|
GOVERNMENT OF VIETNAM
-------
|
SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------
|
|
No. 165/2025/ND-CP
|
Hanoi, June 30, 2025
|
DECREE
ELABORATING ON LAW ON DATA
Pursuant to the Law on
Government Organization dated February 18, 2025;
Pursuant to the Law on
Data dated November 30, 2024;
At the request of the
Minister of Public Security of Vietnam;
The Government of
Vietnam hereby promulgates the Decree elaborating on the Law on Data.
Chapter
I
GENERAL
PROVISIONS
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
This Decree provides for
Clause 3 Article 13, Clause 5 Article 14, Clause 5 Article 15, Clause 3 Article
16, Clause 4 Article 17, Clause 4 Article 18, Clause 3 Article 20, Clause 5
Article 21, Clause 5 Article 22, Clause 4 Article 23, Clause 5 Article 25,
Clause 4 Article 26, Clause 4 Article 27, Clause 3 Article 30, Clause 8 Article
31, Clause 5 Article 35, Clause 4 Article 36, and Clause 3 Article 37 of the
Law on Data and the construction, development, protection, administration,
processing, and use of data; assurance of resources for the operation of the
National Data Center; responsibilities of agencies, organizations, and
individuals relevant to data operations.
Article
2. Regulated entities
1. Vietnamese agencies,
organizations, and individuals.
2. Foreign agencies,
organizations, and individuals in Vietnam.
3. Foreign agencies,
organizations, and individuals directly participating in or involved in
operations concerning digital data in Vietnam.
Chapter
II
DATA
PROCESSING
Article
3. Criteria for determining important data
The determination of
important data shall be based on the potential impact of the data on national
defense and security, cipher, foreign affairs, macroeconomic situations, social
stability, and community health and safety upon illegal collection or use
(excluding state secrets), including:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2. Data that may pose a
dangerous impact on plans for developing foreign relations and/or affect
national interests and the security of international cooperation, Vietnam’s
overseas investment projects, energy security, and maritime security.
3. Data that may pose a
dangerous impact on the development and operation of macroeconomic situations,
key national economic sectors, total supply and demand of society, total
national economic value, unemployment rate, and fields concerning monetary,
trade, and import-export, as well as the supply of essential goods, products,
and services.
4. Data that may pose a
dangerous impact on the lives, health, honor, dignity, property, and legitimate
rights and benefits of agencies, organizations, and individuals; prevention and
control of epidemics; prevention, monitoring, and treatment of infectious and
occupational diseases, and food safety and hygiene; labor supply and provision
of public services.
Article
4. Criteria for determining core data
The determination of core
data shall be based on the direct dangerous impact of the data on national
defense and security, cipher, foreign affairs, macroeconomic situations, social
stability, and community health and safety upon illegal collection or use
(excluding state secrets), including:
1. Data that directly
poses a dangerous impact on national security, independence, sovereignty,
unity, and territorial integrity of the Fatherland and the protection of the
CPV, State, and great national unity bloc; protection of political security and
security in fields concerning ideology-culture, economy, national defense,
foreign affairs, information, society, natural resources, environment,
agriculture, biology, health, labor, construction, education, training, and
science and technology.
2. Data that directly
poses a dangerous impact on plans for developing foreign relations and/or
affects national interests and the security of international cooperation,
Vietnam’s overseas investment projects, energy security, and maritime security.
3. Data directly poses a
dangerous impact on the development and operation of macroeconomic situations,
key national economic sectors, total supply and demand of society, total
national economic value, unemployment rate, and fields concerning monetary,
trade, and import-export, as well as the supply of essential goods, products,
and services.
4. Data that directly
poses a dangerous impact on the lives, health, honor, dignity, property, and
legitimate rights and benefits of agencies, organizations, and individuals;
prevention and control of epidemics; prevention, monitoring, and treatment of
infectious and occupational diseases, and food safety and hygiene; labor supply
and provision of public services.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1. Data owners shall
stipulate specific storage periods for their collected or generated data.
2. State agencies shall
promulgated technical procedures for the storage of data under their
management, ensuring safe data storage.
3. The National Data
Center shall establish data storage services for the needs of data owners and
data governing bodies. Data owners and data governing bodies shall cooperate
with the National Data Center in developing implementation plans and roadmaps
based on specific data storage services.
Article
6. Data access and retrieval
1. Data access refers to
activities of approaching and interacting with data within the granted rights,
including read access, write access, edit access, delete access, execute
access, and other types of access as stipulated by the data owners or data
governing bodies.
2. Data retrieval refers
to activities of accessing and extracting data, including manual retrieval,
automatic retrieval, real-time retrieval, and other types of retrieval as
stipulated by the data owners or data governing bodies.
3. Principles of data
access and retrieval:
a) Ensure legality and
compliance with the procedures for data access and retrieval;
b) Ensure that data
access and retrieval are conducted within the granted rights and necessary for
the determined purposes.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a) Management of use
registration information;
b) Management of data
access and retrieval authorization;
c) Management of data
access and retrieval history;
d) Management of data
access and retrieval tools.
Article
7. Support for data owners in data connection and sharing for state agencies
State agencies shall
implement measures to support data owners in the data connection and sharing
for state agencies, including:
1. Development of
information systems to ensure data connection and sharing; protection and use
of data shared by data owners for the determined purposes.
2. Development of
procedures, applications, and software for data owners to exercise their rights
over the data provided for state agencies under the law.
