Thu, Sep 03, 2026, 14:56:00
Vietnam Chamber of Commerce and Industry (VCCI) has recently submitted comments on the draft Law on Electronic Identification and Authentication at the request of the Ministry of Public Security. VCCI considers the draft an important step toward establishing a legal framework for the national digital identification system.
However, given its broad scope of application, which covers a wide range of production and business activities, products and transactions, VCCI recommended that the drafting committee take into account six key principles: proportionality to risk; leveraging existing identification information without requiring re-identification; technology neutrality and international interoperability; fair competition; protection of business confidentiality; and ensuring feasible compliance costs.
In particular, VCCI proposed conducting a quantitative assessment of compliance costs for enterprises, especially small and medium-sized enterprises and household businesses, arising from requirements related to labeling, data synchronization, log retention and system connectivity.
Based on these principles, VCCI made a number of specific recommendations.
Regarding the linkage between electronic identities and the protection of business confidentiality, VCCI noted that Clauses 2 and 3, Article 19 of the draft Law require the electronic identity of goods, assets and transactions to be linked with the identities of all individuals and organizations that own or manage them, as well as all parties involved, together with information on the time, location and context in which they occur. Clause 4, Article 22 further requires simultaneous authentication of linked information concerning all relevant parties.
According to VCCI, in multi-tier supply chains, enterprises often neither possess nor have the authority to request identification information from all parties at upstream or downstream stages. Therefore, a requirement to link the identities of “all parties” may be difficult to implement in practice.

Illustrative photo.
In addition, information on business partners, product flows, transaction timing and locations constitutes important commercial data, reflecting an enterprise’s business network and competitive advantages. Centralized linkage and traceability therefore require a high level of data security and clearly defined limitations on the purposes for which such information may be used.
VCCI proposed that mandatory linkage should be limited to the parties directly involved in a transaction, rather than extended to the entire supply chain. At the same time, specific provisions should be added on the protection of trade secrets and sensitive commercial information, clearly defining the entities authorized to access such information, the purposes of access, data retention periods, and responsibilities in the event of data leakage or unauthorized disclosure.
Regarding legal liability and risk allocation, VCCI considers this a particularly important issue for credit institutions, payment intermediaries and e-commerce platforms.
Clause 4, Article 44 provides that organizations and individuals using identification and authentication results generated by an artificial intelligence system “shall bear ultimate responsibility for their decisions.” VCCI noted that service users often lack the capacity to independently verify the technical accuracy of the systems to which they are connected.
Therefore, where an enterprise has properly followed the prescribed procedures and applied an appropriate level of authentication, but errors nevertheless arise due to system failures or fraudulent schemes that circumvent existing technical safeguards, assigning ultimate liability to the service user would not be consistent with the principle of allocating risks according to the party’s ability to control them.
VCCI proposed adding a liability exemption mechanism for good-faith service users. Accordingly, organizations and individuals that have carried out electronic authentication in compliance with regulations and at a level appropriate to the nature of the transaction should not be held liable for losses resulting from inaccurate authentication results, unless they are at fault.
In such cases, liability should rest with the organization providing the authentication service in accordance with its service commitments and applicable law. According to VCCI, this mechanism would encourage enterprises to adopt electronic authentication more readily as an alternative to manual verification measures.
Regarding Article 37, VCCI noted that the draft requires organizations providing electronic identification services to notify the Ministry of Public Security before providing such services, but does not clearly specify whether these services constitute a conditional business sector subject to a licensing regime or are governed by a notification mechanism combined with post-inspection.
VCCI proposed that the Law itself clearly establish the applicable regulatory mechanism, competent authorities, required documentation, processing time limits, and grounds for refusal or revocation. Criteria such as “financial capacity to ensure continuous operation” and “dedicated personnel meeting technical and professional requirements” should also be quantified or clarified to avoid gaps in implementation.
At the same time, a mechanism for interoperability with the Law on Electronic Transactions should be established, under which organizations licensed to provide trust services may have the results of assessments of equivalent conditions recognized, without having to demonstrate compliance with the same requirements from the outset.
VCCI also proposed that connection to the Electronic Identification and Authentication System be enabled through open application programming interfaces (APIs) based on publicly disclosed standards, accompanied by commitments regarding service quality and time limits for processing connection requests. This is considered an important condition for creating a transparent, competitive and business-friendly environment for enterprises to participate in the digital identification ecosystem.
