The Decree on the National Database and the National Data Center, led by the Ministry of Public Security, provides detailed regulations on the management, collection, updating, and sharing of data among Party agencies, State agencies, and political-social organizations. The Decree takes effect from July 1, 2025.
Đối tượng áp dụng
Applies to ministries, sectors, localities, and related agencies in national data management.
Các điểm cốt lõi
- State management of data
- Collection, updating of data
- Sharing, connecting data between information systems
- Data security protection
- Financial support for data sharing and collection
🌐 Tác động xã hội từ văn bản này
- Enhance the effectiveness of state management through the use of accurate and timely data.
- Accelerate digital transformation in Party agencies, State agencies, and political-social organizations.
❓ Câu hỏi thường gặp
When does this Decree take effect?
This Decree takes effect from July 1, 2025.
Who is primarily responsible for implementing this Decree?
The Ministry of Public Security is the leading agency in implementing the Decree, coordinating with relevant ministries and sectors.
Toàn văn
DECREE
Detailed regulations on certain provisions and implementation measures of the Data Law
____________
Pursuant to the Government Organization Law dated January 18 the 02 Pursuant to Decree No. 32/2019/NĐ-CP dated April 10, 2019 of the Government on assigning tasks, procurement or tendering for the supply of products and services using state budget from regular operating expenses;25;
Pursuant to the Law on Data dated November 30, 2024;
The Government promulgates this Decree on regulations regarding entry, exit, and residence policies for foreigners at the International Financial Center in Vietnam.
The Government promulgates this Decree detailing and providing implementation measures for the Data Law.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Decree details Clause 3 Article 13, Clause 5 Article 14, Clause 5 Article 15, Clause 3 Article 16, Clause 4 Article 17, Clause 4 Article 18, Clause 3 Article 20, Clause 5 Article 21, Clause 5 Article 22, Clause 4 Article 23, Clause 5 Article 25, Clause 4 Article 26, Clause 4 Article 27, Clause 3 Article 30, Clause 8 Article 31, Clause 5 Article 35, Clause 4 Article 36, and Clause 3 Article 37 of the Data Law, as well as the construction, development, protection, management, processing, and utilization of data; ensuring resources for the operation of the National Data Center; and the responsibilities of agencies, organizations, and individuals related to data activities.
Article 2. Applicability
1. Vietnamese agencies, organizations, and individuals.
2. Agencies, organizations, and individuals from foreign countries operating in Vietnam.
3. Foreign agencies, organizations, and individuals directly participating or related to digital data activities in Vietnam.
Chapter II
DATA PROCESSING ACTIVITIES
Article 3. Criteria for determining important data
The determination of important data is based on the degree to which the data can affect national defense, security, state secrets, foreign relations, macro-economy, social stability, public health, and community safety when collected or used illegally (excluding state secrets), including:
1. Data that may cause dangerous impacts on national security, independence, sovereignty, unity, and territorial integrity of the country, protecting the Party, State, and the great solidarity of the entire people; protecting political security, security in ideological-cultural, economic, defense, foreign relations, information, social, natural resource, environmental, agricultural, biological, health, labor, construction, education, training, science, and technology fields.
2. Data that may cause dangerous impacts on plans for developing foreign relations, affecting national interests and international cooperation security, investment projects of Vietnam abroad, energy security, maritime security.
3. Data that may cause dangerous impacts on macroeconomic development and operation, key economic sectors of the nation, total supply and demand in society, national gross economic value, unemployment rate, monetary field, trade, import and export, essential goods, product, and service supply.
4. Data that may cause dangerous impacts on lives, health, honor, dignity, property, rights, and legitimate interests of agencies, organizations, and individuals; epidemic prevention work, prevention, monitoring, and treatment of infectious diseases, occupational diseases, food safety; labor supply, provision of public services.
Article 4. Criteria for determining core data
The determination of core data is based on the direct dangerous impact of the data on national defense, security, state secrets, foreign relations, macro-economy, social stability, public health, and community safety when collected or used illegally (excluding state secrets), including:
1. Data directly causing dangerous impacts on national security, independence, sovereignty, unity, and territorial integrity of the country, protecting the Party, State, and the great solidarity of the entire people; protecting political security, security in ideological-cultural, economic, defense, foreign relations, information, social, natural resource, environmental, agricultural, biological, health, labor, construction, education, training, science, and technology fields.
2. Data directly causing dangerous impacts on plans for developing foreign relations, affecting national interests and international cooperation security, investment projects of Vietnam abroad, energy security, maritime security.
3. Data directly causing dangerous impacts on macroeconomic development and operation, key economic sectors of the nation, total supply and demand in society, national gross economic value, unemployment rate, monetary field, trade, import and export, essential goods, product, and service supply.
4. Data directly causing dangerous impacts on lives, health, honor, dignity, property, rights, and legitimate interests of agencies, organizations, and individuals; epidemic prevention work, prevention, monitoring, and treatment of infectious diseases, occupational diseases, food safety; labor supply, provision of public services.
Article 5. Data Storage Activities
1. The data owner shall specify the storage period for the data collected and created by themselves.
2. State agencies must issue technical procedures for managing data under their control to ensure safe data storage.
3. The National Data Center establishes data storage services to meet the needs of data owners and data managers. Data owners and data managers shall cooperate with the National Data Center to develop plans and implementation schedules according to specific data storage services.
Article 6. Accessing and Extracting Data
1. Accessing data is the activity of approaching and affecting data within the granted rights, including reading access, writing access, editing access, deleting access, executing access, and other types of access defined by the data owner and data manager.
2. Extracting data is the activity of accessing and extracting data, including manual extraction, automatic extraction, real-time extraction, and other types of extraction defined by the data owner and data manager.
