Article · June 17, 2026

Open-source PDPL cookie banners: Are Klaro and CookieConsent suitable?

Compare Klaro, CookieConsent and PDPL suitability for cookie banners, with notes on implementation, consent evidence and DSAR.

consent.vn Editorial6 min read

Quick answer

If you search for "open-source PDPL cookie banner", the answer is yes: Klaro and CookieConsent are two popular libraries. They can be suitable for deploying consent banners, but businesses still have to configure them, store consent evidence, classify cookies/trackers, and handle DSAR as required.

What is an open-source PDPL cookie banner?

Open-source PDPL cookie banners are free libraries/tools that help display a banner, categorize cookies, block scripts before consent, and record user choices. However, the tool is just the interface; compliance depends on how you configure it, the notice content, and the backend consent log system.

For Vietnamese businesses, remember that the Personal Data Protection Law is the Personal Data Protection Law (Law 91/2025/QH15), expected to take effect 01/01/2026, replacing Decree 13/2023/ND-CP. The enforcement authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05). If a data breach occurs, you must notify within 72 hours of discovery.

How do Klaro and CookieConsent differ?

Both libraries are useful, but they fit different needs. Klaro is strong at managing consent by service groups; CookieConsent is often easier for quickly setting up a basic banner. If you need tighter script control for a web/app with many marketing tags, Klaro is usually more flexible. If you need a compact banner and quick deployment for a small site, CookieConsent may be sufficient.

CriteriaKlaroCookieConsent
Primary goalManage consent by service/groupSimple cookie banner, quick to deploy
Block scripts before consentYes, but requires careful configurationPossible, but depends on integration
Suitable for sites with many trackersBetterAverage
Easy for SMEsQuite good if you have a devGood for simple sites
Record consent evidenceDoes not fully solve on its ownDoes not fully solve on its own
PDPL suitabilityCan be suitable if configured correctlyCan be suitable if configured correctly

Key point: under the regulations, a banner is not just “accept/decline.” You need to clearly describe processing purposes, the types of data collected, data recipients, how to withdraw consent, and the mechanism to store selection states. If you use an open-source tool without a consent log, you still face compliance risk.

Which open-source tool is more suitable for PDPL?

From a PDPL perspective, Klaro is often a better fit for businesses with many cookie/trackers groups because it’s easier to separate purposes and control by service. CookieConsent is more suitable when the need is just a basic banner with few integrations and few vendors.

But “suitability” is not about the tool’s name; it’s about these 5 tasks:

  1. The banner appears before non-essential cookies load.
  2. There is a clear reject button, without nudging users to accept.
  3. Each cookie/tracker group is described in plain Vietnamese.
  4. There is a consent log to prove who consented, when, and to what content.
  5. There is a mechanism to change mind/withdraw consent later.

If you are using Google Tag Manager, Meta Pixel, Hotjar, or a chat widget, check whether each script runs before consent. This is a very common mistake on SME sites: there’s a banner, but trackers still fire before the user clicks anything.

What needs to be done to implement a cookie banner under PDPL?

  1. List all cookies/trackers:

    Specify which tools are running, for what purpose, who provides them, and whether data is transferred overseas.

  2. Group by purpose:

    At minimum split into necessary, analytics, advertising, personalization, embedded content.

  3. Block before consent:

    Configure so non-essential scripts are not loaded before the user agrees.

  4. Write clear banner content:

    Briefly state what data is collected, for what purposes, and how to refuse/withdraw.

  5. Store consent evidence:

    Record the timestamp, policy version, the user’s choices, and source/device if needed by your system design.

  6. Set up withdrawal mechanism:

    Allow changes at any time without forcing users through too many steps.

  7. Test in practice:

    Open an incognito browser and check the network to see if trackers run before consent.

Real-world example: a Vietnamese e-commerce store uses an open-source banner but still loads Facebook Pixel upon landing on the homepage. In this case, the banner is only “good-looking” but not sufficient for compliance. The flow must be fixed so the Pixel only runs after the user accepts the advertising group.

Do you need to store consent evidence?

Yes. If the business relies on consent as the legal basis for processing data, you should be able to store consent evidence as required. For cookie banners, this evidence typically includes the policy version at the time of consent, the user’s choices, the timestamp, and the consent status for each group.

This is especially important in case of complaints, internal audits, or when customers request to review their consent history. Open-source tools often don’t fully cover this; you must connect to a backend, database, or dedicated consent log.

What are the legal risks of misusing an open-source banner?

The risk typically isn’t in open-source code, but in how it’s implemented. If the banner doesn’t block trackers before consent, doesn’t allow easy refusal, or can’t store consent evidence, the business may be considered non-compliant. Specific penalties will follow the Government’s guiding decree; serious violations may be subject to criminal prosecution.

Additionally, if you use cookies to collect user behavior, transfer data to third parties, or use tracking for advertising, you should also review internal policies, access controls, and the process for responding to data subject requests (DSAR).

If the site has many trackers and needs clear consent grouping, Klaro is often a better fit. If the site is simple, CookieConsent may be enough. But both need correct configuration to be suitable for PDPL.
No. The tool only supports the interface and script-blocking logic. Compliance also depends on the notice content, consent logs, withdrawal mechanisms, and how you load trackers.
In practical deployment, you can, but from a compliance standpoint it’s very risky. If you rely on consent to process data, you should store consent evidence as required.
When you have many third parties, transfer data overseas, process sensitive data, or are unsure which trackers run before consent. In these cases, ask a lawyer to review your policies and technical flow.

If you’re deploying a banner for a website/app, consent.vn can help you design the consent flow, store consent evidence, and handle DSAR in a way that’s easy for product and dev teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP at thuvienphapluat.vn; enforcement authority A05 at bocongan.gov.vn

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started