Decree No. 169/2025/NĐ-CP on scientific activities, technology, innovation, and data products and services

This Decree stipulates the authority, application forms, and procedures for issuing business condition certificates for activities related to data platforms, data intermediaries, and comprehensive data analysis. Specifically as follows:

Document No.169/2025/NĐ-CP
Document typeDecree
Issuing authorityMinistry of Public Security
Signed byNguyễn Chí Dũng — Phó Thủ tướng Chính phủ
Updated12/06/2026
FieldUncategorized
Issued date30/06/2025
Effective date01/07/2025
Expiry date
StatusIn effect
✦ Smart summary

This Decree stipulates the authority, application forms, and procedures for issuing business condition certificates for activities related to data platforms, data intermediaries, and comprehensive data analysis. Specifically as follows:

Scope of application

The Ministry of Public Security has the authority to issue Business Condition Certificates for data platform operations, data intermediary products and services, and comprehensive data analysis. - The application form includes an application form according to the prescribed model and documents proving compliance with conditions. - The procedure includes submitting the application online or in person, soliciting opinions from relevant agencies within five working days from the date of receiving complete valid applications, responding to opinions within ten days, and making decisions to issue certificates within five working days from the date of receiving all opinions.

Key points

  • Authority to Issue Business Condition Certificates
  • Application Forms for Issuing Business Condition Certificates
  • Procedures for Issuing Business Condition Certificates
  • Reissuing and Renewing Business Condition Certificates
  • Revoking Business Condition Certificates

🌐 Social impact of this document

  • Enhancing the Effectiveness of State Management over Data Platform Operations, Data Intermediaries, and Comprehensive Data Analysis Activities.
  • Creating a Transparent and Fair Business Environment for Organizations and Individuals Participating in the Data Market.

❓ Frequently asked questions

What is the processing time for applications to obtain a business condition certificate?

The processing time for applications is twenty working days from the date of receipt of complete valid applications, including the time to solicit opinions from relevant agencies.

Can applications be submitted online?

Yes, organizations can submit applications online or through postal services to the competent authority.

Full text

THE GOVERNMENT

__________

 

Number: 169/2025/NĐ-CP

SOCIALIST REPUBLIC OF VIET NAM

Independence - Freedom - Happiness

______________________________________

Hanoi, on 30 the 6 2025

 

DECREE

Regulations on scientific and technological activities, innovation, and data products and services

And data products and services

____________

 

Pursuant to the Government Organization Law on February 18, 2025;

Pursuant to the Law on Identity Cards dated November 27, 2023;

Pursuant to the Law on Data dated November 30, 2024;

The Government promulgates this Decree on regulations regarding entry, exit, and residence policies for foreigners at the International Financial Center in Vietnam.

The Government promulgates this Decree regulating scientific and technological activities, innovation, and data products and services. 

PART I

GENERAL PROVISIONS

Article 1. Scope of Regulation

This Decree stipulates scientific and technological activities, innovation in building, developing, protecting, managing, processing, and using data; controlled testing activities in building, developing, protecting, managing, processing, and using data; intermediary data products and services; data analysis and synthesis products and services; data marketplaces; authorities, files, procedures, and formalities for issuing, renewing, reissuing, and revoking Certificates of Eligibility for Operating Data Marketplaces, Certificates of Eligibility for Intermediary Data Products and Services, Certificates of Eligibility for Data Analysis and Synthesis Products and Services, and Certificates of Eligibility for Providing Data Analysis and Synthesis Products and Services.

Article 2. Applicability

1. Vietnamese agencies, organizations, and individuals.

2. Agencies, organizations, and individuals from foreign countries operating in Vietnam.

3. Foreign agencies, organizations, and individuals directly participating or related to digital data activities in Vietnam.

Article 3. Explanation of Terms

In this Decree, the following terms are understood as follows:

1. Data products and services are products and services created from or primarily utilizing data as a resource for development, application, and transaction.

2. Controlled testing activities in building, developing, protecting, managing, processing, and using data (hereinafter referred to as controlled testing activities) refer to the State agency's permission for organizations and individuals to conduct controlled testing of data products and services that are not yet regulated by law or have incomplete regulations.

3. Risks in controlled testing activities are uncertain factors that may cause negative impacts, disruptions, or influence the implementation process, results, or applicability of projects and initiatives, or have negative effects on the environment and information security.

4. Scientific and technological activities, innovation in building, developing, protecting, managing, processing, and using data (hereinafter referred to as scientific and technological, innovation activities on data) include basic research, applied research, experimental deployment, pilot production, technology application, creation of data products and services, promotion of initiatives, or other creative activities aimed at advancing science and technology in building, developing, protecting, managing, processing, and using data, and generating economic value and social benefits.

Article 4. International cooperation in scientific and technological activities, innovation on data

1. The Ministry of Public Security is responsible for managing international cooperation in scientific and technological activities, innovation on data concerning important data, core data, and data from the National Integrated Database under the Law on Data, except as provided in Clause 2 of this Article.

2. The Ministry of National Defense is responsible for implementing international cooperation in scientific and technological activities, innovation on data within its jurisdiction.

3. Ministries, ministerial-level agencies, and People's Committees of provinces and centrally-administered cities shall implement international cooperation in scientific and technological activities, innovation on data within their assigned functions and tasks.

4. Promote international cooperation in scientific research and technological development with countries having advanced science and technology, innovation on data; prioritize fields such as artificial intelligence, cloud computing, blockchain, data communication, Internet of Things, big data, and other modern technologies.

Article 5. Development of scientific, technological, and data innovation activities

1. Prioritize investment support to enhance the quality of education and training, ensuring a high-quality human resource supply to meet the requirements for developing scientific, technological, and data innovation activities; establish, connect, and develop networks of experts, scientists, and organizations in the field of data science both domestically and internationally; organize the establishment of research centers on data science, innovative applications of artificial intelligence, cloud computing, blockchain, data communication, Internet of Things, big data, and other modern technologies in building, developing, protecting, managing, processing, and using data.

2. Implement special mechanisms to attract overseas Vietnamese and foreigners with high qualifications in information technology, cybersecurity, data science, and artificial intelligence sectors to work for state agencies.

3. The Ministry of Public Security shall take the lead and coordinate with relevant ministries, agencies, and organizations to support the nurturing and development of startup ecosystems in the fields of science, technology, and data innovation.

Article 6. Training of Human Resources and Talent Development in Scientific, Technological, and Data Innovation Activities

1. The Ministry of Public Security shall take the lead and coordinate with the Ministry of Education and Training, the Ministry of Science and Technology, and related ministries and sectors to implement training, upgrading, and enhancing the professional expertise of the workforce in scientific, technological, and data innovation activities nationwide.

2. The Ministry of Education and Training shall take the lead and coordinate with relevant ministries, sectors, agencies, and organizations to organize and build training programs, innovate, and improve the quality of education and training to ensure a high-quality human resource supply that meets the requirements for developing scientific, technological, and data innovation activities; encourage international standard training programs and collaborations with foreign educational institutions; promote student, faculty, and data specialist exchanges; develop online training platforms; establish credit, scholarship, and tuition fee policies to attract students and special public-private partnership mechanisms for training in information technology, cybersecurity, data science, and artificial intelligence fields.

3. The Ministry of Science and Technology shall cooperate with the Ministry of Public Security to implement training, upgrading, and enhancing the professional expertise of the workforce in scientific, technological, and data innovation activities.

Article 7. Preferential Policies for Developing Scientific, Technological, and Data Innovation Activities

1. Organizations and individuals engaged in scientific, technological, and data innovation activities shall enjoy policies for scientific, technological, and innovation activities as prescribed by law; they shall be prioritized for the highest special support regime within their respective industry and sector, equivalent to high-tech industries.

2. Incubation facilities, organizations, and individuals researching and applying scientific, technological, and innovative methods in building, developing, protecting, managing, processing, and using data shall be prioritized for funding, support, loans, and loan guarantees from state financial funds outside the budget, lawful financial sources, and other forms of funding according to the provisions of the law.

