Text size large => Please "Download" to view content.

GOVERNMENT OF VIETNAM
-------

SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------

No. 165/2025/ND-CP

Hanoi, June 30, 2025

 

DECREE

ELABORATING ON LAW ON DATA

Pursuant to the Law on Government Organization dated February 18, 2025;

Pursuant to the Law on Data dated November 30, 2024;

At the request of the Minister of Public Security of Vietnam;

The Government of Vietnam hereby promulgates the Decree elaborating on the Law on Data.

Chapter I

GENERAL PROVISIONS

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



This Decree provides for Clause 3 Article 13, Clause 5 Article 14, Clause 5 Article 15, Clause 3 Article 16, Clause 4 Article 17, Clause 4 Article 18, Clause 3 Article 20, Clause 5 Article 21, Clause 5 Article 22, Clause 4 Article 23, Clause 5 Article 25, Clause 4 Article 26, Clause 4 Article 27, Clause 3 Article 30, Clause 8 Article 31, Clause 5 Article 35, Clause 4 Article 36, and Clause 3 Article 37 of the Law on Data and the construction, development, protection, administration, processing, and use of data; assurance of resources for the operation of the National Data Center; responsibilities of agencies, organizations, and individuals relevant to data operations.

Article 2. Regulated entities

1. Vietnamese agencies, organizations, and individuals.

2. Foreign agencies, organizations, and individuals in Vietnam.

3. Foreign agencies, organizations, and individuals directly participating in or involved in operations concerning digital data in Vietnam.

Chapter II

DATA PROCESSING

Article 3. Criteria for determining important data

The determination of important data shall be based on the potential impact of the data on national defense and security, cipher, foreign affairs, macroeconomic situations, social stability, and community health and safety upon illegal collection or use (excluding state secrets), including:

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



2. Data that may pose a dangerous impact on plans for developing foreign relations and/or affect national interests and the security of international cooperation, Vietnam’s overseas investment projects, energy security, and maritime security.

3. Data that may pose a dangerous impact on the development and operation of macroeconomic situations, key national economic sectors, total supply and demand of society, total national economic value, unemployment rate, and fields concerning monetary, trade, and import-export, as well as the supply of essential goods, products, and services.

4. Data that may pose a dangerous impact on the lives, health, honor, dignity, property, and legitimate rights and benefits of agencies, organizations, and individuals; prevention and control of epidemics; prevention, monitoring, and treatment of infectious and occupational diseases, and food safety and hygiene; labor supply and provision of public services.

Article 4. Criteria for determining core data

The determination of core data shall be based on the direct dangerous impact of the data on national defense and security, cipher, foreign affairs, macroeconomic situations, social stability, and community health and safety upon illegal collection or use (excluding state secrets), including:

1. Data that directly poses a dangerous impact on national security, independence, sovereignty, unity, and territorial integrity of the Fatherland and the protection of the CPV, State, and great national unity bloc; protection of political security and security in fields concerning ideology-culture, economy, national defense, foreign affairs, information, society, natural resources, environment, agriculture, biology, health, labor, construction, education, training, and science and technology.

2. Data that directly poses a dangerous impact on plans for developing foreign relations and/or affects national interests and the security of international cooperation, Vietnam’s overseas investment projects, energy security, and maritime security.

3. Data directly poses a dangerous impact on the development and operation of macroeconomic situations, key national economic sectors, total supply and demand of society, total national economic value, unemployment rate, and fields concerning monetary, trade, and import-export, as well as the supply of essential goods, products, and services.

4. Data that directly poses a dangerous impact on the lives, health, honor, dignity, property, and legitimate rights and benefits of agencies, organizations, and individuals; prevention and control of epidemics; prevention, monitoring, and treatment of infectious and occupational diseases, and food safety and hygiene; labor supply and provision of public services.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



1. Data owners shall stipulate specific storage periods for their collected or generated data.

2. State agencies shall promulgated technical procedures for the storage of data under their management, ensuring safe data storage.

3. The National Data Center shall establish data storage services for the needs of data owners and data governing bodies. Data owners and data governing bodies shall cooperate with the National Data Center in developing implementation plans and roadmaps based on specific data storage services.

Article 6. Data access and retrieval

1. Data access refers to activities of approaching and interacting with data within the granted rights, including read access, write access, edit access, delete access, execute access, and other types of access as stipulated by the data owners or data governing bodies.

2. Data retrieval refers to activities of accessing and extracting data, including manual retrieval, automatic retrieval, real-time retrieval, and other types of retrieval as stipulated by the data owners or data governing bodies.

3. Principles of data access and retrieval:

a) Ensure legality and compliance with the procedures for data access and retrieval;

b) Ensure that data access and retrieval are conducted within the granted rights and necessary for the determined purposes.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



a) Management of use registration information;

b) Management of data access and retrieval authorization;

c) Management of data access and retrieval history;

d) Management of data access and retrieval tools.

Article 7. Support for data owners in data connection and sharing for state agencies

State agencies shall implement measures to support data owners in the data connection and sharing for state agencies, including:

1. Development of information systems to ensure data connection and sharing; protection and use of data shared by data owners for the determined purposes.

2. Development of procedures, applications, and software for data owners to exercise their rights over the data provided for state agencies under the law.

3. Ministers, Directors of ministerial agencies, Directors of governmental agencies, and Presidents of the People’s Committees of provinces and centrally affiliated cities shall decide on the support for data owners, including:

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



b) Financial support to ensure connection and sharing; support to offset costs of data generation and collection based on the norms of state agencies;

c) Personnel support for data connection and sharing; support for training for personnel sources serving data connection and sharing;

d) Other forms of support.

