Data, Technology & Compliance

Data Subject Consent Management in Vietnam

越南数据主体同意管理

Data subject consent is the most common processing basis — and the easiest to invalidate if managed poorly. Personal Data Protection Law 91/2025/QH15 (effective 01/01/2026) dedicates Article 9 to consent validity conditions, Article 10 recognises the right to withdraw and request processing restriction, and Article 19 lists cases where processing needs no consent. In practice, “consent management” is a full lifecycle: collecting, storing evidence, tracking validity, handling withdrawal requests, and refreshing consent when purposes change.

Consent under Article 9: concept and validity conditions

Clause 1 Article 9 defines consent as the subject permitting the processing of their personal data, except where otherwise prescribed by law. Clause 2 sets validity conditions: consent is valid only when based on voluntariness and the subject clearly knows three information groups — processed data types and purposes; the personal data controller or controller-processor; the data subject’s rights and obligations. “Clearly knows” is a substantive standard: a document dozens of pages long in difficult language, which subjects sign because “without signing they cannot use the service”, can hardly satisfy both voluntariness and clear knowledge.

Invalid consent has serious consequences: all processing based on it risks being deemed personal data processing in violation of law — an act prohibited by Clause 4 Article 7. Collecting consent is not a “tick-the-box” procedure but the legal component determining the lawfulness of the entire processing flow.

Forms of expressing consent

Clause 3 Article 9 requires consent to be expressed in a clear, specific manner that can be printed and copied in writing — including electronic form or verifiable formats. The “printable and copyable” requirement has evidentiary meaning: in disputes, companies must produce evidence of what subjects consented to and what they consented to. For paper consent, that is a signed document; for electronic consent, an extractable record — logs recording timing, document contents and identity verification method.

Clause 5 Article 9 assigns the Government to detail Clause 3 — specified in Decree 356/2025/ND-CP. In practice, companies should standardise consent forms by channel: signed paper documents for important direct transactions; electronic checkboxes with log recording for websites and apps; minutes with audio recordings for call-centre consent. Every form must ensure traceability and provability.

Four mandatory principles when collecting consent

Clause 4 Article 9 sets four principles every consent collection mechanism must follow. First, consent expressed per purpose: do not bundle multiple unrelated purposes into a single consent — e.g. one “agree” checkbox covering service provision, marketing, behavioural analytics and partner sharing. Each purpose needs its own consent mechanism so subjects can agree to one purpose while refusing another.

Second, no conditioning on consenting to other purposes within the agreement — subjects cannot be forced to “consent to advertising to use the service”. Third, consent remains valid until the subject changes it — the basis for the withdrawal right at Article 10. Fourth, silence or non-response does not constitute consent — eliminating “default consent” mechanisms (pre-ticked checkboxes).

Cases of processing without consent

Article 19 lists five groups of processing without consent: (a) protecting the life, health, honour, dignity, rights or legitimate interests of the subject or others in urgent cases; (b) resolving emergencies, preventing riots, terrorism, crime; (c) serving state agencies and state management; (d) performing the data subject’s agreements with related agencies, organisations or individuals; (e) other cases under law.

For private enterprises, the two most practical bases are point a (urgent situations) and point d (performing agreements — processing data necessary to perform contracts to which the subject is a party). But Clause 2 Article 19 imposes an accompanying obligation: organisations processing in these cases must establish a supervision mechanism including processing procedures, responsibility allocation, protection measures, regular risk assessments, periodic compliance checks and feedback reception/handling mechanisms. “No consent needed” does not mean “no control needed”.

Consent for children and vulnerable persons

Article 24 sets specifics for children, persons lacking or with restricted civil act capacity, and persons with cognitive or behavioural difficulties. For these groups (except children), legal representatives exercise the data subject’s rights on their behalf, except consent-exempt cases under Clause 1 Article 19. Separately for children, Clause 2 Article 24: disclosing private life information or personal secrets of children aged 07 or older requires consent from both the child and the legal representative.

This directly affects companies serving children — online learning, entertainment, paediatric health — and companies using children’s images for marketing. Consent mechanisms must be designed in two layers: age verification, and where needed, collecting the legal representative’s consent. Clause 3 Article 24 sets the obligation to stop processing when the consenting person withdraws consent, or when competent authorities request.

Withdrawing consent and requesting processing restriction

Article 10 recognises subjects’ right to request consent withdrawal and request processing restriction when doubting the processing scope, purposes or data accuracy — except consent-exempt processing under Article 19 or otherwise prescribed by law. Requests must be in writing, including electronic or verifiable formats, sent to the controller or controller-processor.

