{"id":25207,"date":"2026-08-12T08:00:44","date_gmt":"2026-08-12T01:00:44","guid":{"rendered":"https:\/\/fpt-is.com\/en\/?post_type=goc_nhin_so&#038;p=25207"},"modified":"2026-08-20T18:02:48","modified_gmt":"2026-08-20T11:02:48","slug":"3-consent-design-patterns-most-commonly-penalized-and-how-to-spot-them-on-your-website","status":"publish","type":"goc_nhin_so","link":"https:\/\/fpt-is.com\/en\/insights\/3-consent-design-patterns-most-commonly-penalized-and-how-to-spot-them-on-your-website\/","title":{"rendered":"3 consent design patterns most commonly penalized &#8211; and how to spot them on your website"},"content":{"rendered":"<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Since late 2025, enforcement of Vietnam&#8217;s Personal Data Protection Law (PDPL) has begun to move beyond guidance and into active enforcement. Several major technology companies have already received administrative penalties related to the way they collect and use customer data.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><span style=\"font-weight: 400\">One notable pattern across these cases is that the businesses involved did not lack terms and conditions or privacy policies. Most of them had both &#8211; sometimes lengthy and highly detailed. The issue lay elsewhere: the <\/span><b>validity of consent<\/b><span style=\"font-weight: 400\"> &#8211; specifically, whether the mechanism used to obtain and record users&#8217; consent before collecting or processing their personal data complied with the law.<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">In other words, the problem was not missing documentation. It was that the consent mechanism itself failed to meet the legal requirements.<\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Three design patterns appear repeatedly in enforcement cases. All three are extremely common &#8211; and all of them look perfectly normal if you don&#8217;t know what to look for.<\/span><\/p>\n<h2><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt;color: #ff6600\"><b>Pattern 1: &#8220;Consent or no service&#8221;<\/b><\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>How it appears on a website<\/b><span style=\"font-weight: 400\">: When users visit your website for the first time, they encounter one of the following situations:<\/span><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">A pop-up or full-page overlay that can only be dismissed by clicking &#8220;Accept.&#8221;<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">A notice requiring users to accept updated terms within a specified period or risk having their account restricted.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">A registration form where the Terms of Use and Privacy Policy are bundled together, making it impossible to agree to the service terms without also consenting to every data processing purpose.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>Why do regulators take action against this design?<\/b><\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Law No. 91\/2025\/QH15 requires consent to be freely given. When users have only two choices &#8211; accept everything or lose access to the service &#8211; their consent is no longer genuinely voluntary, particularly when there are few practical alternatives to that service.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><span style=\"font-weight: 400\">The law also prohibits <\/span><b>bundling consent for personal data processing with mandatory conditions for using a service<\/b><span style=\"font-weight: 400\">, except where the data is genuinely necessary to provide that service.<\/span><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>How to spot this on your website:<\/b><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Can users refuse the use of their data for marketing purposes while still accessing the core service?<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">If a user does not click &#8220;Accept,&#8221; what happens? Can they still access the content, or are they blocked entirely?<\/span><\/li>\n<\/ul>\n<h2><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt;color: #ff6600\"><b>Pattern 2: no separate consent mechanism for different purposes &#8211; especially for advertising<\/b><\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>How it appears on a website:<\/b><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">A single checkbox stating &#8220;I agree to the Privacy Policy&#8221; covers everything &#8211; from order fulfillment to advertising retargeting (displaying ads to people who have previously visited your website).<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Users have no way to consent to purpose A (such as receiving order confirmation emails) while refusing purpose B (such as allowing their browsing behavior to be shared with third-party advertising platforms).<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">User data is processed for multiple purposes &#8211; including analytics, personalization, advertising, and third-party data sharing &#8211; but all of these activities are covered by a single, one-time consent.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>Why do regulators take action against this design?<\/b><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><span style=\"font-weight: 400\">This is an area that businesses relying on customer data for marketing should pay particular attention to. <\/span><b>Using personal data for advertising purposes or sharing it with third parties requires separate consent<\/b><span style=\"font-weight: 400\">. It cannot simply be covered by a general acceptance of the Privacy Policy.