3 consent design patterns most commonly penalized – and how to spot them on your website

Since late 2025, enforcement of Vietnam’s Personal Data Protection Law (PDPL) has begun to move beyond guidance and into active enforcement. Several major technology companies have already received administrative penalties related to the way they collect and use customer data.

One notable pattern across these cases is that the businesses involved did not lack terms and conditions or privacy policies. Most of them had both – sometimes lengthy and highly detailed. The issue lay elsewhere: the validity of consent – specifically, whether the mechanism used to obtain and record users’ consent before collecting or processing their personal data complied with the law.

In other words, the problem was not missing documentation. It was that the consent mechanism itself failed to meet the legal requirements.

Three design patterns appear repeatedly in enforcement cases. All three are extremely common – and all of them look perfectly normal if you don’t know what to look for.

How it appears on a website: When users visit your website for the first time, they encounter one of the following situations:

  • A pop-up or full-page overlay that can only be dismissed by clicking “Accept.”
  • A notice requiring users to accept updated terms within a specified period or risk having their account restricted.
  • A registration form where the Terms of Use and Privacy Policy are bundled together, making it impossible to agree to the service terms without also consenting to every data processing purpose.

 

Why do regulators take action against this design?

Law No. 91/2025/QH15 requires consent to be freely given. When users have only two choices – accept everything or lose access to the service – their consent is no longer genuinely voluntary, particularly when there are few practical alternatives to that service.

The law also prohibits bundling consent for personal data processing with mandatory conditions for using a service, except where the data is genuinely necessary to provide that service.

How to spot this on your website:

  • Can users refuse the use of their data for marketing purposes while still accessing the core service?
  • If a user does not click “Accept,” what happens? Can they still access the content, or are they blocked entirely?

How it appears on a website:

  • A single checkbox stating “I agree to the Privacy Policy” covers everything – from order fulfillment to advertising retargeting (displaying ads to people who have previously visited your website).
  • Users have no way to consent to purpose A (such as receiving order confirmation emails) while refusing purpose B (such as allowing their browsing behavior to be shared with third-party advertising platforms).
  • User data is processed for multiple purposes – including analytics, personalization, advertising, and third-party data sharing – but all of these activities are covered by a single, one-time consent.

Why do regulators take action against this design?

This is an area that businesses relying on customer data for marketing should pay particular attention to. Using personal data for advertising purposes or sharing it with third parties requires separate consent. It cannot simply be covered by a general acceptance of the Privacy Policy.

When regulators assess this type of design, they ask a simple question: Do users genuinely understand what their data will be used for? Do they have a real choice?

If the answer is no, the consent mechanism fails to meet two of the law’s core requirements: transparency and specificity.

How to spot this on your website:

  • If a user wants to receive order confirmation emails but does not want their browsing behavior to be used for retargeting ads on Facebook or Google after leaving your website, can they make that choice?
  • Does your Privacy Policy clearly identify the third parties that receive user data, and are users informed about – and allowed to choose – whether that sharing takes place before it happens?

Pattern 3: interface designs that blur the line between “accept” and “decline”

How it appears on a website: This is the most subtle – and often the hardest – pattern to identify because it is not about whether a “Reject” button exists. It is about how the available choices are presented.

  • The “Accept” button is bright blue and visually prominent, while the “Customize” button is smaller, gray, and much less noticeable.
  • The “Reject” option appears only as a text hyperlink rather than a clearly visible button, making it easy for users to overlook.
  • Within the cookie preference page, every non-essential cookie category is enabled by default, requiring users to manually turn each one off instead of actively choosing to turn them on.
  • The buttons use vague labels such as “I Understand” or “Continue” instead of clearly indicating whether the user is giving or refusing consent.

Why do regulators take action against this design?

The law explicitly prohibits interfaces that create unclear or misleading distinctions between consenting and refusing consent. A design that intentionally makes accepting easier than rejecting – whether through visual hierarchy or additional interaction steps – may still violate the principles of voluntariness and transparency, even if it appears technically compliant.

This is also an area where GDPR regulators in Europe have taken enforcement action. Several major platforms were fined not because they lacked a “Reject” button, but because the button was deliberately designed to discourage users from clicking it.

How to spot this on your website:

  • Ask someone who has never used your website before to reject all cookies. How many steps does it take, and how long does it take?
  • On the cookie preferences page, are all non-essential cookie categories disabled by default?
  • Do the labels on your buttons clearly explain whether the user is giving or refusing anything?

What all three patterns have in common

Looking back, all three patterns share one defining characteristic: they place the responsibility – and the risk – on users instead of putting users at the center of the decision-making process.

This is precisely the direction in which the PDPL – as well as the GDPR in Europe and the CCPA in the United States – is tightening its standards. The question is no longer simply “Did the business ask for consent?” Instead, it is “Did users make an informed and voluntary choice?”

3 Consent Patterns Prone To Pdpl Violation 1787223755

If your website uses one of these three patterns, where should you start?

The practical reality is that all three patterns can be addressed – and you do not have to redesign your entire system at once.

The first step is to take inventory: identify which of these patterns exist on your website, where they appear in the customer journey, and which datasets they affect. From there, prioritize remediation based on risk. Areas that collect sensitive personal data or process data for advertising purposes are typically the highest priority.

As for the technical mechanism needed to collect consent correctly, retain verifiable records, and synchronize consent across downstream systems, that is exactly the problem a Consent Management Platform (CMP) is designed to solve.

Frequently asked questions

Are small and medium-sized businesses really on regulators’ radar? Law No. 91/2025/QH15 does not provide any exemption based on the size of a business. In practice, however, the first enforcement actions have generally focused on large platforms that process significant volumes of personal data. For smaller businesses, the risks often come from two other directions: complaints filed by individual users and supply chain compliance requirements, where larger business partners request evidence of compliance.

If users voluntarily provide their information, is a separate consent mechanism still required? Yes. The fact that users voluntarily complete a form does not replace consent for the purpose of processing their data. A customer who provides their address for delivery is not automatically consenting to its use for market analysis or to its disclosure to a logistics partner. Each processing purpose still requires separate consent.

Can a detailed Privacy Policy replace a consent mechanism? No. A Privacy Policy is an informational document that explains how a business processes personal data. Consent is the user’s affirmative action indicating that they agree to that processing. The two serve different purposes and must exist alongside each other—they are not interchangeable.

 

Last updated: July 2026. This article analyzes common non-compliant consent design patterns based on publicly available information released by regulatory authorities. No specific businesses are identified. Legal references: Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP.

Disclaimer: This article is provided for informational purposes only and does not constitute legal advice.

 

Exclusive article by experts from FPT IS

Duong Hong Nhung, Product Marketing, Data Privacy & Compliance Solution , FPT IS, FPT Corporation

 

Additional information about FPT’s CMP solution

FPT’s Consent Management Platform (CMP) enables businesses to manage the entire consent lifecycle – from obtaining user consent to governing how customer data is used – in a transparent and structured manner. Every consent record is captured and securely stored, helping organizations demonstrate compliance, reduce legal risks, and improve operational efficiency.

 

To explore a CMP solution tailored to your business needs, simply leave your contact information at the bottom of this page. An FPT expert will get in touch to discuss your requirements and recommend the most suitable approach.

 

Share:
Avatar

FPT IS

Img Contact

Sign up to receive the latest news from FPT IS

    Bot Avatar