Decree 314 /2026/ND-CP, effective from September 25, 2026, establishes rules for listing, testing, contracting, delivering, and maintaining traceability for data, data products, and data services on regulated data exchanges.
It reflects Vietnam’s move toward enabling the controlled commercial use of data and helps create a more consistent framework for verifying lawful origin, confirming transaction rights, and defining permitted use.
Decree 314 focuses on data exchange activities. Broader obligations under Vietnam’s Data Law, personal data protection, cybersecurity, intellectual property, and other applicable rules continue to apply.

What Changes Under Decree 314
Participation is subject to eligibility, identity verification, and account registration requirements. Foreign legal entities must also satisfy the applicable requirements for a lawful presence in Vietnam. The registration route depends on the electronic identification framework and the exchange procedures in force at the time. Additional supporting documents or verification may be required where electronic identification is unavailable or insufficient.
Decree 314 also provides for a National Data Exchange to be operated by the competent state data authority.
A seller must be able to demonstrate lawful origin and sufficient rights to offer the relevant data, product, or service on the exchange. Listings must provide clear information on technical characteristics, quality, price, applicable limitations, and the scope of rights offered to the buyer. Review by an intermediary or the exchange does not remove the seller’s responsibility for the lawfulness and accuracy of the listing.
Personal data remains outside ordinary trade. Decree 314 prohibits buying or selling it through an exchange or processing it unlawfully. Derived products may be transacted only after de-identification and compliance with other personal-data rules. The Vietnam Personal Data Protection Law still governs the underlying processing; a listing does not authorize collection, disclosure, combination, or reuse.
Transactions are completed electronically and must remain traceable. Contracts must cover the matters required by the Decree, including the subject matter, quality, permitted use, price, delivery, confidentiality, liability, dispute resolution, and termination. The parties must use a signature or authentication method permitted by applicable law and the exchange’s rules. Payments are made on a non-cash basis in Vietnamese dong through permitted payment channels.
Controlled testing is available before purchase. A buyer may assess a product in an isolated environment for up to 30 days. Complex or large-volume products may receive an extension, but total testing cannot exceed 60 days. Original seller data cannot be downloaded, copied, or extracted, and outputs undergo technical review. Each party remains responsible for its data and later use of results.
Why the New Framework Matters to Foreign Investors
For management, an exchange transaction is not simply a technology purchase. It is a licensing and governance decision requiring evidence of origin, rights, quality, permitted use, and compliance with the wider Data Law.
Foreign groups should distinguish participation from operation. Qualifying foreign entities may buy or sell, but Decree 314 does not change rules reserving exchange operation to qualifying public service units and state-owned enterprises. Investors considering data infrastructure, intermediary services, or analytics should assess foreign ownership and market access in Vietnam for each revenue activity.
Cross-border use remains a separate issue. Parties remain subject to data, personal-data, cybersecurity, and related laws; completing an exchange transaction does not clear offshore processing or onward transfer to an overseas affiliate.
What Companies Should Review Before a Data Exchange Transaction
- Confirm the participating entity, role, and authorized signatory. Identify which group entity will act as seller or buyer, who may bind it, and which electronic confirmation method will be used.
- Prepare evidence of data origin and licensing authority. Sellers must retain contracts, consents, creation records, licenses, authorizations, and technical records supporting the data’s origin and available rights.
- Define permitted use before buying. Buyers must translate the agreed purpose, term, territory, copying limits, and onward-transfer restrictions into controls for employees, affiliates, AI systems, and vendors.
- Check which other legal requirements apply. Before listing, testing, or purchase, the company must identify personal data, re-identification risks, non-tradable data, intellectual property, confidential information, and cross-border processing requirements.
- Create an internal approval process. Management should require legal, data, security, finance, and business owners to approve higher-risk transactions and align commercial purpose, delivery, and recorded rights.
- Strengthen contract terms on acceptance and remedies. Management should define quality, testing, security responsibility, correction or replacement, refunds, indemnities, evidence preservation, governing law, and disputes. Weak drafting can turn uncertainty over origin, quality, or misuse into technology disputes in Asia.
Frequently Asked Questions
Q1: Can an overseas company participate without incorporating a Vietnamese subsidiary?
Potentially, depending on the foreign entity’s legal presence in Vietnam, the exchange’s registration requirements, and applicable market access rules. A branch, representative office, or other local presence does not automatically authorize every commercial activity, so the proposed role must be reviewed separately.
Q2: Can personal data be sold after it is listed on a data exchange?
No. Personal data cannot be bought or sold through a data exchange. A derived product may be transacted only after proper de-identification and satisfaction of all other personal-data requirements. Re-identification risk must be assessed.
Q3: Does data-exchange approval protect the parties from later liability?
No. Operator and intermediary checks do not remove seller responsibility for origin, authority, quality, and technical compliance or the buyer’s duty to stay within permitted use. Operators may suspend risky transactions or remove noncompliant listings; contractual remedies and compensation for actual loss may apply. Other laws may also apply. Decree 314 contains no standalone administrative-fine schedule.
Immediate Management Priority
Decree 314 turns data commercialization through regulated exchanges into a documented, traceable process. Before approving or entering a transaction, management should identify the participating entity, confirm lawful origin and transaction rights, and align the permitted use with internal controls. Commercial value depends on clear rights, reliable quality, and compliant use.
Không có nhận xét nào: