Decree 314/2026/ND-CP: what businesses should prepare as data enters the marketplace
The Vietnamese Government issued Decree 314/2026/ND-CP on August 8, 2026, with effect from September 25, 2026, regulating the operation of data exchanges. The decree establishes a framework for listing, exchanging and using data, data products and data services while requiring lawful provenance, cybersecurity, data security and personal data protection.
Data is increasingly moving beyond its traditional role as an internal operational resource. It can also become an asset that generates revenue, supports analytics and enables new digital products.
Vietnam’s Data Law established the broader direction for developing a data market. Decree 314/2026/ND-CP now provides a more concrete framework for an important part of that market by regulating data exchange operations.
For businesses, however, the opportunity to monetize data comes with an equally important challenge. Before focusing on the commercial value of a dataset, organizations need to determine where the data came from, what rights they have over it, who is allowed to use it and how it is protected.
As a result, Decree 314 is not only about the data economy. It also places data governance and cybersecurity directly within the data value chain.

How does Decree 314/2026/ND-CP enable data trading?
Decree 314/2026/ND-CP regulates data exchange operations, including participation requirements, conditions for tradable data, listing, valuation, transaction procedures, risk management and dispute-related processes.
The decree contains 9 chapters and 38 articles and takes effect on September 25, 2026.
Vietnam’s Data Law had already established the concept of a data exchange as an environment for trading and exchanging data, data products and related services. It also set the broader objective of developing a data market and turning data into an asset capable of generating economic value.
Decree 314 further specifies how that mechanism can operate.
A data exchange may support activities such as:
Data purchase and sale offers
Intermediary services
Data analysis and aggregation
Data valuation support
Other data-related activities permitted by law
This means the emerging market is not limited to simply “selling a dataset.”
Businesses may potentially generate value from data usage rights, industry-specific datasets, processed or de-identified datasets, APIs, analytics products and other data-based services.
What data can be listed, and what must businesses be able to prove?
Not every dataset stored by an organization automatically becomes an asset that can be traded.
Under Article 17 of Decree 314/2026/ND-CP, data, data products and data services listed on an exchange must have a lawful origin. This must be supported by documentation showing how the data was collected, generated or obtained through the transfer of data exploitation and usage rights.
Sellers are also required to disclose relevant conditions or restrictions affecting the circulation and use of the data.
Several requirements are particularly relevant for enterprises:
Requirement | What it means for businesses |
Lawful provenance | Organizations need evidence showing how data was collected, generated or transferred |
Exploitation and usage rights | Businesses must understand the scope of the rights they hold over each dataset |
Machine-readable formats | Data needs to be technically structured for processing and use |
API and access controls | API-based services should define structure, authentication, authorization and usage limitations |
Security | Data must be protected during connection, transmission, receipt, storage and use |
Data quality | Accuracy, completeness, timeliness and known limitations should be disclosed |
The decree also prohibits using data exchanges to buy or sell personal data, or to process personal data in violation of the law.
Data and data products derived from personal data may only be traded when they meet applicable legal requirements, including de-identification requirements where relevant.
This distinction is important. There is a significant difference between an organization possessing a database and having the legal right to commercialize the information contained within it.
How could Decree 314 affect businesses?
One of the most important consequences is that organizations may need to begin managing data more explicitly as an asset with a defined lifecycle, provenance and usage rights.
A company seeking to derive commercial value from data should be able to answer at least four questions:
Where did the data come from?
What type of data is it?
What rights does the organization have over it?
Who currently has access to it?
This may increase the need for structured Data Inventory and Data Classification programs.
CRM records, ERP data, customer information, transaction histories, IoT telemetry, operational data, research datasets and information received from third parties should no longer be treated as isolated repositories without clear ownership and governance.
Another important capability is data traceability.
When data becomes part of a commercial transaction, organizations may need to demonstrate who created, modified, downloaded, shared or granted access to a particular dataset.
From a business perspective, the decree may also create opportunities for organizations that own high-quality industry-specific data.
Well-governed datasets can support:
Artificial intelligence
Market analytics
Fraud detection
Demand forecasting
Logistics optimization
Financial services
Insurance
New digital products
Why does the data marketplace create new cybersecurity challenges?
When data has direct economic value, a cybersecurity incident may do more than expose sensitive information. It can also undermine the commercial value, integrity and trustworthiness of the data asset itself.
Decree 314 requires cybersecurity, data security and personal data protection throughout data exchange and storage activities. Data must also remain protected during connection, transmission, receipt, storage and exploitation.
This means organizations need to consider the entire data path:
Data source → storage system → data processor → API or integration → data recipient → transaction logs
Protecting the database alone is not enough.
Potential risks can emerge from:
Compromised administrator accounts
Excessive access privileges
Misconfigured APIs
Cloud storage exposed through incorrect permissions
Stolen credentials
Unauthorized employee downloads
Endpoint compromise
Data exfiltration through unmanaged devices
Encryption is one of the technical controls that can reduce the usefulness of data when unauthorized access occurs.
Organizations handling sensitive information in cloud or hybrid environments can review approaches to enterprise data encryption and encryption key management.
What should businesses prepare before the decree takes effect?
Decree 314/2026/ND-CP takes effect on September 25, 2026.
Organizations planning to provide or consume data through exchanges should review legal, governance and technical requirements together rather than treating them as separate projects.
Priority checklist:
Create an inventory of critical datasets currently owned or processed by the organization.
Classify personal data, confidential business information, sensitive data and datasets intended for commercialization.
Identify the lawful basis for collecting each dataset and the organization's rights to use or exploit it.
Review customer, partner and supplier agreements for clauses governing data ownership, usage and transfer rights.
Apply Least Privilege access controls to sensitive systems and datasets.
Enable MFA for administrator accounts and critical data systems.
Review APIs, tokens and service accounts connected to data platforms.
Encrypt sensitive data both at rest and in transit.
Collect logs capable of tracing access, downloads, modifications and permission changes.
Establish incident response procedures for unauthorized access, data leakage or improper data sharing.
For small and medium-sized enterprises without a dedicated security team, a layered security model covering email, endpoints, cloud and data can help reduce gaps created by fragmented security tools.
IPSIP’s FlexSecure 360 solution for small and medium-sized businesses is designed around this broader security requirement.
What does the IPSIP Vietnam's expert perspective indicate?
Decree 314/2026/ND-CP moves Vietnam’s data market one step further from the concept of “data as a resource” toward a framework in which data can be valued, exchanged and commercially exploited under defined conditions.
For businesses, however, the ability to generate revenue from data is only one side of the equation.
The other side is demonstrating provenance, usage rights, quality and adequate protection of the underlying data asset.
Organizations that strengthen data governance and cybersecurity before participating in the emerging data economy will be better positioned to capture its commercial value without introducing unnecessary security gaps.
References
Government of Vietnam - Decree No. 314/2026/ND-CP regulating the operation of data exchanges
Government News - Full text of the Data Law No. 60/2024/QH15
Government News - Conditions for participating in transactions on data exchanges
Government News - Rules on listing data, data products and data services
Government News - Rules on valuation of data, data products and data services










Comments