3. Ministers, Directors
of ministerial agencies, Directors of governmental agencies, and Presidents of
the People’s Committees of provinces and centrally affiliated cities shall
decide on the support for data owners, including:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b) Financial support to
ensure connection and sharing; support to offset costs of data generation and
collection based on the norms of state agencies;
c) Personnel support for
data connection and sharing; support for training for personnel sources serving
data connection and sharing;
d) Other forms of
support.
Article
8. Provision of data for state agencies
1. Individuals and
organizations are encouraged to provide and share their data with state
agencies for purposes serving common benefits (e.g., healthcare, climate
change, and traffic improvement), facilitating the summary and universalization
of official statistics, and improving the provision of public services, public
policy planning, or scientific research.
Organizations and
individuals shall share and provide data voluntarily based on the consent of
the data subject matters to process their personal data or the permission of
data owners to use their non-personal data.
2. State agencies shall
request organizations and individuals to provide data according to Clause 2
Article 18 of the Law on Data as follows:
a) Prepare written
requests or other forms to ensure confirmation of the request for data
provision, specifying the data types, detail levels, data volume, data access
frequency, data provision method, legal ground, request reason, data use
purpose, use duration, data provision deadline, and expected data processing;
b) Issue notices to the
organizations or individuals subject to the data provision request of the
sanctions to be imposed if the request is not complied with.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a) The handover and
receipt of data shall be conducted according to the proper subject, time, data
type, detail level, data volume, data access frequency, and data provision
method as requested;
b) Participants in the
handover and receipt of data include the data owner, legal representative, or
legal data manager/user; individual or representative of the organization
assigned to manage and use the data;
c) The handover and
receipt of data shall be recorded in writing;
d) The party requesting
the data provision may request the data provider to supplement the data if the
handed-over data does not meet the scope of the requested data.
4. Cancellation of data
provision requests
a) A data provision
request shall be canceled in cases where the data provision request is contrary
to the Law on Data or other relevant laws; the data provision request has not
been implemented, but the conditions for data provisions prescribed in Clause 1
Article 18 of the Law on Data no longer exist; the data provision request has
not been implemented, but the data no longer exists due to objective reasons;
b) The cancellation of
any data provision request shall be recorded in writing.
5. Requests for revision
or withdrawal of data provision requests
a) Before the designated
deadline for data provision, the data owner, legal representative, or legal
data manager/user may request the competent authority to revise or withdraw the
data provision request;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6. Authority to request
data provision
Ministers, Directors of
ministerial agencies, Presidents of the People’s Committees of provinces and
centrally affiliated cities, the Director of the National Data Center, and
Directors of Police Authorities of provinces and centrally affiliated cities
may request data provision within their scope of tasks and entitlements.
Article
9. Data confirmation and authentication
1. Data confirmation
shall be carried out as follows:
a) Data collected and
updated to national databases, specialized databases, and other databases shall
be confirmed by the data owners and/or data governing bodies;
b) The confirmation of
data among state agencies and socio-political organizations shall be carried
out through cooperation regulations and specific data provision, sharing, and
connection methods;
c) Aside from the cases
prescribed in Points a and b of this Clause, data confirmation shall be carried
out under agreements between data users and data governing bodies, data owners,
or other organizations according to the law;
d) Data owners and data
governing bodies shall assume responsibility for the quality, reliability, and
legality of the data (provided or confirmed by them), develop data confirmation
procedures and forms, and organize data confirmation activities.
2. Data owners and data
governing bodies shall develop data confirmation procedures and forms and
organize the confirmation of data under their management and ownership.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4. Data confirmation and
authentication shall be carried out in compliance with electronic
authentication laws and relevant laws.
Article
10. Data disclosure
1. The disclosure of open
data shall be carried out immediately after the data is classified as open
data. Data owners and data governing bodies shall disclose open data through
the following means:
a) National Data Portal;
b) Open data portals, web
portals of ministries, central authorities, local authorities, and other
systems and platforms;
c) Intermediary systems
for data connection and sharing or other forms as prescribed by the law.
2. State agencies shall
announce the list of open data, disclose open data under their management, and
send them to the Ministry of Public Security of Vietnam for summary and
publication on the National Data Portal.
3. Data of state agencies
not prohibited from being disclosed for reasons related to national security,
privacy rights, trade secrets, or other reasons as prescribed by the law shall
be disclosed as open data.
4. State agencies shall
develop and implement open data disclosure decisions, determining the list of
disclosed open data and mechanisms for collecting and analyzing feedback from
individuals and organizations on the use of open data. They shall also assess
the quality, usability, and compliance with laws concerning open data.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1. Agencies,
organizations, and individuals may use one or more encryption solutions and
encryption and decryption processes in conformity with their data
administration and management, including:
a) Data encryption
solutions during data transmission;
b) Data encryption
solutions during data storage;
c) Data encryption
solutions on digital devices;
d) Hardware security
solutions to prevent unauthorized access and ensure that encryption/decryption
operations are only performed in safe environments;
dd) Decryption processes
requiring identity authentication of the person performing the data decryption,
determination, and authorization of access to the encrypted data;
e) Solutions to record
encryption and decryption activities, ensuring legality, transparency, and
fairness and serving lookup capability;
g) Other solutions and
processes as prescribed by the law.
2. The Minister of Public
Security of Vietnam shall decide or delegate the decision to apply data decryption
solutions to cases prescribed in Clause 4 Article 22 of the Law on Data without
requiring consent from data owners or data governing bodies, excluding cases
concerning military or national defense.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article
12. Cross-border data transfer and processing
1. Any data owner or data
governing body that wishes to transfer or process core or important data across
borders shall conduct an impact assessment as prescribed in Clause 2 of this
Article.
