UNIS Hanoi Data Processing Agreement
English
Introduction
This Data Processing Agreement ("DPA") is an integral part of principal or main agreement, contract, or any other document that establishes a relationship between
- United Nations International School of Hanoi with address Nam Thang Long New Urban Area, Phu Thuong Ward, Hanoi City (hereinafter "Data Controller"); and
- An organisation, company or an individual, as specified in the principal or main agreement, contract or any other document (hereinafter "Data Processor").
(Collectively referred to as the "Parties" and individually as a "Party").
where “Data Processor’ receives personal data or information from United Nations International School of Hanoi of any of its employees, students, board members or their family and household members via any means during the time period of the relationship established between both parties as defined in the principal or main agreement, contract, or any other document that establishes such relationship.
Background
The Data Controller and Data Processor have entered into a Principal Agreement (the "Principal Agreement") under which the Data Processor provides certain services to the Data Controller. In providing these services, the Data Processor will process Personal Data on behalf of the Data Controller. This DPA sets out the terms, requirements, and conditions for such processing.
Definitions
Applicable Data Protection Laws means all laws and regulations applicable to the processing of Personal Data under the Principal Agreement, explicitly including:
- Vietnam's Personal Data Protection Law No. 91/2025/QH15 (PDPL), and any subsequent amendments, and/or guiding circulars or regulations issued by the Vietnamese Government.
Personal Data, Basic Personal Data, Sensitive Personal Data, Data Subject, Processing, Data Controller, and Data Processor shall have the meanings given to them under the PDPL. Where the definitions differ, the broader definition ensuring the highest level of protection shall apply.
Competent Authority means any relevant supervisory authority, including the Vietnamese Department of Cybersecurity and Hi-tech Crime Prevention (A05) under the Ministry of Public Security.
Scopes and Roles
- The Parties acknowledge and agree that with regard to the Processing of Personal Data, United Nations International School of Hanoi is the Data Controller and the other party is the Data Processor.
- The details of the processing, including the subject matter, duration, nature, purpose, and categories of Personal Data, are set out in an Annex ‘DPA-A1’ of the principal agreement.
Data Processing Obligations
Documented Instructions: The Data Processor shall process Personal Data only on documented instructions from the Data Controller, unless required to do otherwise by Applicable Data Protection Laws. If the Data Processor is legally required to process data beyond these instructions, it shall inform the Data Controller before processing, unless the law prohibits such disclosure.
Lawfulness: The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction infringes the PDPL, or other Applicable Data Protection Laws.
Purpose Limitation: The Data Processor shall not process the Personal Data for any purpose other than for the specific purposes authorised by the Data Controller.
Confidentiality and Personnel
- The Data Processor shall ensure that all personnel (including employees, agents, and contractors) authorised to process the Personal Data have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality.
- Personnel shall be adequately trained on Applicable Data Protection Laws, including specific handling procedures for Sensitive Personal Data as defined under the PDPL.
Security of Processing
- Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, the Data Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
- These measures must comply with the Applicable Data Protection Laws, specifically including safeguards for preventing data breaches, unauthorised access, and cyberattacks.
- Specific technical and organisational measures implemented by the Data Processor are detailed in Annex ‘DPA-A2’ of the principal agreement.
Sub-Processing
General Authorisation: The Data Controller provides a general authorisation for the Data Processor to engage sub-processors. The Data Processor shall maintain an up-to-date list of its sub-processors and notify the Data Controller of any intended changes at least 14 working days in advance, giving the Data Controller the opportunity to object.
Flow-down Obligations: Where the Data Processor engages a sub-processor, the same data protection obligations set out in this DPA shall be imposed on that sub-processor by way of a written contract. The Data Processor remains fully liable to the Data Controller for the performance of the sub-processor's obligations.
Artificial Intelligence
The Data Processor shall not use, process, or retain any Personal Data provided by the Data Controller for the purpose of training, developing, or improving any Artificial Intelligence or machine learning models. Furthermore, the Data Processor must ensure that any third-party AI tools or platforms engaged in the provision of services do not retain or utilise the Data Controller's data for model training purposes.
Data Subject Rights
The Data Processor shall, taking into account the nature of the processing, assist the Data Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfillment of the Data Controller’s obligation to respond to requests for exercising Data Subject rights under the relevant articles of the PDPL.
