DPO Radio

AesirX ComplianceOne | Vietnam State Secrets Law

Overview Image

Why the Vietnam State Secrets Law Matters

The State Secrets Protection Law 117/2025/QH15 was passed by the National Assembly of Vietnam on 10 December 2025 and took effect on 1 March 2026. It is the parent instrument for classifying, handling, and protecting state-secret information, and it is scope-triggered rather than universal: it applies directly to public-sector bodies, state-owned or state-linked entities, critical infrastructure operators, contractors handling state-secret information, regulated-sector vendors, and organizations that process state-secret-classified data or documents. It is not a general privacy framework and must not be installed universally.

Decree 63/2026/NĐ-CP, issued by the Government on 28 February 2026 and effective the same day as the parent law, sits beneath it as the active implementing decree. It supplies the operational layer, classification determinations, reproduction and transfer records, and the incoming/outgoing registers, and is the only instrument in this stack that carries verified official forms.

Because both the classification content and the six official Decree 63 registers are restricted by nature, this page and its ordinary customer views describe evidence and workflow support only. Sensitive operational or cryptographic detail is never published here. Structured ownership, evidence, and review help teams demonstrate what was assessed, who approved it, and how related frameworks were considered. ComplianceOne supports that operational work without providing legal advice or guaranteeing compliance.

What the Vietnam State Secrets Law Covers

Dimension

Coverage

Parent framework

Law 117/2025/QH15 on State Secrets Protection, passed 10 December 2025, effective 1 March 2026, classification, access, and lifecycle handling of state-secret information.

Active child instrument

Decree 63/2026/NĐ-CP implementing the State Secrets Protection Law, issued 28 February 2026, effective 1 March 2026.

Scope

Public-sector and state-linked entities, critical infrastructure, contractors, and vendors handling classified material.

Operational themes

eKYC, biometrics, verification, matching, exceptions, access, and retention.

Evidence

Restricted classification, inventory, authorization, storage/transmission, copy/transfer/destruction, incident-response, and vendor-readiness records.

Official forms

Six verified Decree 63 registers and records, restricted, role-controlled, and never customer-facing. No verified official form is prescribed by the parent law itself.

Status handling

Active optional security overlay, installed as reference-only until a documented activity-scope assessment confirms direct applicability.

The State Secrets Law Instrument Stack

The State Secrets framework consists of the parent law establishing legal obligations and an implementing decree that sets out how those obligations are applied in practice.

Law 117/2025/QH15 on Protection of State Secrets

Active Parent FrameworkThe State Secrets Law establishes the legal framework for classifying, protecting, handling, storing, transmitting, and disclosing state secrets, together with the responsibilities of organizations and individuals.

Decree 63/2026/NĐ-CP

Active Implementing Decree

Decree 63 is the operational layer beneath the State Secrets Law. It governs how classification is determined and documented, and it carries the six verified official records and registers in this stack: the classification determination record, the reproduction record, the copying/reproduction register, and the outgoing, incoming, and transfer registers. Every one of these artifacts is restricted, role-controlled, and kept out of ordinary customer-facing views.

Overview Image

How ComplianceOne Supports the State Secrets Law

ComplianceOne holds the state-secret applicability assessment, inventory, and classification record as governed, access-restricted evidence rather than exposed content, who assessed scope, what was classified, and who approved the decision, without displaying the protected material itself inside the platform.

For Decree 63, the platform brings the six restricted official registers and records into role-controlled workspaces alongside the nine internal lifecycle templates, the applicability assessment, inventory, classification record, authorized-personnel record, storage/transmission record, copy/transfer/destruction record, incident-response record, vendor/contractor readiness record, and dossier checklist. Authority-issued artifacts keep their official identifiers (Phụ lục I, II, and III) and stay clearly distinguished from platform-prepared working documents.

Loss or disclosure incidents route through an escalated response workflow, and contractor and vendor readiness is evidenced against documented authority, personnel, handling, and exit controls. Where state-secret controls overlap core/important-data classification or cybersecurity work, ComplianceOne cross-links the same underlying evidence without treating the classifications as equivalent.

Related Modules

Access & AccountabilityAccess & Accountability

Enforces need-to-know access and keeps authorization decisions tied to accountable, role-restricted owners.

Explore Access & Accountability

Audit TrailAudit Trail

Preserves classification, access, transfer, and destruction history for restricted records without exposing their content.

Explore Audit Trail

Incident OperationsIncident Operations

Runs the escalated loss-or-disclosure response workflow and keeps detection, impact, and remediation evidence together.

Explore Incident Operations

Program GovernanceProgram Governance

Assigns ownership and recurring review across the classification, contractor, and cross-link obligations.

Explore Program Governance

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconSensitive records are mixed with ordinary compliance evidence.
IconRestrict sensitive artifacts to authorized roles.
IconAccess and disclosure decisions lack controlled lineage.
IconPreserve classification, access, and disclosure history.
IconIncident readiness may expose inappropriate operational detail.
IconCoordinate evidence readiness without publishing classified examples.
IconClassification decisions become difficult to verify over time.
IconMaintain an auditable record of classification reviews and approvals.
IconAuthority requests rely on fragmented records and manual evidence collection.
IconOrganize authority-response evidence without exposing protected information.

Built for State Secrets Law Compliance Operations

Build For Image

Status and scope remain visible throughout the workflow, helping teams distinguish State Secrets obligations from supporting records and related activities.

Build For Image

Authority-issued documents and platform-prepared evidence retain clear source labels, separating official requirements from internal compliance records.

Build For Image

Contributor, reviewer, approval, and evidence history stay connected throughout the workflow, preserving a complete audit trail for governance and accountability.

Background Image

See Vietnam State Secrets Law Compliance in Action

See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

No. It is scope-triggered for organizations that handle state-secret-classified information or documents.

No. The content remains focused on evidence readiness and avoids unsupported or operationally sensitive examples.

Verified Decree 63 registers, records, and stamps are restricted to authorized, non-customer-facing views.

No. It adds a classified-information overlay and cross-links cybersecurity and data-security work.

Direct use requires confirmed scope; other users should treat it as reference-only.

Next Steps

Icon Image

Start a Compliance Pilot

Test scoped workflows, evidence, and review with your compliance team.

Icon Image

Discuss Your Compliance Needs

Review applicability, evidence sources, and operating-model requirements.