3. State agencies, organizations, and individuals assigned tasks by the state for scientific research, technological development, and data innovation shall be encouraged, supported, and prioritized to use infrastructure and equipment invested by the state for scientific, technological, and innovative activities to carry out research.

Chapter II

CONTROLLED EXPERIMENTAL ACTIVITIES IN BUILDING, DEVELOPING, PROTECTING, MANAGING, PROCESSING, AND USING DATA

Article 8. Principles of Controlled Testing

1. Ensuring compliance with the Constitution, Data Law, and related legal regulations in scientific, technological, and innovation activities. In cases where related laws provide different provisions for controlled testing activities, such provisions shall be followed.

2. Creating an environment for testing to evaluate risks, costs, and benefits of innovative data products and services; supporting the development of innovative data products and services that meet market needs, legal frameworks, and management regulations.

3. Minimizing risks when using innovative data products and services provided by organizations and individuals participating in controlled testing activities.

4. The results of controlled testing activities serve as a basis for state agencies to consider and assess potential risks before deciding to officially apply them, determining appropriate management and adjustment mechanisms.

5. Ensuring transparency in the process of evaluating, selecting, and reviewing organizations and individuals participating in controlled testing activities.

6. For scientific, technological, and innovative products and services not yet regulated by law, organizations and individuals with the need and meeting the approved registration conditions and criteria shall be granted a Controlled Testing Activity Permit according to this Decree.

7. The scope of spatial, temporal, scale, and target controlled testing activities should be proposed in accordance with the control capacity of competent state agencies in building, developing, protecting, managing, processing, and using data.

8. State agencies responsible for building, developing, protecting, managing, processing, and using data shall be accountable for conducting controlled testing activities within their assigned functions, tasks, and authorities.

Article 9. Conditions for Participation in Controlled Testing Activities

Organizations and individuals will be considered for issuance of a Certificate to participate in controlled testing activities if they meet the following conditions:

1. The organization is a legal entity established and legally operating in Vietnam; not currently undergoing division, separation, merger, consolidation, transformation, dissolution, or bankruptcy according to issued decisions; the team implementing the testing solution has professional qualifications in the relevant field.

The legal representative of the organization applying to participate in controlled testing activities must be a Vietnamese citizen residing in Vietnam and not fall under any of the following circumstances:

a) Has been indicted by investigative agencies;

b) Has been convicted of national security offenses or other offenses due to intentional fault with a sentence of three years or more imprisonment without having had the criminal record expunged; currently on temporary suspension of serving the prison sentence; currently serving a non-custodial correctional sentence; currently under house arrest, residence prohibition, prohibition from holding positions, or conditional business operation prohibition according to court decisions;

c) Has been administratively punished in the field of data, cybersecurity, information technology, electronic transactions and the punishment period has not expired; currently subject to administrative measures or awaiting application of administrative measures; has been subject to administrative measures but the period has not yet elapsed to be considered as not being subject to administrative measures.

2. Individuals must be Vietnamese citizens residing in Vietnam, have a bachelor's degree or higher in a field relevant to the controlled testing activity, and not fall under any of the circumstances stipulated in points a, b, and c of Clause 1 of this Article.

3. The proposed solution for participation in controlled testing activities must meet the following criteria:

a) Innovative and beneficial, adding value for service users in Vietnam, especially solutions related to scientific, technological, and data innovation activities;

b) A risk management framework regarding privacy and data security, financial risks, social and ethical risks, and national security risks has been designed and built; plans for handling and mitigating risks occurring during the testing process have been developed;

c) The organization or individual participating in controlled testing activities has conducted comprehensive reviews and evaluations on all aspects of functionality and utility;

d) Feasible for deployment and application after completing the testing process.

Article 10. Scope of Controlled Testing

1. The testing space includes: physical space (physical servers), network space (using local area networks (LAN), wide area networks (WAN), the Internet, and cloud services), geographic space (deployed at the location of the organization or individual leading the testing, deployed at locations approved by the data management unit or the Ministry of Public Security).

2. The duration for implementing controlled testing shall not exceed two years according to the reviewed plan, which may be extended once for no more than the approved testing period.

Article 11. Plan for Controlled Testing in Scientific, Technological, and Innovation Activities with Data

Organizations and individuals participating in controlled testing activities must establish a plan including the following main contents:

1. Name of the testing plan.

2. Information about the organization or individual leading the testing plan and other organizations or individuals participating in the testing activity:

a) Personal information of individuals, legal representatives of organizations, and registration for business or establishment decisions of organizations;

b) Personal information, academic degrees, and certificates of individuals participating in controlled testing activities.

3. The necessity and objectives of controlled testing activities.

4. Description of the implementation solution for controlled testing activities, risk assessment, rights and responsibilities of all parties, control measures, detailed risk control measures for: privacy and data security risks, financial risks, social and ethical risks, national security risks.

5. Scope, time frame, and budget for implementation.

6. Expected results.

7. Explanatory documents clarifying the contents and information presented in the plan.

Article 12. Issuance of Certificate for Participation in Controlled Testing Activities

1. Authority to issue the Certificate for Participation in Controlled Testing Activities

a) The Minister, Head of a ministerial-level agency, agency under the Government, Chairman of the People's Committee of provinces and centrally-run cities has the authority to issue or delegate subordinate agencies to issue the Certificate for Participation in Controlled Testing Activities when the controlled testing activity only uses data managed by their own ministry, sector, or locality;

b) The Minister of Public Security has the authority to issue or delegate subordinate agencies to issue the Certificate for Participation in Controlled Testing Activities when using data from two or more ministries, sectors, or localities, except in cases stipulated in point c of this clause;

c) The Minister of National Defense has the authority to issue or delegate subordinate agencies to issue the Certificate for Participation in Controlled Testing Activities when using data in the defense and cryptographic fields.

2. Documents include:

a) Application for issuance of the Certificate for Participation in Controlled Testing Activities for organizations and individuals (according to Model HDTN01, HDTN02 attached to this Decree);

b) Controlled testing plan.

3. Procedure and time limit for cases using one source of data from one data management unit

a) Organizations and individuals submit one set of documents as prescribed in Clause 2 of this Article via online submission, direct submission, or postal service to the competent authority issuing the Certificate for Participation in Controlled Testing Activities;

b) Within three working days from the date of receipt of complete and valid documents, the receiving agency will seek opinions from the Ministry of Public Security (National Data Center) and related units to serve as the basis for approving the documents;

c) Within ten days, the units solicited for opinions will provide written responses to the receiving agency;

d) Within three working days from the date of receipt of complete responses from the units, the competent authority will review and approve the documents, and issue both paper and electronic versions of the Certificate for Participation in Controlled Testing Activities for organizations and individuals (according to Model HDTN03, HDTN04 attached to this Decree); if the certificate is not issued, a written response explaining the reasons must be provided.

4. Procedure and time limit for cases using two sources of data from two data management units

a) Organizations and individuals submit one set of documents as prescribed in Clause 2 of this Article via online submission, direct submission, or postal service to the Ministry of Public Security (National Data Center);

b) Within three working days from the date of receipt of complete and valid documents, the Ministry of Public Security (National Data Center) is responsible for sending letters seeking opinions from the data management units, the Ministry of Science and Technology, and other related units. In necessary cases, the Ministry of Public Security may establish an Advisory Board to evaluate the controlled testing activities.

The Advisory Board consists of: representatives from the leadership of the Ministry of Public Security, representatives from the leadership of the Ministry of Science and Technology, representatives from the leadership of information technology organizations and enterprises, information technology experts and scientists, and representatives from other organizations and individuals decided by the Minister of Public Security;

c) Within ten days, the units solicited for opinions will provide written responses to the Ministry of Public Security;

d) Within three working days from the date of receipt of complete responses from the units, the competent authority will review and approve the documents, and issue both paper and electronic versions of the Certificate for Participation in Controlled Testing Activities for organizations and individuals (according to Model HDTN03, HDTN04 attached to this Decree); if the certificate is not issued, a written response explaining the reasons must be provided.