If the Data Processor receives a request directly from a Data Subject, it shall not respond to the request directly (unless authorised) and shall immediately forward the request to the Data Controller at dpo@unishanoi.org.
Personal Data Breach Notification
- The Data Processor shall notify the Data Controller without undue delay, and in any event no later than 24 hours after becoming aware of a Personal Data Breach.
- The Data Processor shall provide sufficient information and continuous assistance to allow the Data Controller to meet any obligations to report a data breach to Competent Authorities (72-hour reporting window to A05 in Vietnam).
Assistance With Impact Assessments
The Data Processor shall assist the Data Controller in conducting Data Protection Impact Assessments (‘DPIAs’) as and when required.
Furthermore, the Data Processor shall provide all necessary information and assistance to enable the Data Controller to draft, maintain, and submit, and update the DPIA Dossier required under the Vietnamese PDPL.
Cross-Border Data Transfers
Any transfer of Personal Data out of the territory of the Socialist Republic of Vietnam must comply with the PDPL. The Data Processor agrees to assist the Data Controller in compiling and submitting the Outbound Transfer of Personal Data Impact Assessment Dossier to the Ministry of Public Security (A05) prior to any cross-border transfer.
Deletion Or Return Of Data
Upon termination or expiration of the Principal Agreement, the Data Processor shall, at the choice of the Data Controller, securely delete or return all Personal Data to the Data Controller, and delete existing copies unless Vietnamese law requires storage of the Personal Data.
Audit Rights
- The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and Applicable Data Protection Laws.
- The Data Processor shall allow for and contribute to audits, including inspections, conducted by the Data Controller or another auditor mandated by the Data Controller.
Governing Law And Jurisdiction
Without prejudice to any mandatory provisions of the PDPL, this DPA shall be governed by the laws of Vietnam. Any disputes arising out of or relating to the execution of this DPA or the breach, termination, or invalidity thereof shall be attempted to be settled through good faith negotiations between the Parties during a period of up to thirty (30) days or such longer period to which the Parties may agree but not otherwise. Any Party may, by giving the other Party written notice at any time after the expiration of the thirty (30) day period referred to above, submit any dispute that is not settled through negotiations to the Vietnam International Arbitration Centre (“VIAC”) in accordance with its effective Rules of Arbitration. The seat of arbitration shall be Hanoi, Vietnam. The arbitration panel shall be composed of one (01) arbitrator. The prevailing Party shall be entitled to attorney’s fees and all other fees and costs of conducting the arbitration and enforcing the arbitration award. The decision of the arbitrator(s) shall be final and binding upon the Parties.
Tiếng Việt
Giới thiệu
Thỏa thuận Xử lý Dữ liệu này ("DPA") là một phần không thể tách rời của thỏa thuận, hợp đồng chính, hoặc bất kỳ văn bản nào khác xác lập mối quan hệ giữa:
- Trường Quốc tế Liên Hợp Quốc Hà Nội, có địa chỉ tại Khu đô thị mới Nam Thăng Long, Phường Phú Thượng, Thành phố Hà Nội (sau đây gọi là "Bên Kiểm soát Dữ liệu"); và
- Một tổ chức, công ty hoặc cá nhân, được quy định cụ thể trong thỏa thuận hoặc hợp đồng chính hoặc bất kỳ văn bản nào khác (sau đây gọi là "Bên Xử lý Dữ liệu").
(Sau đây gọi chung là "Các Bên" và gọi riêng là "Bên")
Theo đó, Bên Xử lý Dữ liệu tiếp nhận dữ liệu hoặc thông tin cá nhân của nhân viên, học sinh, thành viên Hội đồng trường hoặc thành viên gia đình/hộ gia đình của họ từ Bên Kiểm soát Dữ liệu thông qua bất kỳ phương thức nào trong thời hạn tồn tại mối quan hệ giữa hai bên theo quy định tại thỏa thuận, hợp đồng chính, hoặc bất kỳ văn bản nào khác xác lập mối quan hệ đó.
