Circular No. 64/2024/TT-NHNN on the implementation of application programming interfaces (APIs) in the banking industry

Circular No. 64/2024/TT-NHNN stipulates the implementation of application programming interfaces (Open API) in the banking industry. This Circular applies to banks and related organizations and individuals. Notable points include providing basic and other Open APIs, requiring data security contracts, publicizing Open API information, and defining responsibilities for both banks and third parties.

文号64/2024/TT-NHNN
文件类型Circular
发布机关State Bank of Vietnam
签署人Phạm Tiến Dũng — Phó Thống đốc
更新23/06/2026
行业Banking
领域Banking Information Technology
发布日期31/12/2024
生效日期01/03/2025
失效日期
状态In effect
✦ 智能摘要

Circular No. 64/2024/TT-NHNN stipulates the implementation of application programming interfaces (Open API) in the banking industry. This Circular applies to banks and related organizations and individuals. Notable points include providing basic and other Open APIs, requiring data security contracts, publicizing Open API information, and defining responsibilities for both banks and third parties.

适用范围

Commercial banks, cooperative banks, foreign bank branches (collectively referred to as Banks), organizations, and individuals involved in implementing services through application programming interfaces in the banking industry.

要点

  • Banks are permitted to implement basic and other Open APIs as prescribed;
  • Banks must enter into contracts with third parties regarding the implementation of Open API, including contents such as information security, using data within the scope and purpose;
  • Banks must publicly disclose Open API information on their official electronic websites;
  • Banks are responsible for completing infrastructure systems, developing guidance materials, ensuring data quality, and monitoring access activities;
  • Third parties have rights according to contracts or agreements with Banks and customers;
  • Third parties must provide tools allowing customers to search and withdraw their consent;

🌐 本文件的社会影响

  • Positive: Enhance flexibility in providing banking services, promote cashless payments;
  • Negative: May increase costs for banks and related organizations due to investment in new technical systems; customers may face difficulties in understanding and using Open API;

❓ 常见问题

What types of Open API are banks allowed to implement?

Banks are allowed to implement basic Open API (including querying exchange rates, interest rates, and related services) and other Open API based on actual needs;

What contents should be included in the contract between the Bank and the third party?

Contracts between Banks and third parties need to include contents such as information security, data usage within the scope and purpose, and other necessary provisions.

全文

STATE BANK OF VIETNAM
VIETNAM

Number: 64/2024/TT-NHNN

SOCIALIST REPUBLIC OF VIETNAM

Independence - Freedom - Happiness

Hanoi, December 31, 2024

CIRCULAR

Regulations on the Implementation of Application Programming Interfaces

in the Banking Industry

Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;

Pursuant to the Law on Credit Institutions dated January 18, 2024;

Pursuant to the Law on Electronic Transactions dated June 22, 2023;

||| Pursuant to the Cybersecurity Law dated November 19, 2015;

Based on Decree No. 52/2024/NĐ-CP dated May 15, 2024, of the Government on non-cash payments;

Pursuant to Decree No. 13/2023/NĐ-CP dated April 17, 2023 of the Government on personal data protection;

Pursuant to Decree No. 102/2022/NĐ-CP dated December 12, 2022 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;

At the proposal of the Director of the Department of Information Technology;

The Governor of the State Bank of Vietnam promulgates this Circular regulating the implementation of application programming interfaces in the banking industry.

PART I
GENERAL PROVISIONS

Article 1.  Scope of application

1.  This Circular regulates the implementation of application programming interfaces in the banking industry.

2.   This Circular does not regulate the connection and processing of data containing information within the scope of state secrets. Processing of data containing information within the scope of state secrets shall be carried out in accordance with current laws.

3.   This Circular does not regulate the direct connection and processing of data between:

a)    The information system of the Bank and the information system of an organization through application programming interfaces for internal business operations of that organization;

b)    The information system of the Bank and the information system of the Organization responsible for the electronic settlement system. The Organization responsible for the electronic settlement system is determined according to the regulations of the State Bank of Vietnam on the provision of payment intermediary services.

Article 2.  Applicability

1.  Commercial banks, cooperative banks, foreign bank branches (hereinafter collectively referred to as Banks).

2.   Organizations and individuals related to the implementation of services through open application programming interfaces in the banking industry.

Article 3.  Definitions

Strategic multi-purpose hydropower plant

1. Application Programming Interface (API) (in English: Application Programming Interface, hereinafter abbreviated as API) is an interface allowing communication between software applications within an organization or between organizations.

