DPO Radio

The State Secrets Protection Law 117/2025/QH15 was passed by the National Assembly of Vietnam on 10 December 2025 and took effect on 1 March 2026. It is the parent instrument for classifying, handling, and protecting state-secret information, and it is scope-triggered rather than universal: it applies directly to public-sector bodies, state-owned or state-linked entities, critical infrastructure operators, contractors handling state-secret information, regulated-sector vendors, and organizations that process state-secret-classified data or documents. It is not a general privacy framework and must not be installed universally.
Decree 63/2026/NĐ-CP, issued by the Government on 28 February 2026 and effective the same day as the parent law, sits beneath it as the active implementing decree. It supplies the operational layer, classification determinations, reproduction and transfer records, and the incoming/outgoing registers, and is the only instrument in this stack that carries verified official forms.
Because both the classification content and the six official Decree 63 registers are restricted by nature, this page and its ordinary customer views describe evidence and workflow support only. Sensitive operational or cryptographic detail is never published here. Structured ownership, evidence, and review help teams demonstrate what was assessed, who approved it, and how related frameworks were considered. ComplianceOne supports that operational work without providing legal advice or guaranteeing compliance.
Law 117/2025/QH15 on State Secrets Protection, passed 10 December 2025, effective 1 March 2026, classification, access, and lifecycle handling of state-secret information.
Decree 63/2026/NĐ-CP implementing the State Secrets Protection Law, issued 28 February 2026, effective 1 March 2026.
Public-sector and state-linked entities, critical infrastructure, contractors, and vendors handling classified material.
eKYC, biometrics, verification, matching, exceptions, access, and retention.
Restricted classification, inventory, authorization, storage/transmission, copy/transfer/destruction, incident-response, and vendor-readiness records.
Six verified Decree 63 registers and records, restricted, role-controlled, and never customer-facing. No verified official form is prescribed by the parent law itself.
Active optional security overlay, installed as reference-only until a documented activity-scope assessment confirms direct applicability.
The State Secrets framework consists of the parent law establishing legal obligations and an implementing decree that sets out how those obligations are applied in practice.
Decree 63 is the operational layer beneath the State Secrets Law. It governs how classification is determined and documented, and it carries the six verified official records and registers in this stack: the classification determination record, the reproduction record, the copying/reproduction register, and the outgoing, incoming, and transfer registers. Every one of these artifacts is restricted, role-controlled, and kept out of ordinary customer-facing views.

ComplianceOne holds the state-secret applicability assessment, inventory, and classification record as governed, access-restricted evidence rather than exposed content, who assessed scope, what was classified, and who approved the decision, without displaying the protected material itself inside the platform.
For Decree 63, the platform brings the six restricted official registers and records into role-controlled workspaces alongside the nine internal lifecycle templates, the applicability assessment, inventory, classification record, authorized-personnel record, storage/transmission record, copy/transfer/destruction record, incident-response record, vendor/contractor readiness record, and dossier checklist. Authority-issued artifacts keep their official identifiers (Phụ lục I, II, and III) and stay clearly distinguished from platform-prepared working documents.
Loss or disclosure incidents route through an escalated response workflow, and contractor and vendor readiness is evidenced against documented authority, personnel, handling, and exit controls. Where state-secret controls overlap core/important-data classification or cybersecurity work, ComplianceOne cross-links the same underlying evidence without treating the classifications as equivalent.
Enforces need-to-know access and keeps authorization decisions tied to accountable, role-restricted owners.
Explore Access & AccountabilityPreserves classification, access, transfer, and destruction history for restricted records without exposing their content.
Explore Audit TrailRuns the escalated loss-or-disclosure response workflow and keeps detection, impact, and remediation evidence together.
Explore Incident OperationsAssigns ownership and recurring review across the classification, contractor, and cross-link obligations.
Explore Program Governance


Status and scope remain visible throughout the workflow, helping teams distinguish State Secrets obligations from supporting records and related activities.

Authority-issued documents and platform-prepared evidence retain clear source labels, separating official requirements from internal compliance records.

Contributor, reviewer, approval, and evidence history stay connected throughout the workflow, preserving a complete audit trail for governance and accountability.
See how ComplianceOne helps structure evidence, ownership, and review for this framework.

No. It is scope-triggered for organizations that handle state-secret-classified information or documents.
No. The content remains focused on evidence readiness and avoids unsupported or operationally sensitive examples.
Verified Decree 63 registers, records, and stamps are restricted to authorized, non-customer-facing views.
No. It adds a classified-information overlay and cross-links cybersecurity and data-security work.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.