This Circular details the procedures for connecting, sharing, and exploiting information within the National Population Registry Database among agencies, organizations, and the Ministry of Public Security. This Circular takes effect from December 19, 2022.
Scope of application
Units under the Ministry of Public Security, Provincial Police Chiefs, Municipal Police Chiefs directly under the Central Government, and related agencies, units, and individuals involved in the connection, sharing, and exploitation of information within the National Population Registry Database.
Key points
- Detailed provisions on the rights and responsibilities of participating parties.
- Guidelines for the implementation process of connecting the National Population Registry Database with other databases.
- Requirement to store logs of connections, sharing, and exploitation of information for at least two years.
- Citizens can search and exploit personal information through the public service portal.
- The Ministry of Public Security is responsible for guiding and resolving issues arising during the implementation process.
🌐 Social impact of this document
- Enhance the effectiveness of state management over population.
- Ensure the accuracy and timeliness of population information.
- Reduce costs and time for agencies and organizations when exploiting information.
- Better serve citizens' needs for searching personal information.
❓ Frequently asked questions
How can citizens conduct searches for information?
Citizens log in to the public service portal, select the search or exploitation service for personal information. Results will be returned through the public service portal or via Notification Form No. 01.
What is the duration for storing logs of connections, sharing, and exploitation of information in the National Population Registry Database?
The minimum retention period for logs is two years from the date of performing the connection, sharing, and exploitation of information.
Which agency is responsible for resolving issues during the process of connecting, sharing, and exploiting information?
The Ministry of Public Security leads and coordinates with relevant agencies to resolve incidents and issues that arise.
Full text
CIRCULAR
(vi) Agreement on the amount of reserve left behind and the deadline for selling the purchased cash foreign currency to the authorized credit institution. concerning the connection, sharing and exploitation of individuals registered in accordance with the law continues to be updated into the information between
the National Population Registry with national databases,
specialized databases and other information systems
The Minister of National Defense hereby issues this Circular amending and supplementing certain articles of normative legal documents within the competence to issue of the Minister of National Defense related to the declaration of personal information when performing administrative procedures.
||| Pursuant to the Cybersecurity Law dated November 19, 2015;
||| Pursuant to the Cyber Security Law dated June 12, 2018;
Pursuant to Decree No. 137/2015/NĐ-CP dated December 31, 2015 of the Government detailing certain provisions and measures for implementing the Law on Identity Cards;
Pursuant to Decree No. 37/2021/NĐ-CP dated March 29, 2021 of the Government amending and supplementing certain articles of Decree No. 137/2015/NĐ-CP dated December 31, 2015 of the Government detailing certain provisions and measures for implementing the Law on Identity Cards;
Pursuant to Decree No. 47/2020/NĐ-CP dated April 9, 2020 of the Government on management, connection, and sharing of information by state agencies;
Pursuant to Decree No. 85/2016/NĐ-CP dated July 1, 2016 of the Government on ensuring security levels for information systems;
CPursuant to Decree No. 01/2018/NĐ-CP dated August 6, 2018 of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Public Security;
1. Amending and supplementing Clause 2 and Clause 3 of Article 3 as follows:
The Minister of Public Security issues this Circular stipulating for connection, sharing, and exploitation of information between the National Population Registry with national databases, specialized databases, and other information systems.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Circular stipulates principles for connecting, sharing, and exploiting information between the National Population Registry with national databases, specialized databases, and other information systems; methods for connecting, sharing, and exploiting information; conditions for ensuring security, safety, confidentiality of information, and monitoring the implementation of connections, sharing, and exploitation of information with the National Population Registry.
Article 2. Applicability
1. The managing agency of the National Population Registry.
2. Agencies, organizations, and individuals specified in Article 8 of Decree No. 137/2015/NĐ-CP dated December 31, 2015 of the Government detailing certain provisions and measures for implementing the Law on Identity Cards, as amended and supplemented by Decree No. 37/2021/NĐ-CP dated March 29, 2021.
Article 3. Principles for connecting, sharing, and exploiting information between the National Population Registry with national databases, specialized databases, and other information systems
1. Compliance with laws on personal data protection; ensuring provisions on information security, network security, and safety according to current laws.
2. Not affecting the rights and responsibilities of relevant agencies, organizations, and individuals, and not infringing upon privacy, personal secrets, family secrets except where otherwise provided by law.
3. The managing agency of the National Population Registry under the Ministry of Public Security shall be responsible for connecting and sharing information within the National Population Registry with agencies, organizations, and individuals in accordance with the law.
