> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberskill.world/llms.txt
> Use this file to discover all available pages before exploring further.

# Vietnamese Market Compliance in CyberOS

> CyberOS is built Vietnamese-market-first: MST validation, PDPL data privacy, Decree 145 labour law, BHXH payroll, and MoPS DPIA filing — all native.

CyberOS was designed for the Vietnamese market first. Every regulation below is a first-class platform feature, not a plugin or afterthought — from PDPL data residency enforced at the tenancy layer to Decree 145 overtime caps hard-coded into TIME's write path.

<Tip>
  All Vietnamese compliance features are on by default for `vn-1` residency tenants. No additional configuration required.
</Tip>

## Vietnamese data privacy (PDPL)

Vietnam's Personal Data Protection Law (Decree 13/2023/NĐ-CP) — commonly called the PDPL — is the primary framework governing how CyberOS handles personal data for Vietnamese-market tenants. CyberOS targets the `vn-1` residency tier, which activates the PDPL's data-localisation rules (Decree 53/2022) as part of the `vn-1` compliance package.

<CardGroup cols={2}>
  <Card title="PDPL Art. 38 — Cross-border Transfer" icon="globe">
    Article 38 restricts transferring personal data outside Vietnam without meeting one of the approved legal bases. For `vn-1` tenants, CyberOS stores personal data in the `hanoi-1` region by default. Any cross-border transfer is surfaced to the designated DPO for sign-off before it proceeds.
  </Card>

  <Card title="SME Grace-Period Flag" icon="clock">
    Small and medium enterprises qualify for a transitional grace period under PDPL implementing regulations. Set `pdpl_sme_grace: true` on your tenant settings to enable the grace-period flag. CyberOS tracks the expiry date and notifies the DPO 90 days before it lapses.
  </Card>

  <Card title="DSAR APIs" icon="file-export">
    Data Subject Access Request (DSAR) APIs are available on every module that holds personal data — CRM contacts, TIME entries and expenses, HR records, and REW compensation records. Call `GET /dsar/export?subject=<email>` to receive a structured ZIP bundle fulfilling PDPL Art. 14.
  </Card>

  <Card title="DPO Designation" icon="user-shield">
    PDPL Art. 28 requires a Data Protection Officer for high-risk processing. CyberOS allows you to designate any tenant admin as DPO in **TEN → Compliance → DPO Designation**. During onboarding, the platform defaults to designating the founding account holder as DPO.
  </Card>
</CardGroup>

## Labour law compliance

CyberOS enforces Vietnamese labour law at the data layer — constraints are written into the TIME module's write path, not bolted on as reporting checks after the fact.

### Decree 145/2020 working-hour caps

Decree 145/2020 implements Labour Code 2019 Article 107. TIME enforces the following as hard rules:

<Steps>
  <Step title="Regular hours tracked">
    CyberOS tracks regular working hours per member per ISO week. The cap is **40 hours of regular time per week**. Entries that would push a member past 40 hours in a week are flagged as overtime automatically — no manual categorisation required.
  </Step>

  <Step title="Standard overtime ceiling">
    The default annual overtime ceiling is **200 hours per year** (Labour Code Art. 107 standard limit). TIME evaluates each new overtime entry against the running annual total. Entries that would exceed 200 hours are blocked at the API and page the CHRO.
  </Step>

  <Step title="Extended overtime with consent">
    Up to **300 hours of overtime per year** is permitted with documented employee consent and a MoLISA notification on file. In TIME, the 200–300 hour band is gated: the member must have a signed consent record in HR and a MoLISA notification must be logged before the TIME write path allows entries in this band. Attempting to log overtime above 300 hours is a hard-block regardless of consent.
  </Step>
</Steps>

<Warning>
  Overtime cap enforcement is a non-negotiable hard rule. Entries that violate Labour Code Art. 107 are rejected at the API and trigger an automatic CHRO notification. There is no override path short of filing the correct HR consent and MoLISA notification records first.
</Warning>

### Leave types — Decree 145 and Labour Code 2019

HR tracks eight statutory leave types, each tagged with its legal basis so your records are audit-ready for MoLISA inspection.

| Leave Type        | Statutory Basis                             | Notes                                                           |
| ----------------- | ------------------------------------------- | --------------------------------------------------------------- |
| Annual leave      | Labour Code 2019 Art. 113                   | Accrues from day 1; minimum 12 days/year for standard employees |
| Sick leave        | Labour Code 2019 Art. 112                   | BHXH-funded; requires medical certificate                       |
| Maternity leave   | Labour Code 2019 Art. 139, Decree 145/2020  | 6 months for mothers; BHXH-funded                               |
| Paternity leave   | Labour Code 2019 Art. 34, Decree 145/2020   | 5–14 days depending on delivery type                            |
| Bereavement leave | Labour Code 2019 Art. 115                   | 3 days for immediate family                                     |
| Marriage leave    | Labour Code 2019 Art. 115                   | 3 days                                                          |
| Sabbatical        | Internal policy + Labour Code 2019 Art. 116 | Requires employment anniversary milestone                       |
| Unpaid leave      | Labour Code 2019 Art. 115                   | By agreement; no pay, BHXH suspended                            |

<Note>
  Maternity and paternity leave entitlements are governed by Labour Code 2019 and implemented under Decree 145/2020. CyberOS tags leave records with both the Labour Code article and the relevant Decree so downstream payroll reporting in REW can distinguish BHXH-funded leave from employer-funded leave.
</Note>

## Tax and invoicing

### MST validation

Every time you write or update an account in CRM with an MST (Mã số thuế — Vietnamese business tax code) field, CyberOS invokes the `vietnam-mst-validate` skill. The skill queries the General Department of Taxation (GDT) registry in real time and:

* Confirms the code is valid and active
* Returns the GDT-canonical company name and address
* Flags any mismatch between the name you entered and the GDT canonical name

Validation results are cached for 7 days to handle GDT registry outages gracefully. If the registry is unreachable, the write is permitted but the account is marked `vn_mst_validated: false` and a warning is surfaced to the AM.