Article 8. Provision of data for state agencies

1. Individuals and organizations are encouraged to provide and share their data with state agencies for purposes serving common benefits (e.g., healthcare, climate change, and traffic improvement), facilitating the summary and universalization of official statistics, and improving the provision of public services, public policy planning, or scientific research.

Organizations and individuals shall share and provide data voluntarily based on the consent of the data subject matters to process their personal data or the permission of data owners to use their non-personal data.

2. State agencies shall request organizations and individuals to provide data according to Clause 2 Article 18 of the Law on Data as follows:

a) Prepare written requests or other forms to ensure confirmation of the request for data provision, specifying the data types, detail levels, data volume, data access frequency, data provision method, legal ground, request reason, data use purpose, use duration, data provision deadline, and expected data processing;

b) Issue notices to the organizations or individuals subject to the data provision request of the sanctions to be imposed if the request is not complied with.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



a) The handover and receipt of data shall be conducted according to the proper subject, time, data type, detail level, data volume, data access frequency, and data provision method as requested;

b) Participants in the handover and receipt of data include the data owner, legal representative, or legal data manager/user; individual or representative of the organization assigned to manage and use the data;

c) The handover and receipt of data shall be recorded in writing;

d) The party requesting the data provision may request the data provider to supplement the data if the handed-over data does not meet the scope of the requested data.

4. Cancellation of data provision requests

a) A data provision request shall be canceled in cases where the data provision request is contrary to the Law on Data or other relevant laws; the data provision request has not been implemented, but the conditions for data provisions prescribed in Clause 1 Article 18 of the Law on Data no longer exist; the data provision request has not been implemented, but the data no longer exists due to objective reasons;

b) The cancellation of any data provision request shall be recorded in writing.

5. Requests for revision or withdrawal of data provision requests

a) Before the designated deadline for data provision, the data owner, legal representative, or legal data manager/user may request the competent authority to revise or withdraw the data provision request;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



6. Authority to request data provision

Ministers, Directors of ministerial agencies, Presidents of the People’s Committees of provinces and centrally affiliated cities, the Director of the National Data Center, and Directors of Police Authorities of provinces and centrally affiliated cities may request data provision within their scope of tasks and entitlements.

Article 9. Data confirmation and authentication

1. Data confirmation shall be carried out as follows:

a) Data collected and updated to national databases, specialized databases, and other databases shall be confirmed by the data owners and/or data governing bodies;

b) The confirmation of data among state agencies and socio-political organizations shall be carried out through cooperation regulations and specific data provision, sharing, and connection methods;

c) Aside from the cases prescribed in Points a and b of this Clause, data confirmation shall be carried out under agreements between data users and data governing bodies, data owners, or other organizations according to the law;

d) Data owners and data governing bodies shall assume responsibility for the quality, reliability, and legality of the data (provided or confirmed by them), develop data confirmation procedures and forms, and organize data confirmation activities.

2. Data owners and data governing bodies shall develop data confirmation procedures and forms and organize the confirmation of data under their management and ownership.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



4. Data confirmation and authentication shall be carried out in compliance with electronic authentication laws and relevant laws.

Article 10. Data disclosure

1. The disclosure of open data shall be carried out immediately after the data is classified as open data. Data owners and data governing bodies shall disclose open data through the following means:

a) National Data Portal;

b) Open data portals, web portals of ministries, central authorities, local authorities, and other systems and platforms;

c) Intermediary systems for data connection and sharing or other forms as prescribed by the law.

2. State agencies shall announce the list of open data, disclose open data under their management, and send them to the Ministry of Public Security of Vietnam for summary and publication on the National Data Portal.

3. Data of state agencies not prohibited from being disclosed for reasons related to national security, privacy rights, trade secrets, or other reasons as prescribed by the law shall be disclosed as open data.

4. State agencies shall develop and implement open data disclosure decisions, determining the list of disclosed open data and mechanisms for collecting and analyzing feedback from individuals and organizations on the use of open data. They shall also assess the quality, usability, and compliance with laws concerning open data.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



1. Agencies, organizations, and individuals may use one or more encryption solutions and encryption and decryption processes in conformity with their data administration and management, including:

a) Data encryption solutions during data transmission;

b) Data encryption solutions during data storage;

c) Data encryption solutions on digital devices;

d) Hardware security solutions to prevent unauthorized access and ensure that encryption/decryption operations are only performed in safe environments;

dd) Decryption processes requiring identity authentication of the person performing the data decryption, determination, and authorization of access to the encrypted data;

e) Solutions to record encryption and decryption activities, ensuring legality, transparency, and fairness and serving lookup capability;

g) Other solutions and processes as prescribed by the law.

2. The Minister of Public Security of Vietnam shall decide or delegate the decision to apply data decryption solutions to cases prescribed in Clause 4 Article 22 of the Law on Data without requiring consent from data owners or data governing bodies, excluding cases concerning military or national defense.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



Article 12. Cross-border data transfer and processing

1. Any data owner or data governing body that wishes to transfer or process core or important data across borders shall conduct an impact assessment as prescribed in Clause 2 of this Article.

The impact assessment for the transfer of core or important data abroad or to a foreign organization or individual shall be carried out once for the entire operational duration of the organization or enterprise and updated and supplemented as specified in Clause 8 of this Article.

