Logistics and Cross-Border Customs Data

Sep 30, 202614 minute read

Logistics, Customs and Cross-Border Data in Vietnam: Building an Evidence Position Beyond the Broker Portal

blogdetail image
Logistics and Cross-Border Customs Data: Building an Evidence Position Beyond the Broker Portal

TL;DR: Vietnam’s logistics compliance environment is becoming more connected and more evidence-driven. The Customs Law remains the foundation, while Decree 336/2026/NĐ-CP, effective 15 October 2026, establishes the current National Single Window and ASEAN Single Window procedure layer for goods and transport. Circulars 127 and 128 add related customs information, document and smart-border requirements from the same date. For logistics providers supporting e-commerce, Decree 248/2026/NĐ-CP already adds quarterly reporting under Form 15. ComplianceOne connects shipment identities, parties, customs lodgement evidence, authority acknowledgements, amendments, clearance events, parcels, delivery proof, reporting obligations, claims, authorizations and cross-border processing references. It remains an evidence and GRC layer, not a customs filing, carrier, tax, warehouse or transport-management system.

A container is held at the border.

The customs team asks for the original filing, every amendment, the broker’s acknowledgement and the authority’s latest response.

Operations knows the booking reference.

The carrier uses a master transport document.

The freight forwarder searches by a house document.

The broker searches by a declaration number.

Finance knows an internal shipment code.

All five refer to the same consignment.

None of the systems starts from the same identity.

The evidence then arrives as screenshots, email attachments, portal exports and messages from the broker.

One file shows a status without the source response.

Another contains an amendment without its reason.

A third includes personal information about a consignor or recipient copied into a shared investigation folder.

The customs portal may be working exactly as intended.

The organization can still lack its own evidence position.

Cross-border logistics governance is not about replacing customs systems, carrier networks, transport-management platforms or warehouse applications.

It is about being able to reconstruct:

What was shipped?
Which evidence was lodged?
Who lodged it?
What did the authority return?
What changed?
Which parties and systems were involved?
Which reporting and privacy obligations applied?
And who made each accountable decision?

“Do we still have the photograph?”

The Regulatory Environment Has Moved Beyond the Broker Portal

Vietnam’s logistics evidence environment now has several distinct regulatory layers.

The Customs Law 54/2014/QH13, as amended, remains the core legal framework governing declarations, inspection, supervision and customs clearance.

But a significant new operational layer is now approaching.

Decree 336/2026/NĐ-CP, issued on 22 August 2026 and effective 15 October 2026, regulates administrative procedures for goods exported, imported or in transit, and for means of transport entering, leaving or transiting Vietnam, through the National Single Window and ASEAN Single Window mechanisms.

This matters because the evidence question increasingly extends beyond:

“What did our broker upload?”

Organizations also need to understand:

  • which administrative procedure was involved;
  • which data and documents supported it;
  • which party submitted the information;
  • what acknowledgement or response came back;
  • which amendment replaced or supplemented earlier evidence;
  • and whether the organization's own record can still be reconstructed independently of a portal screen.

ComplianceOne does not connect automatically to the National Single Window or ASEAN Single Window.

It provides the governance and evidence layer around what the organization's authorized systems, brokers and people did.

15 October 2026 Creates a Concrete Readiness Date

Decree 336 is enacted but, as of September 2026, not yet effective.

Its effective date is 15 October 2026.

Two related Ministry of Finance circulars take effect on the same day.

Circular 127/2026/TT-BTC regulates information indicators and declaration-document templates used for procedures involving means of transport entering, leaving or transiting border gates at airports, seaports, railways, roads and inland waterways.

Circular 128/2026/TT-BTC governs customs inspection, supervision and management of goods and means of transport operating in approved smart-border areas. Its scope is therefore more specific and should not be treated as automatically applicable to every logistics operator.

For logistics organizations, the readiness question is therefore not simply whether the broker or customs software will support the new procedures.

It is also:

Can the organization preserve its own evidence of the procedure after the operational transaction has finished?

One Consignment, Every Identity

A shipment is rarely known by one reference.

