Expertise · Coordination and daily operations

SSO, NDA, and DPA: three layers of security that do not replace each other

Many businesses stop at an NDA and think that is sufficient, while the partner is quietly processing personal data without any legal constraints to control it.

Quick summary

These three layers serve three different functions: SSO (single sign-on) controls who can access the system, NDA (non-disclosure agreement) binds to keep strategic information confidential, while DPA (data processing agreement) specifies what the partner can do with personal data and how to protect it. All three should be finalized at the contract signing stage, not patched later. Specifically for DPA, when a partner accesses personal data of customers or end users, legal oversight is needed, as legal obligations extend beyond the scope of brand design or operation.

Quick comparison
You should choose this direction when
  • Partners access users' personal data.
  • businesses with a centralized login system (SSO)
  • You only share strategic documents and unpublished assets.
Not needed when.
  • copying DPA templates from the internet without legal oversight

When an external partner, whether a design studio, content agency, or technical contractor, begins to access the company’s systems and documents, you need three layers of separate controls. Each layer protects something different. Mixing or omitting a layer leaves a gap that can only be discovered after an incident occurs.

Three layers do not replace each other

Sinh Vũ distinguishes three layers as follows:

  • SSO (Single Sign-On): Controls who can access the system, how far they can go, and how to revoke access when they leave the project. SSO connects to the enterprise's centralized login system, assigns permissions based on roles, and logs who accessed what.
  • NDA (Non-Disclosure Agreement): a legal obligation to keep strategic information, unpublished assets, and sensitive content confidential. The NDA covers both direct personnel and subcontractors who have access to the information.
  • DPA (Data Processing Agreement): stipulates what the partner can do with personal data, where the data is stored, how it is protected, and when it must be deleted or returned. The DPA clearly defines who is the data controller and who is the processor.
Is the NDA sufficient, or is a DPA needed?
NDA protects confidential information in a broad sense: strategy, plans, unreleased assets. DPA covers a narrower but tighter scope: personal data of real people, customers, end users, employees. If partners only view design drafts and brand positioning documents, NDA is usually sufficient. If partners access CRM (customer management system), email lists, or any data linked to real people, DPA is mandatory, and NDA cannot replace it.

When each layer becomes mandatory

  • SSO: A priority when the enterprise already has a centralized login system and multiple users or partners accessing resources. It is not necessary from the start if the scale is small, but there must be a manual revocation mechanism in place.
  • NDA: is almost always necessary when sharing strategic documents, brand briefs, or unpublished product plans. It should be signed before sharing any sensitive information, not afterward.
  • DPA: mandatory as soon as an external partner touches personal data. According to GDPR Article 28, the processor may only act according to written instructions, must commit to confidentiality, and cannot subcontract without the controller's consent.

The data processing party may only process personal data according to the documented instructions of the controlling party, unless otherwise required by law.

GDPR Article 28

Common errors to avoid

  • Stopping at NDA, overlooking DPA: this is the most common mistake. NDA does not specify who can do what with personal data, nor does it mention deleting or returning data when the work is done.
  • No revocation of access when personnel leave: Access rights remaining active after someone departs is a real risk, not just theoretical. SSO helps with centralized revocation; if SSO is not yet available, a clear manual process is needed.
  • Use downloaded DPA templates without legal review: Online templates may violate applicable laws in Vietnam or lack clauses appropriate for the actual contract. An incorrect DPA is more dangerous than having none, as it creates a false sense of security.
  • No clear regulations on data deletion and return: When the contract ends, personal data must be deleted or returned. If not stated in the DPA, there is no basis for a request.

Sinh Vũ's viewpoint

Sinh Vũ handles these security requests during the setup phase, often associated with the brand portal that has role-based access. This is an area where Sinh Vũ does not make unilateral decisions on behalf of the client and always recommends that the company's legal team review before signing.

The simple reason: personal data constraints have legal consequences beyond the scope of design or brand operations. Being strict from the beginning incurs lower costs. Fixing issues after they occur is much more expensive and damaging to your reputation.

The principle Sinh Vũ uses when establishing delegation is minimum privilege: each person only sees and interacts with what is necessary for their role, no more. SSO is the tool that implements this principle at the system level. NDA and DPA are implemented at the legal level. Both need to run in parallel; neither can replace the other.

The tool brings back.

Decision checklist

Topic: How to handle SSO, NDA, and DPA security requirements. Sinh Vũ guide, sinhvu.com

0 more than 7 items

Select each item you find appropriate, then print or save as PDF to take with you.

Sign indicating that you should take action
Questions to answer before deciding

If you have marked most of the signs above, this is the time to discuss in more detail. Sinh Vũ can help you review and propose a direction.

References

GDPR Article 28 (Data Processing Agreement); Termly, What Is a Data Processing Agreement; Hyperstart, DPA Complete Guide; Secure Privacy, DPAs for SaaS; Bynder, What is Digital Asset Management. Sinh Vũ's practical experience in establishing a brand portal with delegation.

Frequently asked questions

Is a DPA needed after signing the NDA?

Yes, if your partner handles personal data, such as customer lists, user information, or behavioral data. An NDA protects confidential information broadly but does not specify who can do what with personal data, where the data is stored, and how it is deleted at the end. A DPA fills in that gap. The two documents complement each other, rather than replace one another.

How to handle authorization for a company without an SSO system?

If you do not have SSO yet, you need to manage separate accounts for each tool and manually track changes when personnel changes occur. The risk lies in forgetting to revoke access when someone leaves, which is the most common vulnerability. A temporary solution is to create an access list by name, review it periodically, and revoke access immediately when there are personnel changes. As the scale grows, investing in SSO will save significant management effort.

Can DPA samples from the web be used?

Online samples can be used as references to understand the structure, but they should not be used directly without legal review. The applicable laws vary by country and type of data, and the terms regarding subcontracting and data deletion must align with your actual contract. Sinh Vũ recommends having legal adjust the sample according to the applicable laws instead of signing an unverified version.

← Back to Brand Operations