Technology M&A in Vietnam is an exercise in proving title to things you cannot touch. The value sits in source code, datasets, models, integrations and the developers who understand them, and none of those appear as a line item on the balance sheet. A buyer who verifies the corporate chain of title to the shares but not the chain of title to the code has verified the wrong thing. Every technology M&A review should be able to answer one question in writing: if a contributor, a contractor or a customer disputed ownership tomorrow, what document would the company produce?
The second question is whether the company may lawfully use the data it holds. Vietnamese personal data rules impose consent, record-keeping and impact-assessment obligations that many fast-growing product companies have never formally documented, and cybersecurity rules add storage and local-presence requirements for certain services. In technology M&A these are not compliance footnotes; they determine whether the technology M&A buyer can continue to operate the product after closing, and they are frequently the reason a price is reduced.

Code ownership is a documentary question, not an assumption. Photo: Pexels.
Technology acquisitions in Vietnam often derive most of their value from assets that do not appear clearly on the balance sheet: source code, datasets, algorithms, domain names, product documentation, customer integrations and the expertise of key developers. A buyer must establish not only that these assets exist, but also that the target owns or may lawfully use them and can transfer their benefit after closing.
This guide explains the principal legal and commercial issues in a Vietnam technology M&A transaction, with a focus on software, personal data and intellectual property. It complements our guide to intellectual property and software technology M&A due diligence in Vietnam.
Define the technology transaction perimeter
Start by identifying whether the technology M&A buyer is acquiring shares in the operating company, selected technology assets, a business line or a regional group structure. Map every entity that develops, owns, licences, hosts or commercialises the product. Vietnamese developers may work for an offshore parent, while customer contracts and registrations sit in another group company.
The deal documents should list the code repositories, registered rights, domains, cloud accounts, datasets, contracts and technical records within the technology M&A transaction perimeter. If essential assets remain with the seller, a licence, assignment or transitional service arrangement must be agreed before signing.
Technology M&A: prove ownership of software and inventions
Review employment contracts, invention-assignment provisions, contractor agreements and acceptance records for everyone who contributed to the product. Payment to a developer does not by itself resolve every ownership issue. Missing assignments from founders, freelancers or former employees can undermine the technology M&A buyer’s exclusive control.
Reconcile registered copyrights, trademarks and patents with the target’s actual products and legal name. Check renewal dates, territorial scope, security interests, disputes and coexistence agreements. Important unregistered assets, including trade secrets and know-how, require practical confidentiality controls.
Audit open-source and third-party code
Software products routinely incorporate open-source components, commercial libraries, APIs and development tools. Build a software bill of materials and compare actual use with applicable licence terms. Copyleft obligations, attribution requirements or restrictions on commercial distribution can conflict with the technology M&A buyer’s intended business model.
Confirm whether third-party licences are transferable and whether a change of control triggers consent, repricing or termination. Material cloud, hosting, payment, mapping and AI services should be included in the dependency map.
Assess personal-data compliance
A technology target may process customer, employee, device, behavioural and location data. Due diligence should map collection points, purposes, consent or other legal basis, retention, sharing, cross-border transfers and security safeguards. Compare public privacy notices with actual engineering and marketing practices.
Identify the roles of the target, its customers and vendors for each dataset. Review data-processing agreements, transfer documentation, incident records and responses to data-subject requests. Our dedicated guide to personal data protection technology M&A due diligence in Vietnam M&A provides a deeper checklist.
Decree 13/2023/ND-CP requires a lawful basis, usually consent that is specific and demonstrable, and obliges controllers and processors to prepare and file a data processing impact assessment dossier, with a separate assessment for transfers of Vietnamese personal data abroad. Cybersecurity rules layer on storage and local-presence requirements for defined categories of service. In technology M&A, the practical test is whether the target can produce its consent records, its impact assessment and its data map on request; where it cannot, remediation cost and regulatory exposure should be priced, and the closing conditions should require the dossier to be filed.
Test cybersecurity and operational resilience
Request penetration-test summaries, vulnerability registers, access-control policies, backup results, incident logs and business-continuity plans. Confirm whether critical credentials belong to the company rather than individual founders. Assess privileged access, software-development controls, encryption, logging and vendor risk.
A clean incident register is not enough if monitoring is weak. Technical diligence should determine whether the target could detect an intrusion, recover systems and notify affected parties. See our cybersecurity due diligence guide.
Review customer revenue and product promises
Analyse customer contracts for service levels, uptime credits, warranties, security commitments, data localisation, audit rights, source-code escrow, ownership of custom developments and change-of-control clauses. Sales materials may promise functions or compliance standards that are not reflected in the standard contract.
Determine whether recurring revenue is genuinely recurring, whether discounts or implementation obligations distort margins, and whether customers may terminate after the technology M&A acquisition. Concentration risk is especially important where a few enterprise customers influence the product roadmap.

Data compliance decides whether the product can keep running after closing. Photo: Pexels.
Examine regulatory and sector exposure
Technology businesses may require licences or registrations depending on their services, such as e-commerce, online information, telecommunications, fintech, gaming or cybersecurity products. Confirm that the target’s registered business lines and permits cover its actual activities.
Foreign ownership and market-access conditions should be assessed early. The buyer should also test whether merger-control or M&A approval is required and how regulatory timing affects the long-stop date.
Convert findings into deal protection
Ownership gaps should normally be cured before closing through assignments, registrations or replacement licences. The buyer may require escrow or a holdback for identified data, tax or IP risks. Specific indemnities can address known infringement claims, open-source breaches, security incidents or unlawful datasets.
