Article · June 17, 2026

Software outsourcing and data processing: PDPL, GDPR, processor role

Software outsourcers handling foreign clients’ data must meet PDPL/GDPR and define the processor role correctly. See the practical checklist.

consent.vn Editorial6 min read

Quick answer

If your company outsources software for foreign clients and touches personal data, you usually need to correctly identify the “processor” role in the contract and prepare for Vietnam’s PDPL and for the GDPR if you process data within the EU/EEA scope. The key is to govern by process, not just sign an NDA or DPA for form’s sake.

What is a PDPL/GDPR software outsourcing company handling data?

This question often arises in practice: a Vietnam-based team writes, operates, or supports systems for foreign clients, but user data ends up in the app, databases, logs, tickets, or analytics. In that case, the outsourcing company is not merely an “IT vendor” but can become a data processor under the contract and must comply with applicable obligations under the Personal Data Protection Law (the Personal Data Protection Law (Law 91/2025/QH15, expected effective 01/01/2026)) and the GDPR if there is data about individuals in the EU/EEA.

Important point: the PDPL replaces Decree 13/2023/ND-CP when the law takes effect. The enforcement authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05). For the GDPR, you need to look at where the customer is, where the data flows, and which systems are accessing it.

Is a software outsourcing company a data processor?

Possibly yes, if your company processes personal data on behalf of the client and only under their instructions. Examples include: the dev team reading logs that contain emails, support retrieving orders with names/phone numbers, QA using a production dump, or DevOps administering databases that contain user information.

In outsourcing practice, common roles include:

  • Data processor: you act under the client’s (controller’s) instructions.
  • Data controller: rarer, if you determine the purposes/methods of processing.
  • Sub-processor third party: if you engage cloud, monitoring, ticketing, or AI tools to deliver the service to the client.

If you use tools such as analytics, log aggregators, CRM, or an AI coding assistant that touches real data, your company may incur obligations to control access, storage, sharing, and notifications under the contract and applicable regulations.

ScenarioTypical roleObligations to note
Write code without touching real dataNo direct processingStill need to control dev/test environments
Access production DB via ticketProcessorAccess control, logging, NDA/DPA, revoke access when the task is done
Operate a SaaS system for an EU clientProcessor, possibly in a sub-processor chainGDPR DPA, SCC for cross-border transfers
Unilaterally decide to use user data for internal analyticsMay become a controllerReview legal basis, notices, and data subject rights

Under the PDPL, what must an outsourcing company do?

Under the rules, you should do at least the following five things to avoid “playing the wrong role”:

  1. Define the role in writing:

    State clearly in the contract that you are the processor, process only under the client’s instructions, and will not use the data for your own purposes.

  2. Inventory data and processing flows:

    Know which data goes into dev, test, staging, prod, logging, backup, and who has access.

  3. Set up technical controls:

    Masking, pseudonymization, environment separation, MFA, least privilege, audit logs, secret management.

  4. Manage sub-processors:

    Cloud, email, ticketing, analytics, monitoring, LLM tools… must be assessed before being used with real data.

  5. Prepare an incident process:

    If a data breach is discovered, notify within 72 hours from detection as required.

A practical example: a company outsourcing backend for a Singapore client allows QA to download a database dump containing names, emails, and purchase history onto personal laptops for testing. Although the purpose is testing, this is still personal data being processed. Without masking, access control, and a process to delete copies after testing, PDPL/GDPR risk increases significantly.

Under the GDPR, what should software outsourcing watch for?

If the customer or end users are in the EU/EEA, the GDPR typically requires a data processing agreement (DPA), clear controller/processor roles, and proper controls for data transfers outside the region. Outsourcing companies in Vietnam are often processors or sub-processors, so they must process only under instructions, help clients meet data subject requests, and secure data under “privacy by design”.

Things to check in the project:

  • Is there EU personal data?
  • Is there access from Vietnam into EU systems?
  • Are logs, tickets, or backups transferred into tools hosted outside the EU?
  • Are sub-providers such as AWS, GCP, Azure, OpenAI, Atlassian, Zendesk used?
  • Does the DPA restrict/limit sub-processing?

If there is cross-border data transfer, review the legal mechanism the client has chosen under the GDPR and verify the corresponding contractual clauses. For complex scenarios, seek legal review before go-live.

What checklist should an outsourcing company prepare for foreign client projects?

The checklist below suits SMEs and technical teams for quick implementation:

  • Have a data classification: PII, sensitive data, production data, test data.
  • Have SOPs for role-based access granting and revoking on offboarding.
  • Do not use real production data for dev/test unless anonymized or substituted.
  • Have a DPA/SCC or data processing terms in the MSA/SOW.
  • Have an incident playbook and a point of contact to respond within 72 hours.
  • Have access logs, change logs, and evidence of consent/authorization if needed.
  • Have a data deletion process when the contract ends.

If you operate a cookie banner, store consent evidence, or a DSAR workflow for clients, consent.vn can help you standardize this so the dev and legal teams speak the same language.

Not always. If you only perform technical work under the client’s instructions, you are usually a processor. If you determine the purposes/methods of using the data yourself, the role may differ.
It carries high regulatory risk because the data is still personal data. You should mask or generate synthetic data, and only use copies when you have access controls, logging, and clear deletion policies.
If a data breach within scope occurs, you must notify within 72 hours from discovery under the regulations. You should have an internal process ready.
This is a GDPR issue about data transfers and the supplier chain. Review the DPA, the transfer mechanism, and consult a lawyer before actual processing.

Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement authority A05 at bocongan.gov.vn.

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started