TL;DR: Vietnam’s public-sector data-sharing framework now has several distinct but connected layers. Decree 278/2025/NĐ-CP directly regulates mandatory connection and data sharing between bodies in the political system and establishes the operational role of the National Data Architecture Framework, national data-governance framework, Common Data Dictionary and Data Sharing and Coordination Platform. Decree 194/2025/NĐ-CP governs national databases, connection and sharing, and open data serving state electronic transactions. Decree 137/2024/NĐ-CP governs electronic transactions of state agencies and the information systems supporting them. Decree 337/2026/NĐ-CP adds the current access-to-information and digital-publication layer. ComplianceOne connects system ownership, dataset definitions, sharing arrangements, transfers, acknowledgements, release readiness, corrections, suppliers, incidents and audit history without pretending that software itself authorizes a share or determines legal applicability.
A public body prepares to share a dataset with another agency.
The dataset has a name, an owner and years of operational history.
The receiving agency needs it to deliver a public service.
But the name does not tell anyone exactly what is inside it.
One field contains an identity number. Another contains an address. A free-text field contains notes that were never designed for external exchange. The interface description was written two years ago and no longer matches the current schema.
The sending team understands the broad purpose of the exchange.
What it cannot immediately demonstrate is:
Which version of the dataset was approved?
Which fields were included?
Which authority and purpose supported the exchange?
Which safeguards were reviewed?
Which system transmitted it?
Who received it?
Was receipt acknowledged?
And if the data later proves incorrect, who needs to be notified?
That is not merely an integration problem.
It is an accountability problem.
“A connected interface proves that data can move. It does not prove that the right data moved under the right authority with the right review.”
The Public-Sector Data Framework Has Changed
Vietnam’s public-sector data architecture should no longer be described primarily through one decree.
Several instruments now work together.
Decree 137/2024/NĐ-CP, effective 23 October 2024, governs electronic transactions of state agencies and the information systems supporting those transactions.
Decree 194/2025/NĐ-CP, effective 19 August 2025, provides detailed rules under the Law on Electronic Transactions concerning national databases, data connection and sharing, and open data serving electronic transactions of state agencies.
Most importantly for inter-agency exchange, Decree 278/2025/NĐ-CP, effective 22 October 2025, expressly governs mandatory data connection and sharing between bodies in the political system from central to local level. It also covers the National Data Architecture Framework, national data-governance framework and Common Data Dictionary.
These instruments are related, but they are not interchangeable.
Compliance evidence should therefore preserve which obligation came from which instrument rather than collapsing everything into a generic “government data-sharing” control.
Decree 278 Makes Data Sharing an Operating Model
Decree 278 materially changes the centre of gravity.
It establishes mandatory connection and sharing across specified public-sector databases and requires the process to align with common national architecture, governance and dictionary structures.
The Decree identifies several technical methods, including:
- query-based sharing through the Data Sharing and Coordination Platform;
- synchronisation between agency systems;
- synchronisation into the National Integrated Database for coordinated use;
- and packaged data sharing using information-storage media.
The platform provides authentication and authorization for exchanges, while secure Agent Nodes support connection between participating information systems and the national sharing infrastructure.
The important governance point is that technical connectivity and accountable data governance now have to evolve together.
A successful API call does not answer:
- whether the dataset was the correct one;
- whether its dictionary was current;
- whether the requested fields matched the approved purpose;
- whether personal or restricted data was appropriately handled;
- whether the exchange was acknowledged;
- or who owns remediation if something later proves wrong.
ComplianceOne can organize those evidence relationships around the organization’s existing operational systems.
It does not operate the national platform or authorize the exchange.
The 31 December 2026 Deadline Makes Readiness Concrete
Decree 278 also creates a clear implementation horizon.
For remaining databases and information systems, standardisation is to be completed before 31 December 2026, and mandatory connection and sharing within the political system is to be implemented uniformly through the Data Sharing and Coordination Platform no later than that date.