<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">When regulators assess this type of design, they ask a simple question: Do users genuinely understand what their data will be used for? Do they have a real choice?<\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">If the answer is no, the consent mechanism fails to meet two of the law&#8217;s core requirements: transparency and specificity.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>How to spot this on your website:<\/b><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">If a user wants to receive order confirmation emails but does not want their browsing behavior to be used for retargeting ads on Facebook or Google after leaving your website, can they make that choice?<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Does your Privacy Policy clearly identify the third parties that receive user data, and are users informed about &#8211; and allowed to choose &#8211; whether that sharing takes place before it happens?<\/span><\/li>\n<\/ul>\n<h2><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt;color: #ff6600\"><b>Pattern 3: interface designs that blur the line between &#8220;accept&#8221; and &#8220;decline&#8221;<\/b><\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>How it appears on a website<\/b><span style=\"font-weight: 400\">: This is the most subtle &#8211; and often the hardest &#8211; pattern to identify because it is not about whether a &#8220;Reject&#8221; button exists. It is about how the available choices are presented.<\/span><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">The &#8220;Accept&#8221; button is bright blue and visually prominent, while the &#8220;Customize&#8221; button is smaller, gray, and much less noticeable.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">The &#8220;Reject&#8221; option appears only as a text hyperlink rather than a clearly visible button, making it easy for users to overlook.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Within the cookie preference page, every non-essential cookie category is enabled by default, requiring users to manually turn each one off instead of actively choosing to turn them on.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">The buttons use vague labels such as &#8220;I Understand&#8221; or &#8220;Continue&#8221; instead of clearly indicating whether the user is giving or refusing consent.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>Why do regulators take action against this design?<\/b><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><span style=\"font-weight: 400\">The law explicitly <\/span><b>prohibits interfaces that create unclear or misleading distinctions between consenting and refusing consent<\/b><span style=\"font-weight: 400\">. A design that intentionally makes accepting easier than rejecting &#8211; whether through visual hierarchy or additional interaction steps &#8211; may still violate the principles of voluntariness and transparency, even if it appears technically compliant.<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">This is also an area where GDPR regulators in Europe have taken enforcement action. Several major platforms were fined not because they lacked a &#8220;Reject&#8221; button, but because the button was deliberately designed to discourage users from clicking it.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>How to spot this on your website:<\/b><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Ask someone who has never used your website before to reject all cookies. How many steps does it take, and how long does it take?<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">On the cookie preferences page, are all non-essential cookie categories disabled by default?<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Do the labels on your buttons clearly explain whether the user is giving or refusing anything?<\/span><\/li>\n<\/ul>\n<h2><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt;color: #ff6600\"><b>What all three patterns have in common<\/b><\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><span style=\"font-weight: 400\">Looking back, all three patterns share one defining characteristic: they <\/span><b>place the responsibility &#8211; and the risk &#8211; on users<\/b><span style=\"font-weight: 400\"> instead of putting users at the center of the decision-making process.<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">This is precisely the direction in which the PDPL &#8211; as well as the GDPR in Europe and the CCPA in the United States &#8211; is tightening its standards. The question is no longer simply &#8220;Did the business ask for consent?&#8221; Instead, it is &#8220;Did users make an informed and voluntary choice?&#8221;<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-25369\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/08\/3-consent-patterns-prone-to-pdpl-violation-1787223755.png\" alt=\"3 Consent Patterns Prone To Pdpl Violation 1787223755\" width=\"2528\" height=\"1684\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/08\/3-consent-patterns-prone-to-pdpl-violation-1787223755.png 2528w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/08\/3-consent-patterns-prone-to-pdpl-violation-1787223755-700x466.png 700w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/08\/3-consent-patterns-prone-to-pdpl-violation-1787223755-406x271.png 406w\" sizes=\"(max-width: 2528px) 100vw, 2528px\" \/><\/p>\n<h2><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>If your website uses one of these three patterns, where should you start?<\/b><\/span><\/h2>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">The practical reality is that all three patterns can be addressed &#8211; and you do not have to redesign your entire system at once.