Collecting customer data on your website: How to comply with the personal data protection law (PDPL) without disrupting your marketing activities?

Every day, your website quietly collects hundreds or even thousands of data points from visitors – names, email addresses, and phone numbers submitted through forms; browsing behavior tracked by cookies; location data collected through the “find a store near you” feature; and even payment history if you operate an e-commerce platform.

There is nothing wrong with collecting this data – as long as you do it correctly.

From January 1, 2026, the Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP officially came into effect. The question is no longer “Do we need to comply?” but rather “What is our website still missing to meet the legal requirements?”

This article answers that question in the most practical way possible. Instead of simply explaining legal provisions, it provides clear guidance that helps your marketing, IT, and legal teams work toward the same goal.

Where is your website collecting personal data?

Before discussing compliance, you first need to understand what data your website is collecting.

A typical business website interacts with customer data through at least six to eight touchpoints, many of which collect information automatically without requiring users to fill out a form.

Active touchpoints (data provided directly by users)

  • Contact forms, free trial registrations, and order forms
  • Newsletter and free resource subscription forms
  • Chatbots and live chat that request a visitor’s name and email at the beginning of a conversation
  • Account registration forms

Passive touchpoints (technical data collection)

  • Cookies that track browsing behavior (Google Analytics, Facebook Pixel, Hotjar, etc.)
  • “Find a store near you” features that access location data
  • Device storage such as localStorage and session IDs
  • Third-party advertising pixels embedded on your website

Why does this matter?

The law does not distinguish between data collected through forms and data collected through cookies. As soon as your organization performs any personal data processing activity – including collecting, storing, analyzing, or sharing personal data with third parties – the legal requirements for obtaining consent apply.

General personal data vs. sensitive personal data: What is your website collecting?

Under Article 2 of Law No. 91/2025/QH15, personal data is divided into two categories, each with a different level of legal protection.

General personal data includes basic information such as a person’s full name, gender, date of birth, email address, and phone number. Most contact forms and account registration forms fall into this category.

Sensitive personal data includes health information, financial data (such as bank account details and transaction history), precise location data, biometric information (such as fingerprints and facial recognition), and political or religious views.

Businesses should pay particular attention because many seemingly harmless website features actually collect sensitive personal data.

For example: An online loan application form collects financial information, a home delivery feature collects location data, an online health check registration form collects medical information.

When sensitive personal data is involved, the law requires separate and explicit consent. It cannot simply be bundled into a single checkbox such as “I agree to the terms and conditions.”

Pillar Eng ảnh 1 1784262306

This is the most important section – and also where many websites fail to comply.

The law does not simply require businesses to obtain consent. A valid consent must satisfy all four of the following principles.

1. Freely given

Customers must have a genuine choice to either agree or refuse. They must not be forced into providing consent or be required to consent as a condition for using a service, except where certain personal data is strictly necessary to deliver that service.

For example, a cookie banner that only displays an “Accept” button without a clearly visible “Reject” option does not meet this requirement.

2. Specific to each purpose

One consent cannot cover every purpose. If you intend to use a customer’s email address to: send order confirmations, send promotional newsletters, and share the information with distribution partners, you must obtain separate consent for each purpose. Customers should be able to agree to one purpose while declining another.

3. Demonstrable

You must be able to prove: who gave consent, when the consent was given,

exactly what they agreed to, including the version of the form or privacy policy shown at that time, and through which channel the consent was collected. If regulators conduct an inspection, you must be able to provide this evidence instead of simply stating that the records exist.

4. Easy to withdraw

Withdrawing consent should be just as easy as giving it. If subscribing to a newsletter takes five seconds, but unsubscribing requires three separate steps and an additional confirmation email, the process does not comply with the law.

Pillar Eng ảnh 2 1784262344

This is a question many businesses ask, and the answer comes down to one key point:

Forms and cookie banners are only collection points. What you really need is a complete consent management system.

Here are some of the most common gaps found on business websites in Vietnam today.

  • No audit log: When a customer gives consent through a form, what happens next? Where is the consent stored? Who is responsible for managing it? How long is it retained? If regulators request proof during an inspection, can you provide it?
  • No effective withdrawal process: A customer unsubscribes from marketing emails using the unsubscribe link, but the CRM still labels them as “marketing eligible” and continues to target them with advertisements. This is still a violation, even though the customer has already withdrawn their consent.
  • Consent data is scattered across multiple systems: Consent may be collected on the website but never synchronized with your email marketing platform, customer data platform (CDP), or CRM. As a result, no one knows exactly who has consented to what, or when.
  • Poor cross-functional coordination: Marketing wants to use customer data. IT manages the systems. The legal team is responsible for compliance risks. Without a single source of truth for consent status, these teams often work independently and struggle to stay aligned.

A three-layer framework for a compliant website

Pillar Eng ảnh 3 1784262389

Instead of fixing individual issues one by one, a more sustainable approach is to build your consent management process around three layers.

Layer 1 – Collect right

Redesign every customer data collection point to ensure that:

  • No checkbox is pre-selected by default.
  • Each purpose is presented separately. For example, “I agree to receive promotional emails” should be a different consent from “I agree to analytics cookies being stored on my device.”
  • Every type of sensitive personal data has its own dedicated consent request.
  • The “Reject” button is just as visible and easy to use as the “Accept” button.

Pillar Eng ảnh 4 1784262405

Layer 2 – Prove it

Every consent should generate a record containing: the timestamp, the user ID, the version of the privacy policy or notice displayed, the collection channel, and the version of the form or cookie banner used. This record serves as your audit log, and it is exactly what regulators will request during an inspection.

Pillar Eng ảnh 5 1784262425

Layer 3 – sync everything

Whenever a customer withdraws consent through any channel, that change should automatically be reflected across every system that processes their personal data, including: CRM, email marketing platforms, customer data platforms (CDPs), data warehouses, advertising platforms. Under Decree No. 356/2025/ND-CP, businesses have two working days to respond to a request to withdraw consent and 15–20 days to complete the required actions. Without automatic synchronization, meeting these deadlines is almost impossible through manual processes.

Pillar Eng ảnh 6 1784262445

Where should businesses start?

A practical way to get started this week—without launching a major project—is to follow these four steps.

Step 1 – Map your data collection points

List every location on your website where user data is collected.

Then classify each type of data as either general personal data or sensitive personal data.

Step 2 – Review your existing banners and forms

Ask yourself:

Are any consent checkboxes pre-selected?

Is there a clear and visible “Reject” option?

Are different processing purposes presented separately?

Step 3 – Review your record-keeping system

If regulators ask,

“What exactly did customer X consent to on date Y?”

could your organization provide a complete answer within two working days?

Step 4 – Test your consent withdrawal process

Try unsubscribing from your own marketing emails and check whether you still receive emails within the next 24 hours.

Then submit a request to delete your own personal data and observe how your internal process handles it.

If there is any question you cannot answer with confidence, that is a compliance gap that needs to be addressed.

A Consent Management Platform (CMP) is specifically designed to close these gaps. It is more than just a software solution—it provides the infrastructure needed to manage the entire customer consent lifecycle across all channels.

Duong Hong Nhung

Product Marketing, Data Privacy & Compliance Solution

FPT IS, FPT Corporation

Share:
Img Contact

Sign up to receive the latest news from FPT IS

    Bot Avatar