Bối cảnh
Bên Kiểm soát Dữ liệu và Bên Xử lý Dữ liệu đã giao kết một Hợp đồng Chính ("Hợp đồng Chính"), theo đó Bên Xử lý Dữ liệu cung cấp một số dịch vụ nhất định cho Bên Kiểm soát Dữ liệu. Trong quá trình cung cấp các dịch vụ này, Bên Xử lý Dữ liệu sẽ xử lý Dữ liệu Cá nhân thay mặt cho Bên Kiểm soát Dữ liệu. DPA này quy định các điều khoản, yêu cầu và điều kiện cho việc xử lý đó.
Định nghĩa
Luật Bảo vệ Dữ liệu được Áp dụng: Là toàn bộ các văn bản quy phạm pháp luật liên quan đến việc xử lý dữ liệu cá nhân theo Hợp đồng Chính, bao gồm nhưng không giới hạn ở Nghị định số 13/2023/NĐ-CP, Luật Bảo vệ Dữ liệu Cá nhân Việt Nam (PDPL) và bất kỳ văn bản hướng dẫn, sửa đổi, bổ sung hoặc thay thế nào do cơ quan nhà nước có thẩm quyền của Việt Nam ban hành tại từng thời điểm.
Dữ liệu cá nhân, Dữ liệu cá nhân cơ bản, Dữ liệu cá nhân nhạy cảm, Chủ thể dữ liệu, Xử lý, Bên kiểm soát dữ liệu và Bên xử lý dữ liệu sẽ có ý nghĩa theo quy định của Luật Bảo vệ dữ liệu cá nhân (PDPL). Trong trường hợp có sự khác biệt giữa các định nghĩa, định nghĩa rộng hơn nhằm đảm bảo mức độ bảo vệ cao nhất sẽ được áp dụng.
Cơ quan có thẩm quyền: Là bất kỳ cơ quan nhà nước có thẩm quyền giám sát, quản lý liên quan, bao gồm Cục An ninh mạng và Phòng, chống tội phạm sử dụng công nghệ cao (A05) thuộc Bộ Công an Việt Nam.
Phạm vi và Vai trò
- Các Bên ghi nhận và đồng ý rằng đối với việc Xử lý Dữ liệu Cá nhân, Trường Quốc tế Liên Hợp Quốc Hà Nội là Bên Kiểm soát Dữ liệu và bên còn lại là Bên Xử lý Dữ liệu.
- Các chi tiết về việc xử lý, bao gồm nội dung, thời hạn, bản chất, mục đích và các danh mục Dữ liệu Cá nhân, được quy định cụ thể tại Phụ lục 1.
Nghĩa vụ xử lý dữ liệu
Chỉ thị bằng văn bản: Bên Xử lý Dữ liệu chỉ được xử lý Dữ liệu Cá nhân theo các chỉ thị bằng văn bản từ Bên Kiểm soát Dữ liệu, trừ khi Luật Bảo vệ Dữ liệu được Áp dụng có quy định khác. Nếu Bên Xử lý Dữ liệu bị bắt buộc về mặt pháp lý phải xử lý dữ liệu ngoài các chỉ thị này, Bên Xử lý Dữ liệu phải thông báo cho Bên Kiểm soát Dữ liệu trước khi thực hiện xử lý, trừ khi pháp luật cấm thông báo vì các lý do quan trọng liên quan đến lợi ích công cộng.
Tính hợp pháp: Bên Xử lý Dữ liệu phải thông báo ngay lập tức cho Bên Kiểm soát Dữ liệu nếu theo đánh giá của mình, một chỉ thị vi phạm quy định của Luật Bảo vệ Dữ liệu được Áp dụng.
Giới hạn mục đích: Bên Xử lý Dữ liệu không được xử lý Dữ liệu Cá nhân cho bất kỳ mục đích nào khác ngoài các mục đích cụ thể đã được Bên Kiểm soát Dữ liệu cho phép.
Bảo mật và Nhân sự
- Bên Xử lý Dữ liệu phải đảm bảo rằng tất cả nhân sự (bao gồm nhân viên, đại lý và các nhà thầu) được ủy quyền xử lý Dữ liệu Cá nhân đã cam kết tuân thủ nghĩa vụ bảo mật nghiêm ngặt hoặc chịu ràng buộc bởi nghĩa vụ bảo mật theo luật định tương ứng.