Clause 2 Article 5 of Decree 356/2025/ND-CP specifies timelines: respond within 02 working days with full information on cessation procedures, implement within 15 days — 20 days if processors or third parties need to stop processing too. Complex cases may be extended once up to 15 days, with obligations to notify reasons and prove necessity and reasonableness. Clause 4 Article 10: consent withdrawal does not apply to processing already performed before withdrawal.

Collecting and storing consent evidence

Consent management starts with two foundational links. Collection: design per-purpose consent mechanisms following the four principles at Clause 4 Article 9; documents written in clear, understandable language. Evidence storage: each consent recorded with the document contents at consent time, timing, method and subject identity — retrievable when proof is needed.

Tracking validity, handling withdrawal requests and refreshing consent

Tracking validity: systems record each subject’s consent status per purpose, so when a subject withdraws consent for one purpose, corresponding processing flows stop promptly without affecting other still-valid purposes. Handling withdrawal/restriction requests: unified reception procedures (portals, dedicated emails, written documents), assigned handling, meeting the 02-day — 15/20-day marks under Decree 356/2025. Refreshing consent: when changing processing purposes, adding data types, or old consent documents no longer meet new standards, companies need to re-obtain consent under Article 9 standards. Note Article 39: processing consented under Decree 13/2023 before the Law took effect continues without re-obtaining.

Consent in employment and customer relations

In employment relations, employee consent must be viewed in the dependent relationship context — employees can hardly be considered absolutely “voluntary” when refusing consent may affect their job. Good practice is separation: data necessary for employment contract performance and legal obligation compliance (tax, social insurance) processed on agreement and legal bases; separate consent sought only for purposes beyond that scope (e.g. using employee images for marketing). This approach fits point d Clause 1 Article 19 and avoids “formal consent”.

In customer relations, consent is often tied to privacy notices — documents helping subjects “clearly know” before consenting. For marketing and advertising, Article 28 requires customers to consent on the basis of clearly knowing the content, method, form and frequency of product introductions; companies must provide means for customers to refuse and must stop advertising on request. The “opt-out” mechanism must be as easy as registration.

Risks of invalid consent

When consent fails Article 9 conditions, all processing based on it loses its legal basis. Consequences: administrative, sanctions under Article 8 up to VND 3 billion for organisations (Clause 5 Article 8); civil, subjects may complain, sue and claim damages (point dd Clause 1 Article 4); operational, companies may have to halt business-serving data flows when subjects withdraw consent en masse or authorities require cessation.

For sensitive personal data — health, biometrics, financial information — risks are even higher as this group carries enhanced protection and is authorities’ inspection focus. Consent mechanisms must pass the strictest test: genuine voluntariness, complete information, purpose separation, full evidence storage. See the general obligations framework of the Personal Data Protection Law. FLAT LAW FIRM supports reviewing consent documents, designing collection mechanisms and consent lifecycle governance, and building withdrawal/restriction request handling procedures under Decree 356/2025.

Frequently asked questions

Does a pre-ticked checkbox count as consent?

No. Point d Clause 4 Article 9: silence or non-response does not constitute consent. Pre-ticked checkboxes violate this. The correct mechanism is an unticked checkbox that users actively tick for each purpose.

Can service-use consent be bundled with advertising consent?

No. Clause 4 Article 9 requires per-purpose consent, without conditioning on consenting to other purposes. For advertising, Article 28 additionally requires customers to clearly know the content, method, form and frequency of product introductions and have refusal means.

When a subject withdraws consent, what happens to previously processed data?

Under Clause 4 Article 10, consent withdrawal does not apply to processing already performed before withdrawal. From receiving the request, companies must stop all further processing and fulfil requests (deletion, restriction) within 15 days — 20 days if third parties are involved — under Clause 2 Article 5 of Decree 356/2025/ND-CP.

Is consent obtained before Law 91/2025 took effect still valid?

Yes, within the transition scope. Clause 1 Article 39: processing consented or agreed under Decree 13/2023 before the Law took effect (01/01/2026) continues without re-obtaining. If old consent documents do not meet Article 9 standards, companies should proactively refresh them to reduce risk.

Is consent needed to process data for contract performance?

Point d Clause 1 Article 19 lists performing the data subject’s agreements as a consent-exempt processing case. The exemption covers only data necessary for that agreement; purposes beyond scope still need separate consent. Companies invoking this basis must prove necessity and maintain supervision mechanisms under Clause 2 Article 19.