Article · June 17, 2026

Market research firms, surveys and the PDPL: what should you do?

How do market research firms handle survey data under the PDPL? Consent, anonymization, panels, evidence retention, and DSAR.

consent.vn Editorial7 min read

Quick answer

If a market research company collects opinions, demographics, contact information, response history, or panel data, that may constitute personal data processing under the Personal Data Protection Law (Law 91/2025/QH15). You need to determine your role, have an appropriate legal basis, clearly disclose the purposes, retain evidence of consent when required, and prepare a DSAR process.

What counts as PDPL data in market research surveys?

This is a very practical question: in the survey industry, not all data are “harmless.” If a questionnaire only collects opinions that cannot be linked to an individual at all, PDPL risk is lower. But when you collect email, phone number, panel ID, IP, cookie, voice, images, age, gender, region, occupation, or responses that can be pieced together to identify the respondent, you are processing personal data under the rules.

A key point to note is that many market research companies confuse “research purpose” with “free to collect.” In reality, with identified or identifiable data, businesses still must have an appropriate legal basis, transparent notices, and clear data lifecycle management.

When is survey data considered personal data?

The short answer: when the data can directly or indirectly identify a person, or when it is linked to a personal profile.

Common examples in market research in Vietnam:

  • Panel surveys with member IDs, email, phone numbers used to invite participation.
  • NPS/CX surveys sent via personalized links to existing customers.
  • In-depth interviews with audio or video recording.
  • Surveys asking for age, gender, district, occupation, income, which combined with other data could identify the respondent.
  • Tracking behavior on a survey landing page via cookies or pixels to measure completion rate.

Conversely, if you only aggregate properly anonymized data at a group level, for example “72% of respondents in Ho Chi Minh City prefer product A,” the legal risk is lower because it is no longer tied to a specific individual. However, anonymization must be true anonymization, not just hiding names.

Survey scenarioDoes PDPL compliance apply?Practical notes
A fully anonymous survey with no way to reconnect to the respondentUsually lowerEnsure there are no identifiers and avoid excessive logging
Survey collects email/phone to send gifts or invite to a follow-upYesYou must disclose the purpose and retain evidence of consent if relying on consent
Panel with member profilesYesHave a dedicated policy for panel members and manage sharing with commissioning clients
Interviews with audio/video recordingYesClearly disclose recording, storage, sharing, and retention periods
Reports contain only aggregated, anonymized dataUsually lowerStill assess re-identification risk from background data

When do market research firms need consent?

Not all activities require “asking for consent” in the same way, but in the survey industry, consent is a very common legal basis—especially when you collect data directly from respondents, use data for a panel, run survey remarketing, or share data with the commissioning client.

For practical compliance, you should separate clearly:

  • Consent to participate in the survey.
  • Consent to process personal data.
  • Consent for audio/video recording.
  • Consent to be contacted for future survey invitations.
  • Consent to share identified data with the client, if applicable.

If you lump everything into a single long checkbox, your evidence of consent will be weak. It is better to separate by purpose. For panels, provide a dedicated member sign-up page stating what data are collected, for what purposes, who will receive them, how long they will be kept, and how to withdraw consent.

  1. Map each data flow:

    specify what you collect on the landing page, survey form, panel portal, call center, recordings, cookies, and CRM.

  2. Classify the data:

    separate identified data, contact data, survey data, sensitive data, and anonymized data.

  3. Identify the legal basis:

    consent, performance of a contract, legal obligation, or another lawful basis under the rules; when unsure, consult counsel.

  4. Design a concise notice:

    state purposes, data types, retention period, recipients, how to withdraw consent, and a contact point.

  5. Keep evidence:

    timestamp, version of the notice, consent capture source, checkbox logs, IP, user-agent, campaign code.

  6. Apply proper anonymization:

    remove or separate identifying keys, restrict access, and assess the risk of reversal.

  7. Prepare for DSARs and incidents:

    set up look-up/deletion/copy processes and an incident response plan; in case of a breach, notify of a personal data violation within 72 hours of discovery as required by law.

How should a survey panel be designed for easier compliance?

With panels, it is not just about “a one-time click to agree.” You also have to manage the member lifecycle: registration, screening, survey invitations, rewarding points, inactivity, account deletion, and transferring data to research clients when there is outsourcing.

A minimum template should include:

  • A brief explanation of the panel.
  • Data categories: full name, email, phone number, age, gender, region, interests, participation history.
  • Purposes: sample recruitment, survey invitations, deduplication, reward payout.
  • Sharing: with commissioning clients or processors where applicable.
  • Retention: aligned with purposes and internal policy.
  • Opt-out: delete the panel account and stop receiving invitations.

A real-world example: an FMCG survey company invites 5,000 panel members to respond monthly. If it simultaneously uses personal email to send invitations, cookies to measure completion, and produces reports with filters by very small geographic areas, the company needs to assess re-identification risk. When output data have very small groups, consider masking, grouping, or anonymizing before delivery.

What is a short notice template for online surveys?

You can use the following short template on the landing page or before the form:

“We collect the information you provide in this survey for market research, trend analysis, and to contact you if you consent to receive future survey invitations. Data may include survey responses, basic demographic information, email/phone number, and technical data necessary to operate the system. You can withdraw your consent by following the instructions here. Some data may be shared with the commissioning client in aggregated form or under a separate agreement, in accordance with the law.”

If the survey involves audio/video recording, add a separate line: “We only record with your explicit consent and will disclose the retention period, access scope, and purpose of use.”

What should market research businesses prepare before the Law takes effect?

The Personal Data Protection Law (Law 91/2025/QH15) is expected to take effect on 01/01/2026 and will replace Decree 13/2023/ND-CP. The enforcement authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05). Specific penalties will be provided in the Government’s implementing decree; serious violations may be subject to criminal liability.

For market research companies, five things to do now:

  • Review survey forms and panel sign-up.
  • Separate anonymized and identified data.
  • Standardize consent content and evidence logs.
  • Review contracts with commissioning clients and survey vendors.
  • Establish processes for access, deletion, consent withdrawal requests, and incidents.

If you are using cookies, trackers, CRM, or automation for surveys, consent.vn can help you design banners, store evidence of consent, and streamline DSAR processes for easier audits.

Not every situation is the same, but for surveys that collect identified data, panels, audio/video recording, or sharing with the commissioning client, consent is a very common basis and should be designed clearly.
If truly anonymized, the risk is lower. But check whether any IDs, logs, cookies, or background data could be used to re-identify respondents.
It is advisable. At a minimum, store the registration time, the notice content at that time, which checkboxes were selected, and how members can withdraw consent.
Under the rules, within 72 hours from the discovery of a personal data breach.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; Enforcement authority A05: https://bocongan.gov.vn

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started