It may carry:

  • a booking reference;
  • house and master transport documents;
  • carrier tracking references;
  • customs or authority references;
  • a declaration number;
  • parcel identifiers;
  • and internal shipment or finance codes.

ComplianceOne connects these identifiers to one governed shipment record.

Searching by any recorded identity can resolve to the consignment.

If an identifier matches more than one shipment, the system should not silently select the first candidate.

Ambiguity becomes visible work.

That matters because during a customs inspection, hold, customer dispute or later audit, a plausible answer about the wrong shipment is more dangerous than no answer at all.

The shipment record can then connect the relevant parties, carriers, brokers, routes, cargo, warehouse references, documents, customs evidence, personal-data context and processing records.

It does not become a second TMS.

Operational systems remain responsible for booking, routing, inventory, movement and scanning.

ComplianceOne provides the common governance identity across them.

one consignment every identity

Hold Proof of the Filing, Not a Second Declaration

Customs filing systems and brokers create and transmit declarations and manifests.

ComplianceOne does not.

The governed record instead establishes that an artifact of a particular kind was lodged:

  • under which procedure reference;
  • for which shipment;
  • by which accountable party;
  • through which submission record;
  • and with which returned evidence.

The associated electronic-submission evidence can preserve:

  • the original payload or custody reference;
  • a payload hash;
  • acknowledgement or receipt;
  • authority status;
  • timestamps;
  • and subsequent amendments.

That makes the platform an independent evidence layer rather than another declaration system.

There is an important current product boundary here.

ComplianceOne's customs record does not contain a customs-version field.

Amendment lineage can exist through the linked electronic-submission history, but marketing, demonstrations and exported evidence should not describe that as a native “versioned customs declaration” capability.

The accurate statement is:

The original submission remains attributable, and each recorded amendment can retain its own evidence and relationship to the shipment.

Preserve the Authority’s Words Separately From the Organization’s Interpretation

Clearance belongs to the competent authority.

Compliance software should not derive legal clearance merely because a response contains a familiar code or phrase.

ComplianceOne therefore keeps the authority's response separate from the organization's interpretation of what that response means operationally.

A clearance history may record:

inspection → hold → request for additional information → response → release → later correction

without rewriting the earlier events.

The authority's wording remains part of the evidence.

The organization separately records its understanding and subsequent action.

The platform does not determine:

  • whether goods were correctly classified;
  • whether valuation was correct;
  • whether duty was correctly calculated;
  • whether an import was legally admissible;
  • or whether clearance should have been granted.

Those remain matters for the authority, declarant and qualified specialists.

Keep Commercial Figures as Declared Facts

Cargo records often contain tariff classifications, quantities or commercial values because reviewers need to know what a party declared.

Recording those values does not mean validating them.

ComplianceOne does not calculate:

  • customs duty;
  • customs value;
  • tariff amounts;
  • taxable bases;
  • cargo totals;
  • or customs risk scores.

The figure remains attributable to the system or party that supplied it.

That distinction is important.

The governance layer should preserve the evidence underlying a customs position without quietly creating a competing customs calculation.

E-Commerce Logistics Now Has a Separate Reporting Layer

One of the more important developments since the original version of this article is Vietnam's new e-commerce framework.

The E-Commerce Law 122/2025/QH15 and Decree 248/2026/NĐ-CP have applied since 1 July 2026. The Ministry of Industry and Trade describes the new framework as covering an online economy closely connected with logistics, exports, payments and the wider digital economy.

For organizations that fall within the definition of logistics service providers supporting e-commerce, Decree 248 creates a particularly concrete evidence requirement.

Before the 15th day of the first month of each quarter, those organizations must report online on the previous quarter's transport and delivery activity in Vietnam through the e-commerce activity management system using Form 15 in Appendix II.

That creates a new evidence chain:

Shipment activity
→ source systems
→ reporting population
→ reconciliation
→ Form 15 preparation
→ review and approval
→ submission evidence
→ acknowledgement / follow-up

ComplianceOne should not become the transport system that generates the underlying operational activity.

Instead it can govern:

  • which reporting obligation applies;
  • which legal entity owns it;
  • the quarter being reported;
  • which source systems provide the figures;
  • who prepares and reviews the report;
  • exceptions or mismatches;
  • approved versions;
  • and evidence of submission.