That makes the next question highly operational:
Is the organization only technically preparing its systems, or is it also preparing the evidence needed to govern those connections?
Technical readiness might establish that a system can exchange data.
Governance readiness needs to establish what it shares, where the source of truth sits, who owns the dataset, which definition applies, how exceptions are handled and how a later review can reconstruct the decision.
Those are different forms of readiness.
Both matter.

Start With the Data Dictionary
Decree 278 gives particular importance to shared data architecture and common data definitions.
It also establishes the concept of national master data and sectoral master data, including the principle of a single trusted source for national master data. Sectoral master data is expected to integrate with the Common Data Dictionary and remain capable of connection and traceability across the wider architecture.
This reinforces a principle already built into ComplianceOne’s Public Data Exchange model:
A dataset name is not a sufficient description of the data.
“Citizen service requests”, “business registrations” or “benefit applications” can contain dozens of fields with very different sensitivity and governance requirements.
A governed dataset record should therefore include a versioned, field-level dictionary.
For each relevant field, teams should be able to understand:
- what the field represents;
- its source;
- whether it is master, shared or operational data;
- whether personal-data considerations apply;
- which system maintains it;
- and who owns the definition.
A sharing arrangement should refer to a defined version rather than simply to a dataset name.
That matters because a later schema update should not silently rewrite the evidence behind an earlier exchange.
Separate the Sharing Arrangement From the Actual Transfer
A standing sharing arrangement and an actual data exchange are different things.
The arrangement describes the relationship:
who may share, with whom, for what purpose, under which basis, using which channel, with which dataset and under which safeguards.
The transfer describes what actually happened.
Keeping them separate prevents two common mistakes.
A signed agreement is not proof that a specific exchange occurred.
And an interface log is not proof that an exchange fell within an approved arrangement.
ComplianceOne can record both layers and connect them.
Each recorded transfer can also carry its acknowledgement status.
If acknowledgement has not returned, the transfer stays visibly pending rather than being treated as successful because nothing failed technically.
An acknowledgement still does not establish legal authorization.
It is evidence of an event in the exchange process.
Data Quality Is Also a Sharing-Control Problem
Decree 278’s national data architecture puts significant weight on consistent and reusable data, including trusted master-data sources and standardisation.
That makes data quality more than an internal database issue.
Once information is shared across agencies, a mistake can propagate.
If an incorrect field is corrected only in the source system while recipients continue to hold the previous value, the organization has corrected the database without necessarily correcting the data ecosystem.
ComplianceOne therefore treats correction as an evidence workflow.
When a correction is created, the system can derive the affected recipient contexts from the transfers and releases already recorded.
That means teams do not need to reconstruct the distribution list from memory.
There is an important boundary:
The derived list can only be as complete as the governed history.
If data was exchanged through an undocumented manual process or an unmanaged interface, software cannot magically discover that event.
The organization still needs to reconcile its governance record with operational logs and real delivery channels.

Open Data Is a Different Decision From Inter-Agency Sharing
Controlled exchange between public bodies and publication to the public create different risk profiles.
Once information is published as open data, downstream copying and reuse can extend far beyond the original platform.
Decree 194 provides the dedicated national-database, sharing and open-data layer supporting electronic transactions of state agencies.
ComplianceOne therefore treats open-data release as a separate readiness decision rather than simply another recipient in an inter-agency sharing arrangement.
Before a release is recorded, the operating model should require an explicit personal-data assessment and accountable approval.
That does not mean that a yes/no field proves that publication is safe.
Human reviewers may still need to consider:
- combinations of fields;
- free-text content;
- low-population groups;
- historical versions;
- external datasets;
- indirect identification;
- confidentiality;
- security;
- and statutory publication restrictions.
The purpose of the workflow is not to automate that judgment.
It is to make sure that someone owns it and that the evidence is preserved.
Decree 337 Adds the Access-to-Information Layer
A newer development is Decree 337/2026/NĐ-CP, effective 26 August 2026, implementing the Law on Access to Information.