5. If the Certificate for Participation in Controlled Testing Activities is lost or damaged, organizations and individuals can use the electronic version; if they wish to obtain a new paper version, they only need to submit an application form to the competent authority; within three working days from the date of receipt of the application form, the competent authority will issue a new Certificate for Participation in Controlled Testing Activities; if it is not issued, a written response explaining the reasons must be provided.

6. The Minister of National Defense shall guide the procedures and formalities for issuing the Certificate for Participation in Controlled Testing Activities and bear responsibility for inspecting and supervising scientific research, technological application, and innovation activities in building, developing, protecting, managing, processing, and using data in the defense and cryptographic fields.

Article 13. Adjustment of Controlled Testing Plans

1. When there is an adjustment to the controlled testing plan as prescribed in Article 11 of this Decree, organizations and individuals participating in the testing must complete the procedure for requesting an adjustment to the controlled testing plan and may only implement the adjustment after receiving approval from the agency issuing the Certificate for Participation in Controlled Testing Activities.

2. Documents include:

a) The request for adjustment of the controlled testing plan for organizations and individuals (according to form HDTN05, HDTN06 attached to this Decree);

b) The testing plan after adjusting the controlled testing plan;

c) In cases where the adjustment of the controlled testing plan leads to an extension of the approved testing period, organizations and individuals submit the Report on the Results of Controlled Testing Activities according to form HDTN07 for individuals or form HDTN08 for organizations issued with this Decree.

3. Procedure and method of implementation:

a) Organizations and individuals submit the application file for adjustment of the controlled testing plan through online means, directly, or postal service to the agency that issued the Certificate for Participation in Controlled Testing Activities;

b) Within three working days from the date of receipt of a complete and valid application file, the agency that issued the Certificate for Participation in Controlled Testing Activities seeks opinions from relevant units to serve as the basis for approving the application file.

In cases requiring clarification, the agency that issued the Certificate for Participation in Controlled Testing Activities issues a written request for organizations and individuals to provide explanations and complete the application file. If within five working days from the date the agency issues a written request for explanation and completion of the application file, organizations and individuals do not return the explanatory document and supplementary application file, the agency that issued the Certificate for Participation in Controlled Testing Activities returns the application file to the organization or individual. The time taken for explanation and completion of the application file is not included in the processing time of the application file;

c) Within ten days, the units solicited for their opinions issue written responses to the agency that issued the Certificate for Participation in Controlled Testing Activities. Based on the adjusted testing plan and the comments from related units (if any), the agency that issued the Certificate for Participation in Controlled Testing Activities issues a written approval in both paper and electronic forms for the adjustment of the implementation plan for controlled testing activities; if not approved, it issues a written response stating the reasons.

Article 14. Extension of Controlled Testing Period

1. Within thirty days before the end of the approved testing period, organizations and individuals participating in controlled testing activities who wish to extend the testing period submit a written request for extension (according to form HDTN13, HDTN14 attached to this Decree) along with the Report on the Results of Controlled Testing Activities to the agency that issued the Certificate for Participation in Controlled Testing Activities.

2. The agency issuing the Certificate for Participation in Controlled Testing Activities reviews and decides on the extension of controlled testing activities according to the procedures stipulated in Clause 3 of Article 13 of this Decree.

Article 15. Revocation of the Certificate for Participation in Controlled Testing Activities

1. The authority that issued the Certificate for Participation in Controlled Testing Activities shall examine and decide to revoke the Certificate for Participation in Controlled Testing Activities that it has issued in the following cases:

a) At the request of the organization or individual who has been issued the Certificate for Participation in Controlled Testing Activities;

b) Within ninety days from the date of issuance of the Certificate for Participation in Controlled Testing Activities, if the organization or individual does not implement testing activities and does not request adjustment or extension of the testing period;

c) The organization or individual who has been issued the Certificate for Participation in Controlled Testing Activities fails to meet all conditions prescribed in Clause 1 and Clause 2, Article 9 of this Decree;

d) The organization or individual participating in testing does not properly fulfill the contents required in the Certificate for Participation in Controlled Testing Activities, which the issuing authority has requested to be rectified during regular or spot inspections;

đ) During the testing process, incidents or violations occur that the organization or individual cannot rectify according to the requirements of the authority that issued the Certificate for Participation in Controlled Testing Activities;

2. Not later than fifteen days from the date when grounds under Clause 1 of this Article are established, the authority that issued the Certificate for Participation in Controlled Testing Activities shall issue a Decision to revoke the Certificate for Participation in Controlled Testing Activities and send it to the organization or individual who has been issued the certificate, while simultaneously retrieving the electronic version and announcing on the information system or the website of its own agency;

Upon receiving the revocation decision, the organization or individual shall have the responsibility to return the Certificate for Participation in Controlled Testing Activities to the authority that issued the certificate;

3. The Ministry of National Defense shall be responsible for examining and deciding to stop testing and revoke the Certificate for Participation in Controlled Testing Activities in the defense and cryptographic sectors;

Article 16. Completion of Controlled Testing Activities

When completing controlled testing activities, the competent authority specified in Clause 1, Article 12 of this Decree shall examine and issue a Certificate of Completion of Controlled Testing Activities;

1. The Certificate of Completion of Controlled Testing Activities shall be issued in the following cases:

a) The organization or individual requests to complete controlled testing activities before the approved deadline;

b) Upon expiration of the testing period approved in the Certificate for Participation in Controlled Testing Activities or upon expiration of the extended testing period;

2. Documents include:

a) Application for issuance of the Certificate of Completion of Controlled Testing Activities for organizations or individuals (according to Model HDTN09, HDTN10 attached to this Decree);

b) Report on the results of controlled testing activities according to Model HDTN07 for individuals and Model HDTN08 for organizations attached to this Decree;

3. Procedures for implementation:

a) The organization or individual submits one set of documents as prescribed in Clause 2 of this Article through online submission, direct submission, or postal service to the authority that issued the Certificate for Participation in Controlled Testing Activities;

b) Within three working days from the date of receipt of complete and valid documents, the authority that issued the Certificate for Participation in Controlled Testing Activities shall seek opinions from relevant agencies and organizations, and within ten days, these agencies and organizations shall provide written responses to the authority that sought their opinions;

In case the submitted documents are incomplete or invalid according to regulations, within three working days from the date of receipt, the authority that issued the Certificate for Participation in Controlled Testing Activities shall issue a written request for the organization or individual to supplement, explain, and perfect the documents. If the organization or individual does not submit a written explanation or supplementary documents within five working days from the date of the request, the authority that issued the Certificate for Participation in Controlled Testing Activities shall return the documents to the organization or individual. The time spent on explaining and perfecting the documents shall not be counted towards the processing time of the documents;

c) Where necessary, the authority that issued the Certificate for Participation in Controlled Testing Activities may establish an Advisory Board to inspect the results of controlled testing activities. The composition of the Advisory Board is regulated in point b, Clause 4, Article 12 of this Decree;

d) Within three working days from the date of receipt of complete responses from relevant agencies and organizations, the authority that issued the Certificate for Participation in Controlled Testing Activities shall examine and issue the Certificate of Completion of Controlled Testing Activities to the organization or individual (according to Model HDTN11, HDTN12 attached to this Decree);

4. The Minister of National Defense shall be responsible for issuing the Certificate of Completion of Controlled Testing Activities in the defense and cryptographic sectors;

5. The Certificate of Completion of Controlled Testing Activities does not have the value to replace the Business Registration Certificate or Operating License of the organization participating in controlled testing activities.

Article 17. Supervision and inspection activities during the testing process

1. The agency issuing the Certificate to participate in controlled testing activities shall supervise the implementation of the contents approved in the testing plan with control.