4. Agencies, organizations, and individuals who connect, share, and exploit information from the National Population Registry must ensure infrastructure conditions for information systems, connection models, data structures, information security, safety, and confidentiality in accordance with the law.
Chapter II
MANAGEMENT OF CONNECTIONS, SHARING AND EXPLOITATION OF INFORMATION
IN THE NATIONAL POPULATION REGISTRY
Article 4. Information shared with the National Population Database
1. The shared electronic household registration database, residence database, citizen identity card database, health database, and other specialized databases shall share information about citizens with the National Population Database in accordance with the law to ensure uniformity, completeness, accuracy, and timeliness.
2. Specialized information related to citizens (as specified in the attached Appendix) when shared by agencies and organizations with the Ministry of Public Security shall be received by the National Population Database Management Agency of the Ministry of Public Security as the central point for exploitation and utilization to serve population management work and meet other operational requirements of local public security units according to their assigned functions, tasks, and authorities.
Article 5. Methods of Connecting and Sharing Information between the National Population Database and Other National Databases, Specialized Databases, and Other Information Systems
1. The connection and sharing of information between the National Population Database and other national databases, specialized databases, the National Public Service Portal, the Central and Provincial Administrative Procedure Resolution Information System, and other information systems shall be carried out through the National Data Integration and Sharing Platform, the National Document Interconnection Trunk, and other connection platforms as prescribed by law.
2. Connection methods through application programming interfaces.
Article 6. Conditions for Connecting to the National Population Database
1. Information systems of agencies and organizations connecting to the National Population Database must meet the requirements for ensuring information system security at level 3 or higher as stipulated by laws on information system security levels.
2. Before or after connecting to the National Population Database, if there are adjustments or changes in the design of the information systems of agencies and organizations, they must undergo security and information safety inspections and evaluations. These inspections and evaluations are conducted using specialized devices and software of the People's Public Security Forces; the contents include:
a) Setting up security configurations on system devices, servers, applications, and databases;
b) Detecting malicious code, vulnerabilities, weaknesses, and system penetration testing for system devices, servers, and applications;
c) Application source code security;
d) Hardware security;
đ) Issuing regulations and policies on account management, entry and exit from server areas, password management for administrative accounts, access management, and agreements on rights, obligations, and responsibilities of subjects involved in managing, operating, and providing services for information systems.
3. For information systems managed by the Ministry of National Defense, the National Population Database Management Agency of the Ministry of Public Security has the responsibility to coordinate and guide specialized units of the Ministry of National Defense to implement security and information safety inspections and evaluations as stipulated in Clause 2 of this Article.
4. The Cybersecurity and High-Tech Crime Prevention Bureau shall take the lead and coordinate with the Technical Operations Bureau, the National Population Database Management Agency of the Ministry of Public Security, and relevant units to carry out:
a) Inspections and evaluations of the security and information safety of information systems requiring connection to the National Population Database before connection and issue a confirmation document on the assurance of security and information safety; in cases where information systems requiring connection to the National Population Database have already been connected to the electronic identity verification platform, they are exempted from security and information safety inspections and evaluations as stipulated in Clause 2 of this Article.
b) Random inspections and evaluations of the security and information safety of information systems connected to the National Population Database according to the contents stipulated in Clause 2 of this Article;
c) Regular inspections and evaluations (once every year) of the security and information safety of information systems connected to the National Population Database according to the contents stipulated in Clause 2 of this Article; except for information systems managed by the Ministry of National Defense; information systems that have already shared online data on cybersecurity monitoring and information security with the Ministry of Public Security; or information systems that have been inspected, evaluated, and confirmed by competent authorities within one year according to laws on information system security levels.
Article 7. Procedure for Connecting the National Population Registry Database with Other National Databases, Specialized Databases, and Information Systems
Clause 1. The agency or organization managing the information system shall submit a request for connection to the National Population Registry Database to the management agency of the National Population Registry Database under the Ministry of Public Security.
The request for connection shall include the following contents: registering unit; assigned functions, tasks, and authorities; name of the information system or database proposed for connection and sharing; information on the staff responsible for connection, sharing, and information extraction; purpose, scope, content, and number of fields of information required for sharing; registration service usage within the National Population Registry Database; technical documentation of the system component connected to the National Population Registry Database.
Clause 2. Upon receipt of the request, the management agency of the National Population Registry Database under the Ministry of Public Security shall undertake the following:
Point a) Provide technical materials to serve the connection, sharing, and exploitation of information in the National Population Registry Database for the requesting agencies and organizations.
Point b) Assist agencies and organizations in implementing connections, adjusting software, and conducting technical testing of sharing and exploiting information services in the National Population Registry Database.