The impact assessment for
the transfer of core or important data abroad or to a foreign organization or
individual shall be carried out once for the entire operational duration of the
organization or enterprise and updated and supplemented as specified in Clause
8 of this Article.
2. The transferring party
shall assess the impact based on the following:
a) Legality, necessity,
scope, data transmission methods, and data processing methods of the receiving
party;
b) Risks that the data
transfer may pose to national defense, security, economic activities, foreign
affairs, social stability, public benefits, or legitimate rights and
benefits of organizations or individuals; risks of data being forged,
destroyed, leaked, lost, or misused;
c) Responsibilities,
obligations, and managerial and technical measures of the receiving party;
d) Other relevant issues.
3. The written agreement
between the transferring party and the receiving party shall determine:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b) Data storage location,
period, and data processing methods after the storage period or the completion
of the agreed objectives;
c) Binding requirements
for the receiving party regarding the provision of the transferred data to a
third party;
d) Measures to protect
the data to be used by the receiving party;
dd) Remedial measures,
compensation for damage, contractual violation handling, and measures to settle
disputes for violations of data protection obligations;
e) Responsibilities of
the concerned parties in data processing.
4. A dossier on
assessment of the impact of cross-border data transfer or processing includes
an impact assessment report on the cross-border data transfer or processing
(following Form No. 02 enclosed with this decree) and relevant documents.
5. Where the data
transferred or processed abroad is core data:
a) The transferring party
shall send the dossier on assessment of the impact of cross-border data
transfer or processing to the Ministry of Public Security of Vietnam or the
Ministry of National Defense of Vietnam if it concerns military, national
defense, or cipher;
b) The unit in charge of
the Ministry of National Defense of Vietnam or the Ministry of Public Security
of Vietnam shall receive the dossier and inspect its adequacy and validity.
Where the dossier is inadequate, the unit shall request the transferring party
to supplement and complete the dossier;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d) The transferring party
shall receive a written notice of the assessment results. After receiving a
qualified assessment result, the data governing body shall issue a decision on
the transfer of core data abroad or cross-border data processing.
6. Where the data
transferred or processed across borders is important data:
The transferring party
shall prepare a dossier on impact assessment before cross-border data transfer
or processing in service of the inspection and assessment of the Ministry of
Public Security of Vietnam or the Ministry of National Defense of Vietnam if
necessary (without requiring approval from a competent authority).
The transferring party
shall send 1 original copy of the dossier to the Ministry of Public Security of
Vietnam or the Ministry of National Defense of Vietnam following the form
enclosed with this Decree 15 days before the data processing.
7. The impact assessment
of the competent authority shall focus on the potential risks the cross-border
data transfer or processing may pose to national security, public benefits, or
legitimate rights and benefits of specific organizations or individuals,
including:
a) Legality and necessity
of the purposes, scope, and methods of data transfer or processing;
b) Impacts of policies
and regulations on data protection and cybersecurity environment of the nation
or region of the receiving party regarding the confidentiality of data; data
protection levels of the receiving party compared to the applicable Vietnamese
technical regulations and standards;
c) Scale, scope, data
types, and risks of data being forged, destroyed, leaked, lost, or illegally
transferred or used after the transfer;
d) Responsibilities and obligations
of the concerned parties;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
8. The transferring party
shall revise and supplement the dossier on assessment of the impact of
cross-border data transfer or processing in the following cases:
a) Upon changes to the
purpose, method, scope, and type of data to be transferred or processed and/or
changes to the purpose or method of data processing of the receiving party,
impacting data security; upon prolonged storage of core or important data;
b) Upon changes to policies
and regulations on data protection and cybersecurity environment in the nation
or region of the receiving party, changes to the actual control rights of the
transferring or receiving party, and other impacts on the confidentiality of
the transferred data.
9. The Ministry of
National Defense of Vietnam or the Ministry of Public Security of Vietnam shall
request the transferring party to cease their transfer or processing of core or
important data in the following cases:
a) The core or important
data transferred or processed across borders is used for activities that
infringe on national defense, security, national benefits, public benefits, and
legitimate rights and benefits of the data subject matter or data owner
according to the law of Vietnam and international treaties to which the
Socialist Republic of Vietnam is a signatory.
b) The transferring party
fails to comply with this Article;
c) Upon violations of
regulations on data protection.
10. The quantification of
core or important data upon cross-border data transfer or processing shall be
determined based on the accumulated volume of data transferred or processed
across borders, starting from July 1, 2025 until the time of data transfer or
processing.
11. Cases where approval
from competent authorities is not required for cross-border core data transfer
or processing according to Clause 5 of this Article and cases where notices to
competent authorities are not required for important data transfer or
processing according to Clause 6 of this Article:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b) Upon cross-border
personnel management based on the specific labor principles or regulations and
collective labor agreements according to the law;
c) Where it is necessary
to provide data to conclude or execute a contract, including cases where the
contract is relevant to cross-border transport, logistics, money transfer,
payment, opening of bank and hotel accounts, visa application, and inspection
services.
12. Regarding core or
important data transfer or processing under Clause 11 of this Article, an
impact assessment must be sent to the Ministry of Public Security of Vietnam
(or the Ministry of National Defense of Vietnam for data under its management)
according to Clause 4 of this Article 15 days after implementation.
Article
13. Other operations in data processing
1. Data revocation,
deletion, and destruction
a) Data revocation refers
to the act of requesting the return of data and deletion and/or destruction of
the provided data or requesting the cessation of the data processing or use
where deletion or destruction is not possible.