3. Principles for implementing data access and extraction:
a) Ensuring legality and compliance with data access and extraction procedures;
b) Accessing and extracting data only within the scope of granted rights and necessary for the specified purpose.
4. State agencies must issue technical procedures for accessing and extracting data within their management scope, including the following main contents:
a) Information registration management;
b) Access and extraction permission management;
c) History of access and extraction management;
d) Access and extraction tool management.
Article 7. Supporting Data Owners to Connect and Share Data with State Agencies
State agencies implement measures to support data owners in connecting and sharing data with state agencies, including:
1. Building information systems to ensure data connection and sharing; protecting and using shared data in accordance with the determined purposes.
2. Developing processes, applications, and software to enable data owners to exercise their rights over data provided to state agencies as prescribed by law.
3. The Minister, Head of a ministry-level agency, agency under the Government, Chairman of provincial People's Committees directly under the central government decides on supporting data owners, including:
a) Supporting connectivity infrastructure; supporting tools to ensure technical standards for connectivity and sharing; supporting infrastructure, security, and safety;
b) Supporting funding to ensure connectivity and sharing; supporting compensation for costs of creating and collecting data according to state agency standards;
c) Supporting human resources for data connectivity and sharing; supporting training and capacity building for data connectivity and sharing;
d) Other forms of support.
Article 8. Providing Data to State Agencies
1. Encouraging individuals and organizations to voluntarily share and provide their data to state agencies for common benefits such as healthcare, climate change, traffic improvement, facilitating the compilation and dissemination of official statistics, improving public service delivery, policy planning, or scientific research purposes. Organizations and individuals share and provide data based on the consent of the data subject for processing personal data related to them or the permission of the data owner to use non-personal data.
2. State agencies request organizations and individuals to provide data in accordance with Clause 2, Article 18 of the Data Law as follows:
a) Issuing a written request or another form ensuring confirmation of the data provision request specifying the type of data, level of detail, volume of data, frequency of data access, method of providing data, legal basis, grounds, reasons for the request, purpose of data use, duration of use and required provision time, planned data processing activities;
b) Notifying organizations and individuals requested to provide data about sanctions that will be applied if the request is not fulfilled.
3. Handover and receipt of requested data
a) The handover and receipt of data shall be carried out in accordance with the specified object, time, type of data, level of detail, volume of data, frequency of data access, and method of providing data as requested;
b) Participants in the handover and receipt of data include the data owner, a legally authorized representative or a person legally managing and using the data; individuals or representatives of organizations entrusted with managing and using the data;
c) The handover and receipt of data must be documented in a record;
d) The party requesting data provision may require the data provider to supplement data if the handed-over data does not match the scope of the requested data.
4. Revocation of Data Provision Requests
a) Data provision requests are revoked in cases where the request for data provision contravenes the provisions of the Data Law and other relevant laws; the data provision request has not been implemented but the conditions for data provision stipulated in Clause 1, Article 18 of the Data Law no longer exist; the data provision request has not been implemented but due to objective reasons the data no longer exists;
b) The revocation of data provision requests must be expressed in writing.
5. Request to Amend or Withdraw Data Provision Requests
a) Before the deadline for providing data, the data owner, a legally authorized representative, or a person legally managing and using the data may request the competent authority to amend or withdraw the data provision request;
b) The data owner and data manager may request to amend or withdraw the data provision request in cases where the data provision request contravenes the provisions of the Data Law and other relevant laws; the scope of data managed by the data owner and data manager does not fall within the data provision request; due to objective reasons the data no longer exists.
6. Authority to Request Data Provision The Minister, Head of a ministry-level agency, Chairman of the People's Committee of a province or centrally governed city, Director of the National Data Center, Director of the Provincial Police Department or centrally governed city police department have the authority to request data within their respective duties and powers.
Article 9. Confirmation and Verification of Data
1. Data confirmation shall be carried out as follows:
a) Data collected and updated into the national database, specialized database, or other databases shall be confirmed by the data owner or manager;
b) Data confirmation between state agencies and political-social organizations shall be conducted through cooperation regulations and connection, sharing, and provision methods for data;
c) In cases not provided for in points a and b of this clause, data confirmation shall be carried out according to agreements between data users and data owners or managers, or other organizations as prescribed by law;
d) The data owner or manager shall be responsible for the quality, reliability, and legality of the data they provide and confirm, and shall establish procedures, forms, and organize data confirmation activities.
2. The data owner or manager shall be responsible for establishing procedures, forms, and organizing verification activities within their ownership and management scope.
3. The scope and time of data verification shall be decided by the data owner.
4. Data confirmation and verification shall be carried out in accordance with laws on electronic verification and related laws.
Article 10. Public Disclosure of Data
1. Open data disclosure shall be implemented immediately after the data is classified as open data. The data owner or manager shall disclose open data in the following forms:
a) National Data Portal;
b) Open data portals, electronic information portals of ministries, sectors, localities, and other systems and platforms;
c) Intermediary systems serving data connection, sharing, or other forms as prescribed by law.
2. State agencies shall be responsible for announcing the list of open data and organizing the public disclosure of open data under their management, and submitting it to the Ministry of Public Security for consolidation and publication on the National Data Portal.
3. Data of state agencies that are not prohibited from being disclosed due to national security, privacy, trade secrets, or other reasons as prescribed by law must be disclosed as open data.
4. State agencies shall develop and implement decisions to announce open data, including determining the list of open data to be announced, mechanisms for collecting and analyzing feedback from individuals and organizations regarding the use of open data; evaluating the quality, usability, and compliance with relevant laws concerning open data.
