Law on ELECTRONIC TRANSACTIONS No. 20/2023/QH15 came into effect on July 1, 2024.

A summary of this law by chapter is provided.

Chapter I – General Provisions

This chapter defines the scope of regulation, subjects of application, and foundational concepts of electronic transactions. The Law affirms that data messages, electronic signatures, and electronic certificates all have legal validity; it also sets out policies for the development of electronic transactions and lists prohibited acts.

Article 3. Definitions
In this Law, the following terms are defined as follows:
  • Electronic transaction means a transaction conducted by electronic means.
  • Electronic means refers to hardware, software, information systems, or other means operating on information technology, electrical, electronic, digital, magnetic, wireless transmission, optical, electromagnetic, or similar technologies.
  • Electronic environment means the environment of telecommunications networks, the Internet, computer networks, and information systems.
  • Data message means information created, sent, received, or stored by electronic means.
  • Electronic certificate means a license, certificate, certification, confirmation document, or other approval document issued by a competent authority in electronic data form.
  • Data means symbols, letters, numbers, images, sounds, or other similar forms.
  • Electronic data means data created, processed, or stored by electronic means.
  • Digital data means electronic data created using digital signal methods.
  • Master data means data containing the most fundamental information describing a specific object, serving as a basis for reference and synchronization among databases or different data sets.
  • Database means a collection of electronic data arranged and organized for access, exploitation, sharing, management, and updating through electronic means.
  • Electronic signature means a signature created in electronic data form logically attached to or associated with a data message to authenticate the signer and confirm their approval of the data message.
  • Digital signature means an electronic signature using asymmetric cryptography, consisting of a private key and a public key, where the private key is used to sign and the public key is used to verify the digital signature. A digital signature ensures authenticity, integrity, and non-repudiation but does not ensure confidentiality of the data message.
  • Electronic signature certificate means a data message confirming that an agency, organization, or individual is certified as the signer of an electronic signature. For digital signatures, this is called a digital signature certificate.
  • Digital signature certification service means a service provided by a digital signature certification service provider to authenticate the signer of a data message, ensure non-repudiation, and ensure the integrity of the signed data message.
  • Timestamp means electronic data attached to a data message that identifies the time at which the data message existed at a specific moment.
  • Electronic contract means a contract established in the form of a data message.
  • Intermediary means an agency, organization, or individual representing another agency, organization, or individual to send, receive, or store data messages or provide other services related to such data messages.

Article 6. Prohibited Acts in Electronic Transactions

  • Abusing electronic transactions to infringe upon national interests, ethnic interests, national security, social order and safety, public interests, or lawful rights and interests of agencies, organizations, or individuals.
  • Illegally obstructing or preventing the creation, sending, receiving, or storing of data messages, or committing acts aimed at sabotaging information systems serving electronic transactions.
  • Illegally collecting, providing, using, disclosing, displaying, disseminating, or trading data messages.
  • Forging, falsifying, deleting, destroying, copying, or moving part or all of a data message unlawfully.
  • Creating data messages for unlawful purposes.
  • Committing fraud, forgery, appropriation, or unlawful use of electronic transaction accounts, electronic certificates, electronic signature certificates, or electronic signatures.
  • Obstructing the choice to conduct electronic transactions.
  • Other acts prohibited by law.


Chapter II – Data Messages

This chapter regulates the legal validity of data messages, conditions for them to be considered equivalent to written documents or originals, and their admissibility as evidence. It also provides rules for converting between paper documents and electronic data, requirements for storage, and the time and place of sending and receiving data messages, including automated systems.

Chapter III – Electronic Signatures and Trust Services
This chapter classifies electronic signatures, sets conditions for digital signatures to have legal validity, and regulates the management of public digital signature certification services and specialized government-use digital signatures. It also covers trust services such as timestamps, data message certification, and digital signature certification.

Chapter IV – Formation and Performance of Electronic Contracts
This chapter provides principles for forming and performing electronic contracts, the legal validity of contracts created through automated systems, and rules for sending and receiving data messages during contract formation and performance.
Article 36. Principles for Forming and Performing Electronic Contracts
  • Parties have the right to agree on using data messages or electronic means in whole or in part when forming and performing electronic contracts.
  • When forming and performing electronic contracts, parties may agree on technical requirements and conditions ensuring integrity and confidentiality related to the electronic contract.
  • The formation and performance of electronic contracts must comply with this Law, contract law, and other relevant legal provisions.
Chapter V – Electronic Transactions of State Agencies
This chapter regulates types of electronic transactions within state agencies; management of data, national and local databases; principles for data connection and sharing; open data; and requirements for conducting administrative procedures in electronic environments.

Chapter VI – Information Systems Serving Electronic Transactions

This chapter defines information systems serving electronic transactions, digital platforms, intermediary digital platforms; regulates electronic transaction accounts; and sets responsibilities of system owners.


Chapter VII – State Management of Electronic Transactions
This chapter identifies the scope of state management, including strategy development, technical standards, management of trust services, national electronic authentication infrastructure, inspection, supervision, and international cooperation. The Ministry of Information and Communications is designated as the lead authority.
Chapter VIII – Implementation Provisions
This chapter provides the effective date of the Law (July 1, 2024), amendments to related laws, and transitional provisions for digital certificates, licenses for digital signature certification services, and pending administrative dossiers.

What businesses need to do?

– Ensure integrity, accessibility, and proper storage
– Use legally valid digital signatures and standardized signing procedures
– Establish legally compliant contract signing and storage procedures
– Ensure the system meets information security standards
– Comply with information security and cybersecurity laws
– Avoid forgery, sabotage, and unauthorized data collection
– Ensure electronic records are standardized and digital signatures are valid