This is an important example of the same shipment data serving different legal purposes without becoming one generic “compliance record.”

Reconcile Reporting Against Operational Evidence

Reporting creates another familiar problem.

The carrier system says 120,000 deliveries.

The marketplace integration says 119,870.

The finance system says 119,940 completed transactions.

Thirty-eight shipments were returned after the reporting cut-off.

Which population belongs in the report?

A GRC system should not automatically answer the legal or accounting question.

It should show the discrepancy.

ComplianceOne can preserve:

  • each stated value;
  • its source;
  • the relevant period;
  • the extraction or evidence date;
  • the person reviewing it;
  • and the final human resolution.

The approved regulatory report then remains connected to the evidence that supported it.

That is much stronger than storing only the final Form 15 file.

Keep Parcel Events Append-Only

Parcel operations create dense event histories:

acceptance, routing, scans, failed delivery attempts, returns, customer complaints, remedies and closure.

Those events may be spread across carrier systems, courier applications and customer-service systems.

ComplianceOne can maintain an append-only parcel history.

A correction becomes a new event linked to the earlier event rather than silently altering history.

This matters particularly for disputes.

A delivery marked completed today may be followed by a complaint tomorrow.

A closed operational shipment should not erase later evidence about what happened.

The governing record should preserve the sequence.

Delivery Proof Is Also Personal-Data Evidence

govern delivery proof

Proof of delivery can contain particularly sensitive operational information.

A signature can identify a person.

A photograph can expose an address, home, workplace or household context.

Delivery records can combine recipient name, phone number, location, shipment history and communication records.

The draft already takes the right product position here: ComplianceOne requires a retention position before delivery proof is stored and records the organization's rule, deletion date and accountable author. It does not invent the retention period or automatically delete evidence.

That becomes even more important under Vietnam's current personal-data regime.

The Personal Data Protection Law 91/2025/QH15, Decree 356/2025/NĐ-CP and the enforcement framework under Decree 330/2026/NĐ-CP, effective 19 August 2026, now form the current operational and enforcement context for personal-data handling.

The logistics team therefore needs to know not merely:

“The broker runs the filing and the carrier runs the movement. The organization still needs its own proof of what happened.”

but:

Why do we have it?
Who can access it?
What processing activity is it connected to?
How long is it retained?
Where else was it copied?
And what evidence supports the retention decision?

Link Cross-Border Logistics to Existing Privacy Governance

An international shipment can involve personal data even when the goods themselves are not personal.

Consignor and consignee names, recipient addresses, telephone numbers, proof-of-delivery records, broker contacts and claims evidence can all travel across systems and borders.

ComplianceOne connects shipment and parcel records to the organization's existing processing activity and transfer-governance records.

It does not create a separate “logistics transfer lawfulness” conclusion.

That distinction matters.

A shipment moving internationally does not automatically mean every associated personal-data transfer has been fully assessed merely because the physical logistics transaction is legitimate.

The operational and privacy questions should remain linked but separate.

Cybersecurity and Incident Evidence Can Overlap With Logistics

The new cybersecurity implementation layer also matters where logistics systems fall within its actual scope.

The Government issued Decree 331/2026/NĐ-CP on cybersecurity protection for information systems and Decree 333/2026/NĐ-CP implementing the Cybersecurity Law on 19 August 2026; both took effect immediately.

That does not make every warehouse application or carrier portal automatically subject to identical requirements.

But it does reinforce another reason not to isolate logistics records.

A cyber incident involving a shipment, customs interface, broker connection or delivery platform may need to connect:

system
→ incident
→ affected data
→ operational shipment evidence
→ vendor
→ remediation
→ regulatory assessment

rather than living only as a helpdesk ticket.

Connect Authority Correspondence Without Creating Another Inbox

A shipment may become part of:

  • an inspection;
  • customs information request;
  • enforcement inquiry;
  • parcel dispute;
  • data-protection matter;
  • or another authority interaction.

ComplianceOne should not create a separate logistics correspondence lifecycle if the organization already has an authority-request record.