Article 11. Encryption and Decryption of Data
1. Agencies, organizations, and individuals may use one or more encryption solutions and decryption processes suitable for their data governance and management activities, including:
a) Data encryption solution when transmitting data;
b) Data encryption solution when storing data;
c) Data encryption solution on digital devices;
d) Hardware security measures to prevent unauthorized access and ensure that encryption/decryption operations are only performed in a secure environment;
đ) Decryption process requiring authentication of the identity of the person decrypting the data, determining, and granting access rights to encrypted data;
e) Recording solutions for encryption and decryption activities to ensure legality, transparency, fairness, and facilitate inquiries;
g) Other solutions and processes as prescribed by law.
2. The Minister of Public Security shall decide or delegate the decision-making authority to apply measures to decrypt data in cases specified in Clause 4, Article 22 of the Law on Data without the consent of the data owner or manager, except in cases involving military or defense areas.
3. The Minister of Defense shall decide or delegate the decision-making authority to apply measures to decrypt data related to military or defense in cases specified in Clause 4, Article 22 of the Law on Data without the consent of the data owner or manager.
Article 12. Transfer and Processing of Cross-border Data
1. The data owner and data manager shall conduct an impact assessment in accordance with Clause 2 of this Article when transferring or processing core data and important data across borders. The impact assessment for transferring core and important data abroad to foreign organizations or individuals shall be conducted once during the operational period of the organization or enterprise and updated or supplemented in accordance with Clause 8 of this Article.
2. The data transferor must assess the following issues:
a) The legality, necessity, scope, method of transmitting data, and the way the data recipient processes the data;
b) Risks that the transfer of data may cause to national defense, security, economic activities, diplomacy, social stability, public interest, or the rights and legitimate interests of individuals or organizations; risks of data being falsified, destroyed, leaked, lost, or used illegally;
c) Responsibilities and obligations, management and technical measures of the data recipient;
d) Other related issues.
3. The agreement between the data transferor and the data recipient must clearly specify:
a) The purpose, method, and scope of exporting data, the purpose and method of processing data by the data recipient;
b) The location and time of storing data, methods of handling data after the storage period expires or the agreed objectives are completed;
c) Requirements binding the data recipient regarding providing transferred data to third parties;
d) Data protection measures the data recipient will use;
đ) Measures to remedy consequences, compensate for damages, handle breaches of contract, and resolve disputes arising from the failure to protect data;
e) Responsibilities of the parties in processing data.
4. The documentation for assessing the impact of cross-border data transfer and processing includes the Report on Impact Assessment of Cross-border Data Transfer and Processing (in Form No. 02 issued together with this Decree) and other relevant documents.
5. In cases where the data transferred and processed abroad is core data:
a) The data transferor sends the documentation for the impact assessment of cross-border data transfer and processing to the Ministry of Public Security; if it pertains to military or defense areas, it should be sent to the Ministry of National Defense;
b) The responsible unit under the Ministry of National Defense or the Ministry of Public Security receives the documentation to check its completeness and validity. If the documentation is incomplete, they request the data transferor to supplement and complete it;
c) The responsible unit under the Ministry of National Defense or the Ministry of Public Security completes the evaluation of the impact assessment documentation for cross-border data transfer within ten days from the date of receiving the complete and valid documentation; in complex cases requiring verification and inspection, not exceeding fifteen days;
d) The data transferor must be notified in writing about the evaluation results. After receiving the satisfactory evaluation result, the data manager decides on the transfer of core data abroad and cross-border data processing.
6. In cases where important data needs to be transferred and processed across borders: The data transferor must prepare the documentation for the impact assessment before transferring and processing cross-border data to serve the inspection and evaluation activities of the Ministry of Public Security or the Ministry of National Defense if necessary (without prior approval from the competent authority). The data transferor submits one original copy of the documentation to the Ministry of Public Security or the Ministry of National Defense according to the form issued together with this Decree at least fifteen days before processing the data.
7. The competent authority's impact assessment focuses on evaluating the risks that cross-border data transfer and processing activities may cause to national security, public interest, or the rights and legitimate interests of individuals and organizations, mainly including the following issues:
a) The legality, necessity of the purpose, scope, and method of transferring and processing data;
b) The impact of the data protection policies and regulations and cybersecurity environment of the country or region of the data recipient on data confidentiality; the level of data protection by the data recipient compared to Vietnamese technical standards and norms;
c) The scale, scope, type of data, risks of falsification, destruction, leakage, loss, transfer, or illegal use after transfer;
d) Responsibilities and obligations of the related parties;
đ) Other issues affecting national defense, security, protection of national interests, public interest, and the rights and legitimate interests of data subjects and data owners as stipulated by Vietnamese law and international treaties to which the Socialist Republic of Vietnam is a party.
8. Cases where the data transferor must amend and supplement the documentation for the impact assessment of cross-border data transfer and processing include:
a) When there is a change in the purpose, method, scope, type of data transferred or processed, or a change in the purpose or method of processing data by the data recipient, affecting data security; extending the storage period of core data and important data;
b) Changes in data protection policies and cybersecurity environments in the country or region where the data recipient is located, changes in the actual control rights of the data transferor or recipient, and other impacts on the confidentiality of transferred data.
9. The Ministry of National Defense and the Ministry of Public Security decide to require the data transferor to stop the operation of transferring and processing core data and important data in the following cases:
a) Core data and important data transferred and processed abroad are used in activities infringing upon national defense, security, national interests, public interest, or the rights and legitimate interests of data subjects and data owners as stipulated by Vietnamese law and international treaties to which the Socialist Republic of Vietnam is a party;
b) The data transferor does not comply with the provisions of this Article;
c) There are violations of data protection regulations.
10. The quantification of core data and important data when transferring and processing cross-border data shall be determined based on the cumulative amount of data that has been transferred and processed cross-border, with the time period calculated from July 1, 2025 to the point of transfer and processing of data.