2. The agency issuing the Certificate to participate in controlled testing activities shall coordinate with relevant competent authorities to conduct on-site inspections of organizations participating in controlled testing activities once a year or at any time when there are signs of non-compliance with the contents specified in the Certificate to participate in controlled testing activities. The inspection contents include:

a) Checking legal documentation; the implementation of the contents approved in the controlled testing plan;

b) Checking compliance with the provisions of this Decree and other related legal regulations;

c) Inspecting persons and means, products related to the controlled testing activities of the organization and individuals as prescribed by law.

At the end of the inspection, a record must be established detailing the results, deficiencies, limitations, or violations (if any), and specifying the causes.

3. Within thirty days from the date of completion of the inspection, organizations and individuals participating in testing shall be responsible for rectifying deficiencies, limitations, or violations identified by the competent authority in the inspection record.

4. Based on the nature and severity of the violation, the agency issuing the Certificate to participate in controlled testing activities shall handle it according to the regulations or propose to the competent authority to handle it according to the law.

Article 18. Reporting and Information Provisioning System

1. Organizations and individuals participating in controlled testing activities shall be responsible for reporting quarterly and providing information about the testing process, emerging risks, and testing deployment results to the agency that issued the Certificate to participate in controlled testing activities as stipulated.

2. The submission of reports and provision of information shall be conducted electronically or in writing to the agency that issued the Certificate to participate in controlled testing activities.

3. Quarterly reports on the implementation of controlled testing activities shall be prepared according to Form HDTN08 for organizations and Form HDTN07 for individuals as prescribed in the Appendix accompanying this Decree. Quarterly report data shall be calculated from the first day of the quarter to the last day of the quarter; the deadline for submitting the report is the fifth day of the first month of the following quarter.

4. At least thirty days before the end of the testing period, organizations and individuals participating in controlled testing activities must submit a Report on the Results of Controlled Testing Activities according to Form HDTN08 for organizations and Form HDTN07 for individuals as prescribed in the Appendix accompanying this Decree.

5. In case of incidents causing interruptions to operations or serious risks, organizations and individuals participating in controlled testing activities must immediately report by phone to the agency that issued the Certificate to participate in controlled testing activities, while organizing the resolution of incidents and risks; within three days, they must submit a written report to the agency that issued the Certificate to participate in controlled testing activities.

Article 19. Protection of Subjects Using Products and Services from Controlled Testing Activities

To protect the rights and legitimate interests of subjects during the testing process and after its completion, organizations and individuals participating in testing shall be responsible for:

1. Advising through one or more mass media channels and directly to agencies, organizations, and users about the risks associated with using innovative products and services, new business models created by such innovative products and services during the testing period; ensuring the provision of accurate, complete, and truthful information about innovative products and services, new business models generated by such innovative products and services during testing, service fees, user rights and obligations for each type of innovative product and service, and new business models created by such innovative products and services.

2. Regularly assessing risks on a monthly or quarterly basis, ensuring the implementation of preventive measures against risks and remedying consequences during and at the end of the testing period; promptly informing users of any changes in the risk level of innovative products and services involved in the testing.

3. Announcing customer complaint resolution points on products and services. In case of disputes or complaints, organizations and individuals participating in testing shall be responsible for receiving and taking measures to address all review requests and complaints from users.

4. Implementing compensation measures and remedying consequences according to civil law regulations during and upon completion of the testing period.

5. Other responsibilities under consumer protection laws and other relevant laws.

Article 20. Responsibilities of the Agency Issuing Certificates for Participation in Controlled Testing Activities

1. Advising on the development, supplementation, and adjustment of guidelines for implementing laws for controlled testing activities.

2. Receiving, examining, and answering legal issues arising during the testing process within its authority or proposing that competent authorities examine and resolve them.

3. Periodically and randomly inspecting and supervising testing activities; evaluating the application of risk control measures by testing organizations and individuals during the testing process; promptly identifying and preventing potential abuses and exceeding control limits during the testing process.

4. Receiving, examining, and resolving within its authority or proposing that competent authorities resolve user or third-party recommendations and reflections regarding testing.

5. Requesting testing organizations and individuals to report and explain emerging issues; supplementing risk control measures; deciding to adjust the scope of testing, extend the testing period, decide to temporarily suspend testing; and ending the testing.

The agency issuing certificates for participation in controlled testing activities decides the scope of exemptions from legal provisions applicable to specific testing projects based on the requirements and purposes of the testing, assessed according to the level of risk and control capability.

Article 21. Rights and responsibilities of organizations and individuals participating in controlled testing activities

1. Organizations and individuals conducting controlled testing are permitted not to apply certain provisions of laws on standards and technical regulations concerning technology, products, services, business conditions, licensing procedures, ensuring business conditions, and other provisions that are not suitable for the characteristics and new features of the proposed technology, product, service, or business model being tested.

2. During the testing process, all parties must ensure requirements related to national defense, security, public order, social safety, user benefits, and societal interests.

3. Provide comprehensive reports on the testing status, potential risks that may arise, and compensation measures (if applicable), ensuring transparency and openness during the testing process.

4. Comply with the requirements of the agency issuing the Certificate of Participation in Controlled Testing Activities to ensure that the testing activities are carried out according to the approved plan.

Article 22. Exemption from liability in controlled testing activities

1. Agencies, organizations, and individuals participating in the certification, inspection, supervision, and evaluation of the controlled testing activities, if they have performed their duties fully and properly as stipulated in Article 20 of this Decree within their assigned scope of responsibility, shall be exempted from civil liability when causing damage to the State.

2. Organizations and individuals participating in testing activities shall be exempted from civil liability when causing damage to the State if they have fully implemented all relevant procedures and regulations during the implementation of controlled testing activities. 

Chapter III

INTERMEDIATE DATA PRODUCTS AND SERVICES

Article 23. Intermediate Data Products and Services

1. Intermediate data products are provided by organizations offering products and services to provide infrastructure, equipment, applications, software serving data subjects, data owners to carry out activities as prescribed in Article 24 of this Decree.

2. Intermediate data services are provided by organizations offering products and services to facilitate intermediate data activities connecting, transmitting, accessing, and processing electronic data between data subjects, data owners, and users of data products and services, ensuring safety, effectiveness, and correct format.

3. Organizations providing intermediate data products and services between service users and state agencies shall be registered for management and licensed in accordance with the provisions of this Decree.

4. Intermediate data products and services under this Decree do not include cloud computing services, data center services, provision of intermediate data products and services within organizations, and products and services already regulated by other legal documents.

Article 24. Content of Intermediate Data Activities

1. Representing data subjects and data owners to implement connection, sharing, exchange, and access to data with service users.

2. Advising and assessing the impact of data processing and the provision of intermediate data services between data subjects, data owners, and data service users.

3. Data management services to act on behalf of data subjects and data owners to connect, share, exchange, and access data with data users.

4. Acting as an intermediary to connect, share, exchange, and access data between data subjects, data owners, and data users.

5. Providing infrastructure, equipment, applications, software, transmission services, and other types of services to support intermediate data activities.

6. Supporting and controlling data attributes to ensure privacy, sensitive data, personal data, and risk assessment for core data, important data handling and processing activities in compliance with the law during intermediate data activities.

7. Cooperative and data sharing services to facilitate connection, sharing, exploitation, and access to data in accordance with the law.

8. Assessing the eligibility of data subjects to participate in data platforms; legality and compliance with participation conditions for data products and services; ability to meet requirements for ensuring security and safety when using data products.

9. Other activities carried out in accordance with controlled testing regulations to supplement and evaluate intermediate data activities.

Article 25. Conditions for organizations providing intermediary data products and services between service users and state agenciesintermediary data products and services between the service user and state agencies

1. Organizations specified in Clause 3 of Article 23 of this Decree include public service units and enterprises established and operating under Vietnamese law, which must meet the conditions stipulated in Clauses 2, 3, and 4 of this Article.

2. Personnel conditions:

a) The head of the public service unit or the legal representative of the enterprise must be a Vietnamese citizen residing in Vietnam; they must have a university degree or higher and at least three years of experience in data management, and not fall under any of the cases specified in points a, b, and c of Clause 1 of Article 9 of this Decree.

b) There must be at least five persons with a university degree or higher who hold one of the following certificates or certifications: data science, data analysis, data management, consulting, brokerage, trade promotion; asset management; data evaluation.

