the Government of Vietnam and effective 23 October 2024, implementing the Law on Electronic Transactions for the public sector.
State agencies, state e-transaction systems, public-service portals, integration operators, and relevant suppliers.
Ownership, purpose, users, connected databases, exchanged records, classification, and safeguards.
Creation, sending, receipt, processing, integrity, timestamps, signatures, and status evidence.
Authority, purpose, interfaces, authentication, data fields, transmission, and reconciliation.
Six organization-prepared assessments, inventories, exchange, integration, audit, and dossier records.
Optional; direct after public-sector scope confirmation, or reference-only.

Teams can assign ownership for each state e-transaction system and connect system, data, integration, security, incident, and continuity evidence. Transaction records preserve accountable creation-to-processing history.
Cross-links reuse applicable Electronic Transactions, trust-services, Data Law, cybersecurity, digital-transformation, identity, and state-database evidence without duplicating specialist obligations.
Decree 137 declares no trust regime of its own. Where a state e-transaction depends on a certificate, a signature check, or a filing to an authority, that evidence is held under the regime an installed instrument declares (Decree 23 for trust services, Decree 69 for regulated electronic identity) and cross-linked to the system record here. A credential carries its issue, suspension, revocation, and expiry history as events, so the question of what was valid on the day a transaction was signed is read from a timeline. ComplianceOne records that a filing was made, with the payload hash and the receipt returned; it transmits nothing and signs nothing.
Maps systems, exchanged records, databases, interfaces, and accountable owners.
Explore Data MappingStructures supporting system, exchange, integration, and audit records.
Explore Compliance FormsAssigns reviews, exceptions, remediation, and evidence collection.
Explore Task Management


System ownership, integration details, and record-exchange evidence for a state e-transaction system live in the same workspace, so an audit or incident review starts from one accountable source instead of being reconstructed after the fact.

Evidence gathered for Decree 137 cross-links to Electronic Transactions, trust-services, Data Law, and cybersecurity work already on the platform, so public-sector teams don't duplicate proof they've already produced elsewhere.

Supporting records are presented as ComplianceOne working documents rather than government forms, keeping teams from submitting an internal template as if it carried official appendix-form status.
See how ComplianceOne connects state e-transaction systems, integrations, records, safeguards, and audit evidence.

No. It is primarily public-sector and government-facing. Direct use is appropriate where an organization operates or supplies an in-scope state electronic-transaction system; otherwise reference-only use is available.
It is an implementing overlay beneath the Electronic Transactions Law. ComplianceOne links the records while retaining the legal relationship between them.
The verified Gazette text contains no prescribed numbered appendix forms. The included records support operational evidence and are not presented as government forms.
Yes, where their contracted work directly supports state electronic transactions or the relevant systems. Scope and responsibility should be confirmed before direct installation.
No. It helps teams prepare and review evidence, preserve approvals, and record verified authority interactions under customer control. A filing made electronically is recorded after the fact; which channel carried it, the hash of the payload sent, the receipt that came back, and any later amendment, which never overwrites the original. There is no transmission, and putting the organization's name on a filing record is a separate permission from maintaining the register.

Test system inventory, record exchange, integration, and audit evidence for one in-scope service.

Review public-sector scope, systems, integrations, ownership, and supporting evidence.