Article · June 17, 2026

Ride-hailing apps and the PDPL: location, drivers, customers

Ride-hailing/food delivery apps must manage location, driver, customer data and trip sharing under the PDPL from 01/01/2026.

consent.vn Editorial6 min read

Quick answer

For ride-hailing/food delivery apps, the PDPL directly affects GPS location data, driver–customer information, and trip-sharing features. Businesses must define processing purposes, provide clear notices, manage consent, limit data sharing, and prepare a breach-response process within 72 hours.

What is ride-hailing app location data under the PDPL?

This usually means your app collects, infers, or shares location data to dispatch trips, show ETAs, prevent fraud, support safety, and handle customer care. Under the Personal Data Protection Law (Law 91/2025/QH15), those activities are all personal data processing if they relate to drivers, customers, or recipients.

A key point is that GPS is not just “coordinates.” When combined with phone numbers, trip history, profile photos, license plates, and delivery addresses, that data can form highly sensitive behavioral profiles for compliance. For SMEs, a common mistake is to write vaguely that “data is used to operate the service,” while in reality it’s used for multiple different purposes.

What kinds of data must the app manage?

Short answer: almost all data tied to a trip must be classified and controlled. For ride-hailing/food delivery models, at minimum review these six groups:

  • Identification data: full name, phone number, email, avatar, CCCD if KYC is applied.
  • Location data: real-time GPS, pickup/drop-off points, routes, movement history.
  • Transaction data: order ID, fare, payment method, invoices.
  • Driver/partner data: licenses, license plates, operating areas, performance.
  • Safety data: SOS button, call logs, complaint content, star ratings.
  • Shared data: trip links, notifications to relatives, data exported to e-wallet/map/call-center partners.

If you use a map SDK, analytics SDK, push notifications, or in-app behavioral tracking tools, check what obligations they trigger under the rules: notice, consent, and control over third parties receiving data. Don’t rush to conclude any tool is “illegal”; the issue is whether you are transparent and have a basis for processing.

What should ride-hailing/food delivery apps do to comply with the PDPL?

You should implement four main things: transparency, minimization, controlled sharing, and incident readiness. This is the most practical part for product and engineering teams.

  1. Create a data map:

    document what data the app collects, from where, how long it’s kept, who can access it, and which parties it’s shared with. Without a data map, it’s almost impossible to do PDPL right.

  2. Separate processing purposes:

    for example, location used for matching trips differs from location used for fraud prevention or algorithm improvement. Each purpose needs its own description.

  3. Design notice/consent screens:

    at sign-up, when enabling location, when sharing a trip, and when turning on safety features. Content must be easy to understand and not buried in long terms.

  4. Limit third-party sharing:

    map, payments, cloud, CRM, and analytics providers should only receive what’s necessary. Sign contracts and bind them to security/processing obligations as required.

  5. Prepare DSAR and incident handling:

    set up flows to handle requests to access/delete/correct data, and establish a process to notify breaches within 72 hours of discovery.

Do trip sharing and GPS tracking require a separate notice?

Yes—provide a separate notice and state the purpose clearly. For example, the “Share trip with family” button should not be enabled by default; the app should tell users who will see what, for how long, and how to turn off sharing. Similarly, if the app uses background location to ensure safety or detect fraud, keep it separate from location used only while matching trips.

In Vietnam, many apps set location permission to “Always” but explain it too briefly. Under the PDPL, a better approach is to scope permissions by context: only request location when needed for a trip; if requesting background location, state specific benefits and how users can control it.

What should businesses prepare before the Personal Data Protection Law (Law 91/2025/QH15) takes effect?

The law is expected to take effect from 01/01/2026, replacing Decree 13/2023/ND-CP. Even with time left, ride-hailing/food delivery apps should start with what can be done now: review sign-up flows, request location permissions properly, log consent, put contracts in place with data processors, and prepare incident response scenarios.

Internal roles also matter. Product defines purposes, engineering implements controls, legal/compliance drafts notices and policies, and customer support handles user requests. Without clear ownership, location data often gets pushed into multiple systems with no final accountability.

Practical implementation example for ride-hailing/food delivery apps

A food delivery app in Ho Chi Minh City could do the following: when a customer places an order, the app only collects precise delivery location while the order is open; after delivery, keep order history only to the extent needed for accounting, disputes, and customer care. The “share order with family” feature should only create a status-view link and should not disclose the driver’s phone number if it’s not needed.

For drivers, the app should separate data needed for trip operations from data used for performance evaluation. Do not use the same notice for all purposes, as that makes it harder for users to understand and for you to prove they were fully informed.

Usually yes, if location is used for matching trips, tracking trips, fraud prevention, or safety sharing. Provide a clear purpose and explain how to turn off permissions when not needed.
Yes. This feature involves the link recipient, sharing duration, and the scope of data displayed, so it needs specific description under the rules.
Yes. Limit the data shared, bind them via security/data processing terms, and ensure they only access what’s necessary.
Activate the incident response process, assess impact, and notify the breach within 72 hours of discovery, as required.

If you’re designing a cookie banner, consent logging, or a DSAR flow for a ride-hailing/food delivery app, consent.vn can be a starting point to standardize more quickly.

Source: Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn; Decree 13/2023/ND-CP: https://thuvienphapluat.vn; Ministry of Public Security (A05): https://bocongan.gov.vn

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started