Vendor Liability and Data Processing Agreements under Vietnam’s Personal Data Protection Framework

September 18th, 2026
| |
Privacy

SUMMARY

  1. Data Controller is ultimately liable for any breach occurring during data processing activities.

  2. The Data Processing Agreement (DPA) is a tool for vendor management and sets out the vendor’s obligations and responsibilities.
  3. DPA should cover scope of processing, specified purposes, security obligations, breach notifications and indemnification.
  4. There are operational risks that should be considered when drafting a DPA.
  5. Audit and self-assessment should be utilized to confirm that vendor adopts the appropriate measures to protect personal data.

Vietnamese version

Contact Us

Tel: (84-28) 3824-3026