What is sensitive personal data under the personal data protection law (PDPL)? Why your website forms may be collecting it without you realizing

When people hear the term “sensitive personal data,” they often think of medical records, bank account numbers, or DNA test results.

That’s not wrong – but it’s far from the full picture.

Under the Personal Data Protection Law No. 91/2025/QH15, the list of sensitive personal data is much broader than most people expect. In fact, a significant portion of it can be found in everyday website features, such as delivery forms, “Find a store near you” tools, insurance consultation forms, and even profile photo uploads.

The issue is not that your website includes these features. The issue is that sensitive personal data is subject to a much higher level of legal protection, and if you don’t know what type of data you’re collecting, you can’t obtain the appropriate consent required by law.

What is sensitive personal data? The definition under the Personal data protection Law No. 91/2025/QH15

According to Article 2 of the Personal Data Protection Law No. 91/2025/QH15, sensitive personal data is personal data related to an individual’s privacy that, if compromised, could directly affect their lawful rights and interests. This includes:

    • Health data: medical conditions, treatment history, test results, prescriptions.
    • Financial data: bank account numbers, transaction history, credit limits, loan information.
    • Location data: a person’s real-time geographic location, movement history.
    • Biometric data: fingerprints, facial recognition data, iris scans, voiceprints, DNA.
    • Political, religious, or philosophical beliefs: membership in political parties, organizations.
  • Information about a person’s sex life or sexual orientation.
  • Criminal records and legal violations.
  • Personal data relating to children.

The key point to remember: The law does not classify sensitive personal data based on whether it sounds sensitive. Classification depends on the type of information itself, not on why you collect it or how extensively you use it.

For example, collecting a customer’s real-time location – even if it is only needed once for delivery – is still considered the collection of sensitive personal data and requires separate consent.

The difference between general personal data and sensitive personal data in practice

General personal data – such as a person’s full name, date of birth, gender, email address, phone number, occupation, or home address – still requires consent under the law. However, it does not require a separate consent mechanism for each type of data.

Sensitive personal data is subject to two additional requirements.

First, consent must be obtained separately. It cannot simply be bundled into a general checkbox such as “I agree to the terms and conditions.” Users must take a clear, affirmative action specifically for the processing of sensitive personal data, and the purpose of processing must be clearly stated.

Second, users must be informed that the information being collected is sensitive personal data at the time consent is requested. They should know they are providing data that receives a higher level of legal protection before they submit the form – not afterward.

Cluster 2 Eng Anh 1 1 1784703368

Common website features that may be collecting sensitive personal data without you realizing

This is the section that surprises many businesses the most.

“Home delivery” or “find a store near you”

Any feature that asks users to enable GPS or share their current location is collecting location data, which is classified as sensitive personal data under the law. This is different from asking customers to manually enter a fixed delivery address. It is the collection of real-time location data that falls into the sensitive category.

Insurance, loan, or credit card application forms

Many of these forms collect financial information such as monthly income, existing loans, or credit history. Even if this information is collected only to qualify potential customers, it is still considered sensitive financial data under the law.

Health consultation, nutrition consultation, or clinic appointment forms

Any field asking about a person’s medical condition, allergies, or treatment history – even if it is only intended to prepare for an upcoming appointment – is collecting sensitive health data.

Facial recognition or fingerprint login

More websites and applications are adopting biometric authentication. Facial recognition and fingerprint data are biometric personal data, one of the most sensitive categories under the law and one that is subject to particularly strict legal requirements.

Registration forms for children

Whether it is for a course, an event, or another program, any personal data relating to children under the age of 16 is classified as sensitive personal data. In these cases, consent must be obtained from a parent or legal guardian – not from the child.

A common scenario that’s easy to overlook

Imagine you run an e-commerce website. A customer places an order and enters their delivery address. You store that information so you can deliver the order to the correct location. So far, everything is perfectly normal.

But later, you use that address to analyze customer locations in your business intelligence (BI) system, share it with a third-party logistics provider, and run location-based advertising campaigns on Facebook Ads targeting that area.

You are now using location data – which is considered sensitive personal data – for three different purposes, even though the customer originally consented only to its use for delivery.

This is not an unusual scenario. In fact, it reflects a standard marketing and data workflow. However, from January 1, 2026, each of these purposes requires its own separate consent.

So what should you do differently when your forms collect sensitive personal data?

Each type of sensitive personal data should have its own independent consent. It should not be covered by a single checkbox such as “I agree to the Privacy Policy.”

Example for a real estate website with a “Find properties near you” feature:

❌ Common approach today:

☑ I agree to the Terms of Use and Privacy Policy.

✅ Compliant approach:

☐ I agree to allow [Company Name] to use my current location to show properties near me. I can withdraw this consent at any time by visiting [link].

2. Explain the purpose at the point of collection

Users should know why you are collecting the data, how long it will be retained, and whether it will be shared with anyone.

This information should not be buried in a 20-page Privacy Policy that few people read. It should be presented directly on the form, at the moment the user is asked to provide their information.

Consent for sensitive personal data should come with a clear and accessible withdrawal mechanism. More importantly, once a customer withdraws their consent, that change should be synchronized across every system that processes their data – not simply recorded in a database and forgotten.

Cluster 2 Eng Annh 2 2 1784703404

Frequently asked questions

  • Is a phone number considered sensitive personal data? No. A phone number is classified as general personal data under the law. However, you still need separate consent for each processing purpose. Using a phone number for delivery is one consent, sending marketing SMS messages is another, and sharing it with a third party requires separate consent as well.
  • Is a home address (not GPS location) considered sensitive personal data? A fixed home address that a customer enters manually is generally considered general personal data. Under the law, sensitive location data primarily refers to a person’s real-time location, such as GPS coordinates. That said, regulatory guidance may further clarify this distinction in the future, so the safest approach is to handle both types of location information with appropriate care.
  • Is a user’s uploaded photo considered biometric data? Only if the photo is used to identify the person – for example, through facial recognition technology. A standard profile picture is not automatically considered biometric data. However, if you use AI or facial recognition software to analyze that image for identification purposes, it becomes biometric data.
  • If a customer voluntarily shares sensitive information during a support chat, do I still have any obligations? Yes. Even if the customer voluntarily provides the information, you are still responsible for handling it appropriately. It should not be retained longer than necessary, used for purposes beyond resolving that support request, or left without appropriate security measures.

A quick compliance check for your website

Review your existing website features and forms, and ask yourself the following questions for each one:

  • Does this feature request the user’s location?
  • Does this form collect financial information?
  • Does it collect any health-related information?
  • Does it use facial recognition or fingerprint authentication?
  • Does it collect personal data from users under the age of 16?

If your answer to any of these questions is yes, you should review the consent flow for that feature or form to ensure it includes separate consent, a clearly stated purpose, and an easy-to-use consent withdrawal mechanism.

Exclusive article by experts from FPT IS

Duong Hong Nhung, Product Marketing, Data Privacy & Compliance Solution 

FPT IS, FPT Corporation

Read more

About FPT’s CMP Solution

FPT’s Consent Management Platform (CMP) helps enterprises manage the entire lifecycle of customer data consent — transparently and systematically. Every consent event is recorded and securely stored, giving businesses the audit trail they need to stay compliant, reduce legal risk, and operate with greater efficiency.

Ready to explore the right solution for your business? Leave your details below to connect with FPT.

 

 

 

 

Share:
Img Contact

Sign up to receive the latest news from FPT IS

    Bot Avatar