Among other measures, it requires public bodies to operate and maintain digital information channels, including websites and data portals, and to maintain, update and manage their information databases so information is systematic, complete, searchable, downloadable and usable, while also applying appropriate technical and organizational protection measures.
This is related to public-data governance, but it should remain conceptually separate from mandatory data exchange.
There are now at least three distinct questions:
What must agencies exchange with each other?
What may or must be published openly?
What information must be made accessible through the broader access-to-information regime?
A mature evidence model should not collapse those questions into one “publish/share” status.
Different purposes, decision-makers and evidence may apply.
Personal Data Remains a Separate Compliance Layer
Public-sector sharing does not switch off Vietnam’s personal-data requirements.
Where datasets contain personal data, the Personal Data Protection Law and Decree 356 remain part of the compliance environment.
That means a technically required inter-agency connection can still raise questions around data categories, purposes, access, safeguards, retention, sensitive data, accountability and other applicable privacy requirements.
The correct operating model is therefore not:
Decree 278 says share → therefore every aspect of the processing is resolved.
It is:
Decree 278 establishes the relevant connection/sharing framework → the organization then evaluates the other legal and governance requirements that apply to that processing.
ComplianceOne can link those obligations without merging their legal meaning.
Keep Decree 137 as the Electronic-Transaction System Layer
Decree 137 remains important.
A state electronic-transaction record should allow reviewers to understand the system and the transaction around it, including:
- system ownership and purpose;
- connected databases;
- exchanged record types;
- creation, sending, receipt and processing;
- timestamps and statuses;
- interfaces and authentication;
- security and continuity;
- incidents;
- and supporting audit evidence.
The draft correctly recognized that Decree 137 is about more than data movement.
What should change is its position in the article.
It is one layer of the public-sector data operating environment, not the headline legal basis for mandatory inter-agency data sharing.
Link Trust and Identity Evidence Without Duplicating It
Electronic transactions may depend on digital identity, certificates, electronic signatures or other trust mechanisms.
Those records should remain tied to the legal instrument governing the relevant trust or identity service and be linked to the transaction record where needed.
ComplianceOne can preserve references such as:
- credential lifecycle evidence;
- verification events;
- submission metadata;
- payload hashes;
- receipts;
- acknowledgements;
- and amendments.
It does not itself issue credentials, create signatures, authenticate users or transmit government filings.
This separation matters because evidence reuse should not become obligation duplication.
Suppliers Are Part of the Evidence Chain
Public-sector data ecosystems depend heavily on suppliers:
- system integrators;
- cloud providers;
- application vendors;
- security providers;
- data processors;
- identity and trust providers;
- and operational support teams.
Some may operate interfaces or infrastructure essential to a mandatory sharing process.
That does not automatically make every supplier subject to every duty imposed on the public body.
The organization should distinguish:
- the system or interface operated by the supplier;
- the data it can access;
- contractual responsibilities;
- any independently confirmed legal obligations;
- subcontractors;
- incident responsibilities;
- change control;
- continuity;
- and evidence-return or exit arrangements.
That turns vague contract language such as “support compliance” into observable responsibilities.
Reconcile Governance Records With Technical Reality
A strong GRC record does not become true simply because it is complete.
This is particularly important for public-sector data sharing.
If ComplianceOne says five agencies received a dataset but interface logs show six, the software record is incomplete.
If an API configuration includes twelve fields but the approved dataset dictionary describes ten, there is a governance gap.
If an exchange is shown as complete but the acknowledgement remains unresolved, the operational story is unfinished.
The purpose of the governance layer is therefore not to replace technical logs.
It is to connect technical evidence with accountable decisions.
Periodic reconciliation should compare:
governance records:
↔ interface configuration
↔ transfer logs
↔ acknowledgement records
↔ public releases
↔ manual sharing channels
↔ supplier evidence
The differences become work to resolve rather than facts to hide.