11. Cases where the transfer and processing of core data cross-border do not require approval from the competent authority as stipulated in Clause 5 of this Article, and cases where the transfer and processing of important data do not need to be reported to the competent authority as prescribed in Clause 6 of this Article include:
a) In emergency situations where it is truly necessary to provide personal data abroad to protect the life, health, and property safety of individuals; to fulfill tasks and obligations as prescribed by law;
b) Implementing cross-border human resource management according to labor rules, regulations, and collective labor agreements as prescribed by law;
c) Cases where it is truly necessary to provide data for the purpose of concluding or performing contracts, including cases involving cross-border transportation, logistics, money transfers, payments, opening bank accounts and hotels, visa applications, and inspection services.
12. In cases where the transfer and processing of core data and important data are carried out as prescribed in Clause 11 of this Article, an impact assessment must be submitted to the Ministry of Public Security (or the Ministry of National Defense for data managed by the Ministry of National Defense) within fifteen days from the date of implementation, as stipulated in Clause 4 of this Article.
Article 13. Other activities in data processing
1. Retrieval, deletion, destruction of data
a) Retrieval of data involves requesting the transfer back of data and implementing the deletion or destruction of provided data, or requesting the cessation of data processing and usage if deletion or destruction is not possible. Deletion of data is the activity of removing data from the storage structure and environment. Destruction of data is the activity of removing data from the storage structure and environment and ensuring its irrecoverability through overwriting or physical destruction.
b) The deletion and destruction of data must be completed within seventy-two hours after the data subject's request, and the results of the retrieval, deletion, and destruction of data must be notified to the data owner, except where otherwise provided by law. If deletion or destruction of data is not possible, the data owner and manager must cease processing and using the data.
2. Adjustment and updating of data involve supplementing or modifying one or more records in the database or information system.
Chapter III
DATA MANAGEMENT, PROTECTION
Article 14. Data Management and Administration
3. Agencies managing databases shall develop detailed frameworks for data management and administration, which shall include the following main contents:
a) Mechanisms for managing master data and shared code tables;
b) Mechanisms for managing data processing activities; plans for expanding and backup storage of data;
c) Evaluation of data quality; application of technical standards and norms regarding data quality, connection, and sharing;
d) Mechanisms for managing data description information (metadata);
đ) Data architecture and models;
e) Connection and sharing mechanisms;
g) Data protection mechanisms;
h) Development, exploitation, and utilization mechanisms;
i) Implementation, control, and monitoring mechanisms.
4. Management of master data and shared code tables
a) Agencies managing databases shall issue lists of master data and shared code tables in coordination and agreement with the Ministry of Public Security;
b) Contents of master data management include principles for assigning unique identifiers; basic information to describe, identify, and distinguish specific objects within master data; procedures for creating, updating master data; selection of technologies and tools to ensure accurate, consistent, and complete collection, updating, exploitation, and use of master data; implementation of creation, updating, and management of master data; connection and sharing of master data with the National Comprehensive Database; cooperation with the Ministry of Public Security to monitor and reconcile to ensure the quality of master data across the entire system;
c) Master data in the national database and other databases of agencies responsible for creating and managing master data have official usage value equivalent to paper documents provided by authorized agencies;
d) The Ministry of Public Security shall establish a policy for managing master data integrated into the National Comprehensive Database; develop procedures for collecting, updating, deleting, using, sharing, and coordinating master data in the National Comprehensive Database; clearly define roles and responsibilities for the quality and integrity of master data; monitor the quality of master data.
5. State agencies implementing national database and specialized database information technology projects must seek the opinion of the Ministry of Public Security (National Data Center) on the content of building, developing, protecting, managing, processing, and utilizing data to avoid waste and ensure uniformity and synchronization in implementation.
Article 15. Determination and Management of Risks Arising from Data Processing
1. Types of risks arising from data processing include:
a) Privacy risk arising from non-compliance with legal provisions on the privacy rights of data subjects during data processing and transfer;
b) Cybersecurity risk arising from the failure to apply necessary measures to protect non-public data from unauthorized access from external entities or leakage of data to the outside;
c) Identification and access management risk arising from the failure to ensure protection of non-public data from unauthorized access;
d) Other risks in data processing include: data sharing risk occurring when there is no ability to maintain control over shared data; data management risk due to the quality of data not being guaranteed.
2. Some preventive measures for risks arising from data processing include:
a) Regularly backing up data and ensuring security;
b) Periodically maintaining, servicing, upgrading systems to maintain and improve system performance, features, security, and consistency; implementing recovery measures to ensure system continuity;
c) Implementing data protection measures as prescribed;
d) Strictly classifying access rights for each type of data to prevent unauthorized data access;
đ) Using monitoring and intrusion detection systems to track network activities and detect abnormal behavior or unauthorized access;
e) Installing and maintaining security software;
g) Conducting annual risk assessments to identify system vulnerabilities and applying corresponding preventive measures;
h) Developing contingency plans to proactively and promptly respond to and resolve incidents;
i) Training, enhancing, and instructing skills in data protection, recognizing threats, handling security risks; regularly conducting drills to prevent incidents, monitor, detect, and ensure timely response and resolution of incidents;
k) Other measures as prescribed by law.
Article 16. Data Protection
1. State agencies have the responsibility to organize management and protection of data within their jurisdiction, including establishing management systems, supervision, risk assessment, and early warning throughout the entire data processing process; implementing appropriate classification and access authorization for different types of data, ensuring compliance with general data protection policies. Non-state data controllers are encouraged to establish their own regulations on data protection.
3. Data controllers providing or entrusting the processing of core data and important data to organizations or individuals not covered by Article 12 of this Decree must meet the following requirements:
a) Agree with the receiving party on the purpose, method, scope, and security obligations through contracts and supervise the implementation of the receiving party's obligations. Records of the processing of important data provided or entrusted to other receiving parties must be stored for at least three years;
b) When providing or entrusting the processing of core data and important data, data controllers need to implement encryption, digital signatures, and other security measures to ensure confidentiality, integrity, and non-repudiation;
c) The receiving party of core data and important data must fulfill the obligation to protect data and process core data and important data according to the agreed purpose, method, and scope.
