Template · June 17, 2026

PDPL Vendor Data Processing Assessment Template

PDPL vendor assessment: review checklist, scoring table, and ready-to-use template for SMEs.

consent.vn Editorial7 min read

Edit & copy

This is a reference template. Consult a legal advisor before using in production.

Quick answer

If you use a CRM, cloud, marketing automation, or outsourced customer support (CS), the vendor data processing assessment template helps you review PDPL risks before signing a contract. Below are a question checklist, a scoring table, and a pre-filled template SMEs can use right away.

What is the vendor data processing assessment template?

The vendor data processing assessment template is an internal checklist to determine whether a partner will touch personal data, where the risks lie, and which clauses the contract needs to add under the regulations. Under the PDPL, this is the practical step to control outsourced data processing, especially when the provider can access, store, analyze, or transfer data abroad.

You should use this template before signing with: email/SMS platforms, CRM, HRM, call centers, ad agencies, cloud hosting, accounting firms, eKYC onboarding providers, or any party that may see customer, employee, or candidate data.

Why do businesses need to assess vendors under the PDPL?

Because responsibility for data protection does not disappear when you outsource. If the provider mishandles data, causes a breach, or uses data beyond the stated purposes, the business must still demonstrate it has selected, managed, and supervised the partner in line with the regulations. The Personal Data Protection Law (Law 91/2025/QH15) is expected to take effect 01/01/2026, replacing Decree 13/2023/ND-CP.

For enforcement, the relevant authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05). If a data breach occurs, businesses must notify within 72 hours of discovery as required.

Checklist of questions to review partners that process personal data

Below is the core set of questions for the “vendor data processing assessment template.” You can use it when onboarding new vendors or during annual reassessments.

  1. Identify data scope:

    Which types of data will the provider touch: full name, phone number, email, citizen ID, bank account, HR data, behavior logs, sensitive data?

  2. Identify role:

    Is this party a processor on your behalf, an independent controller, or a joint controller under the regulations?

  3. Assess purposes:

    What are they processing the data for, and is it consistent with the purposes you disclosed to data subjects?

  4. Check security:

    Do they have encryption, access controls, MFA, access logs, backups, data deletion procedures, and vulnerability management?

  5. Review transfers:

    Is data sent outside Vietnam, do they use sub-processors, and do they control storage location?

  6. Lock down the contract:

    Are there clauses on confidentiality, incident notification, DSAR support, deletion/return upon termination, and audit rights?

Practical question checklist for procurement / legal / IT

Topic Questions to ask the vendor Expected outcome
Data Which data fields will you process? Clear data inventory
Purpose What will the data be used for, and for how long? Limited purposes, defined retention
Access Who within your system can access it? Role-based access control
Security Do you have MFA, encryption, logs, backups, security testing? Minimum technical measures in place
Sub-processor Do you engage any third parties? Approved sub-processor list
Incidents If data is exposed, how quickly will you notify us? Commitment to timely notice, aligned with 72 hours
Storage Where is the data stored, is it transferred abroad? Storage/transfer locations known
Data deletion Upon termination, will data be deleted or returned? Deletion/return process exists
Rights support Do you support deletion, rectification, and providing copies upon request? DSAR process in place

Ready-to-use sample vendor assessment sheet

You can copy the sheet below into Google Sheets/Notion/Excel to implement immediately.

Item Sample answer Risk score
Vendor name Company A - SaaS CRM
Service Store leads, send email automation
Data types Full name, email, phone number, transaction history
Any sensitive data? No Low
Role under the contract Processor on behalf of the business Medium
Cross-border data transfer Yes, servers in Singapore High
Security measures MFA, at-rest encryption, audit logs for 180 days Medium
Sub-processor 2 disclosed sub-processors Medium
DSAR support Yes, respond within 10 business days Low
Incident notice Committed to immediate notice and no later than 72 hours Medium
Deletion/return upon termination Data deletion certificate provided Low
Conclusion Conditional approval: add a DPA and security addendum

How should you score vendors?

You don’t need an overly complex system. For SMEs, use three levels: Low, Medium, High.

  • Low: Only basic data, MFA in place, clear contract, no cross-border transfers.
  • Medium: Many users with access, uses sub-processors, logs exist but are incomplete.
  • High: Touches sensitive data, cross-border transfers, unclear storage location, or no commitment to incident notification.

Practical rule: if a vendor scores high risk, don’t sign immediately. Ask to add security clauses, a data processing addendum, or switch providers. When legal wording is uncertain, have a lawyer review per the regulations.

Sample screening questions you can send to vendors now

Below is a shortened version to send via email/Google Form:

  1. Please describe the personal data your service will process.
  2. In which country is the data stored? Is it transferred to third parties or overseas?
  3. Do you use sub-processors? If yes, please list them.
  4. Do you have MFA, data encryption, access controls, and audit logs?
  5. Can you commit to notifying us immediately upon detecting a data incident so we can meet the 72-hour requirement?
  6. Upon contract termination, how will you delete or return the data?
  7. Do you support handling data subject requests (access, rectification, deletion, withdrawal of consent where applicable)?

When should you reassess a vendor?

You should reassess when any of the following occurs: system changes, new features are added, servers are moved, a new sub-processor arises, a security incident occurs, or the types of data processed change. For vendors processing significant customer data, review every 12 months.

There isn't always a single mandatory form, but businesses should have a review template to evidence vendor oversight under the PDPL.
Yes. As long as they can access, store, or process data on your behalf, you should still review security, purposes, and contract terms.
Yes. It's critical so the business can meet the obligation to notify within 72 hours of discovery.
Don't conclude it's a violation outright. You need to check the data transfer, legal basis, and contract terms under the regulations; for complex cases, consult a lawyer.

If you're building a vendor review process, consent.vn can support the cookie banner, consent evidence storage, and DSAR flows to align with your compliance records.

Source: the Personal Data Protection Law (Law 91/2025/QH15), Decree 13/2023/ND-CP — thuvienphapluat.vn; Enforcement authority — Ministry of Public Security (A05) — bocongan.gov.vn

Access the full template library — no account needed.

Need more PDPL templates?

Get started