<\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">The first step is to take inventory: identify which of these patterns exist on your website, where they appear in the customer journey, and which datasets they affect. From there, prioritize remediation based on risk. Areas that collect sensitive personal data or process data for advertising purposes are typically the highest priority.<\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">As for the technical mechanism needed to collect consent correctly, retain verifiable records, and synchronize consent across downstream systems, that is exactly the problem a Consent Management Platform (CMP) is designed to solve.<\/span><\/p>\n<h2><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt;color: #ff6600\"><b>Frequently asked questions<\/b><\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>Are small and medium-sized businesses really on regulators&#8217; radar? <\/b><span style=\"font-weight: 400\">Law No. 91\/2025\/QH15 does not provide any exemption based on the size of a business. In practice, however, the first enforcement actions have generally focused on large platforms that process significant volumes of personal data. For smaller businesses, the risks often come from two other directions: complaints filed by individual users and supply chain compliance requirements, where larger business partners request evidence of compliance.<\/span><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>If users voluntarily provide their information, is a separate consent mechanism still required? <\/b><span style=\"font-weight: 400\">Yes. The fact that users voluntarily complete a form does not replace consent for the purpose of processing their data. A customer who provides their address for delivery is not automatically consenting to its use for market analysis or to its disclosure to a logistics partner. Each processing purpose still requires separate consent.<\/span><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>Can a detailed Privacy Policy replace a consent mechanism? <\/b><span style=\"font-weight: 400\">No. A Privacy Policy is an informational document that explains how a business processes personal data. Consent is the user&#8217;s affirmative action indicating that they agree to that processing. The two serve different purposes and must exist alongside each other\u2014they are not interchangeable.<\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Last updated: July 2026. This article analyzes common non-compliant consent design patterns based on publicly available information released by regulatory authorities. No specific businesses are identified. Legal references: Law No. 91\/2025\/QH15 and Decree No. 356\/2025\/ND-CP.<\/span><\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">Disclaimer: This article is provided for informational purposes only and does not constitute legal advice.<\/span><\/p>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b>Exclusive article by experts from FPT IS<\/b><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><i><span style=\"font-weight: 400\">Duong Hong Nhung, <\/span><\/i><span style=\"font-weight: 400\">Product Marketing, Data Privacy &amp; Compliance Solution ,<\/span><i><span style=\"font-weight: 400\"> FPT IS, FPT Corporation<\/span><\/i><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><b><i>Additional information about FPT&#8217;s CMP solution<\/i><\/b><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><i><span style=\"font-weight: 400\">FPT&#8217;s Consent Management Platform (CMP) enables businesses to manage the entire consent lifecycle &#8211; from obtaining user consent to governing how customer data is used &#8211; in a transparent and structured manner. Every consent record is captured and securely stored, helping organizations demonstrate compliance, reduce legal risks, and improve operational efficiency.<\/span><\/i><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;font-family: arial, helvetica, sans-serif;font-size: 12pt\">To explore a CMP solution tailored to your business needs, simply leave your contact information at the bottom of this page. An FPT expert will get in touch to discuss your requirements and recommend the most suitable approach.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"author":21,"featured_media":25209,"parent":0,"template":"","nang_luc":[790,821],"danh_muc_goc_nhin_so":[],"dich_vu":[],"linh_vuc":[],"platform":[],"san_pham":[],"the_goc_nhin_so":[],"class_list":["post-25207","goc_nhin_so","type-goc_nhin_so","status-publish","has-post-thumbnail","hentry","nang_luc-experts-sharing","nang_luc-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so\/25207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so"}],"about":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/types\/goc_nhin_so"}],"author":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/users\/21"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media\/25209"}],"wp:attachment":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media?parent=25207"}],"wp:term":[{"taxonomy":"nang_luc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/nang_luc?post=25207"},{"taxonomy":"danh_muc_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/danh_muc_goc_nhin_so?post=25207"},{"taxonomy":"dich_vu","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/dich_vu?post=25207"},{"taxonomy":"linh_vuc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/linh_vuc?post=25207"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/platform?post=25207"},{"taxonomy":"san_pham","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/san_pham?post=25207"},{"taxonomy":"the_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/the_goc_nhin_so?post=25207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}