If you apply an ACL on vlan1, it will be checked any time traffic ingresses that vlan/ve. It will not affect traffic that never uses vlan1 as a path (ex. vlan10>vlan3).
Overall, this seems like a design question that should be handled by the Systems Engineer and/or your account team. I would advise getting in touch with them and they can help you from that standpoint. If you are unsure who that is, please feel free to open a support case (see below) and we can try to find the correct contact for you.
Ben Beck, RCNA, RCNI, Principal Technical Support Engineer