Data, Technology & Compliance

Technology Vendor Review and Cybersecurity Due Diligence in Vietnam

越南技术供应商与网络安全审查

Businesses today depend heavily on technology vendors: management software, cloud services, IT outsourcing providers, camera and timekeeping system suppliers, marketing platforms. Every vendor touches a business’s data to some degree, and each touchpoint is a point of risk. When a vendor suffers a cyberattack or processes data in breach of regulations, the business is the first party that must explain itself to customers and the authorities.

Vietnamese law from 01/01/2026 sets out clearer requirements on the responsibility of businesses for third parties that process data on their behalf, in particular under Article 7 of Decree 356/2025/ND-CP on personal data processing agreements.

Quick Summary

Legal basisArticle 7 of Decree 356/2025/ND-CP; Law 91/2025/QH15; Law on Cybersecurity 2018
Key pointClassify vendors by risk; mandatory data processing agreements; continuous monitoring after signing
AudienceProcurement, IT and in-house legal teams at businesses using multiple technology vendors

Why Review Technology Vendors

In the modern business model, a company’s data rarely sits neatly within its internal systems. Customer data lives on an outsourced CRM, personnel data is synchronized to the group’s systems, email runs on a cloud platform, the website is managed by an agency. Every vendor is a data “processor” acting on the business’s behalf, and the law does not allow a business to disclaim responsibility on the grounds that “it was the vendor’s fault.”

As the data controller, a business is responsible for all data processing activities, including those entrusted to third parties. When a data leak originates from a vendor’s systems, the business remains the party that must notify the authorities, answer to customers, and bear sanctions. Reviewing vendors is therefore not a formality but a mandatory self-protection measure.

Technology Supply Chain Risks in Practice

The most common risk scenarios all originate from vendors. First: a cloud or software vendor is attacked, and the data of many customers, including the business, is stolen. Second: an IT outsourcing provider’s employee gains unauthorized access to the business’s data due to lax access controls. Third: a vendor goes bankrupt or terminates the service abruptly, and the business cannot retrieve its data.

A fourth scenario, less visible but increasingly common: the vendor uses the business’s data for its own purposes — for example, using the business’s customer data to train its AI models, or sharing aggregated data with third parties without the business’s knowledge. All these scenarios share one thing in common: the business only discovers the problem after the damage is done, because there was no review and monitoring mechanism from the outset.

Legal Framework for Technology Vendor Relationships

Three areas of law govern these relationships. First, personal data protection law: Law 91/2025/QH15 and Decree 356/2025/ND-CP, in which Article 7 of Decree 356 regulates agreements and contracts on personal data processing between controllers and processors, prescribing the mandatory contents. Second, cybersecurity law: the Law on Cybersecurity 2018 and its guiding documents, which apply when the business’s or the vendor’s information systems fall within their scope.

Third is general contract law: the Civil Code 2015 and the Commercial Law 2005 govern the parties’ rights and obligations and liability for breach. For foreign vendors providing cross-border services such as SaaS, additional issues arise around cross-border data transfers and foreign contractor tax.

Classifying Vendors by Risk Level

Not every vendor needs the same level of review. The effective approach is to classify vendors by their exposure to data and their importance to operations. The high-risk group comprises vendors processing sensitive personal data or data of a large number of data subjects: HR system providers, CRM, payment platforms, IT outsourcing providers with access to core systems. This group needs in-depth assessment before signing and close supervision during performance.

The medium-risk group comprises vendors with limited data contact: marketing agencies that only receive aggregated data, digital stationery suppliers, hardware maintenance providers. The low-risk group consists of vendors that barely touch any data.

What to Assess in a Technology Vendor Review

An effective vendor assessment must cover both legal and technical aspects. On the legal side: verify legal status and signing capacity; assess the vendor’s data protection policy; verify compliance with data protection and cybersecurity regulations; review history of violations and disputes where public information is available. On the technical and operational side: assess the security measures the vendor applies; access control and authorization policies; incident response procedures; data backup and recovery policies.

For high-risk vendors, businesses should require detailed assessment questionnaires and security certifications or audit reports where available. Assessment results should be kept on file. Assessment is not a one-off exercise: it should be repeated periodically, at least annually for the high-risk group.

Key Contract Terms with Technology Vendors

The contract is the most important legal instrument for controlling vendor risk. Core terms include: a clear description of the scope of services and each party’s responsibilities; the vendor’s commitments on confidentiality and data protection; the obligation to notify promptly upon discovering an incident; the business’s right to inspect and assess the vendor’s systems; and terms on data handling upon contract termination.