Instead, the shipment can be linked to that record.

The correspondence process continues to govern:

  • the request;
  • channel;
  • responsible owner;
  • response work;
  • verification;
  • evidence;
  • acknowledgement;
  • and conclusion.

The logistics record provides the shipment context.

This prevents two teams from maintaining different versions of the same authority response.

Preserve Postal and Operational Authorization Evidence

Logistics and postal businesses may also need evidence relating to licenses, notifications, amendments and reissues.

ComplianceOne can record authorization history and supersession.

But another existing product limitation should remain explicit:

The underlying regulatory content may distinguish an authority-issued artifact from an organization-prepared working record, while current register/evidence-pack exports do not necessarily preserve that distinction as an explicit exported marker.

A reviewer therefore should not assume that every document appearing in an export is an official authority form.

Artifact provenance still needs to be checked before filing or representing something externally.

Design Evidence Exports With Known Limits

An evidence package should answer a particular question.

It should not simply reproduce the largest possible dataset.

Before exporting logistics evidence, teams should determine:

  • which shipment, route, procedure or reporting period is in scope;
  • which identifiers are needed;
  • whether names and addresses are necessary;
  • whether proof-of-delivery media is required;
  • whether customs source wording and internal interpretation are clearly separated;
  • whether unresolved amendments or acknowledgements remain;
  • whether the recipient needs Form 15 or other regulatory-reporting context;
  • and how the exported copy will be protected and eventually retired.

Another current boundary should remain.

ComplianceOne does not yet have a validated timed or volume-based performance claim for very large logistics datasets. The current evidence supports governed query and export behaviour, not a blanket claim about enterprise-scale throughput.

Customers with large shipment volumes should test realistic populations during deployment.

A Practical Logistics and Customs Evidence Sequence

1. Confirm the business role.
Identify the importer, exporter, carrier, freight forwarder, broker, warehouse operator, postal provider, e-commerce logistics provider and internal owners.

2. Scope the applicable regulatory layers.
Distinguish customs, National Single Window, postal, e-commerce logistics, personal-data, cybersecurity and other sector obligations rather than treating “logistics compliance” as one law.

3. Establish one shipment identity.
Connect booking, house, master, carrier, declaration, customs, parcel and internal references.

4. Connect parties and processing records.
Use governed references and connect personal-data processing and transfer context where relevant.

5. Register customs evidence.
Record the artifact, procedure reference, lodging party and submission evidence without rebuilding the declaration itself.

6. Preserve acknowledgement and amendment history.
Keep what was sent and what came back without inventing a native customs-version field.

7. Record authority events.
Keep inspections, holds, releases and later actions in sequence, preserving source wording.

8. Prepare for the 15 October Single Window changes.
Confirm which Decree 336 and Circular 127 requirements apply to actual procedures, and whether Circular 128 is relevant to any approved smart-border operations.

9. Establish e-commerce reporting where applicable.
For in-scope e-commerce logistics providers, connect quarterly operational evidence to the Decree 248 Form 15 reporting workflow.

10. Govern parcel and delivery history.
Preserve scans, corrections, complaints, returns and proof of delivery without rewriting events.

11. Define retention.
Require an accountable retention position for privacy-sensitive evidence and coordinate deletion across external copies.

12. Rehearse an inspection.
Take one shipment and reconstruct it from operational identity through filing evidence, amendments, authority responses, privacy context and regulatory reporting.

The rehearsal should expose:

ambiguous shipment identities
missing acknowledgements
unrecorded amendments
orphaned party references
evidence copied outside governed systems
reporting figures without provenance
delivery proof without workable retention
and exports containing more personal data than the review requires

The Defensible Logistics Evidence Standard

The standard is not automated customs clearance.

It is independent, attributable and reviewable evidence.

A defensible logistics operating model should be able to show:

  • one shipment across every identity it carries;
  • the parties and systems involved;
  • what was lodged;
  • who lodged it;
  • what acknowledgement returned;
  • how later amendments relate to the original submission;
  • what the authority actually said;
  • how the organization interpreted and acted on it;
  • which parcel and delivery events followed;
  • which personal-data processing was involved;
  • which retention position applied;
  • whether e-commerce logistics reporting was required;
  • which report population and evidence supported the filing;
  • and who made every material decision.

