In a context where data has become a core asset, entering into IT service contracts for customer data storage is an essential requirement to ensure legal compliance and risk control. A well-structured contract helps clearly define responsibilities, security standards, and incident response mechanisms, thereby protecting businesses against the risk of data breaches.
I. Introduction to IT service contracts for customer data storage in the current context
At present, IT service contracts for customer data storage have become an important legal instrument enabling businesses and service providers to clearly define rights, obligations, and data protection responsibilities. Such contracts must specify in detail the scope of services, security standards, access rights, data storage, deletion or return mechanisms, while ensuring compliance with Decree No. 13/2023/ND-CP on personal data protection.

When using third-party services, businesses must closely supervise operations to minimize risks of privacy violations or data leakage. A comprehensive and clearly drafted contract helps reduce legal disputes and protect the interests of both parties, while enhancing reputation and information security in business operations.
1. Definition of IT service contracts for customer data storage
An IT service contract for customer data storage is a legal agreement between a business and a technology service provider, under which the provider commits to storing, managing, and securing customer data. The contract must clearly stipulate the scope of services, security standards, rights and obligations of the parties, data retention period, and responsibilities for handling violations.
It serves as an important legal basis for businesses to comply with personal data protection regulations under Decree No. 13/2023/ND-CP, minimize dispute risks, and safeguard the rights of data subjects. At the same time, the contract ensures transparency of responsibilities when data-related incidents occur.
2. Practical example related to IT service contracts for data storage
An e-commerce company entered into a contract with an IT firm to store customer data on a cloud platform, but the contract did not clearly define security standards or monitoring mechanisms. During operation, the service provider’s system was attacked by hackers, resulting in the leakage of personal data of thousands of customers.
Although the incident originated from a third party, the company was still sanctioned by authorities and required to compensate for damages due to failure to fulfill data protection obligations. Such a case illustrates that IT service contracts must clearly define security responsibilities, system audit requirements, and incident-handling mechanisms to minimize legal risks.
3. Why IT service contracts for customer data storage are necessary
IT service contracts for storing customer data are essential legal tools that help businesses clearly define rights, obligations, and security responsibilities among parties. Under Decree No. 13/2023/ND-CP, all data storage and processing activities must ensure transparency, proper purpose, and information security.
A clear contract helps businesses reduce legal risks if data is misused or leaked. It also serves as a basis to protect customer rights and require service providers to implement appropriate technical and organizational measures. Proper implementation of such contracts ensures legal compliance while enhancing reputation and data security.
II. Legal regulations related to IT service contracts for customer data storage
1. Main legal provisions to consider
When entering into such contracts, the business, acting as the Personal Data Controller, must comply with data processing principles under Article 3 of Decree No. 13/2023/ND-CP, including processing data for proper purposes, within necessary scope, and ensuring security throughout storage.
Outsourcing IT services constitutes transferring data to a Personal Data Processor. Therefore, under Clauses 1 and 2, Article 39, the service provider may only process data after a written agreement and must comply strictly with agreed terms and implement all required data protection measures.