Point c) Coordinate with the Cybersecurity and High-Tech Crime Prevention Bureau, the Technical Operations Bureau under the Ministry of Public Security, and related units to conduct inspections and evaluations of the security and safety of the information systems of the requesting agencies and organizations.
Article 8. Logging of Connections, Sharing, and Exploitation of Information
Clause 1. The management agency of the National Population Registry Database under the Ministry of Public Security and agencies and organizations engaging in connections, sharing, and exploitation of information from the National Population Registry Database shall be responsible for recording logs of these activities to support monitoring, inspection, and supervision work.
Clause 2. The minimum retention period for logs regarding connections, sharing, and exploitation of information in the National Population Registry Database System is two years from the date of implementation of such activities.
Article 9. Handling Incidents, Providing Support, and Resolving Issues in Connection, Sharing, and Exploitation of Information in the National Population Registry Database
Clause 1. Agencies and organizations engaging in connections, sharing, and exploitation of information in the National Population Registry Database shall be responsible for developing user guides and implementing information exploitation services within the National Population Registry Database of their own agencies and units.
Clause 2. Agencies, organizations, and individuals seeking to handle incidents, receive support, or resolve issues during operations and usage of functions, connections, sharing, and exploitation of information with the National Population Registry Database may do so through the email address [email protected], via contact phone numbers, at the office of the management agency of the National Population Registry Database under the Ministry of Public Security, or by submitting a written request for support and resolution of issues.
Article 10. Rights and Responsibilities of Agencies, Organizations, and Individuals Engaging in Connections, Sharing, and Exploitation of Information with the National Population Registry Database
Clause 1. Agencies, organizations, and individuals engaging in connections, sharing, and exploitation of information with the National Population Registry Database have the following rights:
Point a) To exploit and use information in the National Population Registry Database according to their functions, tasks, and registered purposes with the management agency of the National Population Registry Database.
Point b) To request the management agency of the National Population Registry Database under the Ministry of Public Security to resolve issues affecting their right to exploit and use information in the National Population Registry Database.
Clause 2. Agencies, organizations, and individuals engaging in connections, sharing, and exploitation of information with the National Population Registry Database have the following responsibilities:
Point a) To comply with the provisions of this Circular and other laws governing the management, connection, sharing, and use of information.
Point b) To exploit and use information in the National Population Registry Database within the permitted scope and consistent content of shared information.
Point c) To share information as stipulated in Article 4 of this Circular with the National Population Registry Database.
Point d) To promptly notify the management agency of the National Population Registry Database under the Ministry of Public Security about any errors in shared or exploited information.
Point đ) To cooperate with competent authorities and the management agency of the National Population Registry Database to resolve issues arising during the process of connecting, sharing, and exploiting and using information in the National Population Registry Database.
Article 11. Responsibilities of the National Population Registry Management Authority under the Ministry of Public Security
1. Develop guidance materials and technical support for connecting, sharing, and exploiting information within the National Population Registry.
2. Take the lead and coordinate with agencies and organizations that have systems connected to the National Population Registry and related agencies to resolve and address issues arising during implementation.
3. Coordinate with relevant units to conduct inspections according to regulations on ensuring the security and safety of information in systems that connect and share information with the National Population Registry.
Article 12. Citizens' Implementation of Information Search and Exploitation through the Public Service Portal
Citizens shall implement information search and exploitation through the public service portal as follows:
1. Citizens log into the public service portal.
2. Citizens select either the search service or the personal information exploitation service.
3. The Ministry of Public Security will provide citizens with search results via information displayed on the public service portal or issue a Notification according to Model No. 01 promulgated together with this Circular.
Chapter III
IMPLEMENTATION
Article 13. Effective Date
This Circular takes effect from December 19, 2022.
1. The Minister, Heads of Ministries equivalent to ministries, Heads of government agencies, Chairmen of provincial People's Committees under the central government, and related agencies, units, and individuals are responsible for implementing this Circular.
1. The Administrative Police Department is responsible for guiding, inspecting, urging, and enforcing this Circular.
2. Heads of units under the Ministry of Public Security, Provincial Police Directors, and heads of agencies and individuals involved are responsible for implementing this Circular. In case of difficulties or issues during the implementation of this Circular, local police units shall report to the Ministry of Public Security (through the Administrative Police Department) for timely guidance.
During the implementation of this Circular, if there are difficulties or issues, local police units shall report to the Ministry of Public Security (through the Administrative Police Department) for timely guidance./.
Relations map
Click a document to open. A red border = a relation that changes validity.
Translations
This document is available in the following languages: