Guidance on procedures for issuance of the Certificate of eligibility to trade in data intermediary products and services

Insights
Guidance on procedures for issuance of the Certificate of eligibility to trade in data intermediary products and services
Posted on: 02/01/2026

    Data intermediary is a type of business of products and services that help connect data subjects, data owners and users, through commercial agreements. This is a potential type of business because data is considered a high-value asset in the digital era and agencies,  organizations and individuals currently have a high demand for connecting, sharing, exchanging and accessing data. However, opportunity comes with responsibility.[1] Enterprises providing data intermediary products and services between service users and state agencies must be registered, managed and licensed.

    This article will provide some guidelines for businesses when carrying out the procedures for applying for a Certificate of eligibility to trade in data intermediary products and services ("Data Intermediary Certificate") before starting business and exploiting the value of data.

     

    Source: The Congress Office

     

    Conditions for being granted a data intermediary certificate

    Enterprises established and operating under Vietnamese law that meet the following conditions shall be considered for issuance of a data intermediary certificate:

    Personnel conditions: The legal representative of the enterprise must be a Vietnamese citizen, permanently residing in Vietnam; have a university degree or higher, have at least 03 years of work experience related to data management. This person must not be concurrently in the case of being prosecuted; committing a crime that is serving a penalty or has not yet had its criminal record expunged; and be sanctioned for administrative violations in the fields of data, network security, information technology, and electronic transactions.

    On the other hand, a data intermediary enterprise needs to have at least 05 people with a university degree or higher and have one of the certificates and certifications in data science, data analysis, management, data administration, consulting, brokerage, trade promotion; asset management; data validation. Businesses can refer to courses and certification exams organized by data industry "giants" such as Google, Oracle, Microsoft to disseminate and guide their personnel.

    Conditions on material foundations, technical equipment, service provision management process and plans to ensure security and order:

    Before carrying out the procedures for applying for a data intermediary certificate, enterprises must prepare infrastructure and equipment to be located in Vietnam, be inspected for information security and security in accordance with the provisions of law and have a scheme for the provision of products and services.

    The Scheme includes the following main contents:

    Financial conditions: The enterprise must make a deposit at a commercial bank operating in Vietnam of not less than VND 5 billion, and at the same time commit to pay the cost of receiving and maintaining the enterprise's database in case the license is revoked.

    Components of a dossier of application for a Certificate of eligibility to trade in data intermediary products and services

    To do so, the enterprise prepares a set of documents including:

    • A declaration for issuance of a data intermediary certificate according to form TK02 issued together with Decree 169/2025/ND-CP, which lists the data intermediary products and services that the enterprise intends to do business;
    • Papers and documents proving the satisfaction of statutory conditions to provide data intermediary products and services such as enterprise registration certificates; legal papers of the legal representative of the enterprise; statutory certificates and certifications of at least 05 personnel in the enterprise,  etc.

    Procedures for applying for a Certificate of eligibility to trade in data intermediary products and services

    According to the provisions of the law, enterprises submit dossiers directly or via postal service to the National Data Center, Ministry of Public Security at 96 Nguyen Du, Cua Nam Ward, Hanoi City or online through the National Public Service Portal. However, in fact, the online process for this procedure is not complete because the Ministry of Public Security is still in the process of standardizing public services to integrate with the National Public Service Portal. Therefore, businesses still need to submit documents directly or via postal services.

    Within 20 working days from the date of receipt of a complete and valid dossier, the competent authority will consider and decide to grant a data intermediary certificate to the enterprise; in case of refusal, a written notice will be issued clearly stating the reason. The detailed sequence is specified damaged after:

     

     

    Notes for businesses when they have been granted a Data Intermediary Certificate

    Once granted a data intermediary certificate and throughout the course of business and operation, enterprises need to ensure the full implementation of statutory responsibilities related to personal data, information security, cyber security, and data security. The regular responsibilities of the enterprise will include:

    • Proving responsibility through connecting, sharing, exchanging, accessing data and data protection and personal data protection in accordance with the law;
    • Notify organizations and individuals that are data owners, data subjects, and data users of the purpose of providing data intermediary products and services and ensure the rights of individuals in accordance with the law on personal data protection;
    • Collect, use or disclose personal data for lawful purposes and with the consent of the data subject;
    • Ensure accurate and complete data from data subjects and data owners provided to service users;
    • Ensuring the access to data for the right purposes, for the right subjects, and exploitation in accordance with the signed contracts;
    • Implement reasonable safeguards and security measures to protect personal data in the organization's possession, including preventing unauthorized access, collection, use, disclosure or similar risks;
    • Limit the storage of personal data for as long as necessary and properly process personal information when it is no longer necessary for business or legal purposes;
    • Ensuring the limit of cross-border transfers of personal data in accordance with regulatory requirements, ensuring that the standard of protection is equivalent to the standard required by the relevant law;
    • Notify the affected organization or individual as soon as possible if there is a data breach that is likely to cause significant harm to individuals or is of a significant scale;
    • Ensure the ability to transfer data to the right data user in accordance with the signed agreement;
    • Ensure the ability to advise and assess the impact of data processing, data appraisal, flexible forms of payment, regulations on taxes, fees and prices in accordance with the regulations of e-commerce activities;
    • Carry out identity authentication in accordance with the law on electronic identification and authentication.

    It is necessary to remedy violations at the request of competent state agencies so that enterprises do not fall into the case of revocation of the Certificate of eligibility to trade in data intermediary products and services. Enterprises also need to pay attention to ensure stable business, avoid the case of having the Certificate revoked when not operating continuously for 06 months or more.

    In conclusion, in the context of increasing digitalization and information connectivity, data intermediary products and services play an important role in connecting and optimizing data flows between different systems. To exploit the potential of this type of business, enterprises need to meet the requirements and conditions to be granted a data intermediary certificate, and at the same time ensure that data is shared, accessed and used legally, and protect the interests of stakeholders.