Data deletion refers to
the removal of data from the structure or environment in which it is
stored.
Data destruction refers
to the removal of data from the structure or environment in which it is stored,
ensuring that it cannot be restored using methods such as overwriting or
physical destruction.
b) Data deletion and
destruction shall be carried out within 72 hours after receiving a request from
the data subject matter, and the notice of the results of the data revocation,
deletion, or destruction is sent to the data owner unless otherwise prescribed
by laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Chapter
III
DATA
ADMINISTRATION, MANAGEMENT, AND PROTECTION
Article
14. Data administration and management
1. The Ministry of Public
Security of Vietnam shall promulgate a general data administration and
management framework for common application by state agencies involved in data
connection and sharing with the National Data Center.
2. Database management
agencies involved in data connection and sharing with the National Data Center
shall develop detailed data administration and management framework applicable
to data under their management, ensuring conformity with the general data administration
and management framework promulgated by the Ministry of Public Security of
Vietnam.
3. A detailed data
administration and management framework shall include:
a) Mechanisms for
managing master data and general list codes;
b) Mechanisms for managing
data processing; plans for data expansion and backup storage;
c) Assessment of data
quality; application of technical regulations and standards on data quality and
data connection and sharing;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
dd) Data architecture and
data models;
e) Connection and sharing
mechanisms;
g) Data protection
mechanisms;
h) Data development,
utilization, and use mechanisms;
i) Supervision, control,
and implementation mechanisms.
4. Management of master data
and general list data
a) Database management
agencies shall promulgate lists of master data and general list data based on
cooperation and agreement with the Ministry of Public Security of Vietnam;
b) Contents requiring
master data administration and management include identification code issuance
principles; basic information for describing, identifying, and distinguishing
specific entities in the master data; procedures for generating and updating
master data; selection of technologies and tools to ensure that master data is
collected, updated, utilized, and used accurately, consistently, and
adequately; generation, update, and management of master data; master data
connection and sharing with the National General Database; cooperation with the
Ministry of Public Security of Vietnam in supervision and reconciliation,
ensuring master data quality across the entire system;
c) The master data in
national databases and other databases of agencies assigned to generate and
manage master data shall hold official validity, equivalent to the written
documents provided by competent authorities
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
5. State agencies implementing
information technology projects concerning national databases and specialized
databases shall solicit opinions from the Ministry of Public Security of
Vietnam (National Data Center) on the construction, development, protection,
administration, processing, and use of data to prevent waste, ensuring
consistency and synchronization during implementation.
Article
15. Determination and management of risks arising during data processing
1. Types of risks arising
during data processing include:
a) Risks of privacy
rights, occurring due to non-compliance with the law on privacy rights of data
subject matters during data processing and transfer;
b) Risks of
cybersecurity, occurring due to failure to apply necessary measures to protect
data prohibited from disclosure from unauthorized access by external entities
or from being leaked;
c) Risks of
identification and access management due to failure to ensure the protection of
data prohibited from disclosure from unauthorized access;
d) Other risks during
data processing, including risks of data sharing (occurring due to the
inability to maintain control rights over the shared data) and risks of data
management (occurring due to poor data quality).
2. Measures to prevent
risks arising during data processing include:
a) Regular data backup
and data safety assurance;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c) Implementation of data
protection measures as per regulation;
d) Authorization of
access rights for each data type to prevent unauthorized access;
dd) Use of systems for
supervision and detection of intrusions to monitor network operations and
detect unusual acts or unauthorized access;
e) Installation and
maintenance of confidentiality software;
g) Implementation of
annual risk assessment to determine system vulnerabilities and apply respective
risk prevention measures;
h) Development of
incident handling schemes and plans to proactively and promptly respond and
remedy incidents;
i) Training and advanced
training in data protection skills, threat recognition, and handling methods
upon confidentiality risks; organization of regular drills for incident
prevention, supervision, detection, and timely response and remedy;
k) Other measures as
prescribed by the law.
Article
16. Data protection
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Data governing bodies not
subject to state agencies are encouraged to develop separate regulations on the
protection of data under their management.
2. The protection of core
and important data, being personal data, shall comply with the Law on Data and
this Decree.
In case of transferring
or processing core or important data across borders and managing and protecting
core or important data, being personal data, comply with Article 12 and Clause
11 Article 17 of this Decree without having to conduct an impact assessment
according to the law on personal data protection.
3. Any data governing
body providing or entrusting the processing of core or important data to an
organization or individual not prescribed in Article 12 of this Article shall:
a) Make an agreement with
the receiving party on the purpose, method, scope, and security protection
obligation through the contract and supervise the obligation implementation of
the receiving party; ensure that the dossier on important data processing
provided or entrusted to other receiving parties must be stored for at least 3
years;
b) When providing or
entrusting the processing of core or important data, conduct encryption,
provide digital signatures, and adopt other confidentiality measures to ensure
confidentiality, integrity, and non-repudiation;
c) Ensure that the party
receiving the core or important data fulfills the obligations of data
protection and processes the core or important data according to the agreed
purpose, method, and scope.
4. Data protection
measures include:
a) Managerial measures
concerning data processing, including the development of policies, regulations,
and criteria for assessing data safety and security to ensure compliance with technical
regulations and standards, regulations on data protection, and other managerial
measures according to the law;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c) Measures to manage
data protection personnel, including the development of regulations on
management and training for data protection personnel;
d) Other data protection
measures as prescribed by the law.
