Many businesses stop at an NDA and think that is sufficient, while the partner is quietly processing personal data without any legal constraints to control it.
These three layers serve three different functions: SSO (single sign-on) controls who can access the system, NDA (non-disclosure agreement) binds to keep strategic information confidential, while DPA (data processing agreement) specifies what the partner can do with personal data and how to protect it. All three should be finalized at the contract signing stage, not patched later. Specifically for DPA, when a partner accesses personal data of customers or end users, legal oversight is needed, as legal obligations extend beyond the scope of brand design or operation.
When an external partner, whether a design studio, content agency, or technical contractor, begins to access the company’s systems and documents, you need three layers of separate controls. Each layer protects something different. Mixing or omitting a layer leaves a gap that can only be discovered after an incident occurs.
Sinh Vũ distinguishes three layers as follows:
The data processing party may only process personal data according to the documented instructions of the controlling party, unless otherwise required by law.
GDPR Article 28
Sinh Vũ handles these security requests during the setup phase, often associated with the brand portal that has role-based access. This is an area where Sinh Vũ does not make unilateral decisions on behalf of the client and always recommends that the company's legal team review before signing.
The simple reason: personal data constraints have legal consequences beyond the scope of design or brand operations. Being strict from the beginning incurs lower costs. Fixing issues after they occur is much more expensive and damaging to your reputation.
The principle Sinh Vũ uses when establishing delegation is minimum privilege: each person only sees and interacts with what is necessary for their role, no more. SSO is the tool that implements this principle at the system level. NDA and DPA are implemented at the legal level. Both need to run in parallel; neither can replace the other.
Topic: How to handle SSO, NDA, and DPA security requirements. Sinh Vũ guide, sinhvu.com
Select each item you find appropriate, then print or save as PDF to take with you.
If you have marked most of the signs above, this is the time to discuss in more detail. Sinh Vũ can help you review and propose a direction.
GDPR Article 28 (Data Processing Agreement); Termly, What Is a Data Processing Agreement; Hyperstart, DPA Complete Guide; Secure Privacy, DPAs for SaaS; Bynder, What is Digital Asset Management. Sinh Vũ's practical experience in establishing a brand portal with delegation.
Yes, if your partner handles personal data, such as customer lists, user information, or behavioral data. An NDA protects confidential information broadly but does not specify who can do what with personal data, where the data is stored, and how it is deleted at the end. A DPA fills in that gap. The two documents complement each other, rather than replace one another.
If you do not have SSO yet, you need to manage separate accounts for each tool and manually track changes when personnel changes occur. The risk lies in forgetting to revoke access when someone leaves, which is the most common vulnerability. A temporary solution is to create an access list by name, review it periodically, and revoke access immediately when there are personnel changes. As the scale grows, investing in SSO will save significant management effort.
Online samples can be used as references to understand the structure, but they should not be used directly without legal review. The applicable laws vary by country and type of data, and the terms regarding subcontracting and data deletion must align with your actual contract. Sinh Vũ recommends having legal adjust the sample according to the applicable laws instead of signing an unverified version.