3. Conditions regarding physical infrastructure, technical equipment, service provision management procedures, and security and public order assurance plans.

Organizations applying for a Certificate of Eligibility to Operate Intermediary Data Products and Services must have their infrastructure and technical equipment located in Vietnam, subject to information security testing according to the law, and must have a business operation plan including the following main contents:

a) Service provision intermediary data operation plan and procedure, including a description of the information technology system.

b) Technical solution plan.

c) Data storage plan ensuring data integrity and information security of the service provision system.

d) Plan for protecting individual and organizational data.

đ) Public order assurance plan.

e) Payment plan.

g) Data evaluation plan.

h) Electronic identification and authentication service usage plan.

i) Fire prevention, disaster recovery, and stable service operation assurance plan.

k) Description of the technical equipment used.

4. Financial conditions:

Deposit at least five billion Vietnamese dong in a commercial bank operating in Vietnam to address risks and compensation that may occur during the provision of intermediary data products and services due to the organization's fault, and to cover the costs of receiving and maintaining databases of organizations and enterprises in case of license revocation.

Article 26. Responsibilities of organizations providing intermediary data products and servicesproviding intermediary data products and services

1. Demonstrate responsibility through data connection, sharing, exchange, access, and protection, including personal data protection in accordance with the law.

2. Notify individuals and organizations that are data owners, data subjects, and data users about the purpose of providing intermediary data products and services and ensure the rights of individuals as prescribed by the law on personal data protection.

3. Collect, use, or disclose personal data for legitimate purposes and only with the consent of the data subject.

4. Ensure the accuracy and completeness of data provided by the data subject and owner to the service user.

5. Ensure data access for the intended purpose, correct target, and exploitation strictly in accordance with signed contracts.

6. Implement reasonable measures to protect personal data within the organization's ownership, including preventing unauthorized access, collection, use, disclosure, or similar risks.

7. Limit the retention of personal data to the necessary period and process personal information appropriately when it is no longer needed for business or legal purposes.

8. Ensure cross-border data transfer limitations in accordance with requirements, ensuring equivalent protection standards to those required by relevant laws.

9. Report data breaches to affected organizations and individuals immediately if there is a potential significant impact on individuals or a significant scale.

10. Ensure the ability to transfer data to the correct data user according to the agreed terms.

11. Ensure the ability to advise on data processing impact assessments, data evaluations, flexible payment methods, tax and fee regulations, pricing according to electronic commerce activities.

12. Organizations participating in data intermediary activities must comply with legal provisions on electronic identification and authentication. 

Chapter IV

DATA ANALYSIS AND COMBINATION PRODUCTS, SERVICES

Article 27. Levels of data analysis and synthesis

1. Level 1: Data analysis and synthesis is directly performed by humans using devices and software that do not integrate artificial intelligence.

2. Level 2: Data analysis and synthesis is directly performed by humans with partial support from artificial intelligence.

3. Level 3: Data analysis and synthesis is fully performed by artificial intelligence, under human supervision during execution.

4. Level 4: Data analysis and synthesis is fully performed by artificial intelligence without human supervision.

Article 28. Management of data analysis and synthesis products and services

1. Organizations providing data analysis and synthesis products and services listed below must be granted a Certificate of Eligibility for Business in Data Analysis and Synthesis Products and Services, including:

a) Data analysis and synthesis products and services belonging to levels 3 and 4 in the information system of state agencies.

Organizations providing data analysis and synthesis products and services that may cause harm to national defense, national security, public order, social safety, and community health;

b) Providing data analysis and synthesis products and services that connect and share with national databases, specialized databases;

c) Data analysis and synthesis products and services using core data and important data.

2. Organizations providing data analysis and synthesis products and services not covered by Clause 1 of this Article shall notify the Ministry of Public Security when providing such products and services, and may request the Ministry of Public Security to review and assess them to enjoy incentives for such products and services as enterprises operating in high-tech, innovation, creative startups, digital industry sectors; policies for promoting scientific and technological activities and innovation in data, including:

a) Virtual assistants, generative artificial intelligence systems, automatic content analysis systems for videos, images, news, articles, and similar interactive products and services that pose a risk of suggesting or guiding users towards misleading content;

b) Products and services analyzing and synthesizing sensitive personal data with a scale of one million individuals or more;

c) Level 3 and level 4 products and services performing automatically in industrial and production systems accounting for 20% or more of the usage structure in those industries and production sectors;

d) Reaching a certain scale of data for training analysis and synthesis models, with at least 10 TB of data.

3. Data analysis and synthesis products and services under this Decree do not include internal provision of data analysis and synthesis products and services within organizations and products and services already regulated by other legal documents.

Article 29. Conditions for business in data analysis and synthesis products and services

Organizations engaged in business in data analysis and synthesis products and services must meet the following conditions:

1. Being a public service unit or enterprise established and operating according to Vietnamese law.

2. Human resources conditions

The head of the public service unit or the legal representative of the enterprise must be a Vietnamese citizen residing in Vietnam; having a bachelor's degree or higher, with at least three years of work experience related to data management, and not falling into any of the cases stipulated in Points a, b, and c of Clause 1 of Article 9 of this Decree.

Having a management team capable of meeting the professional requirements for data analysis and synthesis; having technical staff responsible for the main tasks who hold certificates or have completed courses in one of the following specialties: Data Science, Data Analysis, Data Management, Data Governance; Data Auditing, or having at least three years of experience in: Data Science, Data Analysis, Data Management, Data Governance; Data Auditing.

3. Having equipment, infrastructure, and production technology systems suitable for the business plan for data analysis and synthesis products and services.

4. Having a business plan including the scope of target customers for products and services; types of products expected to be provided; compliance with relevant technical standards and norms for each type of product and service; basic technical features of products and services.

Article 30. Criteria for assessing data analysis and synthesis products and services

1. Assess the source of data for analysis and synthesis in accordance with the provisions of the law.

2. Assess the model and formula for data analysis and synthesis that do not affect or guide users to influence national security, defense, social order and safety, the safety of industrial systems, important national information systems, public health, traffic, environment, judiciary, and public affairs.

3. Assess the accuracy of the data analysis and synthesis model.

Article 31. Responsibilities of organizations engaged in business and providing data analysis and synthesis products and services

1. Provide data analysis and synthesis products and services to organizations and individuals based on agreements through product and service supply contracts in accordance with the regulations; bear responsibility for the provided products and services.

2. During the provision of data analysis or synthesis products or services, the supplier must provide and ensure that the user clearly understands the following contents:

a) Name, contact information, and methods to access related information of the supplier;

b) Function, purpose, scope of use, and operational mechanism of the product or service;

c) Impact and risks that may affect the rights and interests of the service user;

d) Information about the Certificate of Eligibility for Providing Data Analysis and Synthesis Products and Services;

e) Rights and obligations of the service user.

3. Comply with legal regulations on personal data protection, information security, cybersecurity, data security, electronic transactions, technical standards and specifications for data, confidentiality, ensuring the accuracy of service provision; issue business operation procedures for data analysis and synthesis products and services and obtain approval from the competent state agency for data management.

4. Comply with approved business operation plans and procedures.

5. Organizations providing data analysis and synthesis products and services as stipulated in Article 28 of this Decree shall submit regular reports on the provision of products and services according to Form BC01 attached to this Decree to the Ministry of Public Security (through the National Data Center) before December 20 each year (reporting figures calculated from December 15 of the previous year to December 14 of the reporting year) or submit ad hoc reports when requested (submitted directly or via postal service or online method).

Chapter V

DATA MARKETPLACE

Article 32. Activities of the data marketplace

The activities of the data marketplace include:

1. Providing resources related to data to serve research, startup development, innovation and creativity; providing data-related services to support economic and social development:

a) Data in specialized databases, National Databases;

b) Data provided by other agencies, organizations, and individuals.

