Fri, Aug 28, 2026, 15:03:00
VCCI urges reduction in compliance costs for electronic identification. Illustrative photo: Quoc Tuan
Beyond advocating a narrower scope for mandatory identification, VCCI noted that the draft Law on Electronic Identification and Authentication needs to be designed for seamless interoperability with existing systems. This approach would avoid creating redundant identification codes, processes, and compliance costs for the business community.
According to VCCI, specialised legislation has already established numerous functional identification mechanisms, including enterprise numbers, tax identification numbers, vehicle registration numbers, land parcel identifiers, medical device registration numbers, pharmaceutical registration codes, and product traceability tags. In international trade, enterprises also widely adopt global identification standards such as GS1, LEI, and VIN.
Consequently, if entities already assigned identifiers under specialised laws are subjected to a secondary identification process under the new legislation, businesses risk having to maintain a "dual-layer" system for a single entity. This could drive up operational costs and heighten the risk of data discrepancies.
VCCI recommends incorporating a principle whereby existing specialised legislation takes precedence in matters of identification. Under this proposal, the Law on Electronic Identification and Authentication would apply solely to areas and entities not currently governed by specialised laws.
Furthermore, a framework should be established to recognise and map existing identifiers. Registration numbers and codes issued by Government authorities, alongside recognised international standards, should be accepted as official identifiers or mapped directly to national identification codes, rather than requiring businesses to reapply. The Government could issue a registry of recognised existing codes to ensure uniform execution.
VCCI also highlighted concerns regarding the procedural requirements in Articles 9 and 10, which appear tailored primarily to public sector operations. Applying these rules to commercial identification service providers could stifle product innovation and limit customer experience design.
To address this, VCCI suggests the law focus solely on mandatory output criteria for providers—such as data accuracy, integrity, auditability, personal data protection, and identity assurance levels. Specific technical processes should be left to enterprises to design, disclose, and assume responsibility for independently.
VCCI further urged clarification on which authority holds the mandate to issue guidelines on data collection, processing, and standardisation. This would prevent each ministry from issuing its fragmented standards, which would undermine the goal of a unified identification infrastructure.
Crucially, VCCI raised red flags over provisions concerning electronic identity linking and traceability. Under the draft law, the electronic identities of goods, assets, and transactions could be linked to the identities of their owners, managers, and participating parties, tied to specific transaction times and locations.
VCCI warned that such a requirement may prove unworkable in multi-tiered supply chains, where an enterprise does not necessarily know—nor have the right to demand—the identity details of parties across other nodes in the chain.
More importantly, data regarding trade partners, cargo flows, transaction timing, locations, and volumes directly reflect a firm’s business strategy and trade networks. If aggregated, linked, and traced without strict boundaries, this data presents a severe risk to trade secrets.
VCCI advocates restricting linking obligations strictly to direct counterparties in a transaction. It also calls for dedicated provisions to safeguard business secrets and sensitive commercial information—clearly defining access rights, permitted usage scopes, retention periods, and liabilities in the event of data leaks.
Finally, digital identity tracing must be bound by clear conditions, mandates, and due process to prevent it from becoming an avenue for accessing commercial data beyond regulatory necessity.