2. The transferring party shall assess the impact based on the following:

a) Legality, necessity, scope, data transmission methods, and data processing methods of the receiving party;

b) Risks that the data transfer may pose to national defense, security, economic activities, foreign affairs, social stability, public benefits, or legitimate rights  and benefits of organizations or individuals; risks of data being forged, destroyed, leaked, lost, or misused;

c) Responsibilities, obligations, and managerial and technical measures of the receiving party;

d) Other relevant issues.

3. The written agreement between the transferring party and the receiving party shall determine:

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



b) Data storage location, period, and data processing methods after the storage period or the completion of the agreed objectives;

c) Binding requirements for the receiving party regarding the provision of the transferred data to a third party;

d) Measures to protect the data to be used by the receiving party;

dd) Remedial measures, compensation for damage, contractual violation handling, and measures to settle disputes for violations of data protection obligations;  

e) Responsibilities of the concerned parties in data processing.

4. A dossier on assessment of the impact of cross-border data transfer or processing includes an impact assessment report on the cross-border data transfer or processing (following Form No. 02 enclosed with this decree) and relevant documents.

5. Where the data transferred or processed abroad is core data:

a) The transferring party shall send the dossier on assessment of the impact of cross-border data transfer or processing to the Ministry of Public Security of Vietnam or the Ministry of National Defense of Vietnam if it concerns military, national defense, or cipher;

b) The unit in charge of the Ministry of National Defense of Vietnam or the Ministry of Public Security of Vietnam shall receive the dossier and inspect its adequacy and validity. Where the dossier is inadequate, the unit shall request the transferring party to supplement and complete the dossier;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



d) The transferring party shall receive a written notice of the assessment results. After receiving a qualified assessment result, the data governing body shall issue a decision on the transfer of core data abroad or cross-border data processing.

6. Where the data transferred or processed across borders is important data:

The transferring party shall prepare a dossier on impact assessment before cross-border data transfer or processing in service of the inspection and assessment of the Ministry of Public Security of Vietnam or the Ministry of National Defense of Vietnam if necessary (without requiring approval from a competent authority).

The transferring party shall send 1 original copy of the dossier to the Ministry of Public Security of Vietnam or the Ministry of National Defense of Vietnam following the form enclosed with this Decree 15 days before the data processing.

7. The impact assessment of the competent authority shall focus on the potential risks the cross-border data transfer or processing may pose to national security, public benefits, or legitimate rights and benefits of specific organizations or individuals, including:

a) Legality and necessity of the purposes, scope, and methods of data transfer or processing;

b) Impacts of policies and regulations on data protection and cybersecurity environment of the nation or region of the receiving party regarding the confidentiality of data; data protection levels of the receiving party compared to the applicable Vietnamese technical regulations and standards;

c) Scale, scope, data types, and risks of data being forged, destroyed, leaked, lost, or illegally transferred or used after the transfer;

d) Responsibilities and obligations of the concerned parties;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



8. The transferring party shall revise and supplement the dossier on assessment of the impact of cross-border data transfer or processing in the following cases:

a) Upon changes to the purpose, method, scope, and type of data to be transferred or processed and/or changes to the purpose or method of data processing of the receiving party, impacting data security; upon prolonged storage of core or important data;

b) Upon changes to policies and regulations on data protection and cybersecurity environment in the nation or region of the receiving party, changes to the actual control rights of the transferring or receiving party, and other impacts on the confidentiality of the transferred data.

9. The Ministry of National Defense of Vietnam or the Ministry of Public Security of Vietnam shall request the transferring party to cease their transfer or processing of core or important data in the following cases:

a) The core or important data transferred or processed across borders is used for activities that infringe on national defense, security, national benefits, public benefits, and legitimate rights and benefits of the data subject matter or data owner according to the law of Vietnam and international treaties to which the Socialist Republic of Vietnam is a signatory.

b) The transferring party fails to comply with this Article;

c) Upon violations of regulations on data protection.

10. The quantification of core or important data upon cross-border data transfer or processing shall be determined based on the accumulated volume of data transferred or processed across borders, starting from July 1, 2025 until the time of data transfer or processing.

11. Cases where approval from competent authorities is not required for cross-border core data transfer or processing according to Clause 5 of this Article and cases where notices to competent authorities are not required for important data transfer or processing according to Clause 6 of this Article: 

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



b) Upon cross-border personnel management based on the specific labor principles or regulations and collective labor agreements according to the law;

c) Where it is necessary to provide data to conclude or execute a contract, including cases where the contract is relevant to cross-border transport, logistics, money transfer, payment, opening of bank and hotel accounts, visa application, and inspection services.

12. Regarding core or important data transfer or processing under Clause 11 of this Article, an impact assessment must be sent to the Ministry of Public Security of Vietnam (or the Ministry of National Defense of Vietnam for data under its management) according to Clause 4 of this Article 15 days after implementation.

Article 13. Other operations in data processing

1. Data revocation, deletion, and destruction

a) Data revocation refers to the act of requesting the return of data and deletion and/or destruction of the provided data or requesting the cessation of the data processing or use where deletion or destruction is not possible.  

Data deletion refers to the removal of data from the structure or environment in which it is stored. 

Data destruction refers to the removal of data from the structure or environment in which it is stored, ensuring that it cannot be restored using methods such as overwriting or physical destruction.

b) Data deletion and destruction shall be carried out within 72 hours after receiving a request from the data subject matter, and the notice of the results of the data revocation, deletion, or destruction is sent to the data owner unless otherwise prescribed by laws.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



Chapter III

DATA ADMINISTRATION, MANAGEMENT, AND PROTECTION

Article 14. Data administration and management

1. The Ministry of Public Security of Vietnam shall promulgate a general data administration and management framework for common application by state agencies involved in data connection and sharing with the National Data Center.

2. Database management agencies involved in data connection and sharing with the National Data Center shall develop detailed data administration and management framework applicable to data under their management, ensuring conformity with the general data administration and management framework promulgated by the Ministry of Public Security of Vietnam.

3. A detailed data administration and management framework shall include:

a) Mechanisms for managing master data and general list codes;

b) Mechanisms for managing data processing; plans for data expansion and backup storage;

c) Assessment of data quality; application of technical regulations and standards on data quality and data connection and sharing;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



dd) Data architecture and data models;

e) Connection and sharing mechanisms;

g) Data protection mechanisms;

h) Data development, utilization, and use mechanisms;

i) Supervision, control, and implementation mechanisms.

4. Management of master data and general list data 

a) Database management agencies shall promulgate lists of master data and general list data based on cooperation and agreement with the Ministry of Public Security of Vietnam;

b) Contents requiring master data administration and management include identification code issuance principles; basic information for describing, identifying, and distinguishing specific entities in the master data; procedures for generating and updating master data; selection of technologies and tools to ensure that master data is collected, updated, utilized, and used accurately, consistently, and adequately; generation, update, and management of master data; master data connection and sharing with the National General Database; cooperation with the Ministry of Public Security of Vietnam in supervision and reconciliation, ensuring master data quality across the entire system;

c) The master data in national databases and other databases of agencies assigned to generate and manage master data shall hold official validity, equivalent to the written documents provided by competent authorities

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



5. State agencies implementing information technology projects concerning national databases and specialized databases shall solicit opinions from the Ministry of Public Security of Vietnam (National Data Center) on the construction, development, protection, administration, processing, and use of data to prevent waste, ensuring consistency and synchronization during implementation.

Article 15. Determination and management of risks arising during data processing

1. Types of risks arising during data processing include:

a) Risks of privacy rights, occurring due to non-compliance with the law on privacy rights of data subject matters during data processing and transfer;

b) Risks of cybersecurity, occurring due to failure to apply necessary measures to protect data prohibited from disclosure from unauthorized access by external entities or from being leaked;

c) Risks of identification and access management due to failure to ensure the protection of data prohibited from disclosure from unauthorized access;

d) Other risks during data processing, including risks of data sharing (occurring due to the inability to maintain control rights over the shared data) and risks of data management (occurring due to poor data quality).

2. Measures to prevent risks arising during data processing include:

a) Regular data backup and data safety assurance;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



c) Implementation of data protection measures as per regulation;

d) Authorization of access rights for each data type to prevent unauthorized access;

dd) Use of systems for supervision and detection of intrusions to monitor network operations and detect unusual acts or unauthorized access;

e) Installation and maintenance of confidentiality software;

g) Implementation of annual risk assessment to determine system vulnerabilities and apply respective risk prevention measures;

h) Development of incident handling schemes and plans to proactively and promptly respond and remedy incidents;

i) Training and advanced training in data protection skills, threat recognition, and handling methods upon confidentiality risks; organization of regular drills for incident prevention, supervision, detection, and timely response and remedy;

k) Other measures as prescribed by the law.

Article 16. Data protection

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



Data governing bodies not subject to state agencies are encouraged to develop separate regulations on the protection of data under their management.

2. The protection of core and important data, being personal data, shall comply with the Law on Data and this Decree.

In case of transferring or processing core or important data across borders and managing and protecting core or important data, being personal data, comply with Article 12 and Clause 11 Article 17 of this Decree without having to conduct an impact assessment according to the law on personal data protection.

3. Any data governing body providing or entrusting the processing of core or important data to an organization or individual not prescribed in Article 12 of this Article shall:

a) Make an agreement with the receiving party on the purpose, method, scope, and security protection obligation through the contract and supervise the obligation implementation of the receiving party; ensure that the dossier on important data processing provided or entrusted to other receiving parties must be stored for at least 3 years;

b) When providing or entrusting the processing of core or important data, conduct encryption, provide digital signatures, and adopt other confidentiality measures to ensure confidentiality, integrity, and non-repudiation;

c) Ensure that the party receiving the core or important data fulfills the obligations of data protection and processes the core or important data according to the agreed purpose, method, and scope.

4. Data protection measures include:

a) Managerial measures concerning data processing, including the development of policies, regulations, and criteria for assessing data safety and security to ensure compliance with technical regulations and standards, regulations on data protection, and other managerial measures according to the law;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



c) Measures to manage data protection personnel, including the development of regulations on management and training for data protection personnel;

d) Other data protection measures as prescribed by the law.

Article 17. Data protection management during processing

1. Data governing bodies shall establish management systems for data protection throughout the entire data processing.

2. Data governing bodies shall adopt measures to protect data during data collection and generation. For core and important data, data governing bodies shall:

a) Develop procedures for data collection and generation and assess and apply protective measures before data collection and generation;

b) Inspect authenticity, supervise data quality, and retrieve data sources.

3. Data governing bodies shall store data in compliance with the methods and periods prescribed by the law. For core and important data, data governing bodies shall:

a) Develop procedures for data storage, including procedures for data backup, recovery, and storage, backup, and recovery logging;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



c) Delete and destroy data when the storage period expires or when the data is no longer necessary for processing purposes.

4. During the processing and use of core and important data, data governing bodies shall:

a) Develop and implement mechanisms for access and data retrieval, ensuring compliance with the principle of least privilege during data processing and use; 

b) Develop data access control systems, including consistent identification and access management platforms; apply technical measures to protect data, control access, and retrieve data during data processing and use.

5. Data governing bodies shall define the scope, purpose, procedure, and development of regulations on the protection and application of protective measures based on the classification, level, purpose, and intended use of data provided outward.

6. Data owners shall analyze and assess impacts on national defense, security, foreign affairs, macroeconomic situations, social stability, and community health and safety before disclosing the data.

7. Data owners and data governing bodies shall develop schemes to delete and destroy data, specifying the purposes, principles, procedures, and techniques for deleting, destroying, recording, and storing deletion and destruction activities. Where the deletion or destruction involves core or important data, the data governing bodies shall provide written evidence that the deletion or destruction renders the data irrecoverable.  

8. Where data governing bodies wish to transfer data due to reorganization, dissolution, or bankruptcy, they shall specify the plans for data transfer and issue notices to the affected agencies, organizations, and individuals.

In case of reorganization or dissolution of organizations managing core or important data, the data governing bodies shall apply measures to ensure data safety and submit reports on schemes for data processing and names or information of the receiving parties to relevant competent authorities.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



10. Governing bodies of core or important data shall prepare data processing logs for the entire data processing. The logs shall be retained for at least six months.

11. Governing bodies of core or important data shall annually assess risks in the processing of core or important data within their management scope and prepare and store risk assessment reports following the form enclosed with this Decree, ensuring availability of such reports to serve inspection and assessment by competent authorities, excluding cases where dossiers on assessment of the impact of cross-border data transfer or processing are already prepared according to Article 12 of this Decree. A risk assessment report includes:

a) Basic information on the data governing body, information on the data protection department, and contact information of the data protection officer (DPO);

b) Purpose, type, quantity, method, scope, storage period, storage location, data processing, and data processing situation;

c) Data protection management system, technical measures for encryption, backup, labeling, access control, authentication, and other necessary measures;

d) Detected risks of data safety, past data safety incidents, and solutions;

dd) Other reporting contents according to regulations of relevant competent authorities.

Article 18. Personnel management and data protection personnel training and advanced training

1. Data owners and governing bodies of core and important data shall identify DPOs and data protection departments.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



3. Data protection departments shall have the following functions and tasks:

a) Develop and implement data protection management systems, operational procedures, and plans for emergency responses to data protection incidents;

b) Periodically organize and implement the supervision of data safety risks, risk assessments, emergency drills, dissemination, education, training, and timely settlement of network data safety risks and incidents;

c) Research and propose decisions concerning the protection of core and important data;

d) Receive and handle reports on data protection of specific units.

4. Data owners and governing bodies of core and important data shall:

a) Specify requirements for safety management in the recruitment, use, training, introduction, transfer, resignation, assessment, and selection of personnel;

b) Refrain from appointing persons with criminal records in information technology or telecommunications networks as DPOs;

c) Concluding agreements on confidentiality responsibility with data processing personnel.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



6. DPOs may agree with data owners or data governing bodies on conditions for exemption from responsibilities for damage to the protected data.

Article 19.  Data confidentiality supervision, early warnings, and emergency management

1. Data confidentiality supervision, early warnings, and emergency management include:

a) Establishment of mechanisms for data safety risk supervision;

b) Preparation of draft supervision standards and interfaces;

c) Development of mechanisms for reporting and sharing information on data safety risks and assurance of the consistency of the collection, analysis, assessment, and reporting of information on data safety risks;

d) Development of plans for responses to data safety incident emergencies.

2. The Ministry of Public Security of Vietnam shall conduct confidentiality supervision, issue early warnings, and manage data emergencies, excluding the contents prescribed in Clause 3 of this Article.

3. The Ministry of National Defense of Vietnam shall conduct confidentiality supervision, issue early warnings, and manage emergencies concerning data under its management.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



a) Promptly issue notices to data owners concerning data safety incidents that may potentially damage the legitimate rights and benefits of specific organizations and individuals and propose measures to minimize damage;

b) After any data safety incident, promptly execute emergency responses according to emergency response plans and submit reports on confidentiality incidents concerning core and important data to the Ministry of Public Security of Vietnam or the Ministry of National Defense of Vietnam as soon as possible.

5. The Ministry of Public Security of Vietnam shall establish mechanisms for supervising data safety risks, develop standards concerning supervision and early warnings concerning data safety, cooperate in developing technical equipment for supervision and early warnings concerning data safety, and strengthen the capacity for supervision, early warning, processing, origin tracing, and intensification of information sharing with relevant departments.

Data governing bodies shall supervise data safety risks, promptly investigate potential security risks, and adopt necessary measures to prevent data safety risks.

6. The Ministry of Public Security of Vietnam shall develop mechanisms for reporting and sharing information on data safety risks, ensure consistent collection, analysis, assessment, and reporting of information on data safety risks, and encourage confidentiality service providers and scientific research organizations to share information on data safety risks.

Data governing bodies shall summarize and separately analyze data confidentiality risks within their management scope and report potential risks of major confidentiality incidents to the Ministry of Public Security of Vietnam.

7. The Ministry of Public Security of Vietnam shall develop emergency response plans for data safety incidents, including the organizational structure and responsibilities for emergencies, classification of data safety incidents, supervision and early warnings, procedures for responding to emergencies, and protective measures, and organize and cooperate in responses to incidents concerning the safety of core and important data.