Article
17. Data protection management during processing
1. Data governing bodies
shall establish management systems for data protection throughout the entire
data processing.
2. Data governing bodies
shall adopt measures to protect data during data collection and generation. For
core and important data, data governing bodies shall:
a) Develop procedures for
data collection and generation and assess and apply protective measures before
data collection and generation;
b) Inspect authenticity,
supervise data quality, and retrieve data sources.
3. Data governing bodies
shall store data in compliance with the methods and periods prescribed by the
law. For core and important data, data governing bodies shall:
a) Develop procedures for
data storage, including procedures for data backup, recovery, and storage,
backup, and recovery logging;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c) Delete and destroy
data when the storage period expires or when the data is no longer necessary
for processing purposes.
4. During the processing
and use of core and important data, data governing bodies shall:
a) Develop and implement
mechanisms for access and data retrieval, ensuring compliance with the
principle of least privilege during data processing and use;
b) Develop data access
control systems, including consistent identification and access management platforms;
apply technical measures to protect data, control access, and retrieve data
during data processing and use.
5. Data governing bodies
shall define the scope, purpose, procedure, and development of regulations on
the protection and application of protective measures based on the
classification, level, purpose, and intended use of data provided outward.
6. Data owners shall
analyze and assess impacts on national defense, security, foreign affairs,
macroeconomic situations, social stability, and community health and safety
before disclosing the data.
7. Data owners and data
governing bodies shall develop schemes to delete and destroy data, specifying
the purposes, principles, procedures, and techniques for deleting, destroying,
recording, and storing deletion and destruction activities. Where the deletion
or destruction involves core or important data, the data governing bodies shall
provide written evidence that the deletion or destruction renders the data
irrecoverable.
8. Where data governing bodies
wish to transfer data due to reorganization, dissolution, or bankruptcy, they
shall specify the plans for data transfer and issue notices to the affected
agencies, organizations, and individuals.
In case of reorganization
or dissolution of organizations managing core or important data, the data
governing bodies shall apply measures to ensure data safety and submit reports
on schemes for data processing and names or information of the receiving
parties to relevant competent authorities.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
10. Governing bodies of
core or important data shall prepare data processing logs for the entire data
processing. The logs shall be retained for at least six months.
11. Governing bodies of
core or important data shall annually assess risks in the processing of core or
important data within their management scope and prepare and store risk
assessment reports following the form enclosed with this Decree, ensuring
availability of such reports to serve inspection and assessment by competent
authorities, excluding cases where dossiers on assessment of the impact of
cross-border data transfer or processing are already prepared according to
Article 12 of this Decree. A risk assessment report includes:
a) Basic information on
the data governing body, information on the data protection department, and
contact information of the data protection officer (DPO);
b) Purpose, type,
quantity, method, scope, storage period, storage location, data processing, and
data processing situation;
c) Data protection
management system, technical measures for encryption, backup, labeling, access
control, authentication, and other necessary measures;
d) Detected risks of data
safety, past data safety incidents, and solutions;
dd) Other reporting
contents according to regulations of relevant competent authorities.
Article
18. Personnel management and data protection personnel training and advanced
training
1. Data owners and
governing bodies of core and important data shall identify DPOs and data
protection departments.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3. Data protection
departments shall have the following functions and tasks:
a) Develop and implement
data protection management systems, operational procedures, and plans for
emergency responses to data protection incidents;
b) Periodically organize
and implement the supervision of data safety risks, risk assessments, emergency
drills, dissemination, education, training, and timely settlement of network
data safety risks and incidents;
c) Research and propose
decisions concerning the protection of core and important data;
d) Receive and handle
reports on data protection of specific units.
4. Data owners and
governing bodies of core and important data shall:
a) Specify requirements
for safety management in the recruitment, use, training, introduction,
transfer, resignation, assessment, and selection of personnel;
b) Refrain from
appointing persons with criminal records in information technology or
telecommunications networks as DPOs;
c) Concluding agreements
on confidentiality responsibility with data processing personnel.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6. DPOs may agree with
data owners or data governing bodies on conditions for exemption from
responsibilities for damage to the protected data.
Article
19. Data confidentiality supervision, early warnings, and emergency
management
1. Data confidentiality
supervision, early warnings, and emergency management include:
a) Establishment of
mechanisms for data safety risk supervision;
b) Preparation of draft
supervision standards and interfaces;
c) Development of
mechanisms for reporting and sharing information on data safety risks and
assurance of the consistency of the collection, analysis, assessment, and
reporting of information on data safety risks;
d) Development of plans
for responses to data safety incident emergencies.
2. The Ministry of Public
Security of Vietnam shall conduct confidentiality supervision, issue early
warnings, and manage data emergencies, excluding the contents prescribed in
Clause 3 of this Article.
3. The Ministry of
National Defense of Vietnam shall conduct confidentiality supervision, issue
early warnings, and manage emergencies concerning data under its management.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a) Promptly issue notices
to data owners concerning data safety incidents that may potentially damage the
legitimate rights and benefits of specific organizations and individuals and
propose measures to minimize damage;
b) After any data safety
incident, promptly execute emergency responses according to emergency response
plans and submit reports on confidentiality incidents concerning core and
important data to the Ministry of Public Security of Vietnam or the Ministry of
National Defense of Vietnam as soon as possible.
5. The Ministry of Public
Security of Vietnam shall establish mechanisms for supervising data safety
risks, develop standards concerning supervision and early warnings concerning
data safety, cooperate in developing technical equipment for supervision and
early warnings concerning data safety, and strengthen the capacity for
supervision, early warning, processing, origin tracing, and intensification of
information sharing with relevant departments.