2. Open API in the banking industry (Open API) is a set of APIs provided by the Bank to third parties for direct connection and processing of data to provide services to customers. Open API includes Basic Open API and Other Open API.

3. Open API testing system is the information system of the Bank provided to third parties for testing Open API before official deployment.

4. Customer is an individual using the Bank's services.

5. Third party is an organization or another Bank that has agreed by contract with the Bank for connection and processing of data through Open API to provide services to customers.

6. Customer consent is the clear, voluntary expression of permission for the processing of customer personal data.

Article 4.  General Principles

When implementing Open API, the Bank, customer, and third party (hereinafter referred to as the parties) must comply with the following requirements:

1.  Compliance with legal provisions on maintaining confidentiality, providing customer information, and protecting personal data. Processing of customer personal data must only serve the customer themselves, except as provided by law.

2.  Data during processing must be managed, stored, exploited, and used for the purpose specified in the contract between the parties and in compliance with legal provisions.

3.  Data during processing must ensure accuracy and timeliness. In case of discrepancies, timely corrections and adjustments must be made according to the agreement between the parties.

Chapter II
SPECIFIC REGULATIONS ON THE IMPLEMENTATION OF OPEN API

Section 1

REGULATIONS ON THE IMPLEMENTATION OF OPEN API

Article 5.  Principles for Implementing Open API

1.   When implementing Basic Open API as stipulated in Article 6 of this Circular, the Bank must comply with the provisions in Appendix 01 and Appendix 02 issued together with this Circular.

2.  When implementing Other Open API based on actual needs and in compliance with legal provisions outside the list of Open API stipulated in Article 6 of this Circular, the Bank must comply with the provisions in Appendix 02 issued together with this Circular.

3.   The Bank may only implement Open API stipulated in point c, Clause 1, Article 6 for third parties that are Banks or organizations providing payment intermediary services.

Article 6.  List of Open API

1.   The basic list of Open API is organized into the following groups:

a)  Open API for querying exchange rates and interest rates of the Bank including: Interest Rate Information Retrieval API, Exchange Rate Information Retrieval API;

b)   Open API for querying customer information including: Customer Consent and Retrieval API, Access Code Retrieval API, Refresh Access Code API, Withdraw Access Code API, Account List Retrieval API, Account Information Retrieval API, Transaction History Retrieval API;

c)   Open API for initiating payments, topping up e-wallets, withdrawing from e-wallets including:

(i)  Open API for initiating payments including: Payment Initiation API, Redirect Flow Customer Confirmation API, Redirect Flow Access Code Retrieval API, Decoupled Flow Customer Payment Confirmation Status Update API, Payment Confirmation API, Transaction Status Retrieval API, Decoupled Flow Customer Payment Confirmation Status Retrieval API;

(ii)   Open API for topping up e-wallets including: E-Wallet Top-Up API, OTP Confirmation API, Decoupled Flow Customer E-Wallet Top-Up Confirmation Status Update API, Decoupled Flow Customer E-Wallet Top-Up Confirmation Status Retrieval API, E-Wallet Top-Up Confirmation API, Transaction Status Retrieval API;

(iii) Open API for withdrawing from e-wallets.

2.  Detailed specifications of the list of Open API at Clause 1 of this Article are specifically regulated in Appendix 01 issued together with this Circular.

Article 7.  List of Technical Standards

1.  Technical standards for implementing Open API include architectural standards, data standards, and information security standards.

2.  Technical standards for implementing Open API in the banking industry are specifically regulated in Appendix 02 issued together with this Circular.

Article 8.  Contract between the Bank and the Third Party

The Bank must enter into a contract with the third party regarding the implementation of Open API, including at least the following contents:

1. Commitment to information security, including agreements on ensuring safety and security of information when processing data through Open API provided by the Bank.

2. Commitment to use data provided by the Bank within the prescribed scope and purpose.

3. The third party must notify the Bank upon discovering personnel violating network security regulations when implementing Open API.

4. Information about services provided to customers implemented through Open API.

5. Information on service fees provided to customers through Open API (if applicable).

6. Terms regarding the third-party information system connected and processing data through Open API must be evaluated and determined at the appropriate level according to the Government's regulations on ensuring the security of information systems by level.

7. Third party's access rights to data when implementing Open API.

8. Termination clause.

Article 9.  Publicizing Open API Information

Before officially connecting and processing data with third parties, the Bank must publicize Open API information on its official electronic website, including at least the following contents:

1. Information about the Open API Testing System.

2. List of Open APIs implemented by the Bank.

Section 2 

COMPETENT AUTHORITY AND RESPONSIBILITIES OF THE BANK AND THIRD PARTIES

Article 10.  Rights of the Bank

1.   Requesting third parties to provide necessary information related to the connection and data processing through Open API.