8. Data governing bodies shall organize backup plan drills for incidents concerning the safety of core/important data once every 6 months, store drill dossiers, prepare summary reports on the drills, and promptly update backup plans based on major changes to data processing systems or the external environment.

Chapter IV

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



Article 20. Infrastructures of National Data Center

1. The information system of the National Data Center shall be separated from the development, inspection, and testing system. It shall also ensure level-based security and confidentiality to control, detect, and prevent risks of losing information safety and security.

2. The National Data Center shall construct and develop cloud computing infrastructures and implement functional zones to serve the needs of state agencies, ensuring the development of integrated and synchronized subsystems, data utilization, and high requirements for information confidentiality.

3. The National Data Center shall establish high-capacity calculation infrastructures and data analysis systems serving the management of predictive analysis models in service of utilization operations from the National General Database. It shall also provide the technical conditions necessary to support applied mathematics research and development, as well as assist in developing mechanisms, policies, plans, and strategies related to national development and data-related products and services for socio-economic development.

4. The National Data Center shall establish a National Data Portal as the focal point for state agencies to announce information on data types under their management and to announce and provide open data, thereby enhancing transparency in the Government of Vietnam’s operations and promoting creativity and socio-economic development. It shall also enable organizations and individuals to provide data for objectives concerning common benefits, improvement of public service provision, public policy making, or scientific research for common benefits; 

5. The National Data Center shall develop applications on digital devices to facilitate the utilization and use of its data, provide data-related products and services, and develop other utilities serving agencies, organizations, and individuals.

6. The National Data Center shall develop contact systems with individuals and organizations serving its operations.

7. The National Data Center shall provide the following services:

a) Services concerning station infrastructures, server colocation, provision of physical spaces for the server locations, power systems, air conditioning, and other relevant devices to implement database information systems, permitting database governing bodies, agencies, and organizations to proactively use and control their systems, either in shared or dedicated spaces, in compliance with regulations on the management and operation of the National Data Center;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



c) Services concerning the implementation and operation of technical infrastructures serving national databases, database information systems, and other databases and information systems.

8. State agencies and socio-political organizations shall determine the types of services provided by the National Data Center as prescribed in Clause 7 of this Article, ensuring conformity with the current situation, professional requirements, and regulations on investment in state budget-funded information technology projects. They shall also send written requests to the National Data Center providing the services. The written requests shall specify the needs for the services of the National Data Center, the scale of the systems to be placed at the National Data Center, and the needs for personnel supporting the administration and operation of infrastructures and information systems.

9. The Minister of Public Security of Vietnam shall provide guidelines on the provision and implementation of the National Data Center's services when infrastructure conditions are deemed sufficient. 

Article 21. Responsibilities of National Data Center

1. Provide guidelines for agencies, organizations, and individuals on the application of technical regulations and standards on data within a scope of synchronization with the National Data Center.

2. Adopt measures to supervise and assess the quality of data shared or synchronized with the National Data Center.

3. Regulate the data of the National General Database.

4. Adopt data protection measures from the start and throughout data processing in compliance with Clause 6 Article 16 of this Decree.

5. Conclude agreements and/or memorandums of understanding with international agencies and organizations to promote international cooperation in management, data protection, scientific research, cross-border data transfer, training, and improvement of capacity and qualification concerning data-related content to promote innovation and technology transfer in service of socio-economic development.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



Article 22. Assurance of resources for construction and development of National Data Center

1. The National Data Center shall develop plans and programs on training, international cooperation, and personnel quality improvement.

2. Officials and officers working at the National Data Center shall be entitled to a support allowance of 500.000 VND per working day, funded by revenues from the fees for utilization and use of data in the National General Database after they are transferred to the state budget.

Organizations and public service providers of the National Data Center may utilize the support allowances above to decide on the allowances for data specialists. 

3. The Minister of Public Security of Vietnam shall promulgate a list of job positions in the National Data Center, as well as mechanisms for attracting, utilizing, and providing incentives for high-quality personnel working at the National Data Center.

Article 23. Utilization and use of National General Database

1. Utilization through direct connection and sharing of information with the National General Database

a) The National Data Center shall issue accounts to agencies and organizations to access and utilize information in the National General Database;

b) Agencies and organizations issued with accounts by the National Data Center shall create and manage separate accounts on their information systems connected to the National General Database and authorize the use of the created accounts to individuals under their management according to the assigned functions and tasks;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



d) The information systems of agencies and organizations shall send requests for information utilization to the National General Database through the accounts issued by the National Data Center. The results of the utilization shall be presented in physical or electronic form and stored in the information systems connected for information sharing and utilization;

dd) The National Data Center shall inspect and verify account information and return the utilization results as requested in conformity with the entitlements and scope of information permitted for the utilization of the accounts.

2. Agencies, organizations, and individuals shall utilize information in the National General Database through the National Data Portal or the National Public Service Portal at the National Data Center or by using specific devices, equipment, and software following the guidelines of the Ministry of Public Security of Vietnam.

3. Agencies, organizations, and individuals shall utilize information in the National General Database through web portals and information systems for settlement of administrative procedures following the guidelines of ministries, ministerial agencies, governmental agencies, and People’s Committees of provinces and centrally affiliated cities.

