Establishing a common legal framework for goods traceability: What are the enforcement barriers?

Insights
Establishing a common legal framework for goods traceability: What are the enforcement barriers?
Posted on: 13/05/2026

    According to the report of the Market Surveillance Force, in 2025, the country will handle more than 23,000 cases of violations related to counterfeit goods and goods of unknown origin, with a total value of nearly 290 billion VND. In just the first three months of 2026, the number of violations continues to reach 9,574 cases[1]. These figures show that the problem of counterfeit goods and goods of unknown origin is still a big challenge for management agencies, businesses and consumers.

     

    One of the most notable points of the Draft is the proposal to build a national platform for identification, authentication and registration of products and goods under the management of the Ministry of Public Securit

     

    In that context, the Ministry of Public Security is presiding over the development of a Draft Decree regulating the identification, authentication and traceability of products and goods ("Draft").[2] If approved, this will be one of the important steps to establish a unified data infrastructure for goods traceability activities in Vietnam. However, to be implemented effectively, this new legal framework will face many significant barriers from both institutional, technological and compliance perspectives of enterprises.

    From distributed management to shared data platforms                

    One of the most notable points of the Draft is the proposal to build a national platform for identification, authentication and registration of products and goods under the management of the Ministry of Public Security. Currently, goods traceability data in Vietnam is still being managed distributed among many ministries, sectors, localities and individual systems of enterprises. In fact, each regulatory agency often builds its own data platform, with different technical standards and operating mechanisms, leading to a lack of connectivity and difficulty in sharing data.

    The draft aims to connect these systems into a shared platform, allowing data to be synchronized, shared, and relayed between parties in the supply chain. Accordingly, data that has been validly authenticated will not have to be re-declared many times, thereby reducing duplication of procedures and supporting businesses to reuse data in management activities.

    In addition, the Draft proposes for the first time a mechanism for standardizing product and goods identifiers (UIDs) for each product unit or shipment. This is considered a remarkable shift compared to the current practice when many businesses are still using QR codes or internal codes according to their own standards.

    More notably, the Draft also proposes a mechanism for applying decentralized identifiers (DIDs) on the national blockchain platform (Blockchain). Accordingly, each organization and individual participating in the system will be issued a unique DID code to serve data identification and authentication activities.

    From the perspective of state management, this model can help increase transparency and supply chain control. However, from a business perspective, the transition to a unified data system also means changing the data governance process, upgrading technological infrastructure and adapting to new technical standards.

    Possible barriers when the regulation is enforced

    The biggest hurdle: the problem of data interconnection

    Although the orientation of building a shared platform is considered necessary, this is also the biggest technical barrier of the Draft.

    In fact, current data systems are built at different times, by many different agencies and according to different technical standards. Connecting these systems is not only a matter of "data pooling", but also about compatibility in terms of data structures, security standards, authentication mechanisms, and operational procedures.

    If the problem of data standardization and system connection is not solved synchronously, the goal of building a shared goods traceability data ecosystem will be difficult to achieve substantive efficiency.

    In addition, the operation of a centralized data platform on a national scale also places great requirements on governance capacity and coordination between state management agencies. In the absence of a clear assignment mechanism, the risk of overlapping responsibilities or additional administrative procedures is completely possible.

    Compliance costs and pressure on businesses

    The draft is built in the direction of taking advantage of the existing technology infrastructure of businesses through connecting to systems such as ERP, POS or goods traceability platforms that are being used. The draft also stipulates that the creation of UID codes through the National Platform will be carried out free of charge. However, in reality, joining the new system can still incur significant costs for businesses.

    To meet the requirements of automatic data connection and transfer, businesses may have to invest in upgrading management software, logistics systems, storage servers, and data security mechanisms. For small and medium-sized businesses, this can be significant financial pressure.

    Not only businesses, but also state agencies will have to invest huge resources in technical infrastructure, data centers, system maintenance and operation personnel training.

    Without an appropriate implementation roadmap or effective support mechanism, the simultaneous application of goods traceability regulations can invisibly create an additional compliance burden for businesses, especially in difficult economic periods.

     

    Source: Government News

     

    Risks of information security and trade secrets

    The essence of goods traceability activities is to make the entire product life cycle transparent, from production, warehousing, transportation to distribution and consumption.

    This means that businesses will have to regularly update and share a large amount of supply chain-related data on a shared platform. This may include sensitive information such as raw material sources, production processes, supplier data, distribution networks, or customer information.

    Therefore, information security and protection of business secrets will become one of the key risks when deploying a centralized goods traceability system.

    If the data access decentralization mechanism is not strictly designed, the risk of information leakage or exploitation of data for the wrong purpose is completely possible. This is also a problem that can make many businesses afraid to join the system.

    In addition, the processing of goods traceability data should also be placed in connection with the applicable legal regulations on cybersecurity, data and personal data protection, especially in the case of data containing consumer information or data shared across borders.

    It is necessary to manage according to risk instead of applying it simultaneously

    Another issue that needs to be considered is the scope of application of the compulsory goods traceability mechanism. With a very large volume of goods circulating in the market, the simultaneous and rigid application of identification, authentication and goods traceability mechanisms to all items can increase compliance costs and affect the speed of goods circulation. Meanwhile, not all commodities have the same level of risk.

    Therefore, the implementation should be based on the principle of risk-based management. In this direction, the State may prioritize mandatory application to groups of goods with a high risk of affecting health, safety or security, such as food, pharmaceuticals, cosmetics, chemicals or products related to children. For lower-risk commodity groups, voluntary mechanisms or appropriate application roadmaps can be considered.

    This approach not only reduces pressure on the regulatory system, but also limits the risk of creating unnecessary trade barriers.

    What do businesses need to prepare?

    In the context that the Draft is continuing to be finalized, businesses should actively review their readiness early instead of waiting for the regulations to officially take effect.

    First of all, businesses need to assess the current status of the data management system, the connectivity between internal software, and the level of response to real-time goods traceability requirements.

    In addition, enterprises should also build internal processes for goods traceability data management, including a mechanism for updating data, checking the accuracy of information, decentralizing access and processing when detecting false data.

    Another important issue is data classification. Businesses need to clearly define what data can be made public to consumers, which data is only available to regulators or partners in the supply chain, and which data needs to be protected as trade secrets.

    In addition, businesses should also review agreements with suppliers, logistics units, distributors or e-commerce platforms to clarify the responsibility for updating, authenticating and storing goods traceability data.

    The development of a common legal framework on goods export shows the trend of shifting from traditional administrative management to supply chain data management on a digital platform. If implemented effectively, this system can contribute to improving market transparency, supporting anti-counterfeiting and increasing consumer confidence in goods circulating in the Vietnamese market. However, the challenge of the Draft does not lie in whether goods traceability is needed, but in how to design a mechanism that is strong enough to combat counterfeiting, but flexible enough so as not to increase compliance costs and risks for businesses.

    Lawyer Nguyen Van Phuc - Tieu Minh Quan

    HM&P Law Firm

    Read moreTruy xuất nguồn gốc hàng hóa khung pháp lý chung và rào cản thực thi