4. Data protection measures include:
a) Management related to data processing includes: establishing policies, regulations, criteria for assessing data safety and security to ensure compliance with technical standards, data protection regulations, and other management measures prescribed by law;
b) Technical measures related to data processing: ensuring physical security, access control, cybersecurity checks, and other technical measures prescribed by law;
c) Human resource management for data protection: establishing human resource management regulations, training personnel for data protection;
d) Other data protection measures as prescribed by law.
Article 17. Data protection management during processing
1. The data controller must establish a system for managing data protection throughout the entire data processing process.
2. The data controller shall implement measures to protect data during the collection and creation of data. For core data and important data, the data controller must carry out the following contents:
a) Establish a data collection and creation process and evaluate, apply protective measures before collecting and creating data;
b) Verify the authenticity, monitor the quality of data, and trace the origin of data.
3. The data controller shall store data according to the methods and time limits prescribed by law. For core data and important data, the data controller must carry out the following contents:
a) Establish a data storage process, including provisions on backup, recovery procedures, logging of storage, backup, and recovery operations;
b) Establish a data storage management system and apply technical tools and measures to protect data during storage, automatically performing backup and recovery operations;
c) Implement deletion and destruction of data when the retention period has expired or the data is no longer necessary for the processing purpose.
4. When processing and using core data and important data, the data controller must carry out the following:
a) Develop and implement access and retrieval regulations ensuring compliance with minimum privilege principles during processing and use of data;
b) Establish a data access control system, including setting up a unified access management and identification platform; applying technical measures to protect data and control access and retrieval during processing and use of data.
5. The data controller is responsible for clarifying the scope, purpose, process, establishing protection regulations, and implementing protective measures based on the classification, level, and application scenarios of data provided externally.
6. The data owner must analyze and assess the impact on national defense, security, foreign relations, macroeconomic stability, social stability, public health, and community safety before publicly disclosing data.
7. The data owner and data controller must develop plans for deleting and destroying data, clarify objectives, rules, processes, techniques for deletion and destruction, record and retain activities of deletion and destruction. In cases of deleting and destroying important data and core data, the data controller must provide documentation proving that the deletion and destruction activities ensure irreversibility.
8. If the data controller needs to transfer data due to restructuring, dissolution, or bankruptcy, they must clarify the data transfer plan and notify affected agencies, organizations, and individuals. In cases of restructuring or dissolving organizations managing core data and important data, the data controller must implement security measures, report data handling plans, and the name or information of the receiving party to the relevant competent authority.
9. If the data controller entrusts another organization or individual to perform data processing activities, they must clarify the responsibilities and confidentiality obligations of both the entrusting party and the entrusted party through contracts or agreements. In cases of entrusting the processing of important data and core data, the entrusting party must verify the capacity and expertise of the entrusted party in data protection.
10. The data controllers of core data and important data must log all data processing activities throughout the entire data processing process. Logs must be retained for at least six months.
11. The data controllers of core data and important data must annually conduct risk assessments of core data and important data processing activities within their management scope, prepare Risk Assessment Reports according to the form issued together with this Decree, and always have them available for inspection and assessment activities by competent authorities, except where Border Crossing Data Transfer and Processing Impact Assessment Files have been established in accordance with Article 12 of this Decree. The Risk Assessment Report includes:
a) Basic information about the data controller, information about the department responsible for data security, the name and contact information of the person responsible for data protection;
b) Purpose, type, quantity, method, scope, storage period, storage location of data, data processing activities, and circumstances under which such activities are carried out;
c) Data protection management system, technical encryption, backup, labeling, access control, authentication measures, and other necessary measures;
d) Identified data security risks, occurred security incidents, and resolution methods;
đ) Other reporting contents as required by relevant competent authorities.
Article 18. Personnel Management and Training for Data Protection
1. Data owners and core data managers, important data managers must identify the person responsible for data protection and the data security department.
2. The person responsible for data protection has the functions and tasks of managing and protecting core data and important data, including organizing the development of important data security plans, risk assessments; directly reporting on data protection situations to competent authorities as prescribed; must be trained and provided with knowledge about data protection.
3. The data security department has the following functions and tasks:
a) Developing and implementing a data protection management system, operational procedures, emergency response plans for data protection incidents;
b) Regularly organizing and conducting activities such as monitoring data security risks, risk assessments, emergency drills, awareness campaigns, training, promptly addressing data security risks and incidents;
c) Researching and proposing decisions related to core data protection and important data protection;
d) Receiving and processing reports on data protection from units.
4. Data owners and core data managers, important data managers must implement:
a) Clarifying management security requirements in recruitment, use, training, introduction, rotation, resignation, evaluation, and selection of personnel;
b) Not assigning individuals with criminal records in the field of information technology, telecommunications networks to be responsible for data protection;
c) Signing confidentiality agreements with data processing employees.
5. Building and implementing annual training programs on data protection.
6. The person responsible for data protection agrees with the data owner and manager on exemptions from liability in cases where damage occurs to protected data.
Article 19. Data Security Monitoring, Early Warning, and Emergency Management
1. The contents of data security monitoring, early warning, and emergency management include:
a) Establishing a mechanism for monitoring data security risks;
b) Organizing the drafting of monitoring interfaces and standards;
c) Building a reporting and information sharing mechanism for data security risks, uniformly collecting, analyzing, evaluating, and reporting data security risk information;
d) Building an emergency response plan for data security incidents.
2. The Ministry of Public Security implements data security monitoring, early warning, and emergency management except for the content stipulated in Clause 3 of this Article.