4. Utilization by written requests for information utilization and provision

a) Agencies, organizations, and individuals shall prepare and send written requests for utilization and provision of information in the National General Database to the National Data Center;

b) A written request for utilization and provision of information must specify the purpose, content, scope of the requested information in the National General Database, and commitment to assume responsibility during the use of information permitted for utilization and other information;

c) Within 3 working days from the receipt of written requests for utilization of information in the National General Database, competent persons shall assess and decide on the permission for information utilization;

d) In case of permitting the information utilization, competent persons shall issue written responses and provide information for agencies, organizations, and individuals. In the event of refusal to permit the utilization of information, competent persons shall provide written responses and explanations.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



a) Automatically implement administrative procedures, benefits, and policies for individuals and organizations when the information and data serving the assessment and settlement of administrative procedures is adequate in the National General Database.  Competent authorities and persons shall proactively settle administrative procedures, benefits, and policies for individuals and organizations based on the information and data connected, shared, and utilized from the National General Data Base and the consent of the individuals and organizations;

b) Reutilize/reuse data and develop concentrated online public services on the National Public Service Portal, ensuring simplicity, consistency, user-friendliness, thrift, and effectiveness;

c) Connect and share data between the National General Database and the ministerial and provincial information systems for settlement of administrative procedures serving the receipt and settlement of administrative procedures for organizations and individuals, ensuring that individuals and organizations are not required to declare or provide information and papers available in the National General Database; adequately synchronize data on dossier digitalization and results of the settlement of administrative procedures from the ministerial and provincial information systems for settlement of administrative procedures, national databases, and the National General Database in service of the data reutilization/reuse, ensuring that individuals and organizations only provide information, data, and papers once for state agencies during the implementation of administrative procedures and public services.

Article 24. Data connection and sharing with National General Database

1. The governing bodies of state agencies' databases, when developing databases with connections to the National Data Center, shall comply with the guidelines of the National Data Center to ensure data connection and sharing.

2. The National Data Center and database management agencies shall develop agreements on data connection and sharing, including:

a) Purposes of data sharing;

b) Scope of data to be shared;

c) Methods for data connection and sharing;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



dd) Other relevant contents.

3. Data sharing methods

a) Data sharing among state agencies’ databases shall be carried out through the data sharing and regulation platform of the National Data Center and other data sharing and integration platforms;

b) Data sharing between organizations/individuals and the National General Database shall be carried out through the data sharing and regulation platform, data portals, files, and other methods under agreements among the concerned parties.

4. The National Data Center shall supervise data sharing through its supervision system to assess the provision and use of data.

Article 25. Provision of data for National General Database

1. Organizations and individuals that are not state agencies providing data for the National General Database through agreements with the National Data Center or written agreements on data provision shall specify the data provision purposes, scope of the data to be provided, methods of data provision, and time and frequency of the provision and other relevant contents.

2. Responsibilities of database management agencies in the provision of data for the National General Database

a) Synchronize data for the National General Database according to Clause 1 Article 34 of the Law on Data;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



c) For other data types, conduct the synchronization upon adjustments or updates according to agreements with the National Data Center.

3. The National Data Center shall cooperate with database management agencies in adopting appropriate technical measures to ensure that any changes to the master data are reflected across all related reference databases through respective synchronization.

Chapter V

RESPONSIBILITIES OF AGENCIES AND ORGANIZATIONS

Article 26. Responsibilities of Ministry of Public Security of Vietnam

1. Take charge and cooperate with relevant agencies in implementing, instructing, inspecting, and urging the implementation of this Decree.

2. Take charge and cooperate with relevant agencies in managing the construction, development, protection, administration, processing, and use of data; ensure data security and combat crimes and law violations concerning data; manage, monitor, and supervise business operations involving data-related products and services in compliance with this Decree.

3. Take charge and cooperate with relevant agencies in constructing the National Data Center in accordance with applicable regulations, technical standards, and regulations on data centers.

4. Develop, promulgate, or issue requests to competent state authorities for promulgation and provide guidance on the implementation of legislative documents guiding the implementation of data laws.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



6. Organize data connection, sharing, and regulation between information systems/databases of agencies, organizations, and individuals and the National General Database through the data sharing and regulation platform of the National Data Center.

7. Ensure information technology infrastructures for agencies of the CPV, the State, and socio-political organizations serving the management, administration, and processing of data under their management at the National Data Center.

8. Take charge and cooperate with the Ministry of Science and Technology of Vietnam in appraising, assessing, inspecting, and supporting the supervision and regulation in response to incidents concerning cybersecurity and information safety during the development, implementation, and operation of information systems and databases at the National Data Center.

9. Take charge and cooperate with the Ministry of Science and Technology of Vietnam in developing technical regulations, standards, or guidelines on the organization, connection, sharing, and synchronization of data with the National Data Center.

10. Develop structural standards of the software system at the National Data Center. 

11. Provide guidelines for the data classification of agencies of the CPV, the State, and socio-political organizations; organize and direct professional training and advanced training in data nationwide.

12. Develop and operate the National Data Portal.

13. The Minister of Public Security of Vietnam shall decide on expenditures on financial support for ensuring connection and sharing; provide support for offsetting the costs of data collection and generation based on consensus with the Minister of Finance of Vietnam and the Minister of Science and Technology of Vietnam.

Article 27. Responsibilities of Ministry of National Defense of Vietnam

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



2. Cooperate with the Ministry of Public Security of Vietnam and relevant agencies and organizations in arranging appropriate forces and equipment to remotely detect and prevent acts of infringement on the National Data Center, both geographically and online.

3. Take charge of the data storage, protection, and security assurance; manage, monitor, supervise, and implement data connection, sharing, and regulation among information systems and databases; apply science to the processing, management, utilization, and use of data; manage and license data transfer abroad; use national data development funds for data types under the management of the Ministry of National Defense of Vietnam.