2. Providing services:

a) Services of buying, selling, introducing, representing, agency, consulting, brokerage, supporting valuation, technical support, negotiation support, signing data transactions, data products, and services;

b) Auction services for data;

c) Services providing an environment for data transactions and exchanges and related products and services.

Article 33. Supplying products and data services to the data exchange platform for trading

1. Data products and services of organizations and individuals on the data exchange platform operate under a market mechanism, supported by pricing from the data exchange service provider organization or other organizations with valuation functions according to demand.

2. State agencies supplying data products and services charge fees/prices in accordance with the provisions of the law; select the data exchange platform to supply products and services; organize auctions with a starting price not lower than the input cost for data products and services.

3. Data products and services on the data exchange platform must ensure the authenticity of data sources; the data exchange service provider organization or other organizations with the function of verifying data sources are responsible for verifying the data sources.

4. Organizations and individuals are responsible for the products and services they provide on the data exchange platform; the data exchange service provider organization is responsible for reviewing data products and services to ensure compliance with the provisions of the law.

5. Agencies, organizations, and enterprises providing data products and services must do so through the data exchange platform except where otherwise provided by law.

6. Data that is not permitted to be traded includes:

a) Core data and important data;

b) Data without the consent of the data subject, except where otherwise provided by law;

c) Other data prohibited from being traded as prescribed by law.

Article 34. Conditions for Issuing a Certificate of Eligibility for Operating a Data Exchange Platform

The organization providing the data exchange platform must meet the following conditions:

1. It must be a public institution or state-owned enterprise established and operating in accordance with Vietnamese law, meeting the conditions stipulated in Clauses 2, 3, and 4 of this Article.

2. Conditions regarding personnel

a) The head of the organization and the legal representative of the enterprise must have a bachelor's degree or higher, directly engaged in management at data centers, with at least three years of work experience related to data management and not falling within any of the cases specified in Points a, b, and c of Clause 1 of Article 9 of this Decree;

b) There must be at least five persons with a bachelor's degree or higher, of which at least 40% work full-time, and 30% hold certificates or completion certificates for courses in: data science, data analysis, management, data governance, consulting, brokerage, trade promotion; asset management; data appraisal.

3. Conditions regarding infrastructure, technical equipment, service provision management procedures, and security and order assurance plans

Infrastructure and equipment must be located in Vietnam, tested for information security and safety in accordance with the law, and have a business plan for the data exchange platform including the following main contents:

a) Business plan and procedures for the data exchange platform including a description of the information technology system;

b) Technical solution plan.

c) Plan for storing data, ensuring data integrity, and securing information security of the service provision system;

d) Plan for protecting individual and organizational data.

đ) Public order assurance plan.

e) Payment plan.

g) Data evaluation plan.

h) Electronic identification and authentication service usage plan.

i) Fire prevention and firefighting plan, disaster prevention, and ensuring stable and smooth operation;

k) Description of the technical equipment used.

4. In the case of organizing data auctions, the data exchange service provider organization must have a license to provide auction services for assets in accordance with the law.

Article 35. Responsibilities of organizations providing data exchange platform services

1. Inspect and evaluate the fulfillment of conditions for participating in the data exchange platform by relevant subjects; the legality and fulfillment of conditions for participating in transactions of data products and services; the ability to meet requirements in ensuring security and safety when using data products, specifically as follows:

a) Conditions for participating in transactions of relevant subjects include: civil capacity of individuals; civil legal capacity of legal entities;

b) Legality and fulfillment of conditions for participating in transactions of data products and services include: source of creation of products and services; object, content, method, process of creating products and services; determination of requirements related to restrictions or non-restrictions on circulation and distribution of products and services;

c) Meeting requirements for ensuring security and safety when using data products include: compliance with technical standards and specifications for data products and services; receiving, storing, and processing data.

2. Monitor activities on the data exchange platform, decide to suspend participation of parties, continue listing and delist data products and services; resolve disputes; monitor, promptly detect, handle, prevent, and report violations of laws; coordinate with relevant state management agencies in inspection, investigation, and evidence collection.

3. Issue operational regulations and publicly list them on their electronic information website. The operational regulations must include the following main contents:

a) Conditions for participation and responsibilities of participating parties;

b) Transaction procedures;

c) Requirements for ensuring confidentiality of information and preventing fraudulent behavior;

d) Risk management, handling complaints and disputes, protecting personal data;

e) Conditions for data products and services to be listed on the data exchange platform.

4. Establish a system to ensure transaction security according to legal provisions; guide participating parties on the data exchange platform to protect data, trace origin, identify risks, check compliance, and use effective measures to protect personal data, privacy rights, trade secrets, and important data as prescribed by the state.

5. Develop emergency response plans for data security incidents, conduct disaster recovery backups of critical systems and databases, and regularly conduct emergency data security drills to enhance response capabilities to data security incidents; ensure continuous information reception channels and service usage 24 hours a day, 7 days a week; comply with approved operation plans and procedures.

6. Develop technical parameters to assess and manage the quality of data products and services, a set of evaluation indices for data assets, and support pricing of data products and services.

7. Submit periodic reports every six months before June 20 (reporting figures from December 15 of the previous year to June 14 of the reporting year), annually before December 20 (reporting figures from December 15 of the previous year to December 14 of the reporting year) or upon request for data exchange platform service provision according to Model Report BC02 attached to this Decree to the Ministry of Public Security (through the National Data Center).

Chapter VI

AUTHORITY, FILE, PROCEDURE, AND PROCEDURES FOR ISSUING, RENEWING, REPLACING, REVOKING LICENSES FOR OPERATING DATA EXCHANGE PLATFORMS, LICENSES FOR OPERATING DATA PRODUCTS AND SERVICES, LICENSES FOR OPERATING DATA ANALYSIS AND COMBINATION PRODUCTS AND SERVICES, LICENSES FOR PROVIDING DATA ANALYSIS AND COMBINATION PRODUCTS AND SERVICES ISSUING, REVOKING LICENSES MEETING REQUIREMENTS LICENSES FOR OPERATING DATA EXCHANGE PLATFORMS, LICENSES FOR OPERATING DATA PRODUCTS AND SERVICES, LICENSES FOR OPERATING DATA ANALYSIS AND COMBINATION PRODUCTS AND SERVICES DATA, LICENSES MEETING BUSINESS REQUIREMENTS LICENSES FOR OPERATING DATA ANALYSIS AND COMBINATION PRODUCTS AND SERVICES LICENSE FOR PROVIDING PRODUCTS MEETING REQUIREMENTS, LICENSES FOR PROVIDING DATA ANALYSIS AND COMBINATION PRODUCTS AND SERVICES

 

Article 36. Competence to issue Certificates of Eligibility for Business Operations on Data Platforms; Certificates of Eligibility for Business Operations on Intermediary Data Products and Services; Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services

Clause 1. The Ministry of Public Security shall issue Certificates of Eligibility for Business Operations on Data Platforms; Certificates of Eligibility for Business Operations on Intermediary Data Products and Services; Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services.

Clause 2. The Minister of Public Security shall delegate responsibility to subordinate agencies to implement the issuance of Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services in accordance with regulations.

Article 37. Documents, Procedures, and Formalities for Issuing Certificates of Eligibility for Business Operations on Data Platforms; Certificates of Eligibility for Business Operations on Intermediary Data Products and Services; Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services

1. The documents include:

a) Application forms for requesting Certificates of Eligibility for Business Operations on Data Platforms according to Form TK01; Certificates of Eligibility for Business Operations on Intermediary Data Products and Services according to Form TK02; Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services according to Form TK03; Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services according to Form TK04 attached as an Appendix to this Decree;

b) Documents and materials proving compliance with conditions stipulated in Articles 25, 29, and 34 of this Decree, except in cases where Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services are requested.