3. The Ministry of National Defense implements data security monitoring, early warning, and emergency management for data within its jurisdiction.
4. Data managers have the responsibility:
a) Timely informing the data owner about potential data security incidents that may harm the rights and legitimate interests of individuals and organizations and proposing measures to minimize losses;
b) After a data security incident occurs, promptly implementing emergency responses according to the emergency response plan, reporting relevant security incidents involving important data and core data to the Ministry of Public Security and the Ministry of National Defense as soon as possible.
5. The Ministry of Public Security establishes a mechanism for monitoring data security risks, builds monitoring and early warning standards for data security, collaborates in building technical means for monitoring and early warning of data security, forms capabilities for monitoring, early warning, handling, tracing origins, and enhancing information sharing with relevant departments. Data managers must monitor data security risks, promptly investigate potential security risks, and apply necessary measures to prevent data security risks.
6. The Ministry of Public Security builds a mechanism for reporting and sharing information on data security risks, uniformly collecting, analyzing, evaluating, and reporting data security risk information, encouraging service providers and scientific research organizations to share information on data security risks. Data managers must summarize and analyze separately the security risks within their management scope, and promptly report significant security risks that could cause major security incidents to the Ministry of Public Security.
7. The Ministry of Public Security builds an emergency response plan for data security incidents, including organizational structure and responsibilities, classification and grading of data security incidents, monitoring and early warning, emergency response procedures, protective measures, and organizing and coordinating responses to important data incidents and core data security.
8. Data managers conduct regular emergency drills for important and core data security incidents every six months, keeping drill records, summarizing drill reports, and promptly updating contingency plans based on significant changes in the data processing system or external environment.
Chapter IV
NATIONAL DATA CENTER, NATIONAL COMBINED DATABASE
Article 20. National Data Center Infrastructure
1. The information system of the National Data Center shall be separate from the development, testing, and trial systems; ensuring security and confidentiality at different levels to control, detect, and prevent risks of information security breaches.
2. The National Data Center shall construct and develop cloud computing infrastructure and deploy it into functional zones to meet the needs of state agencies, ensuring the development of integrated and synchronized subsystems, data exploitation, and high-level information security requirements.
3. The National Data Center shall establish high-performance computing infrastructure and a data analysis system to serve management work with predictive analysis models serving the exploitation of the National Comprehensive Database. It shall provide technical conditions to support research and development in applied mathematics fields; assist in the construction of mechanisms, policies, planning, and national development strategies, products, and services related to data for economic and social development.
4. The National Data Center shall establish the National Data Portal as the central point for state agencies to publish information on managed data types; publish open data and provide open data to enhance transparency in government operations and promote innovation, economic, and social development; for organizations and individuals to provide data for common benefit purposes, improve public service delivery, policy-making, or scientific research for common benefits; and to serve the access, search, exploration, and use of open data by agencies, organizations, and individuals.
5. The National Data Center shall build applications on digital devices to serve the exploitation and use of National Data Center data, provide data products and services, and develop other utilities to serve agencies, organizations, and individuals.
6. The National Data Center shall establish a communication system with individuals and organizations to serve the activities of the National Data Center.
7. The National Data Center shall provide the following types of services:
a) Infrastructure station house, server placement space, providing infrastructure space, power supply, air conditioning, and related equipment for deploying information systems and databases, allowing database managers, agencies, and organizations with needs to proactively use and control their own systems, either through shared space usage or dedicated areas, in compliance with regulations on managing and operating the National Data Center;
b) Server provision, network equipment, network security, cybersecurity, data protection, or storage services with diverse configurations and corresponding placement spaces at National Data Centers, meeting the needs of database managers, agencies, and organizations with requirements;
c) Deployment and operation of technical infrastructure to serve national databases and information systems, databases, and other information systems.
8. State agencies and political-social organizations shall determine the type of service provided by the National Data Center as stipulated in Clause 7 of this Article, ensuring compatibility with current status, operational requirements, regulations on investment projects using state budget funds, and submit a request document to the National Data Center for service provision. The request document must clearly define the need for National Data Center services; the scale of the system expected to be placed at the National Data Center; and the human resource requirements for supporting management and operation of the infrastructure and information systems.
9. The Minister of Public Security shall guide the provision and deployment of National Data Center services when sufficient infrastructure conditions are met.
Article 21. Responsibilities of the National Data Center
1. Guide agencies, organizations, and individuals in applying technical standards and norms related to data within the scope of the National Data Center.
2. Implement measures for monitoring and evaluating the quality of shared and synchronized data at the National Data Center.
3. Coordinate national integrated database data.
4. Implement protective measures for data from the outset and throughout the data processing process as stipulated in Clause 6, Article 16 of this Decree.
5. Sign agreements and memoranda of understanding with international agencies to promote international cooperation in managing, protecting data, scientific research, cross-border data transfer, training, and enhancing capabilities and qualifications related to data to promote innovative activities and technology transfer serving economic and social development.
6. Assist the Ministry of Public Security in state management of data.
Article 22. Ensuring Resources for Building and Developing the National Data Center
1. The National Data Center develops plans, programs for training, international cooperation, and improving the quality of human resources at the National Data Center.
2. Staff working at the National Data Center shall be entitled to a daily support allowance of VND 500,000 from the revenue generated from the exploitation and use of data in the National Integrated Database after being paid into the State budget. Publicly owned organizations under the National Data Center may apply this support system to determine benefits for personnel engaged in specialized data work.
3. The Minister of Public Security shall issue a list of job positions at the National Data Center; establish mechanisms to attract, utilize, and reward high-quality human resources working at the National Data Center.