Article 28. Responsibilities of Ministry of Science and Technology of Vietnam

1. Provide guidelines for agencies of the CPV, the State, and socio-political organizations on the development and completion of information technology technical infrastructures and the development of technical regulations and standards concerning data organization, connection, sharing, and synchronization; conduct standardization, connection, and sharing of data and optimal calculation between investing in new infrastructures and using infrastructures provided by the National Data Center.

2. Review and assess the capacity of specialized data transmission networks of agencies to develop schemes for upgrades, ensuring that all units can access and administer the systems located at the National Data Center via the specialized data transmission networks.

3. Cooperate with the Ministry of Public Security of Vietnam and relevant agencies in researching, mastering, and applying digital technologies and data to form products and services that support the advancement of digital government, digital authority, and socio-economic development through key scientific and technological programs at the national level.

4. Cooperate with the Ministry of Public Security of Vietnam in determining expenditures on financial support for ensuring connection and data; provide support for offsetting the costs of data generation and collection.

Article 29. Responsibilities of the Office of the Government of Vietnam

1. Develop requirements for functionality, operation, and interface; support and instruct ministries, central authorities, and local authorities to handle issues concerning functions, professional procedures, and data of the National Public Service Portal; cooperate with the Ministry of Public Security of Vietnam in administering and operating the National Public Service Portal at the National Data Center; perform other tasks concerning the development of the National Public Service Portal as requested by the Government of Vietnam and/or Prime Minister of Vietnam; manage and operate the National Data Center regarding administrative procedures;

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



Article 30. Responsibilities of Government Cipher Committee

1. Take charge and cooperate with relevant units in implementing data encryption and decryption products.

2. Assist the Minister of National Defense of Vietnam in the state management of cipher-related data.

3. Cooperate with the Ministry of Public Security of Vietnam in adopting measures to ensure safety, authentication, and information using cryptography; implement authentication services for the Government of Vietnam’s specialized digital signatures for information systems and databases of agencies of the CPV, the State, and socio-political organizations.

Article 31. Responsibilities of Ministry of Finance of Vietnam

1. Cooperate with the Ministry of Public Security of Vietnam in determining expenditures on financial support for ensuring connection and data; provide support for offsetting the costs of data generation and collection.

2. Promulgate Circulars on fees for utilization and use of information in national general databases, national databases, and specialized databases based on the suggestions of ministries and ministerial agencies.

Article 32. Responsibilities of ministries, ministerial agencies, governmental agencies, and People’s Committees of provinces and centrally affiliated cities

1. Take charge and cooperate with the Ministry of Public Security of Vietnam, the Ministry of National Defense of Vietnam, and relevant agencies in managing the collection, update, adjustment, copying, sharing, transfer, deletion, destruction, storage, and protection of data under their management.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



3. Ministries, central authorities, and local authorities shall cooperate with the Office of the Government of Vietnam, the Ministry of Public Security of Vietnam, and relevant units in restructuring regulations and amending legislative documents following roadmaps for data collection, update, and synchronization with the National General Database.

4. Upgrade, maintain, and repair infrastructures and devices of agencies when using those of the National Data Center.

5. Provide suggestions to the Ministry of Finance of Vietnam on the fees for utilization and use of information in national general databases, national databases, and specialized databases concerning sectors and fields under its management, collection, payment, exemption, reduction, management, and use thereof.

Chapter VI

IMPLEMENTATION

Article 33. Entry into force

This Decree comes into force as of July 1, 2025.

Article 34. Implementation responsibilities

Ministers, Directors of ministerial agencies, Directors of governmental agencies, Presidents of People’s Committees of provinces and centrally affiliated cities, and relevant agencies, organizations, and individuals shall implement this Decree.

...

...

...

Please sign up or sign in to your Pro Membership to see English documents.



 

ON BEHALF OF THE GOVERNMENT
PP. PRIME MINISTER
DEPUTY PRIME MINISTER




Nguyen Chi Dung

 

You are not logged!


So you only see the Attributes of the document.
You do not see the Full-text content, Effect, Related documents, Documents replacement, Gazette documents, Written in English,...


You can register Member here


You are not logged!


So you only see the Attributes of the document.
You do not see the Full-text content, Effect, Related documents, Documents replacement, Gazette documents, Written in English,...


You can register Member here


You are not logged!


So you only see the Attributes of the document.
You do not see the Full-text content, Effect, Related documents, Documents replacement, Gazette documents, Written in English,...


You can register Member here


Decree 165/2025/ND-CP guiding Law on Data
Official number: 165/2025/ND-CP Legislation Type: Decree of Government
Organization: The Government Signer: Nguyen Chi Dung
Issued Date: 30/06/2025 Effective Date: Premium
Gazette dated: Updating Gazette number: Updating
Effect: Premium

You are not logged!


So you only see the Attributes of the document.
You do not see the Full-text content, Effect, Related documents, Documents replacement, Gazette documents, Written in English,...


You can register Member here


Decree No. 165/2025/ND-CP dated June 30, 2025 on elaborating on Law on Data

Address: 17 Nguyen Gia Thieu street, Ward Xuan Hoa, Ho Chi Minh City
Phone: (+84)28 3930 3279 (06 lines)
Email: inf[email protected]

Copyright© 2019 by THƯ VIỆN PHÁP LUẬT
Editorial Director: Mr. Bui Tuong Vu

DMCA.com Protection Status