### Hóa Đơn (VAT invoice) — Decree 123/2020

When a CRM deal moves to `closed_won`, CyberOS automatically triggers the `vietnam-vat-invoice` skill via the INV module. The resulting hóa đơn (electronic VAT invoice) conforms to Decree 123/2020/NĐ-CP and Circular 78/2021/TT-BTC. The account manager must confirm the amount and recipient before the invoice is issued — this is a mandatory human-confirm gate.

Invoice data includes seller information, buyer MST, line items, and a VAT split computed per item type (standard 10%, reduced 5%, or 0% for exports). Issued invoices are stored in INV with a link to the CRM deal and retained for 10 years per Decree 123 requirements.

### PIT and payroll deductions in REW

REW computes the following statutory deductions on every payroll run for Vietnamese employees:

| Deduction                     | Rate (Employee)   | Legal Basis                   |
| ----------------------------- | ----------------- | ----------------------------- |
| BHXH (Social insurance)       | 10.5%             | Decree 152/2020               |
| BHYT (Health insurance)       | 1.5%              | Decree 152/2020               |
| BHTN (Unemployment insurance) | 1.0%              | Labour Code 2019              |
| PIT (Personal income tax)     | Progressive 5–35% | PIT Law (progressive bracket) |

<Note>
  The employer-side contributions (BHXH 17.5%, BHYT 3%, BHTN 1%) are computed in REW and surfaced on the payroll summary but are not deducted from the employee's net pay.
</Note>

### Expense OCR — Vietnamese Hóa Đơn receipts

Upload a Vietnamese hóa đơn receipt image in TIME and the OCR pipeline extracts the MST, seller name, line items, and VAT split automatically. Extracted fields are editable before you save the expense, and the `vietnam-mst-validate` skill cross-checks the vendor MST against the GDT registry as part of the OCR flow.

## Vietnamese legal entity types in CRM

CRM maps Vietnamese legal entity types to the `account_type` field. Each type controls the hóa đơn template used on deal close:

| Code              | Vietnamese      | English                     | Hóa Đơn Template    |
| ----------------- | --------------- | --------------------------- | ------------------- |
| `sole_proprietor` | Hộ kinh doanh   | Sole proprietor             | 06GTKT (simplified) |
| `llc`             | Công ty TNHH    | LLC                         | 01GTKT              |
| `jsc`             | Công ty cổ phần | JSC                         | 01GTKT              |
| `fdi`             | FDI             | Foreign-invested enterprise | 01GTKT              |
| `individual`      | Cá nhân         | Individual                  | 06GTKT              |

## Language and localisation

CyberOS ships with full Vietnamese and English UI for `vn-1` tenants. The following Vietnamese-specific features are active by default:

* **Vietnamese bigram search (PGroonga)** in the KB module for accurate full-text search across Vietnamese content without requiring word-boundary tokenisation
* **Salutation logic (Anh/Chị/Em)** in CRM contact fields — the platform derives the correct Vietnamese salutation from gender and seniority signals and renders it on every contact card and outbound email template
* **Vietnamese address parsing** on CRM accounts — ward (phường/xã), district (quận/huyện), and province (tỉnh/thành phố) are parsed into structured fields

## Compliance feature summary

| Module | VN Compliance Feature                                                                                             |
| ------ | ----------------------------------------------------------------------------------------------------------------- |
| TIME   | Decree 145 overtime caps (40 h regular/week, 200 h OT/year, 300 h with consent + MoLISA notification)             |
| HR     | 8 statutory leave types tagged to Labour Code 2019 and Decree 145/2020                                            |
| REW    | BHXH 10.5%, BHYT 1.5%, BHTN 1% payroll deductions; PIT progressive computation                                    |
| CRM    | MST validation against GDT registry, hóa đơn emission on deal close, VietQR payment codes                         |
| KB     | Vietnamese bigram full-text search via PGroonga                                                                   |
| TEN    | PDPL Art. 38 cross-border transfer gate, DSAR APIs, `vn-1` data residency, DPO designation, SME grace-period flag |


## Related topics

- [VietQR Payments and Hóa Đơn Invoicing](/guides/vietqr-invoicing.md)
- [What Is CyberOS? The AI-Native Operations Platform](/introduction.md)
- [CyberOS Platform Changelog](/reference/changelog.md)
- [TIME: Billable Hours, Expenses, and Labour Compliance](/modules/time.md)
- [HR Module: Member Lifecycle and Vietnamese Labour Law](/modules/hr.md)
- [CRM: Sales Pipeline, Accounts, and Vietnamese Commerce](/modules/crm.md)
- [CyberOS Glossary: Terms, Acronyms, and Concepts](/reference/glossary.md)
- [TEN: Tenant Lifecycle, Plans, and Billing Management](/modules/ten.md)
- [CyberOS Core Concepts: Memory, Skills, and Workflows](/concepts.md)
- [CUO: CyberOS Workflow Orchestration and Persona Routing](/modules/cuo.md)
