What is sensitive personal data under the personal data protection law (PDPL)? Why your website forms may be collecting it without you realizing
When people hear the term “sensitive personal data,” they often think of medical records, bank account numbers, or DNA test results.
That’s not wrong – but it’s far from the full picture.
Under the Personal Data Protection Law No. 91/2025/QH15, the list of sensitive personal data is much broader than most people expect. In fact, a significant portion of it can be found in everyday website features, such as delivery forms, “Find a store near you” tools, insurance consultation forms, and even profile photo uploads.
The issue is not that your website includes these features. The issue is that sensitive personal data is subject to a much higher level of legal protection, and if you don’t know what type of data you’re collecting, you can’t obtain the appropriate consent required by law.
What is sensitive personal data? The definition under the Personal data protection Law No. 91/2025/QH15
According to Article 2 of the Personal Data Protection Law No. 91/2025/QH15, sensitive personal data is personal data related to an individual’s privacy that, if compromised, could directly affect their lawful rights and interests. This includes:
-
- Health data: medical conditions, treatment history, test results, prescriptions.
- Financial data: bank account numbers, transaction history, credit limits, loan information.
- Location data: a person’s real-time geographic location, movement history.
- Biometric data: fingerprints, facial recognition data, iris scans, voiceprints, DNA.
- Political, religious, or philosophical beliefs: membership in political parties, organizations.
- Information about a person’s sex life or sexual orientation.
- Criminal records and legal violations.
- Personal data relating to children.
The key point to remember: The law does not classify sensitive personal data based on whether it sounds sensitive. Classification depends on the type of information itself, not on why you collect it or how extensively you use it.
For example, collecting a customer’s real-time location – even if it is only needed once for delivery – is still considered the collection of sensitive personal data and requires separate consent.
The difference between general personal data and sensitive personal data in practice
General personal data – such as a person’s full name, date of birth, gender, email address, phone number, occupation, or home address – still requires consent under the law. However, it does not require a separate consent mechanism for each type of data.
Sensitive personal data is subject to two additional requirements.
First, consent must be obtained separately. It cannot simply be bundled into a general checkbox such as “I agree to the terms and conditions.” Users must take a clear, affirmative action specifically for the processing of sensitive personal data, and the purpose of processing must be clearly stated.
Second, users must be informed that the information being collected is sensitive personal data at the time consent is requested. They should know they are providing data that receives a higher level of legal protection before they submit the form – not afterward.
Common website features that may be collecting sensitive personal data without you realizing
This is the section that surprises many businesses the most.
“Home delivery” or “find a store near you”
Any feature that asks users to enable GPS or share their current location is collecting location data, which is classified as sensitive personal data under the law. This is different from asking customers to manually enter a fixed delivery address. It is the collection of real-time location data that falls into the sensitive category.
Insurance, loan, or credit card application forms
Many of these forms collect financial information such as monthly income, existing loans, or credit history. Even if this information is collected only to qualify potential customers, it is still considered sensitive financial data under the law.
Health consultation, nutrition consultation, or clinic appointment forms
Any field asking about a person’s medical condition, allergies, or treatment history – even if it is only intended to prepare for an upcoming appointment – is collecting sensitive health data.
Facial recognition or fingerprint login
More websites and applications are adopting biometric authentication. Facial recognition and fingerprint data are biometric personal data, one of the most sensitive categories under the law and one that is subject to particularly strict legal requirements.
Registration forms for children
Whether it is for a course, an event, or another program, any personal data relating to children under the age of 16 is classified as sensitive personal data. In these cases, consent must be obtained from a parent or legal guardian – not from the child.
A common scenario that’s easy to overlook
Imagine you run an e-commerce website. A customer places an order and enters their delivery address. You store that information so you can deliver the order to the correct location. So far, everything is perfectly normal.
But later, you use that address to analyze customer locations in your business intelligence (BI) system, share it with a third-party logistics provider, and run location-based advertising campaigns on Facebook Ads targeting that area.
You are now using location data – which is considered sensitive personal data – for three different purposes, even though the customer originally consented only to its use for delivery.
This is not an unusual scenario. In fact, it reflects a standard marketing and data workflow. However, from January 1, 2026, each of these purposes requires its own separate consent.
So what should you do differently when your forms collect sensitive personal data?
1. Use separate consent checkboxes – don’t bundle everything together
Each type of sensitive personal data should have its own independent consent. It should not be covered by a single checkbox such as “I agree to the Privacy Policy.”
Example for a real estate website with a “Find properties near you” feature:
❌ Common approach today:
☑ I agree to the Terms of Use and Privacy Policy.
✅ Compliant approach:
☐ I agree to allow [Company Name] to use my current location to show properties near me. I can withdraw this consent at any time by visiting [link].
2. Explain the purpose at the point of collection
Users should know why you are collecting the data, how long it will be retained, and whether it will be shared with anyone.
This information should not be buried in a 20-page Privacy Policy that few people read. It should be presented directly on the form, at the moment the user is asked to provide their information.
3. Make consent easy to withdraw – and ensure the withdrawal is enforced
Consent for sensitive personal data should come with a clear and accessible withdrawal mechanism. More importantly, once a customer withdraws their consent, that change should be synchronized across every system that processes their data – not simply recorded in a database and forgotten.
Frequently asked questions
- Is a phone number considered sensitive personal data? No. A phone number is classified as general personal data under the law. However, you still need separate consent for each processing purpose. Using a phone number for delivery is one consent, sending marketing SMS messages is another, and sharing it with a third party requires separate consent as well.
- Is a home address (not GPS location) considered sensitive personal data? A fixed home address that a customer enters manually is generally considered general personal data. Under the law, sensitive location data primarily refers to a person’s real-time location, such as GPS coordinates. That said, regulatory guidance may further clarify this distinction in the future, so the safest approach is to handle both types of location information with appropriate care.
- Is a user’s uploaded photo considered biometric data? Only if the photo is used to identify the person – for example, through facial recognition technology. A standard profile picture is not automatically considered biometric data. However, if you use AI or facial recognition software to analyze that image for identification purposes, it becomes biometric data.
- If a customer voluntarily shares sensitive information during a support chat, do I still have any obligations? Yes. Even if the customer voluntarily provides the information, you are still responsible for handling it appropriately. It should not be retained longer than necessary, used for purposes beyond resolving that support request, or left without appropriate security measures.
A quick compliance check for your website
Review your existing website features and forms, and ask yourself the following questions for each one:
- Does this feature request the user’s location?
- Does this form collect financial information?
- Does it collect any health-related information?
- Does it use facial recognition or fingerprint authentication?
- Does it collect personal data from users under the age of 16?
If your answer to any of these questions is yes, you should review the consent flow for that feature or form to ensure it includes separate consent, a clearly stated purpose, and an easy-to-use consent withdrawal mechanism.
| Exclusive article by experts from FPT IS
Duong Hong Nhung, Product Marketing, Data Privacy & Compliance Solution FPT IS, FPT Corporation |
Read more
- Collecting customer data on your website: how to comply with the personal data protection law (PDPL) without disrupting your marketing
- Five signs your website is collecting customer data in violation of the PDPL
About FPT’s CMP Solution
FPT’s Consent Management Platform (CMP) helps enterprises manage the entire lifecycle of customer data consent — transparently and systematically. Every consent event is recorded and securely stored, giving businesses the audit trail they need to stay compliant, reduce legal risk, and operate with greater efficiency.
Ready to explore the right solution for your business? Leave your details below to connect with FPT.