ComplianceOne does not:

  • file customs declarations;
  • clear goods;
  • calculate customs value or duty;
  • classify goods;
  • operate the National Single Window;
  • connect automatically to the ASEAN Single Window;
  • run carrier networks;
  • operate warehouse systems;
  • calculate compensation;
  • automatically delete proof of delivery;
  • or replace legal, customs, privacy or tax professionals.

Its role is different.

The broker portal records the filing.
The carrier records the movement.
The warehouse records the handling.
The marketplace records the order.

ComplianceOne creates the governed evidence layer that connects those events to obligations, owners, decisions and audit history.

That becomes especially important when the question arrives months or years later:

What happened to this shipment and can you prove it?

Ronni K. Gothard Christiansen
Technical Privacy Engineer and CEO, AesirX.io

Laws and instruments referenced

  • Law on Customs 54/2014/QH13, as amended: principal customs framework for declarations, inspection, supervision and clearance.
  • Decree 336/2026/NĐ-CP: enacted 22 August 2026, effective 15 October 2026; governs relevant administrative procedures for import, export, transit goods and means of transport through the National Single Window and ASEAN Single Window.
  • Circular 127/2026/TT-BTC: effective 15 October 2026; regulates information indicators and declaration-document forms for means of transport entering, leaving or transiting border gates.
  • Circular 128/2026/TT-BTC: effective 15 October 2026; customs inspection, supervision and management within approved smart-border areas.
  • Law on E-Commerce 122/2025/QH15 and Decree 248/2026/NĐ-CP: active from 1 July 2026; relevant, among other matters, to reporting by logistics providers supporting e-commerce.
  • Law on Post 49/2010/QH12, as amended: postal operations and authorization context.
  • Law on Electronic Transactions 20/2023/QH15: relevant to electronic submissions, data messages, acknowledgements and electronic evidence.
  • Personal Data Protection Law 91/2025/QH15 and Decree 356/2025/NĐ-CP: personal-data governance for consignors, consignees, recipients and logistics evidence.
  • Decree 330/2026/NĐ-CP: current administrative-penalty layer for cybersecurity and personal-data protection, effective 19 August 2026.
  • Cybersecurity Law 116/2025/QH15 with Decrees 331/2026/NĐ-CP and 333/2026/NĐ-CP: relevant where actual logistics information systems or activities fall within their scope.

Disclaimer

This article provides general operational and compliance information from a platform vendor and does not constitute legal, customs, tax, cybersecurity or professional advice. Applicability depends on the organization, legal entity, shipment, goods, transport mode, logistics role, information system and processing activity. Organizations should confirm their obligations with qualified Vietnamese legal, customs and regulatory professionals.

Frequently Asked Questions

Answer: No. ComplianceOne records the organization's governed evidence around submissions, procedure references, responsible parties, acknowledgements, amendments and authority interactions. Operational filing remains with authorized customs systems, brokers and government mechanisms.

Answer: Decree 336/2026/NĐ-CP becomes effective for relevant administrative procedures under the National Single Window and ASEAN Single Window. Circulars 127 and 128 also take effect on that date, covering transport-declaration information/forms and, conditionally, customs management in approved smart-border areas.

Answer: No. The provision is specifically directed at organizations providing logistics services supporting e-commerce. Where the organization falls within that scope, the previous quarter's transport and delivery activity must be reported online before the 15th day of the first month of the following quarter using Form 15. Scope should be confirmed for the organization's actual service model.

Answer: No. Clearance is an authority act. Classification, customs value and duty remain with authorized declarants, customs professionals and competent authorities. ComplianceOne preserves the evidence and human decision trail.

Answer: Because the authority's communication is source evidence. A later operational interpretation should not rewrite what was originally received. Keeping both allows an auditor or reviewer to reconstruct what was known at the time.

Answer: Shipment and party evidence can be linked to the organization's established processing and transfer-governance records. This makes the relationship visible without treating international physical movement as an automatic legal conclusion about personal-data transfer lawfulness.

Enjoyed this read? Share the blog!