On liability, the contract should clearly provide for the vendor’s responsibility when a data leak occurs or confidentiality commitments are breached, including compensation for the actual losses the business suffers such as remediation costs, customer notification costs, and administrative fines. Avoid liability caps that are disproportionately low relative to the scale of the risk.

Data Processing Agreements with Processors under Article 7 of Decree 356

Article 7 of Decree 356/2025/ND-CP regulates agreements and contracts on personal data processing between the parties — the direct legal basis for the obligation to sign binding documents with vendors that process data. Such an agreement may be an appendix to the main contract or a standalone document, but it must include the core contents: clear identification of the controller and processor roles; the scope of data processed; processing purposes; processing duration; and the processor’s confidentiality and data protection obligations.

Particularly important are the processor’s obligation to process data only on the controller’s instructions and not to use data for its own purposes without consent; the obligation to assist the controller in responding to data subjects’ rights; and the obligation to delete and return data when the contract ends. Businesses should standardize a data processing agreement template for use with all vendors (see also SaaS Contracts for Companies in Vietnam).

Assessing a Vendor’s Cybersecurity

In addition to the legal assessment, businesses need to evaluate the vendor’s actual cybersecurity capability, as this is the direct line of defense protecting the data. Assessment areas include: data encryption measures at rest and in transit; authentication and access control mechanisms; vulnerability patching and system update procedures; incident detection and response capability; backup policies and post-incident recovery plans.

The contract should require the vendor to maintain the committed security level, to notify of major changes to system architecture, and to allow the business or an independent third party to conduct assessments when necessary.

Ongoing Monitoring After Contract Signing

Review does not end when the contract is signed. During performance, businesses need to maintain monitoring mechanisms: tracking compliance with security commitments through the vendor’s periodic reports; reassessing when the vendor undergoes major changes in systems, key personnel or ownership structure; and conducting spot checks when there are signs of irregularity. For the high-risk group, there should be a scheduled review meeting at least once a year.

Businesses also need to track legal changes affecting vendor relationships so that records can be reviewed and supplemented in a timely manner.

Handling Vendor Breach or Contract Termination

When a vendor breach or incident is discovered: require the vendor to report details and remediation measures; assess the impact; fulfill the obligation to notify the authorities and data subjects if thresholds are reached; reserve the right to claim compensation under the contract.

Upon contract termination, post-termination data handling terms are decisive: the vendor must return all data to the business in a usable format, then delete all copies in its systems and confirm in writing. Businesses should have a vendor transition plan (exit plan) from the moment the contract is signed, covering the transition period, technical support and related fees, so as not to be “locked in” to a single vendor.

How FLAT LAW FIRM Supports Businesses

FLAT LAW FIRM helps businesses build technology vendor review processes: designing classification and assessment criteria; drafting a standardized data processing agreement template; reviewing and negotiating vendor contracts on confidentiality, liability and post-termination data handling; assessing cybersecurity compliance in technology contracts.

When an incident originates from a vendor, we support crisis handling: assessing notification obligations, working with the authorities, negotiating compensation. We work in Vietnamese, Chinese and English. See also Contracts and Risk Governance When Using AI and Data and Technology Compliance Checklist.

Frequently Asked Questions

If a vendor leaks data, who is responsible?

As the data controller, the business remains responsible to the authorities and data subjects. Afterwards, the business may claim compensation from the vendor under the contract and the data processing agreement.

Is a data processing agreement with vendors mandatory?

Yes. Article 7 of Decree 356/2025/ND-CP regulates agreements and contracts on personal data processing between controllers and processors. Businesses should standardize a template agreement for use with all vendors.

How often should vendors be assessed?

In-depth assessment should be conducted before signing, with periodic reassessment — at least annually for the high-risk vendor group — plus continuous monitoring during performance.

What happens to data upon contract termination?

The vendor must return all data in a usable format, then delete all copies and confirm in writing. Businesses should have a vendor transition plan from the moment the contract is signed.

What extra considerations apply to foreign SaaS vendors?

Additional assessment is needed on cross-border data transfer obligations, data hosting location terms, and foreign contractor tax issues. See our article on SaaS Contracts for Companies in Vietnam.

Talk to FLAT LAW FIRM

If your business needs to build a technology vendor review process or negotiate vendor contracts, FLAT LAW FIRM is ready to assist in Vietnamese, Chinese and English.