Clause 2. Procedure and Time Limit for Resolution:

a) Organizations submit one set of documents prescribed in Clause 1 of this Article online, directly, or through postal services to the competent authority;

b) Within five working days from the date of receipt of complete and valid documents, the competent authority shall be responsible for soliciting opinions from relevant agencies, organizations, and individuals;

c) Within ten days, units solicited for their opinions shall provide written responses;

d) Within five working days from the date of receipt of complete participation opinions from relevant units, the competent authority specified in Article 36 of this Decree shall examine and decide to issue paper and electronic copies of Certificates of Eligibility for Business Operations on Data Platforms according to Form GCN01, Certificates of Eligibility for Business Operations on Intermediary Data Products and Services according to Form GCN02, Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services according to Form GCN03, Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services according to Form GCN04 attached as an Appendix to this Decree; in case of non-issuance, a written notification must be issued stating the reasons.

Article 38. Reissue and Replacement of Certificates of Eligibility for Business Operations on Data Platforms; Certificates of Eligibility for Business Operations on Intermediary Data Products and Services; Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services

Clause 1. Reissue when the paper Certificate of Eligibility for Business Operations on Data Platforms; Certificate of Eligibility for Business Operations on Intermediary Data Products and Services; Certificate of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificate of Eligibility for Provision of Data Analysis and Aggregation Products and Services is lost or damaged.

In case an organization requests reissue of the paper certificate, it shall fill out the application form according to Form TK05, TK06, TK07, TK08 attached as an Appendix to this Decree, and send it to the competent authority via online, direct submission, or postal service; within five working days from the date of receipt of complete and valid documents, the competent authority shall examine and reissue the certificate according to the prescribed model for Certificates of Eligibility for Business Operations on Data Platforms; Certificates of Eligibility for Business Operations on Intermediary Data Products and Services; Certificates of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificates of Eligibility for Provision of Data Analysis and Aggregation Products and Services; in case of non-issuance, a written notification must be issued stating the reasons.

Clause 2. Replacement when there is incorrect information or changes in the content of the Certificate of Eligibility for Business Operations on Data Platforms; Certificate of Eligibility for Business Operations on Intermediary Data Products and Services; Certificate of Eligibility for Business Operations on Data Analysis and Aggregation Products and Services; Certificate of Eligibility for Provision of Data Analysis and Aggregation Products and Services.

a) The documents include:

Application forms for requesting replacement according to Form TK05, TK06, TK07, TK08 attached as an Appendix to this Decree;

Documents and materials proving incorrect information or changes in information on the already issued certificate.

b) Procedure and Time Limit for Resolution:

Organizations submit one set of the above documents via online, direct submission, or postal service to the competent authority. Within five working days from the date of receipt of complete and valid documents for cases requesting replacement due to incorrect information or changes in information about the data platform operation plan, intermediary data business products and services, data analysis and aggregation business products and services stipulated in Articles 25, 29, and 34 of this Decree, the competent authority shall be responsible for soliciting opinions from relevant units.

Within ten days, units solicited for their opinions shall provide written responses.

Within five working days from the date of receiving full comments from relevant units, the person authorized under Article 36 of this Decree shall be responsible for examining and deciding to issue paper and electronic certificates according to the prescribed model for Certificates of Eligibility for Operating Data Marketplaces; Certificates of Eligibility for Trading Intermediary Data Products and Services; Certificates of Eligibility for Trading Analytical and Aggregating Data Products and Services; Certificates of Eligibility for Providing Analytical and Aggregating Data Products and Services. In case of non-issuance, a written notification specifying the reasons must be issued.

Article 39. Revocation of Certificates of Eligibility for Operating Data Marketplaces; Certificates of Eligibility for Trading Intermediary Data Products and Services; Certificates of Eligibility for Trading Analytical and Aggregating Data Products and Services; Certificates of Eligibility for Providing Analytical and Aggregating Data Products and Services.

1. Organizations providing data marketplace activities, trading intermediary data products and services, and trading analytical and aggregating data products and services shall have their Certificates of Eligibility revoked in the following cases:

a) Not operating continuously for six months or more;

b) Being dissolved or declared bankrupt in accordance with the law;

c) Failing to rectify violations related to personal data protection, information security, cybersecurity, and data security as required by competent state agencies.

2. The person authorized under Article 36 of this Decree shall decide on the revocation of Certificates of Eligibility for Operating Data Marketplaces using Model QĐ01, Certificates of Eligibility for Trading Intermediary Data Products and Services using Model QĐ02, Certificates of Eligibility for Trading Analytical and Aggregating Data Products and Services using Model QĐ03, and Certificates of Eligibility for Providing Analytical and Aggregating Data Products and Services using Model QĐ04 attached as an appendix to this Decree.

3. Organizations trading data marketplace activities, trading intermediary data products and services, and trading analytical and aggregating data products and services that have had their Certificates of Eligibility for Operating Data Marketplaces; Certificates of Eligibility for Trading Intermediary Data Products and Services; Certificates of Eligibility for Trading Analytical and Aggregating Data Products and Services; Certificates of Eligibility for Providing Analytical and Aggregating Data Products and Services revoked shall be responsible for returning the issued Certificates to the issuing authority within five working days from the date of receipt of the revocation decision.

Submitting the issued Certificates back to the issuing authority within five working days from the date of receipt of the revocation decision.

4. Competent authorities when issuing Decisions to revoke these types of certificates shall simultaneously carry out the revocation of the electronic versions and announce on their Information System or Official Website.

Chapter VII

STATE MANAGEMENT RESPONSIBILITIES FOR SCIENCE AND TECHNOLOGY ACTIVITIES, INNOVATION AND DATA PRODUCTS AND SERVICES SCIENCE AND TECHNOLOGY, INNOVATION AND CREATIVE PRODUCTS AND SERVICES RELATING TO DATA

Article 40. Responsibilities of the Ministry of Public Security

1. Taking the lead and coordinating with relevant ministries and agencies to manage international cooperation in science and technology activities and innovation related to data; supporting the nurturing and development of startup ecosystems for data products and services; implementing training, upgrading, and enhancing the professional expertise of the scientific and technological workforce in the field of data.

2. Promoting, disseminating, and educating laws in areas under specialized management related to science and technology activities, innovation, and data products and services.

3. Guiding and organizing the issuance, reissuance, replacement, and revocation of Certificates of Participation in Controlled Testing Activities, Certificates of Completion of Controlled Testing Activities, Certificates of Eligibility for Operating Data Marketplaces, Certificates of Eligibility for Trading Intermediary Data Products and Services, Certificates of Eligibility for Trading Analytical and Aggregating Data Products and Services, and Certificates of Eligibility for Providing Analytical and Aggregating Data Products and Services.

4. Leading and coordinating with ministries and sectors to implement inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to controlled testing activities, data marketplace trading activities, trading intermediary data products and services, and trading and providing analytical and aggregating data products and services as stipulated in this Decree within their jurisdiction.

5. Issuing and proposing amendments, supplements, and improvements to regulatory legal documents in the fields of science and technology, innovation, and data products and services within their jurisdiction.