Data governing bodies
shall supervise data safety risks, promptly investigate potential security
risks, and adopt necessary measures to prevent data safety risks.
6. The Ministry of Public
Security of Vietnam shall develop mechanisms for reporting and sharing
information on data safety risks, ensure consistent collection, analysis,
assessment, and reporting of information on data safety risks, and encourage
confidentiality service providers and scientific research organizations to
share information on data safety risks.
Data governing bodies
shall summarize and separately analyze data confidentiality risks within their
management scope and report potential risks of major confidentiality incidents
to the Ministry of Public Security of Vietnam.
7. The Ministry of Public
Security of Vietnam shall develop emergency response plans for data safety
incidents, including the organizational structure and responsibilities for
emergencies, classification of data safety incidents, supervision and early
warnings, procedures for responding to emergencies, and protective measures,
and organize and cooperate in responses to incidents concerning the safety of
core and important data.
8. Data governing bodies
shall organize backup plan drills for incidents concerning the safety of
core/important data once every 6 months, store drill dossiers, prepare summary
reports on the drills, and promptly update backup plans based on major changes
to data processing systems or the external environment.
Chapter
IV
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article
20. Infrastructures of National Data Center
1. The information system
of the National Data Center shall be separated from the development,
inspection, and testing system. It shall also ensure level-based security and
confidentiality to control, detect, and prevent risks of losing information
safety and security.
2. The National Data
Center shall construct and develop cloud computing infrastructures and
implement functional zones to serve the needs of state agencies, ensuring the
development of integrated and synchronized subsystems, data utilization, and
high requirements for information confidentiality.
3. The National Data
Center shall establish high-capacity calculation infrastructures and data
analysis systems serving the management of predictive analysis models in
service of utilization operations from the National General Database. It shall
also provide the technical conditions necessary to support applied mathematics
research and development, as well as assist in developing mechanisms, policies,
plans, and strategies related to national development and data-related products
and services for socio-economic development.
4. The National Data
Center shall establish a National Data Portal as the focal point for state
agencies to announce information on data types under their management and to
announce and provide open data, thereby enhancing transparency in the
Government of Vietnam’s operations and promoting creativity and socio-economic
development. It shall also enable organizations and individuals to provide data
for objectives concerning common benefits, improvement of public service
provision, public policy making, or scientific research for common
benefits;
5. The National Data
Center shall develop applications on digital devices to facilitate the
utilization and use of its data, provide data-related products and services,
and develop other utilities serving agencies, organizations, and individuals.
6. The National Data
Center shall develop contact systems with individuals and organizations serving
its operations.
7. The National Data
Center shall provide the following services:
a) Services concerning
station infrastructures, server colocation, provision of physical spaces for
the server locations, power systems, air conditioning, and other relevant
devices to implement database information systems, permitting database
governing bodies, agencies, and organizations to proactively use and control
their systems, either in shared or dedicated spaces, in compliance with
regulations on the management and operation of the National Data Center;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c) Services concerning
the implementation and operation of technical infrastructures serving national databases,
database information systems, and other databases and information systems.
8. State agencies and
socio-political organizations shall determine the types of services provided by
the National Data Center as prescribed in Clause 7 of this Article, ensuring
conformity with the current situation, professional requirements, and
regulations on investment in state budget-funded information technology
projects. They shall also send written requests to the National Data Center
providing the services. The written requests shall specify the needs for the
services of the National Data Center, the scale of the systems to be placed at
the National Data Center, and the needs for personnel supporting the
administration and operation of infrastructures and information systems.
9. The Minister of Public
Security of Vietnam shall provide guidelines on the provision and
implementation of the National Data Center's services when infrastructure
conditions are deemed sufficient.
Article
21. Responsibilities of National Data Center
1. Provide guidelines for
agencies, organizations, and individuals on the application of technical
regulations and standards on data within a scope of synchronization with the
National Data Center.
2. Adopt measures to
supervise and assess the quality of data shared or synchronized with the
National Data Center.
3. Regulate the data of
the National General Database.
4. Adopt data protection
measures from the start and throughout data processing in compliance with
Clause 6 Article 16 of this Decree.
5. Conclude agreements
and/or memorandums of understanding with international agencies and
organizations to promote international cooperation in management, data
protection, scientific research, cross-border data transfer, training, and
improvement of capacity and qualification concerning data-related content to
promote innovation and technology transfer in service of socio-economic
development.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article
22. Assurance of resources for construction and development of National Data
Center
1. The National Data
Center shall develop plans and programs on training, international cooperation,
and personnel quality improvement.
2. Officials and officers
working at the National Data Center shall be entitled to a support allowance of
500.000 VND per working day, funded by revenues from the fees for utilization
and use of data in the National General Database after they are transferred to
the state budget.
Organizations and public
service providers of the National Data Center may utilize the support
allowances above to decide on the allowances for data specialists.
3. The Minister of Public
Security of Vietnam shall promulgate a list of job positions in the National
Data Center, as well as mechanisms for attracting, utilizing, and providing
incentives for high-quality personnel working at the National Data Center.