Additionally, the contract must clearly stipulate obligations to delete or return all personal data upon termination of services (Clause 5, Article 39), as well as responsibilities in handling data protection violations. In case of data breaches, the business must notify competent authorities under Article 23 and bear responsibility toward data subjects for damages under Clause 6, Article 38.
Compliance with these provisions is a crucial legal basis for minimizing risks, protecting customer rights, and ensuring legal safety in using IT data storage services.
2. Conditions for applying such contracts
To ensure legality, businesses must satisfy the following conditions:
- Entering into a written contract with the IT service provider (Clause 1, Article 39);
- Clearly defining scope, purpose, security measures, processing duration, and responsibilities, consistent with data protection requirements under Clause 1, Article 26;
- Ensuring the provider has adequate technical capacity and fulfills obligations to secure data and delete/return it after processing (Clauses 3 and 5, Article 39);
- Conducting data processing impact assessments (Article 24) and cross-border data transfer assessments (Article 25) where applicable, including notification procedures.
Meeting these conditions ensures lawful, secure data processing and protection of customer rights under Vietnamese law.
3. Measures for handling violations
- In such contracts, the service provider acts as the Data Processor and may only process data within contractual scope (Article 39).
- If the processor violates obligations, such as misuse, leakage, loss, or unauthorized use of data, it must compensate for damages and delete or return data upon contract termination (Clauses 4, 5 Article 39; Clause 6 Article 38).
- Violations may also require cessation of processing and deletion of data within 72 hours upon valid request from data subjects (Article 12; Article 16).
- Additionally, the Data Controller must notify the Ministry of Public Security within 72 hours of detecting violations and coordinate remedial actions (Article 23).
- Depending on severity, violators may take administrative sanctions or criminal liability, particularly for prohibited acts such as unlawful data collection, transfer, or processing without consent (Articles 4, 8, 22).
III. Questions on IT service contracts for customer data storage
1. Must the contract be in writing?
Under the Civil Code 2015, contracts may be established verbally, in writing, or through specific acts (Article 119). Therefore, such contracts are not strictly required to be in writing unless otherwise mandated by law.
However, in practice, written contracts are strongly recommended as they clearly record rights, obligations, and security terms, reduce dispute risks, and provide legal evidence of contract validity.
2. Who is responsible if data loss occurs?
The Data Processor takes primary responsibility if the incident results from failure to comply with security measures or contractual obligations (Article 39).
However, the Data Controller may also be liable if it fails to supervise properly or selects an inadequate provider. Therefore, contracts must clearly define responsibilities and incident response mechanisms.
3. Can the contract be amended after signing?
Under Articles 385 and 421 of the Civil Code 2015, contracts may be amended by mutual agreement.
Amendments should be documented in written addenda or appendices consistent with the original contract form to ensure legal validity.
4. What data processing activities are included?
These typically include collection, recording, analysis, storage, modification, disclosure, access, retrieval, encryption, transmission, sharing, transfer, deletion, destruction, and other related actions as defined in Article 2 of Decree No. 13/2023/ND-CP.

Clearly defining these activities helps establish responsibilities and minimize misuse or violations.
5. What is the dispute resolution process in an IT service contract for customer data storage?
When disputes arise in an IT service contract relating to the storage of customer data, the parties must follow an appropriate resolution process to safeguard their lawful rights and interests while minimizing legal risks. The dispute resolution process is typically implemented through the following steps:
- Step 1: First, the parties must clearly identify the subject matter of the dispute, such as the IT service provider’s failure to ensure data security, breach of confidentiality obligations, failure to deliver services as agreed, or the service user’s delayed or non-payment of service fees. The determination of the grounds for dispute is based on the executed contract in accordance with Articles 513 and 514 of the Civil Code 2015, together with provisions on obligations, data confidentiality, and liability for breach of contract.
- Step 2: The parties should prioritize resolving the dispute through negotiation on the basis of goodwill and respect for freedom of agreement. At such a stage, the aggrieved party may request the other party to remedy the breach, continue performing its obligations, compensate for damages, or amend contractual terms. Negotiation helps save time and costs while ensuring the confidentiality of customer data.
- Step 3: If negotiation fails, the parties may choose mediation, particularly commercial mediation at a commercial mediation center in accordance with Decree No. 22/2017/ND-CP. The mediator acts as an intermediary to assist the parties in clarifying their rights and obligations and in reaching an appropriate resolution. Mediation outcomes are only binding if voluntarily accepted by the parties.
- Step 4: If the IT service contract contains an arbitration clause, the dispute may be resolved through commercial arbitration in accordance with the parties’ agreement. Arbitral awards are final and binding, providing a professional resolution mechanism while ensuring data confidentiality.
- Step 5: Where the parties cannot reach an agreement or where no arbitration clause exists, the aggrieved party may initiate legal proceedings before a court in accordance with civil procedure laws. Court judgments and decisions are legally binding and enforced by state authority.
- Step 6: After a dispute resolution outcome is reached (whether through settlement, arbitral award, or court judgment), the parties are obligated to strictly comply. In cases of non-compliance, the entitled party may request the civil judgment enforcement authority to apply coercive enforcement measures in accordance with the law.
IV. Are you looking for legal advice to effectively assist you with your IT service contract for storing customer data?
When facing challenges in drafting, risk assessment, or dispute resolution related to IT service contracts for customer data storage, seeking professional legal assistance from NPLaw is an optimal solution. Legal experts can help review contract terms, establish compliant security mechanisms, and represent businesses before authorities or partners.
This ensures legal compliance, enhances data security, and improves operational efficiency.
The above information is for reference purposes only. For detailed advice tailored to specific cases, please contact NPLaw for immediate consultation.