Article 41. Responsibilities of the Ministry of National Defense, the Ministry of Science and Technology, the Ministry of Finance, and the Ministry of Education and Training

1. Responsibilities of the Ministry of National Defense

a) Implement international cooperation in scientific, technological, and innovation activities related to data within their respective areas of management;

b) Popularize, promote, and educate laws in specialized fields related to scientific, technological, and innovation activities and products and services about data within their respective areas of management;

c) Guide and organize the issuance of Certificates for participation in controlled testing activities, Certificates for completion of controlled testing activities; decide on adjustments, extensions of controlled testing periods; inspect, supervise research, application of science, technology, and innovation in the construction, development, protection, management, processing, and use of data in the defense and classified sectors;

d) Carry out inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to controlled testing activities concerning data in the defense and classified sectors; coordinate with the Ministry of Public Security to carry out inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to the business and provision of intermediary data products and services, business and provision of data analysis and synthesis products and services, and data trading platform business as stipulated in this Decree within their respective authorities;

e) Issue regulations within their authority and propose amendments and supplements to improve normative legal documents in the fields of science, technology, innovation, and data products and services;

2. Responsibilities of the Ministry of Science and Technology

a) Implement international cooperation in scientific, technological, and innovation activities related to data within the scope of their assigned functions and tasks;

b) Coordinate with the Ministry of Public Security and the Ministry of Education and Training to develop training programs and implement training and capacity building to enhance the professional expertise of the scientific and technological workforce in the field of data;

c) Coordinate with the Ministry of Public Security to carry out inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to controlled testing activities concerning data, business and provision of intermediary data products and services, business and provision of data analysis and synthesis products and services, and data trading platform business as stipulated in this Decree within their respective authorities;

d) Propose amendments and supplements to improve normative legal documents in the fields of science, technology, innovation, and data products and services;

3. Responsibilities of the Ministry of Finance

a) Implement international cooperation in scientific, technological, and innovation activities related to data within the scope of their assigned functions and tasks;

b) Coordinate with the Ministry of Public Security to carry out inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to controlled testing activities concerning data, business and provision of intermediary data products and services, business and provision of data analysis and synthesis products and services, and data trading platform business as stipulated in this Decree within their respective authorities;

c) Propose amendments and supplements to improve normative legal documents in the fields of science, technology, innovation, and data products and services;

4. Responsibilities of the Ministry of Education and Training

a) Implement international cooperation in education and training related to data, consistent with their assigned functions and tasks;

b) Take the lead and coordinate with the Ministry of Public Security and relevant ministries, agencies, and organizations to organize and develop proposals for training high-quality human resources to meet the requirements of scientific, technological, and innovation activities related to data;

c) Take the lead and coordinate with the Ministry of Public Security and relevant ministries, agencies, and organizations to establish mechanisms and policies on credit, scholarships, and tuition fees to attract students and special mechanisms for public-private partnership in training fields such as information technology, cybersecurity, data science, and artificial intelligence;

d) Coordinate with the Ministry of Public Security to carry out inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to controlled testing activities concerning data, business and provision of intermediary data products and services, business and provision of data analysis and synthesis products and services, and data trading platform business as stipulated in this Decree within their respective authorities;

đ) Propose amendments and supplements to improve normative legal documents in the fields of education and training related to science, technology, innovation, and data products and services.

Article 42. Responsibilities of other ministries, ministerial-level agencies, government agencies, provincial People's Committees, and centrally governed city People's Committees

1. Implement international cooperation in scientific, technological, and innovation activities related to data within their assigned functions, tasks, and jurisdictions.

2. Popularize, promote, and educate laws in specialized fields related to scientific, technological, and innovation activities and products and services about data managed by their own ministries, sectors, and localities.

3. Guide and organize the issuance of Certificates for participation in controlled testing activities, Certificates for completion of controlled testing activities; decide on adjustments, extensions of controlled testing periods; inspect, supervise research, application of science, technology, and innovation activities in building, developing, protecting, managing, processing, and using data within their management areas.

4. Coordinate with the Ministry of Public Security to implement inspection, supervision, complaint resolution, prevention, detection, and handling of violations related to controlled testing activities on data, data intermediary product and service business operations, data analysis and synthesis product and service business operations, and data exchange platform business operations as stipulated in this Decree according to their authority and jurisdiction.

5. Propose amendments and supplements to improve regulatory legal documents in the fields of science, technology, innovation, and data products and services.

6. Direct subordinate agencies to record and transfer to competent authorities the certificates submitted by organizations and individuals, including: Certificates for participation in controlled testing activities; Certificates for meeting conditions to conduct data exchange platform business operations; Certificates for meeting conditions to conduct data intermediary product and service business operations; Certificates for meeting conditions to conduct data analysis and synthesis product and service business operations; Certificates for meeting conditions to provide data analysis and synthesis products and services.

Chapter VIII

IMPLEMENTATION

Article 43. Amending and supplementing certain articles of Decree No. 69/2024/NĐ-CP dated June 25, 2024, of the Government on electronic identification and authentication

1. Amend and supplement Clause 4, Clause 6, and Clause 9 of Article 3 as follows:

a) Amend and supplement Clause 4 as follows:

"4. The agency managing electronic identification and authentication is the Ministry of Public Security.";

b) Amend and supplement Clause 6 as follows:

"6. Electronic authentication is the activity of verifying electronic data to confirm its accuracy, carried out through the National Integrated Database, the electronic identification and authentication system, and other data platforms organized and implemented by the data owner or manager.";

c) Amend and supplement Clause 9 as follows:

"9. An organization providing electronic authentication services is a public service unit or state-owned enterprise operating in Vietnam that meets the conditions for conducting electronic authentication business operations as stipulated in this Decree and relevant laws.".

2. Amending and supplementing Article 21 as follows:

"Article 21. Methods of electronic authentication in implementing transactions through the electronic identification and authentication system, data exchange platforms, the National Integrated Database, or other methods provided by the Ministry of Public Security

1. Electronic authentication for online transactions is conducted through appropriate authentication means based on the level of authentication required by the online service provider.

2. For cases where electronic identification account information verification is performed at the transaction location, it is conducted through solutions provided in the National Identification Application, data exchange platforms, the National Integrated Database or other methods provided by the Ministry of Public Security.".

3. Amend and supplement Clause 1 of Article 23 as follows:

"1. Organizational and business conditions

Public service units and state-owned enterprises operating in Vietnam.".

4. Replace and abolish certain phrases in points, clauses, and articles of Decree No. 69/2024/NĐ-CP dated June 25, 2024, of the Government on electronic identification and authentication as follows:

a) Replace the phrase "police station, commune police station, town police station, or identity management agency of the provincial public security department, district public security department" with the phrase "police station, commune police station, special zone police station, or identity management agency of the provincial public security department" in Articles 15, 29, and 30;

b) Replace the phrase "convenient identity management agency" with the phrase "convenient identity management agency or commune police station" in Clause 1 of Article 12; replace the phrase "Ministry of Information and Communications" with the phrase "Ministry of Science and Technology", and the phrase "Ministry of Planning and Investment" with the phrase "Ministry of Finance" in Articles 34, 35, 36, and 41;

c) Abolish the phrase "nearest district public security department" in point c of Clause 2 and point b of Clause 3 of Article 15, Clause 2 and Clause 3 of Article 29, and Clause 2 and Clause 3 of Article 30; remove the phrase "district public security department" in point d and point đ of Clause 2 and point c and point d of Clause 3 of Article 15, Clause 4 and Clause 5 of Article 29, and Clause 4 and Clause 5 of Article 30;

d) Abolish Clause 4 of Article 23.

Article 44. Effectiveness and Responsibility for Implementation

1. This Decree takes effect from July 1, 2025.

2. The Ministry of Public Security shall be responsible for guiding, inspecting, and urging the implementation of this Decree.

3. The Minister, head of a ministerial-level agency, head of a government agency, and Chairperson of the provincial or centrally governed city People's Committee shall be responsible for enforcing this Decree.

Place of Receipt:
- Central Party Committee Secretariat;
- Prime Minister, Deputy Prime Ministers;
- Ministries, ministerial-level agencies, government-affiliated agencies;
- People's Councils, People's Committees of provinces and centrally-administered cities;
- Central Party Office and Party Committees;
- General Secretary's Office;
- President's Office;
- Ethnic Council and Committees of the National Assembly;
- National Assembly's Office;
- Supreme People's Court;
- Supreme People's Procuracy;
- State Audit Office;
- Vietnam Fatherland Front Central Committee;
- Central agencies of mass organizations;
- VPCP: BTCN, all PCN, Assistant PM, Director General of the Government Portal,

  various Departments, Bureaus, subordinate units, Official Gazette;
- Note: VT, KSTT (2b).

PRIME MINISTER

DEPUTY PRIME MINISTER

DEPUTY PRIME MINISTER

 

Nguyen Chi Dung

 

The original file of this document is being updated. Please read the full text and check back later.

Relations map

169/2025/NĐ-CP
Decree No. 169/2025/NĐ-CP on scientific activities, technology, innovation, and data products and services
In effect

Click a document to open. A red border = a relation that changes validity.