Article 23. Exploitation and Use of the National Integrated Database
1. Exploitation through direct connection and information sharing with the National Integrated Database
a) The National Data Center provides accounts to agencies and organizations to access and exploit information in the National Integrated Database;
b) Agencies and organizations provided with accounts by the National Data Center shall be responsible for establishing and managing their own accounts on their information systems connected to the National Integrated Database and assigning usage rights to individuals under their management according to their assigned functions and tasks;
c) Individuals granted usage rights to their organization's account may use that account to search and exploit citizen-related information in the National Integrated Database through their organization's information system;
d) The information system of the agency or organization sends exploitation requests to the National Integrated Database via the account provided by the National Data Center. The exploitation results are presented in paper or electronic form and stored in the connected, shared, and exploited information system;
đ) The National Data Center is responsible for verifying account information and providing exploitation results in accordance with the account's authority and scope of exploitable information.
2. Agencies, organizations, and individuals exploit information in the National Integrated Database through the National Data Portal, the National Public Service Portal at the National Data Center, and equipment, means, and software as directed by the Ministry of Public Security.
3. Agencies, organizations, and individuals exploit information in the National Integrated Database through electronic portals, administrative procedure resolution information systems as directed by ministries, ministerial-level agencies, government agencies, provincial people's committees, and centrally governed city people's committees.
4. Exploitation by submitting a written request for information exploitation and provision
a) Agencies, organizations, and individuals submit a written request for information exploitation and provision in the National Integrated Database and send it to the National Data Center;
b) The written request for information exploitation and provision must clearly state the purpose, content, and scope of information to be exploited in the National Integrated Database and commit to responsibility in using the information when it is exploited and other relevant information;
c) Within three working days from the date of receipt of the written request for information exploitation in the National Integrated Database, the authorized person reviews and decides whether to allow information exploitation;
d) In case of agreement to allow information exploitation, a written response and provision of information to the agency, organization, or individual is issued. In case of disagreement to allow information exploitation, a written response stating the reasons must be issued.
5. The National Integrated Database serves the implementation of administrative procedures:
a) Automatically implement administrative procedures and policies for individuals and organizations when the information and data required for administrative procedure examination and resolution are fully available in the National Integrated Database. Agencies and authorized persons proactively resolve administrative procedures and policies for individuals and organizations based on the connected, shared, and exploited information from the National Integrated Database and with the consent of the individuals and organizations;
b) Exploit, reuse data, and build centralized online public services on the National Public Service Portal, ensuring simplicity, smoothness, convenience, user-friendliness, cost-effectiveness, and efficiency.
c) Connecting, sharing data between the National Integrated Database and the administrative procedure handling information system at the ministerial and provincial levels to serve the acceptance and processing of administrative procedures for individuals and organizations, ensuring that individuals and organizations are not required to report or provide again information and documents already available in the National Integrated Database; synchronizing all digitalized file data and administrative procedure handling results from the administrative procedure handling information systems at the ministerial and provincial levels, national and specialized databases managed by ministries, agencies, and localities with the National Public Service Portal and the National Integrated Database to facilitate data exploitation and reuse, ensuring that individuals and organizations only need to provide information, data, and documents once to state agencies when implementing administrative procedures and public services.
Article 24. Connecting and Sharing Data with the National Integrated Database
1. The managers of state agency databases, when building databases connected to the National Data Center, shall be responsible for complying with the guidance of the National Data Center to ensure connection and data sharing.
2. The National Data Center and the database management agencies shall establish agreements on data connection and sharing, including the following contents:
a) Purpose of data sharing;
b) Scope of shared data;
c) Methods of connecting and sharing data;
d) Time and frequency of data sharing;
đ) Other related contents.
3. Methods of data sharing
a) Data sharing between state agency databases shall be carried out through the National Data Sharing and Coordination Platform and other integrated and shared data platforms;
b) Data sharing between organizations and individuals and the National Integrated Database shall be conducted through the data sharing and coordination platform, data gateways, files, and other methods according to the agreement between the parties;
4. The National Data Center shall monitor data sharing activities through a monitoring system to evaluate data provision and usage.
Article 25. Provision of Data to the National Integrated Database
1. Organizations and individuals that are not state agencies shall provide data to the National Integrated Database through agreements with the National Data Center. The data provision agreement must clearly define the purpose of providing data; scope of provided data; method of data provision; time and frequency of provision, and related contents.
2. Responsibilities of the database management agency in providing data to the National Integrated Database
a) Synchronizing data to the National Integrated Database in accordance with Clause 1, Article 34 of the Data Law;
b) Synchronizing master data and data serving administrative procedure handling on the National Public Service Portal within their jurisdiction immediately upon any adjustment or update in the National Integrated Database;
c) For other data, synchronization shall be carried out upon adjustment or update according to the agreement with the National Data Center.
3. The National Data Center shall coordinate with the database management agency to implement appropriate technical measures to ensure that when master data changes, corresponding data in reference databases must be synchronized accordingly.
Chapter V
RESPONSIBILITIES OF AUTHORITIES AND ORGANIZATIONS
Article 26. Responsibilities of the Ministry of Public Security
1. To take the lead and coordinate with relevant agencies to organize the implementation, guidance, inspection, and supervision of this Decree.
2. To take the lead and coordinate with relevant agencies to manage activities related to construction, development, protection, management, processing, and utilization of data; ensure data security, combat and prevent criminal acts and violations of laws in the field of data; manage, monitor, and supervise business operations of products and services related to data as prescribed by this Decree.
3. To take the lead and coordinate with relevant agencies to implement the construction of the National Data Center that meets the regulations, standards, and technical norms for data centers.
4. To take the lead in drafting, promulgating, or submitting to competent state authorities for promulgation and guiding the implementation of normative legal documents to guide the implementation of laws on data.
5. To take the lead and coordinate with the Ministry of Justice, the Government Office, the Ministry of Science and Technology, and other relevant agencies to review, compile, and propose recommendations to the Government to direct ministries, agencies, and localities to build, amend, and supplement related documents for the implementation and operation management of the National Data Center.