Article
23. Utilization and use of National General Database
1. Utilization through
direct connection and sharing of information with the National General Database
a) The National Data
Center shall issue accounts to agencies and organizations to access and utilize
information in the National General Database;
b) Agencies and
organizations issued with accounts by the National Data Center shall create and
manage separate accounts on their information systems connected to the National
General Database and authorize the use of the created accounts to individuals
under their management according to the assigned functions and tasks;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d) The information
systems of agencies and organizations shall send requests for information
utilization to the National General Database through the accounts issued by the
National Data Center. The results of the utilization shall be presented in
physical or electronic form and stored in the information systems connected for
information sharing and utilization;
dd) The National Data
Center shall inspect and verify account information and return the utilization
results as requested in conformity with the entitlements and scope of
information permitted for the utilization of the accounts.
2. Agencies,
organizations, and individuals shall utilize information in the National
General Database through the National Data Portal or the National Public
Service Portal at the National Data Center or by using specific devices,
equipment, and software following the guidelines of the Ministry of Public
Security of Vietnam.
3. Agencies,
organizations, and individuals shall utilize information in the National
General Database through web portals and information systems for settlement of
administrative procedures following the guidelines of ministries, ministerial
agencies, governmental agencies, and People’s Committees of provinces and
centrally affiliated cities.
4. Utilization by written
requests for information utilization and provision
a) Agencies,
organizations, and individuals shall prepare and send written requests for utilization
and provision of information in the National General Database to the National
Data Center;
b) A written request for
utilization and provision of information must specify the purpose, content,
scope of the requested information in the National General Database, and
commitment to assume responsibility during the use of information permitted for
utilization and other information;
c) Within 3 working days
from the receipt of written requests for utilization of information in the
National General Database, competent persons shall assess and decide on the
permission for information utilization;
d) In case of permitting
the information utilization, competent persons shall issue written responses
and provide information for agencies, organizations, and individuals. In the
event of refusal to permit the utilization of information, competent persons
shall provide written responses and explanations.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a) Automatically
implement administrative procedures, benefits, and policies for individuals and
organizations when the information and data serving the assessment and
settlement of administrative procedures is adequate in the National General
Database. Competent authorities and persons shall proactively settle
administrative procedures, benefits, and policies for individuals and
organizations based on the information and data connected, shared, and utilized
from the National General Data Base and the consent of the individuals and
organizations;
b) Reutilize/reuse data
and develop concentrated online public services on the National Public Service
Portal, ensuring simplicity, consistency, user-friendliness, thrift, and
effectiveness;
c) Connect and share data
between the National General Database and the ministerial and provincial
information systems for settlement of administrative procedures serving the
receipt and settlement of administrative procedures for organizations and
individuals, ensuring that individuals and organizations are not required to
declare or provide information and papers available in the National General
Database; adequately synchronize data on dossier digitalization and results of
the settlement of administrative procedures from the ministerial and provincial
information systems for settlement of administrative procedures, national
databases, and the National General Database in service of the data
reutilization/reuse, ensuring that individuals and organizations only provide
information, data, and papers once for state agencies during the implementation
of administrative procedures and public services.
Article
24. Data connection and sharing with National General Database
1. The governing bodies
of state agencies' databases, when developing databases with connections to the
National Data Center, shall comply with the guidelines of the National Data
Center to ensure data connection and sharing.
2. The National Data
Center and database management agencies shall develop agreements on data
connection and sharing, including:
a) Purposes of data
sharing;
b) Scope of data to be
shared;
c) Methods for data
connection and sharing;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
dd) Other relevant
contents.
3. Data sharing methods
a) Data sharing among
state agencies’ databases shall be carried out through the data sharing and
regulation platform of the National Data Center and other data sharing and
integration platforms;
b) Data sharing between
organizations/individuals and the National General Database shall be carried
out through the data sharing and regulation platform, data portals, files, and
other methods under agreements among the concerned parties.
4. The National Data
Center shall supervise data sharing through its supervision system to assess
the provision and use of data.
Article
25. Provision of data for National General Database
1. Organizations and
individuals that are not state agencies providing data for the National General
Database through agreements with the National Data Center or written agreements
on data provision shall specify the data provision purposes, scope of the data
to be provided, methods of data provision, and time and frequency of the
provision and other relevant contents.
2. Responsibilities of
database management agencies in the provision of data for the National General
Database
a) Synchronize data for
the National General Database according to Clause 1 Article 34 of the Law on
Data;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c) For other data types,
conduct the synchronization upon adjustments or updates according to agreements
with the National Data Center.
3. The National Data
Center shall cooperate with database management agencies in adopting
appropriate technical measures to ensure that any changes to the master data
are reflected across all related reference databases through respective
synchronization.
Chapter
V
RESPONSIBILITIES
OF AGENCIES AND ORGANIZATIONS
Article
26. Responsibilities of Ministry of Public Security of Vietnam
1. Take charge and
cooperate with relevant agencies in implementing, instructing, inspecting, and
urging the implementation of this Decree.
2. Take charge and
cooperate with relevant agencies in managing the construction, development,
protection, administration, processing, and use of data; ensure data security
and combat crimes and law violations concerning data; manage, monitor, and
supervise business operations involving data-related products and services in
compliance with this Decree.
3. Take charge and cooperate
with relevant agencies in constructing the National Data Center in accordance
with applicable regulations, technical standards, and regulations on data
centers.
4. Develop, promulgate,
or issue requests to competent state authorities for promulgation and provide
guidance on the implementation of legislative documents guiding the
implementation of data laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6. Organize data
connection, sharing, and regulation between information systems/databases of
agencies, organizations, and individuals and the National General Database
through the data sharing and regulation platform of the National Data Center.
7. Ensure information
technology infrastructures for agencies of the CPV, the State, and
socio-political organizations serving the management, administration, and
processing of data under their management at the National Data Center.
