Business context

Vietnam’s Decree 314/2026/ND-CP takes effect on 25 September 2026 and establishes operating conditions for data exchanges. The Government’s published summary says tradable data, data products and services must have lawful and documented origin, clearly disclosed usage conditions and limitations, machine-readable formats, appropriate API documentation where relevant, and security throughout connection, transmission, storage and use. Foreign organisations generally need a lawful commercial presence, branch or representative office in Vietnam unless an applicable treaty provides otherwise.

This creates a commercial route for data, but it also changes the standard of proof. Possessing a file, database or analytical model does not by itself mean a company can sell it, license it or support it as a dependable product. A buyer is purchasing usable rights, stated quality and reliable delivery—not merely access to information.

Core management problem

The main risk sits between functions. Business development may see recurring revenue, legal may focus on rights, technology may focus on connectivity, information security may focus on protection, and operations may own service performance. Each function can approve its own piece while the complete offer remains commercially unsafe.

Management therefore needs one decision path from source to revenue. The question is not only whether data may be listed. It is whether the seller can prove authority, define permitted use, deliver the promised quality, control access, manage incidents and meet customer expectations through the full contract period.

Common mistakes

The first mistake is confusing control with commercial permission. Data collected internally may include third-party rights, personal information, customer restrictions, confidential inputs or purpose limits. Storage location and system ownership do not settle the right to commercialise.

The second mistake is selling an undefined product. Descriptions such as “accurate,” “complete” or “real-time” are not operating specifications. Without a measurable coverage period, refresh cadence, error rule, format, support scope and permitted use, sales language can become an unpriced service obligation.

The third mistake is separating cybersecurity from delivery economics. Authentication, access logging, encryption, incident response, API availability and revocation create cost and capacity requirements. If they are added after pricing, the apparent margin may disappear.

The fourth mistake is treating the first successful transaction as proof of scalability. A bespoke extraction, manual quality check or senior-engineer workaround can satisfy one buyer while hiding a fragile operating model. Commercial growth increases the number of permissions, versions, users and incidents that must be governed.

Practical framework: the rights-to-delivery risk gate

Gate one is provenance and authority. Record where each data element came from, who created or transferred it, the lawful basis for possession, the rights granted and any exclusion. Link every assertion to a document, system record or accountable owner. Unverified provenance stays outside the sellable product.

Gate two is permitted use. Define the buyer, territory, purpose, users, duration, redistribution rights, model-training rights, combination rights and deletion or return obligations. Commercial scope must match the authority actually held. An attractive use case does not expand the seller’s rights.

Gate three is product definition. Publish the schema, coverage, refresh frequency, accuracy method, known limitations, service hours, change policy and support level. Convert broad quality claims into acceptance criteria that operations can measure and customers can understand.

Gate four is controlled delivery. Confirm identity, access authority, API or file-transfer controls, logging, monitoring, incident escalation, backup and revocation. ISO/IEC 27001 provides a general reference for managing information-security risk, but certification or technical controls cannot replace product-specific rights and contractual clarity.

Gate five is commercial exposure. Test pricing against delivery cost, support demand, security controls, quality remediation, service credits, indemnity boundaries and the cost of termination. Decide who may approve exceptions and which terms require executive review.

Gate six is lifecycle evidence. Keep the listing, contract, permission set, delivered version, access history, quality record, incident record and customer acceptance connected. When a source right, regulation, product definition or customer purpose changes, trigger review before the next delivery.

Patrick Lee Business Lens

Growth asks whether the data solves a repeated customer problem and whether buyers will pay for the defined outcome. Manufacturing thinking asks whether the product can be produced, checked and delivered repeatedly with controlled variation. Risk asks whether the company can stop access, trace decisions and contain exposure when an assumption fails.

Growth × Manufacturing × Risk turns data commercialisation into an operating business rather than a one-off transaction. My judgement is that evidence should become part of the product architecture. The strongest offer is not the one with the most data; it is the one whose rights, quality, delivery and economics remain clear as volume grows.

Management process

Create one release record for every data product. Assign owners for provenance, legal applicability, product quality, security, delivery and commercial terms. Require all six gates before launch, then review them at contract renewal, material product change, new use case, new source or security incident.

Track a small set of operating measures: authorised sources, unresolved rights exceptions, failed quality checks, delivery availability, support effort, access anomalies, incident closure time, realised gross margin and renewals. A dashboard is useful only when each threshold has a named decision owner and an agreed response.

Management implication

Vietnam’s data-exchange rules make commercial opportunity more concrete while raising the evidence required to transact responsibly. Leaders should not send the issue to legal or IT alone. The commercial product exists only when rights, specifications, controls, economics and accountability operate as one system.

The Government source establishes the policy context and ISO/IEC 27001 offers a general information-security reference. Neither determines a specific company’s legal position or guarantees eligibility for a data exchange. Companies should obtain qualified legal, privacy and cybersecurity advice where applicable; this article provides independent commercial-management judgement and does not provide regulated legal, technology or investment advice.