Cookie banners “for show” and four common misconceptions that make businesses think they comply with the PDPL

Today, most business websites already display a cookie banner. This is a positive sign—it shows that awareness of personal data protection is growing among businesses in Vietnam.

What is worth noting, however, is that having a cookie banner and having a legally compliant cookie banner are two different things. The gap between the two often comes down to a few specific design choices—not intentional mistakes, but simply a lack of complete information about what the law actually requires.

Below are the four most common misconceptions, along with practical ways to address each one.

Many cookie banners operate in the simplest way possible: they appear, the user clicks “Accept,” and that’s it. There is no breakdown of purposes, no options to choose from, and no explanation of what the user is actually consenting to.

This is not how the PDPL defines valid consent.

Why is this a problem? The law requires consent to be specific to each purpose of data processing. Cookies used to analyze browsing behavior serve one purpose. Cookies used for personalized advertising serve another. Cookies that share behavioral data with third-party platforms represent yet another purpose. Users have the right to consent to one purpose while refusing another.

A single “Accept” button that bundles everything together is not valid consent – it is simply a button.

What good compliance looks like: The cookie banner includes a “Customize” or “Manage Preferences” option, allowing users to enable or disable each category of cookies separately, such as essential cookies (which do not require consent), analytics cookies, marketing cookies, and third-party cookies. Each category includes a brief explanation of its purpose and the types of data it collects.

This is one of the most common misconceptions and also one of the hardest to notice because, from the user’s perspective, nothing appears unusual.

In practice, the banner appears, the user clicks the “X” to close it or simply scrolls down the page without interacting with it. The system records this as consent and immediately activates all cookies.

Under Law No. 91/2025/QH15, silence, inaction, or continued use of a service does not constitute consent. This requirement is explicitly stated in the law, leaving no room for interpretation.

This means that if your system treats every user who closes the banner as having given consent and then activates marketing cookies accordingly, the data collected through those cookies is based on invalid consent.

What good compliance looks like: Non-essential cookies are activated only after the user takes a clear affirmative action, such as clicking “Accept All” or selecting specific cookie categories in the preference settings. No non-essential cookies should be activated simply because the user closes the banner, scrolls down the page, or continues browsing. Instead, the system should record that consent has not yet been given and display the banner again during a future visit.

A user clicks “Accept” in January. In June, you add a new advertising partner to receive customer data or expand your data processing to support a new feature. The user is never asked for consent again.

This is one of the most common operational mistakes – and also one of the hardest to detect because, from the user’s perspective, nothing appears to have changed.

Why is this a problem? Consent is only valid for the purposes described at the time it is given. If the purpose of processing changes – for example, you add a new partner, introduce a new feature, or expand the scope of data processing – you must update your privacy notice and obtain fresh consent for those changes.

In addition, users must be able to withdraw their consent at any time, and withdrawing consent should be just as easy as giving it. If giving consent takes two seconds but withdrawing it requires sending an email to customer support and waiting three days for a response, the design does not comply with the law.

What good compliance looks like: Users can access a “Cookie Preferences” page at any time – not just during their first visit to the website. Whenever there is a significant change to the privacy policy or the list of third-party partners, the cookie banner is displayed again to request updated consent instead of silently applying the changes to existing consent records.

This is an area that IT teams are often aware of, but marketing teams tend to overlook: a cookie banner needs a backend, not just a frontend.

Specifically, every time a user interacts with the banner – whether they accept, reject, or customize their preferences – the system should record:

  • The exact time of the interaction (timestamp);
  • The user’s choices (which cookie categories they accepted or rejected);
  • The version of the privacy policy or cookie banner displayed at that time; and
  • The channel and device used.

Without these records, you have no evidence of consent. Without evidence of consent, any personal data you collect lacks a legal basis if your business is subject to a regulatory inspection or involved in a dispute.

In practice, many cookie banners are added to websites simply by embedding a small script that displays a pop-up. However, there is no system behind it to store and manage consent records in a way that allows reports to be generated when needed.

What good compliance looks like: Every consent interaction is stored as a searchable record linked to a user ID or session. When the privacy policy changes, previous versions remain archived so they can be matched with the consent records collected under those versions. The system can generate reports such as: “On date X, Y users consented to processing purpose Z,” supporting both internal audits and regulatory requests.

Use the checklist below as a quick self-assessment.

Question

Compliant

Needs review

Does your cookie banner categorize cookies by purpose? At least three separate categories are available. There is only a single “Accept” button.
If users close the banner, are cookies activated? No – non-essential cookies are activated only after a clear affirmative action. Yes – closing the banner is treated as consent.
Can users change their preferences after making a choice? Yes – through a “Manage Preferences” page. No – preferences cannot be changed after the initial choice.
Does the system keep a log of every interaction with the cookie banner? Yes – including timestamps and the applicable policy version. No – only the current consent status is stored.

Cluster 3 Eng ảnh 1 1784779487

One of the most common concerns businesses have when they hear they need to add a clearly visible “Reject” button is: “Won’t that reduce our consent rate and leave us with less data?”

The answer is yes in terms of quantity – but no when it comes to data quality and legal risk.

Experience from markets that have implemented the GDPR shows that cookie banners designed to be clear, transparent, and easy to customize actually build greater trust with users. People understand what they are consenting to, make more informed choices, and are less likely to file complaints or raise concerns. As a result, businesses may collect less data, but the data they do collect is cleaner – and, more importantly, legally valid for marketing purposes.

Data collected through a “cookie banner for show” may appear more valuable because of its volume. In reality, however, it lacks a valid legal basis and could become evidence against the business during a regulatory inspection.

Exclusive article by experts from FPT IS

Duong Hong Nhung, Product Marketing, Data Privacy & Compliance Solution

FPT IS, FPT Corporation

Last updated: July 2026. This article is based on Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP.

Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. Businesses should consult their legal department or a qualified legal professional before making specific compliance decisions.

Additional information about FPT’s CMP solution

FPT’s Consent Management Platform (CMP) enables businesses to manage the entire consent lifecycle – from obtaining user consent to governing how customer data is used – in a transparent and structured manner. Every consent record is captured and securely stored, helping organizations demonstrate compliance, reduce legal risks, and improve operational efficiency.

To explore a CMP solution tailored to your business needs, simply leave your contact information at the bottom of this page. An FPT expert will get in touch to discuss your requirements and recommend the most suitable approach.

Share:
Img Contact

Sign up to receive the latest news from FPT IS

    Bot Avatar