8. Take charge and
cooperate with the Ministry of Science and Technology of Vietnam in appraising,
assessing, inspecting, and supporting the supervision and regulation in
response to incidents concerning cybersecurity and information safety during
the development, implementation, and operation of information systems and
databases at the National Data Center.
9. Take charge and
cooperate with the Ministry of Science and Technology of Vietnam in developing
technical regulations, standards, or guidelines on the organization,
connection, sharing, and synchronization of data with the National Data Center.
10. Develop structural
standards of the software system at the National Data Center.
11. Provide guidelines
for the data classification of agencies of the CPV, the State, and
socio-political organizations; organize and direct professional training and
advanced training in data nationwide.
12. Develop and operate
the National Data Portal.
13. The Minister of
Public Security of Vietnam shall decide on expenditures on financial support
for ensuring connection and sharing; provide support for offsetting the costs
of data collection and generation based on consensus with the Minister of
Finance of Vietnam and the Minister of Science and Technology of Vietnam.
Article
27. Responsibilities of Ministry of National Defense of Vietnam
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2. Cooperate with the
Ministry of Public Security of Vietnam and relevant agencies and organizations
in arranging appropriate forces and equipment to remotely detect and prevent
acts of infringement on the National Data Center, both geographically and
online.
3. Take charge of the
data storage, protection, and security assurance; manage, monitor, supervise,
and implement data connection, sharing, and regulation among information
systems and databases; apply science to the processing, management,
utilization, and use of data; manage and license data transfer abroad; use national
data development funds for data types under the management of the Ministry of
National Defense of Vietnam.
Article
28. Responsibilities of Ministry of Science and Technology of Vietnam
1. Provide guidelines for
agencies of the CPV, the State, and socio-political organizations on the
development and completion of information technology technical infrastructures
and the development of technical regulations and standards concerning data
organization, connection, sharing, and synchronization; conduct standardization,
connection, and sharing of data and optimal calculation between investing in
new infrastructures and using infrastructures provided by the National Data
Center.
2. Review and assess the
capacity of specialized data transmission networks of agencies to develop
schemes for upgrades, ensuring that all units can access and administer the
systems located at the National Data Center via the specialized data
transmission networks.
3. Cooperate with the
Ministry of Public Security of Vietnam and relevant agencies in researching,
mastering, and applying digital technologies and data to form products and
services that support the advancement of digital government, digital authority,
and socio-economic development through key scientific and technological programs
at the national level.
4. Cooperate with the
Ministry of Public Security of Vietnam in determining expenditures on financial
support for ensuring connection and data; provide support for offsetting the
costs of data generation and collection.
Article
29. Responsibilities of the Office of the Government of Vietnam
1. Develop requirements
for functionality, operation, and interface; support and instruct ministries,
central authorities, and local authorities to handle issues concerning
functions, professional procedures, and data of the National Public Service
Portal; cooperate with the Ministry of Public Security of Vietnam in
administering and operating the National Public Service Portal at the National
Data Center; perform other tasks concerning the development of the National
Public Service Portal as requested by the Government of Vietnam and/or Prime
Minister of Vietnam; manage and operate the National Data Center regarding
administrative procedures;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article
30. Responsibilities of Government Cipher Committee
1. Take charge and
cooperate with relevant units in implementing data encryption and decryption
products.
2. Assist the Minister of
National Defense of Vietnam in the state management of cipher-related data.
3. Cooperate with the
Ministry of Public Security of Vietnam in adopting measures to ensure safety,
authentication, and information using cryptography; implement authentication
services for the Government of Vietnam’s specialized digital signatures for
information systems and databases of agencies of the CPV, the State, and
socio-political organizations.
Article
31. Responsibilities of Ministry of Finance of Vietnam
1. Cooperate with the
Ministry of Public Security of Vietnam in determining expenditures on financial
support for ensuring connection and data; provide support for offsetting the
costs of data generation and collection.
2. Promulgate Circulars on
fees for utilization and use of information in national general databases,
national databases, and specialized databases based on the suggestions of
ministries and ministerial agencies.
Article
32. Responsibilities of ministries, ministerial agencies, governmental
agencies, and People’s Committees of provinces and centrally affiliated cities
1. Take charge and
cooperate with the Ministry of Public Security of Vietnam, the Ministry of
National Defense of Vietnam, and relevant agencies in managing the collection,
update, adjustment, copying, sharing, transfer, deletion, destruction, storage,
and protection of data under their management.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3. Ministries, central
authorities, and local authorities shall cooperate with the Office of the
Government of Vietnam, the Ministry of Public Security of Vietnam, and relevant
units in restructuring regulations and amending legislative documents following
roadmaps for data collection, update, and synchronization with the National
General Database.
4. Upgrade, maintain, and
repair infrastructures and devices of agencies when using those of the National
Data Center.
5. Provide suggestions to
the Ministry of Finance of Vietnam on the fees for utilization and use of
information in national general databases, national databases, and specialized
databases concerning sectors and fields under its management, collection,
payment, exemption, reduction, management, and use thereof.
Chapter
VI
IMPLEMENTATION
Article
33. Entry into force
This Decree comes into
force as of July 1, 2025.
Article
34. Implementation responsibilities
Ministers, Directors of
ministerial agencies, Directors of governmental agencies, Presidents of
People’s Committees of provinces and centrally affiliated cities, and relevant
agencies, organizations, and individuals shall implement this Decree.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
ON BEHALF OF THE GOVERNMENT
PP. PRIME MINISTER
DEPUTY PRIME MINISTER
Nguyen Chi Dung