Template · June 17, 2026
PDPL Vendor Data Processing Assessment Template
PDPL vendor assessment: review checklist, scoring table, and ready-to-use template for SMEs.
Edit & copy
This is a reference template. Consult a legal advisor before using in production.
Quick answer
What is the vendor data processing assessment template?
The vendor data processing assessment template is an internal checklist to determine whether a partner will touch personal data, where the risks lie, and which clauses the contract needs to add under the regulations. Under the PDPL, this is the practical step to control outsourced data processing, especially when the provider can access, store, analyze, or transfer data abroad.
You should use this template before signing with: email/SMS platforms, CRM, HRM, call centers, ad agencies, cloud hosting, accounting firms, eKYC onboarding providers, or any party that may see customer, employee, or candidate data.
Why do businesses need to assess vendors under the PDPL?
Because responsibility for data protection does not disappear when you outsource. If the provider mishandles data, causes a breach, or uses data beyond the stated purposes, the business must still demonstrate it has selected, managed, and supervised the partner in line with the regulations. The Personal Data Protection Law (Law 91/2025/QH15) is expected to take effect 01/01/2026, replacing Decree 13/2023/ND-CP.
For enforcement, the relevant authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05). If a data breach occurs, businesses must notify within 72 hours of discovery as required.
Checklist of questions to review partners that process personal data
Below is the core set of questions for the “vendor data processing assessment template.” You can use it when onboarding new vendors or during annual reassessments.
Identify data scope:
Which types of data will the provider touch: full name, phone number, email, citizen ID, bank account, HR data, behavior logs, sensitive data?
Identify role:
Is this party a processor on your behalf, an independent controller, or a joint controller under the regulations?
Assess purposes:
What are they processing the data for, and is it consistent with the purposes you disclosed to data subjects?
Check security:
Do they have encryption, access controls, MFA, access logs, backups, data deletion procedures, and vulnerability management?
Review transfers:
Is data sent outside Vietnam, do they use sub-processors, and do they control storage location?
Lock down the contract:
Are there clauses on confidentiality, incident notification, DSAR support, deletion/return upon termination, and audit rights?
Practical question checklist for procurement / legal / IT
| Topic | Questions to ask the vendor | Expected outcome |
|---|---|---|
| Data | Which data fields will you process? | Clear data inventory |
| Purpose | What will the data be used for, and for how long? | Limited purposes, defined retention |
| Access | Who within your system can access it? | Role-based access control |
| Security | Do you have MFA, encryption, logs, backups, security testing? | Minimum technical measures in place |
| Sub-processor | Do you engage any third parties? | Approved sub-processor list |
| Incidents | If data is exposed, how quickly will you notify us? | Commitment to timely notice, aligned with 72 hours |
| Storage | Where is the data stored, is it transferred abroad? | Storage/transfer locations known |
| Data deletion | Upon termination, will data be deleted or returned? | Deletion/return process exists |
| Rights support | Do you support deletion, rectification, and providing copies upon request? | DSAR process in place |
Ready-to-use sample vendor assessment sheet
You can copy the sheet below into Google Sheets/Notion/Excel to implement immediately.
| Item | Sample answer | Risk score |
|---|---|---|
| Vendor name | Company A - SaaS CRM | |
| Service | Store leads, send email automation | |
| Data types | Full name, email, phone number, transaction history | |
| Any sensitive data? | No | Low |
| Role under the contract | Processor on behalf of the business | Medium |
| Cross-border data transfer | Yes, servers in Singapore | High |
| Security measures | MFA, at-rest encryption, audit logs for 180 days | Medium |
| Sub-processor | 2 disclosed sub-processors | Medium |
| DSAR support | Yes, respond within 10 business days | Low |
| Incident notice | Committed to immediate notice and no later than 72 hours | Medium |
| Deletion/return upon termination | Data deletion certificate provided | Low |
| Conclusion | Conditional approval: add a DPA and security addendum |
How should you score vendors?
You don’t need an overly complex system. For SMEs, use three levels: Low, Medium, High.
- Low: Only basic data, MFA in place, clear contract, no cross-border transfers.
- Medium: Many users with access, uses sub-processors, logs exist but are incomplete.
- High: Touches sensitive data, cross-border transfers, unclear storage location, or no commitment to incident notification.
Practical rule: if a vendor scores high risk, don’t sign immediately. Ask to add security clauses, a data processing addendum, or switch providers. When legal wording is uncertain, have a lawyer review per the regulations.
Sample screening questions you can send to vendors now
Below is a shortened version to send via email/Google Form:
- Please describe the personal data your service will process.
- In which country is the data stored? Is it transferred to third parties or overseas?
- Do you use sub-processors? If yes, please list them.
- Do you have MFA, data encryption, access controls, and audit logs?
- Can you commit to notifying us immediately upon detecting a data incident so we can meet the 72-hour requirement?
- Upon contract termination, how will you delete or return the data?
- Do you support handling data subject requests (access, rectification, deletion, withdrawal of consent where applicable)?
When should you reassess a vendor?
You should reassess when any of the following occurs: system changes, new features are added, servers are moved, a new sub-processor arises, a security incident occurs, or the types of data processed change. For vendors processing significant customer data, review every 12 months.
- There isn't always a single mandatory form, but businesses should have a review template to evidence vendor oversight under the PDPL.
- Yes. As long as they can access, store, or process data on your behalf, you should still review security, purposes, and contract terms.
- Yes. It's critical so the business can meet the obligation to notify within 72 hours of discovery.
- Don't conclude it's a violation outright. You need to check the data transfer, legal basis, and contract terms under the regulations; for complex cases, consult a lawyer.
If you're building a vendor review process, consent.vn can support the cookie banner, consent evidence storage, and DSAR flows to align with your compliance records.
Source: the Personal Data Protection Law (Law 91/2025/QH15), Decree 13/2023/ND-CP — thuvienphapluat.vn; Enforcement authority — Ministry of Public Security (A05) — bocongan.gov.vn
Access the full template library — no account needed.
Need more PDPL templates?