- Nhân sự phải được đào tạo đầy đủ về các Luật Bảo vệ Dữ liệu Áp dụng, bao gồm các quy trình xử lý cụ thể đối với Dữ liệu Cá nhân Nhạy cảm theo quy định của PDPL.
An toàn trong xử lý dữ liệu
- Xét đến trình độ kỹ thuật hiện tại, chi phí triển khai, cũng như bản chất, phạm vi, bối cảnh và mục đích của việc xử lý, Bên Xử lý Dữ liệu phải thực thi các biện pháp kỹ thuật và tổ chức phù hợp để đảm bảo mức độ bảo mật tương xứng với rủi ro.
- Các biện pháp này phải đáp ứng đầy đủ tiêu chuẩn theo Luật Bảo vệ Dữ liệu được Áp dụng, đặc biệt bao gồm các cơ chế bảo vệ nhằm ngăn ngừa vi phạm dữ liệu, truy cập trái phép và các cuộc tấn công mạng.
- Các biện pháp kỹ thuật và tổ chức cụ thể do Bên Xử lý Dữ liệu thực hiện được quy định chi tiết tại Phụ lục 2.
Xử lý dữ liệu phụ
Chấp thuận chung: Bên Kiểm soát Dữ liệu cấp phép chung cho Bên Xử lý Dữ liệu được phép thuê các bên xử lý phụ. Bên Xử lý Dữ liệu phải duy trì một danh sách cập nhật về các bên xử lý phụ của mình và thông báo cho Bên Kiểm soát Dữ liệu về bất kỳ thay đổi dự kiến nào trước ít nhất 14 ngày làm việc, tạo điều kiện cho Bên Kiểm soát Dữ liệu có cơ hội phản đối.
Chuyển giao nghĩa vụ: Trong trường hợp Bên Xử lý Dữ liệu thuê một bên xử lý phụ, các nghĩa vụ bảo vệ dữ liệu tương tự như quy định trong DPA này phải được áp đặt lên bên xử lý phụ đó thông qua một hợp đồng bằng văn bản. Bên Xử lý Dữ liệu vẫn phải chịu trách nhiệm hoàn toàn trước Bên Kiểm soát Dữ liệu đối với việc thực hiện các nghĩa vụ của bên xử lý phụ.
Trí tuệ nhân tạo
Bên Xử lý Dữ liệu không được phép sử dụng, xử lý, hoặc lưu trữ bất kỳ Dữ liệu Cá nhân nào do Bên Kiểm soát Dữ liệu cung cấp cho mục đích huấn luyện, phát triển, hoặc cải tiến bất kỳ mô hình Trí tuệ Nhân tạo (AI) hoặc học máy (machine learning) nào. Ngoài ra, Bên Xử lý Dữ liệu phải đảm bảo rằng mọi công cụ hoặc nền tảng AI của bên thứ ba được huy động trong quá trình cung cấp dịch vụ đều không được lưu trữ hoặc sử dụng dữ liệu của Bên Kiểm soát Dữ liệu cho các mục đích huấn luyện mô hình.
Quyền của chủ thể dữ liệu
Bên Xử lý Dữ liệu, tùy theo bản chất của việc xử lý, phải hỗ trợ Bên Kiểm soát Dữ liệu bằng các biện pháp kỹ thuật và tổ chức phù hợp trong phạm vi có thể, nhằm đáp ứng các yêu cầu thực hiện quyền của Chủ thể Dữ liệu theo Luật Bảo vệ Dữ liệu được Áp dụng.
Nếu Bên Xử lý Dữ liệu nhận được yêu cầu trực tiếp từ Chủ thể Dữ liệu, bên đó không được phản hồi trực tiếp yêu cầu (trừ khi được ủy quyền) và phải chuyển tiếp ngay lập tức yêu cầu đó cho Bên Kiểm soát Dữ liệu qua email: dpo@unishanoi.org
Thông báo vi phạm dữ liệu cá nhân
- Bên Xử lý Dữ liệu phải thông báo cho Bên Kiểm soát Dữ liệu ngay khi phát hiện và trong mọi trường hợp không muộn hơn 24 giờ kể từ thời điểm phát hiện sự cố vi phạm Dữ liệu Cá nhân.