6. To organize the connection, sharing, and coordination of data between information systems and databases of agencies, organizations, and individuals with the National Comprehensive Database through the National Data Sharing and Coordination Platform.
7. To ensure the information technology infrastructure for Party and State agencies, social-political organizations to serve the management, administration, and processing of data within the scope of management at the National Data Center.
8. To take the lead and coordinate with the Ministry of Science and Technology to appraise, evaluate, inspect, support monitoring, and coordinate responses to cyber security incidents and information security during the construction, deployment, and operation of information systems and databases at the National Data Center.
9. To take the lead and coordinate with the Ministry of Science and Technology to establish technical standards and guidelines regarding organization, connection, sharing, and synchronization of data with the National Data Center.
10. To establish architectural standards for software systems at the National Data Center.
11. To guide the classification of data of Party and State agencies, social-political organizations; organize and direct training and capacity building on specialized knowledge and skills in data nationwide.
12. To establish and operate the National Data Portal.
13. The Minister of Public Security shall decide the level of funding for activities supporting financial assurance for connectivity and sharing; support compensation for costs incurred in creating and collecting data based on consensus with the Minister of Finance and the Minister of Science and Technology.
Article 27. Responsibilities of the Ministry of National Defense
1. To be responsible before the Government for performing state management tasks over data within its jurisdiction.
2. To coordinate with the Ministry of Public Security and relevant agencies and organizations to deploy appropriate forces and means to detect and prevent from afar all acts of intrusion into the National Data Center both geographically and in cyberspace.
3. To take the lead in managing activities related to data storage, protection, ensuring data security; manage, monitor, and supervise, organize the connection, sharing, and coordination of data between information systems and databases; apply science in processing, managing, exploiting, and using data; manage and issue permits for transferring data abroad; utilize the national data development fund for data under the jurisdiction of the Ministry of National Defense.
Article 28. Responsibilities of the Ministry of Science and Technology
1. Guide Party agencies, State agencies, political-social organizations to develop and improve information technology infrastructure and the establishment of technical standards and norms regarding organization, connection, sharing, synchronization of data; implement standardization, connection, and sharing of data, optimal calculation between new infrastructure investment and the use of infrastructure provided by the National Data Center.
2. Review and evaluate the capacity of specialized data transmission networks of agencies to develop plans for upgrading to ensure units can access and manage systems located at the National Data Center through specialized data transmission networks.
3. Coordinate with the Ministry of Public Security and relevant agencies in researching and applying digital technologies and data to form products and services serving the development of digital government, digital administration, and socio-economic development through key national science and technology programs.
4. Coordinate with the Ministry of Public Security to determine funding levels for activities supporting connectivity and sharing costs; support compensation for costs incurred in creating and collecting data.
Article 29. Responsibilities of the Government Office
1. Lead in establishing functional requirements, business processes, user interfaces; assist and guide ministries, sectors, localities in handling issues related to functions, business processes, and data of the National Public Service Portal; coordinate with the Ministry of Public Security to manage and operate the National Public Service Portal at the National Data Center; perform other tasks related to the development of the National Public Service Portal according to the Government's requirements.
2. Coordinate with the Ministry of Public Security and relevant units to assess needs and implement the transition of information technology infrastructure for systems serving government guidance and management.
Article 30. Responsibilities of the Government Cryptographic Agency
1. Lead in coordinating with relevant units to deploy encryption and decryption products.
2. The Government Cryptographic Agency assists the Minister of Defense in performing state management responsibilities for cryptographic data.
3. Coordinate with the Ministry of Public Security to implement solutions ensuring information security, authentication, and encryption; deploy specialized government digital signature services for information systems and databases of Party agencies, State agencies, and political-social organizations.
Article 31. Responsibilities of the Ministry of Finance
1. Coordinate with the Ministry of Public Security to determine funding levels for activities supporting connectivity and sharing costs; support compensation for costs incurred in creating and collecting data.
2. Issue Circulars stipulating fees for exploiting and using information in the national consolidated database, national databases, and specialized databases based on proposals from ministries and ministerial-level agencies.
Article 32. Responsibilities of Ministries, Ministerial-Level Agencies, Government Agencies, and People's Committees of Provinces and Central Cities
1. Lead and coordinate with the Ministry of Public Security, the Ministry of Defense, and relevant agencies to manage activities related to data collection, updating, adjustment, copying, sharing, transfer, deletion, storage, and protection within their jurisdiction.
2. Synchronize data under their jurisdiction to the National Data Center in accordance with this Decree and coordinate with the Ministry of Public Security to monitor and reconcile to ensure the accuracy of the data.
3. Ministries, sectors, and localities coordinate with the Government Office, the Ministry of Public Security, and relevant units to restructure processes, amend legal documents according to the schedule for data collection, updating, and synchronization to the National Consolidated Database.
4. Upgrade, maintain, and repair agency infrastructure and equipment when using infrastructure from the National Data Center.
5. Propose to the Ministry of Finance the levels of collection, payment, exemption, reduction, management, and use of fees for exploiting and using information in the national consolidated database, national databases, and specialized databases within their sectoral and field management.
Chapter VI
IMPLEMENTING PROVISIONS
Article 33. Effective Date
This Decree takes effect from July 1, 2025.
Article 34. Responsibility for Implementation
Ministers of ministries, Heads of ministerial-level agencies and government agencies, Chairmen of provincial and central city people's committees, and related agencies, organizations, and individuals are responsible for implementing this Decree.
|
|
PRIME MINISTER DEPUTY PRIME MINISTER DEPUTY PRIME MINISTER |
|
|
(Signed) |
|
|
Nguyen Chi Dung |
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.