A Practical Public-Sector Data-Sharing Sequence
1. Confirm scope.
Identify the agency, dataset owner, receiving bodies, system operators and suppliers. Determine which duties come from Decree 278, Decree 194, Decree 137, Decree 337, the Data Law, PDPL and other relevant instruments.
2. Inventory the systems.
Record the databases, services, interfaces, purpose, owners, classifications and operational responsibilities.
3. Establish the data dictionary.
Describe the dataset at field level and connect it to authoritative source and master-data definitions.
4. Record the standing sharing arrangement.
Capture the parties, purpose, authority, scope, dictionary version, channel, safeguards and review ownership.
5. Record actual transfers.
Keep the real exchange distinct from the standing arrangement.
6. Track acknowledgement.
Do not interpret silence as proof of successful receipt.
7. Evaluate connected privacy and security requirements.
Make data categories, safeguards, personal-data questions and accountable reviews explicit.
8. Govern publication separately.
Use dedicated open-data and access-to-information workflows rather than treating publication as another ordinary transfer.
9. Connect suppliers, identity, trust and incident evidence.
Reuse evidence without merging the underlying legal obligations.
10. Test a correction.
Introduce a controlled data-quality error and determine whether the recorded history identifies every known recipient.
11. Reconcile with technical reality.
Compare the governance records with interface logs, platform records and manual channels.
12. Prepare for the 31 December 2026 operating horizon.
Verify not only whether systems can connect through the national sharing architecture, but whether the organization can explain and evidence what those systems are doing.
The Accountable Public-Sector Data Standard
Vietnam’s evolving public-data framework is increasingly moving from general principles toward operational infrastructure.
That makes governance evidence more important, not less.
A defensible model should be able to show:
- which dataset and version were involved;
- where its authoritative source sits;
- which fields were shared;
- which arrangement governed the exchange;
- which actual transfers occurred;
- whether they were acknowledged;
- which privacy and security reviews applied;
- which suppliers participated;
- what was published;
- what changed later;
- which recipients were affected by a correction;
- and who made each accountable decision.
ComplianceOne does not make the legal decision to share data.
It does not certify a dataset as safe.
It does not connect directly to the national Data Sharing and Coordination Platform merely because a regulatory pack exists.
And it does not turn connectivity into compliance.
Its role is to preserve the regulatory operations and evidence layer around the organization’s real systems.
That gives public bodies, advisers, auditors and responsible suppliers a more useful answer than:
“The API worked.”
It lets them answer:
What was shared?
Why?
From which authoritative source?
To whom?
Under which arrangement?
What evidence came back?
And what happened when the facts changed?
Ronni K. Gothard Christiansen
Technical Privacy Engineer and CEO, AesirX.io
Laws and standards referenced
- Law on Electronic Transactions 20/2023/QH15 — establishes the wider framework for electronic transactions and electronic systems.
- Data Law 60/2024/QH15 — provides the broader national framework for data governance, management, development, sharing and use.
- Decree 137/2024/NĐ-CP — governs electronic transactions of state agencies and the information systems supporting them.
- Decree 194/2025/NĐ-CP — covers national databases, data connection and sharing, and open data serving electronic transactions of state agencies.
- Decree 278/2025/NĐ-CP — directly governs mandatory data connection and sharing between bodies in the political system and the associated national architecture, governance and Common Data Dictionary.
- Personal Data Protection Law 91/2025/QH15 and Decree 356/2025/NĐ-CP — relevant where shared or published information contains personal data.
- Decree 337/2026/NĐ-CP — effective 26 August 2026 and relevant to the access-to-information, digital-channel and public-information-management layer.
Disclaimer
This article provides operational and compliance information from a platform vendor and does not constitute legal or regulatory advice. Applicability depends on the organization, system, dataset, legal role, purpose and activity. Public bodies and suppliers should confirm their obligations with qualified Vietnamese legal and regulatory specialists.