2.    Other rights stipulated in the contract with third parties.

Article 11.  Responsibilities of the Bank

1.   Completing the infrastructure for the information system serving the implementation of Open API to be ready for connection and data processing.

2.    Developing and perfecting guidance documents for connection and data processing.

3.     Ensuring data quality during the implementation of Open API. Timely notifying third parties of any data discrepancies and coordinating with them to correct and adjust promptly.

4.     Ensuring cybersecurity for the information system implementing Open API, meeting at least Level 3 according to the Government's regulations on ensuring the security of information systems by level and complying with the State Bank of Vietnam's regulations on information system security in banking operations.

5.     Providing tools or functions allowing customers to perform:

a)     Querying customer data that they have agreed to allow third parties to process;

b)      Withdrawing customer consent in accordance with the law.

6.      Establishing a timeframe for querying customer information after obtaining customer consent not exceeding 180 days, except in cases where there is a different agreement between the customer and the Bank.

7.       Providing information on the implementation of Open API to the State Bank of Vietnam (through the Department of Information Technology) upon request.

8.   Cooperating with third parties according to agreements and with competent authorities to resolve issues and disputes during the implementation of Open API.

9.   Implementing technological solutions to limit the number of automatic queries of customer information from third parties.

10.   Being responsible for selecting, assessing, monitoring, and managing third parties.

11.   Updating or revoking third parties' data access rights when changes occur according to the contract.

12.   Monitoring access activities:

a)     Having a monitoring system to detect and prevent abnormal or unauthorized access from third parties;

b)      Recording all usage of Open API from third parties for a minimum of three months and backing up for a minimum of one year to serve necessary inspections.

Article 12.  RIGHTS AND RESPONSIBILITIES OF THIRD PARTIES

1.    Third parties have rights according to contracts or agreements with the Bank and customers.

2.     Responsibilities of third parties:

a)  Providing tools or functions allowing customers to perform online:

(i) Querying customer data that they have agreed to allow third parties to process;

(ii) Withdrawing customer consent in accordance with the law.

b)  Notifying customers of terms and conditions for using services and guiding them on how to use services.

c)  Issuing risk management procedures; customer care procedures; complaint handling procedures; dispute resolution procedures; continuity assurance procedures; and service usage procedures when providing services to customers.

d)  Exploiting and using data within the agreed scope among the parties and in accordance with the law.

d) Promptly notifying the Bank of any IT incidents or information security issues when implementing Open API. The form and time of notification shall be agreed upon between the Bank and the third party.

e)  Promptly notifying the Bank of any data discrepancies and coordinating with the Bank to correct and adjust promptly. The form and time of notification shall be agreed upon between the Bank and the third party.

Chapter III
IMPLEMENTING PROVISIONS

Article 13.  Responsibilities of the Department of Information Technology

1.  Taking the lead and coordinating with relevant units under the State Bank of Vietnam to handle issues arising during the implementation of this Circular.

2.   Monitoring, summarizing, and reporting to the Governor of the State Bank of Vietnam on the implementation status of banks as prescribed in this Circular.

3.     Inspecting banks in their implementation of this Circular.

Article 14.  Effectiveness

This Circular takes effect from March 1, 2025.

Article 15.  Transitional Provisions

Banks that have directly connected and processed data with third parties through API or Open API to provide services to individual customers before the effective date of this Circular must implement:

1.   Compiling a list of currently implemented APIs, Open APIs, and detailed plans to ensure compliance with this Circular's provisions and submit it to the State Bank of Vietnam (through the Department of Information Technology) by July 1, 2025.

2.    Complying with the provisions of this Circular by March 1, 2027.

Article 16.  Implementation

Heads of units under the State Bank of Vietnam, commercial banks, cooperative banks, and foreign bank branches are responsible for organizing the implementation of this Circular./.

 Place of Receipt:
- As per Article 16;

- SBV Leadership;
- Government Office;
- Ministry of Justice (for verification);
- Official Gazette;

- The State Bank of Vietnam's Online Portal;
- To be filed: VP, PC, CNTT (three copies).

DIRECTOR
DEPUTY DIRECTOR

(Signed)

Pham Tien Dung

原始文件(PDF)

在新标签页打开PDF ↗

关系图

64/2024/TT-NHNN
Circular No. 64/2024/TT-NHNN on the implementation of application programming interfaces (APIs) in the banking industry
In effect

点击文件即可打开。红色边框=改变效力的关系。