- Bên Xử lý Dữ liệu phải cung cấp đầy đủ thông tin và hỗ trợ liên tục để Bên Kiểm soát Dữ liệu hoàn thành nghĩa vụ báo cáo vi phạm dữ liệu tới Cơ quan có Thẩm quyền (bao gồm việc tuân thủ thời hạn báo cáo 72 giờ cho Cục A05 - Bộ Công an theo quy định).
Hỗ trợ đánh giá tác động
Bên Xử lý Dữ liệu phải hỗ trợ Bên Kiểm soát Dữ liệu thực hiện Đánh giá Tác động Bảo vệ Dữ liệu (DPIA) khi có yêu cầu.
Đồng thời, Bên Xử lý Dữ liệu phải cung cấp tất cả thông tin và sự hỗ trợ cần thiết để cho phép Bên Kiểm soát Dữ liệu soạn thảo, duy trì và nộp Hồ sơ Đánh giá Tác động Xử lý Dữ liệu Cá nhân theo quy định pháp luật.
Chuyển dữ liệu xuyên biên giới
Mọi hoạt động chuyển giao Dữ liệu Cá nhân ra khỏi lãnh thổ Cộng Hòa Xã Hội Chủ Nghĩa Việt Nam đều phải tuân thủ Luật Bảo vệ Dữ liệu Cá nhân (PDPL). Bên Xử lý Dữ liệu đồng ý phối hợp và hỗ trợ Bên Kiểm soát Dữ liệu lập và nộp Hồ sơ Đánh giá Tác động Chuyển Dữ liệu Cá nhân ra nước ngoài cho Bộ Công an (A05) trước khi thực hiện bất kỳ hoạt động chuyển dữ liệu xuyên biên giới nào.
Xóa hoặc trả lại dữ liệu
Khi chấm dứt hoặc hết hạn Hợp đồng Chính, Bên Xử lý Dữ liệu phải, theo sự lựa chọn của Bên Kiểm soát Dữ liệu, xóa một cách an toàn hoặc trả lại toàn bộ Dữ liệu Cá nhân cho Bên Kiểm soát Dữ liệu, đồng thời xóa mọi bản sao hiện có, trừ trường hợp pháp luật Việt Nam có quy định bắt buộc về việc tiếp tục lưu trữ dữ liệu đó.
Quyền kiểm tra
- Bên Xử lý Dữ liệu phải cung cấp cho Bên Kiểm soát Dữ liệu tất cả thông tin cần thiết để chứng minh việc tuân thủ các nghĩa vụ được quy định trong DPA này và các Luật Bảo vệ Dữ liệu Áp dụng.
- Bên Xử lý Dữ liệu phải cho phép và tham gia vào các hoạt động kiểm tra, bao gồm cả thanh tra, được thực hiện bởi Bên Kiểm soát Dữ liệu hoặc đơn vị kiểm toán độc lập do Bên Kiểm soát Dữ liệu ủy quyền.
Luật Điều chỉnh và Thẩm quyền xét xử
DPA này được điều chỉnh và giải thích theo pháp luật nước Cộng hòa Xã hội Chủ nghĩa Việt Nam. Bất kỳ tranh chấp nào phát sinh từ hoặc liên quan đến DPA này, bao gồm mọi tranh chấp về sự vi phạm, chấm dứt hoặc tính vô hiệu của DPA, trước hết sẽ được giải quyết thông qua thương lượng hòa giải trên tinh thần thiện chí giữa Các Bên trong thời hạn ba mươi (30) ngày kể từ ngày phát sinh tranh chấp, trường hợp tranh chấp không giải quyết được qua thương lượng trong thời hạn nêu trên, bất kỳ Bên nào cũng có quyền đưa tranh chấp ra giải quyết tại Trung tâm Trọng tài Quốc tế Việt Nam ("VIAC") theo Quy tắc Trọng tài có hiệu lực của Trung tâm này. Địa điểm trọng tài sẽ là Hà Nội, Việt Nam. Hội đồng trọng tài sẽ bao gồm một (01) trọng tài viên. Phán quyết trọng tài là chung thẩm và có giá trị bắt buộc thi hành đối với Các Bên. Bên thua kiện có trách nhiệm thanh toán toàn bộ chi phí luật sư, lệ phí trọng tài và các chi phí hợp lý khác liên quan đến quá trình tố tụng theo quyết định của Hội đồng Trọng tài.
