Blog · AI Agent

Data security for AI agents: an 8-step checklist under Decree 13

Two people looking at messages on a screen, illustrating customer data flowing through chat channels with an AI agent

For an AI agent to advise well, you have to let it read customer data: names, phone numbers, purchase history, health notes. Which means from the day you switch it on, your customers' data flows through more systems than before - and one weak point is enough to lose trust built over years, plus legal liability under Vietnam's Decree 13.

TL;DR

Decree 13/2023/ND-CP applies to every business processing personal data, including a small shop storing phone numbers for loyalty points. With an AI agent, customer data additionally passes through the chatbot platform and the model provider - and you remain the primarily responsible party. What to do: get consent at collection, give the agent minimum-necessary data, pick vendors that commit to not training on your data, set role-based permissions + two-factor authentication, log access, back up, prepare a breach procedure and review every 6 months. The first three steps are nearly free and block most common risks.

Where does data flow once you switch on an AI agent?

Before the legal talk, see the map clearly: messages and customer records no longer sit still in your phone. One "Lan asking about package prices" now passes through 4 stations - each one a lock to close:

CUSTOMER DATA CROSSES 4 STATIONS - ONE LOCK EACH 1. CHAT CHANNEL Zalo OA, Messenger, web Customers send names, phones, needs Lock: consent at first contact + 2FA on the channel account 2. AGENT PLATFORM Runs scripts, stores conversations Conversations + profiles concentrate here Lock: role-based permissions + access logs: who saw what, when 3. MODEL PROVIDER OpenAI, Anthropic, Google... Receives content to generate replies Lock: no-training tier, in writing + strip unnecessary identifiers 4. CRM / DATABASE Sheets, Supabase, your CRM Where profiles live long-term Lock: encryption + regular backups + deletable on customer request Principle: you remain the data controller and primarily responsible party - even when the incident happens at station 2 or 3.

What does Decree 13 require from small businesses?

Hand holding a smartphone showing ChatGPT and OpenAI, illustrating data sent to a third-party model provider

Decree 13/2023/ND-CP on personal data protection took effect on July 1, 2023 and applies to every organization processing personal data - with no size exemption. Four essentials: first, you need the customer's explicit consent before collecting and using their data (no pre-ticked defaults). Second, data splits into basic (name, phone, address) and sensitive (health, finance...) - sensitive data demands stronger protection, and a spa or dental clinic keeping treatment notes is holding sensitive data. Third, customers have the right to view, correct, withdraw consent and request deletion. Fourth, when you pass data to third-party processors (chatbot platform, model provider), you remain the primarily responsible party - "it was the vendor" is not an accepted answer when things go wrong.

4 questions to ask any AI vendor before signing

  1. "Is my data used to train your models?" - the answer must be NO, in writing. API and business tiers of major providers commit to this; free consumer tiers usually do not.
  2. "Where are conversations and profiles stored, and for how long?" - know the storage region and retention; ask for auto-deletion of old conversations you do not need.
  3. "Is data encrypted in transit and at rest?" - TLS in transit and encryption at rest must be defaults, not paid add-ons.
  4. "Can I delete all my data, and how fast?" - your customers' deletion rights under Decree 13 only work if you can actually delete data on the vendor side.

From building these systems for clients: a serious vendor answers all 4 questions in one email with documentation links. A vendor that stalls, promises verbally, or says "let me check with engineering" for over a week - that is your answer.

What is the 8-step security checklist for SMBs?

8-STEP CHECKLIST - WORK LEFT TO RIGHT FREE GROUP - DO THIS WEEK 1. Add a consent line to forms, chatbot and loyalty sign-ups 2. Cut the data the agent can read to what its job requires 3. Turn on 2FA for every admin account (OA, CRM, email) CONFIGURATION GROUP - FIRST MONTH 4. Choose a no-training vendor tier (commitment in writing) 5. Role-based permissions - staff see only what they need 6. Strip unnecessary identifiers before sending to the model MAINTENANCE GROUP - QUARTERLY 7. Regular backups + test a restore at least once 8. Review every 6 months: who holds which access, what stale data to delete PREPARED IN ADVANCE - HOPE UNUSED Breach procedure: revoke access, rotate passwords, notify affected customers and authorities as regulations require

Worth noting: the free group blocks most real-world risk. Most SMB incidents are not sophisticated hackers but everyday failures: a shared channel account with a weak password, an ex-employee whose access was never revoked, a customer spreadsheet sent over personal chat. Close those three doors first.

Security proportional to your size - do not let fear stop you

A user checking a website on a phone, illustrating periodic reviews of access and data

A common reaction at this point is "too complicated, forget AI then". That is the wrong conclusion: everything above was already your obligation the day you saved a customer's phone number in Excel - the AI agent just makes the existing data flow visible. Doing it right is also a sales advantage: a privacy-policy line saying "your data is protected under Decree 13 and never used to train AI" is something competitors your size rarely have. A clean, structured foundation as described in data is the foundation of AI agents also makes security easier - tidy data means fewer doors to lock. And if you are building your own CRM with AI agents, put permissions and backups into the very first version, not "later".

Frequently asked questions

Does Vietnam's Decree 13 apply to small businesses?

Yes. Decree 13/2023/ND-CP applies to every organization or individual processing personal data in Vietnam, regardless of size. A cafe storing phone numbers for loyalty points or a homestay keeping booking details is a data processor: it needs customer consent and must protect that data.

Is sending customer data to ChatGPT or Claude a violation?

Not automatically, but you must do it properly: choose a service tier that commits in writing to not training models on your data (API and business plans do), strip unnecessary identifiers before sending, disclose in your privacy policy that you use third-party processors, and have a data processing agreement with the vendor.

Where should a small business start with AI agent security?

Three things this week: add a consent line wherever you collect customer information (forms, chatbot, loyalty), review what data the agent can read and cut everything not needed for its job, and turn on two-factor authentication for every admin account. These cost almost nothing and block most common risks.

This article is practical guidance, not legal advice. For sensitive data at scale, consult a data protection lawyer.

Want an agent that is secure from day one?

Get a free security review