Representations and warranties should cover IP ownership, non-infringement, software composition, data compliance, cybersecurity, material licences, customer commitments and absence of undisclosed incidents. Disclosure schedules must identify exceptions precisely rather than relying on broad data-room references.
Plan signing-to-closing controls
Between signing and closing, require the target to preserve repositories, licences, customer relationships and security controls. Restrict unusual releases, material architecture changes, transfers of IP, deletion of datasets and entry into contracts with exceptional warranties. Critical incidents should trigger prompt notice and a defined response process.
Secure a workable handover
The closing plan should cover repository administration, cloud tenants, domains, app-store accounts, certificates, encryption keys, vendor accounts, customer support tools and technical documentation. Multi-factor authentication and recovery contacts should be transferred securely rather than circulated in closing emails.
Retention arrangements for founders and key engineers may be as important as the legal transfer. Document transition services, knowledge transfer, non-solicitation and post-closing development responsibilities clearly.
Technology M&A checklist
- Map ownership across all group entities and contributors.
- Review registered and unregistered IP rights.
- Audit open-source and third-party dependencies.
- Map personal data and cross-border transfers.
- Test cybersecurity and incident readiness.
- Review customer, cloud and platform contracts.
- Check licences, foreign ownership and approvals.
- Translate findings into remediation, price and contractual protection.
Key takeaway
Successful technology M&A in Vietnam depends on proving control over the software, data and relationships that generate value. Legal, technical and commercial diligence should be integrated, and identified gaps should be cured or priced before ownership changes.
Frequently asked questions about technology M&A
Who owns software written by employees of a Vietnamese target company?
Where a program is created by an employee performing assigned duties, the economic rights generally belong to the employer that assigned and financed the work, while the author keeps moral rights such as attribution. That default is easy to displace by a poorly drafted contract, so a buyer should read the employment agreements and any internal IP policy rather than rely on the statutory position. The higher risk sits with contractors and outsourced teams, who keep their rights unless there is a written assignment.
Should the target register its copyright before a technology M&A deal closes?
Registration is not required for copyright to exist, but it is worth doing. A certificate issued by the Copyright Office is prima facie evidence of authorship and ownership, which materially improves the company position in an infringement claim or an ownership dispute. Where the code is core to value, buyers commonly make registration of the principal modules, together with recordal of trade mark and domain assets, a pre-closing or post-closing covenant rather than a deal breaker.
What open-source risk should a buyer test?
The question is not whether open-source components are used, because they always are, but whether copyleft licences have been combined with proprietary code in a way that could require disclosure of that code. Ask for a software bill of materials produced by a scanning tool, reconcile it against the licences in use, and separate permissive components from reciprocal ones. Where a genuine conflict exists, remediation is usually engineering work rather than litigation, but it takes time and belongs in the closing timetable.
How do Vietnamese personal data rules affect a technology acquisition?
They affect both the target compliance position and the technology M&A transaction itself. The target must have a lawful basis for its processing, maintain consent records, prepare a data processing impact assessment dossier and, where data leaves Vietnam, a transfer impact assessment. During diligence, personal data in the data room should be minimised or anonymised, because sharing customer records with a bidder is itself a processing activity. Buyers should also confirm whether any local storage or local-presence obligations apply to the services offered.
How is technology risk usually reflected in the contract?
Through targeted protection rather than general warranties. The standard package is specific warranties on ownership, non-infringement, open-source use and data compliance; a specific indemnity, uncapped or separately capped, for identified ownership gaps or data breaches; retention of part of the price until assignments are executed and registrations recorded; and retention arrangements for the key engineers whose knowledge the buyer is really acquiring.
Next step
Before you sign, ask the target to produce the assignment, the licence inventory and the data dossier rather than a summary of them. Check the corporate steps for the share transfer itself in the Law on Enterprises, then convert each technology M&A gap into a condition precedent, an indemnity or a price adjustment.
IVLF Lawyer advises acquirers of Vietnamese software, platform and data businesses on intellectual property title, data compliance and deal protection. If you need a Vietnam M&A lawyer to lead a technology M&A diligence exercise and negotiate the resulting protections, see our legal services or contact IVLF Lawyer.
Related reading: Cybersecurity due diligence for technology company acquisitions, Personal data protection due diligence in Vietnam M&A, and Representations and warranties in Vietnam M&A.
Speak With IVLF About This Transaction
IVLF Advisors supports buyers, sellers and investors through the full lifecycle of a Vietnamese transaction as part of its M&A advisory Vietnam practice. Our Vietnam M&A lawyer team can help you apply the points in this guide to your specific deal, from structuring through closing.
For related reading, see our guides on Acquiring a Vietnamese Family Business: Succession and Shareholder Risks, Managing Conditions Precedent Before Closing, Checking Foreign Ownership Limits Before Signing a Term Sheet, Managing Foreign Exchange Risk in Cross-Border M&A. Contact IVLF Advisors to discuss your transaction.
Speak With IVLF About This Transaction
IVLF Advisors supports buyers, sellers and investors through the full lifecycle of a Vietnamese transaction as part of its M&A advisory Vietnam practice. Our Vietnam M&A lawyer team can help you apply the points in this guide to your specific deal, from structuring through closing.
For related reading, see our guides on Acquiring a Vietnamese Family Business: Succession and Shareholder Risks, Managing Conditions Precedent Before Closing, Checking Foreign Ownership Limits Before Signing a Term Sheet, Managing Foreign Exchange Risk in Cross-Border M&A. Contact IVLF Advisors to discuss your transaction.


