Article · June 17, 2026
Self-hosted vs cloud cookie banners: what should you choose?
Compare self-hosted vs cloud cookie banners under PDPL: cost, maintenance, evidence storage, reliability, and how SMEs should choose.
Quick answer
Self-hosted vs cloud cookie banners: what’s different?
A cookie banner is not just a UI layer. Under personal data protection rules, it usually comes with obligations to record users’ choices, prove the time of consent, the content shown, and how consent can be withdrawn. From this perspective, self-hosted and cloud mainly differ in control and operational responsibility.
Self-hosted means you deploy the banner on your own infrastructure: JS/CSS files, consent logs, database, backup, monitoring, and mechanisms to return evidence during an audit or upon user request. Cloud means using a third-party service, usually with templates, a CMP, dashboard, consent logs, tag manager integrations, and updates aligned with legal changes.
Self-hosted or cloud: which to choose for cost, maintenance, and reliability?
Choose based on scale and your team’s technical maturity. For SMEs with few web/app properties, moderate traffic, and a capable dev team, self-hosting can save subscription cost. For marketing teams that need to move fast across many domains and campaigns, cloud usually shortens time to launch and reduces the risk of missing updates.
| Criteria | Self-hosted | Cloud service | |
|---|---|---|---|
| Upfront cost | Low if you already have an engineering team | Usually fast to start but with subscription fees | |
| Long-term cost | Can be lower, but requires maintenance staffing | More predictable by service tier | |
| Maintenance | You patch bugs, update policies, fix integrations | Provider updates many parts | |
| Evidence storage | You design logs, retention, export | Usually comes with dashboard/reports | |
| Reliability | Depends on internal capability | Depends on SLA and vendor reputation | |
| Data control | High | Must review data transfers and processing roles | |
| Best for | SMEs with in-house devs, control-first | SMEs needing fast rollout, fewer resources |
The key under the PDPL is that a “pretty” banner or simply having Accept/Reject buttons is not enough; you must be able to demonstrate how consent is collected and managed. If your system cannot store consent evidence, cannot record choice changes, or cannot export logs when requested, then whether self-hosted or cloud, you still have a problem.
What are the PDPL advantages of self-hosting a cookie banner?
Self-hosting fits when you want to control the entire data chain: how the banner displays, where consent is recorded, how long it is retained, and who can access the logs. For businesses with internal products, bespoke apps/websites, or high audit requirements, the biggest advantage is not depending on an external provider.
However, self-hosting is not automatically “safer.” You must handle: timestamped logging, snapshotting the policy version at the time of consent, log tamper-resistance, cross web/app synchronization, and designing a proof mechanism for complaints. If implemented loosely, you can still violate the rules and be reviewed by the competent authority.
Determine data to track:
list cookie/SDK groups, purposes, data recipients, and states requiring consent.
Design evidence logs:
store timestamp, user/session ID, banner version, policy version, accept/decline choice, IP or minimal technical traces needed under data minimization.
Separate sensitive data from logs:
only store what’s needed to prove consent; avoid stuffing extra personal data into log tables.
Set retention and backup:
define how long to retain evidence, how to back up, and internal access rights.
Build an export API:
to output evidence for DSARs, complaints, or internal audits.
Test regularly:
simulate users changing their mind, deleting cookies, and accessing from other devices to check whether logs remain traceable.
Are cloud services more trustworthy?
Cloud is not inherently more trustworthy, but it often reaches a stable operational baseline faster. CMP vendors typically provide banner templates, consent state management, legal updates, and reporting. This helps companies without an in-house legal team or specialized privacy engineering.
But when using cloud, scrutinize contracts and configuration: what role does the provider assume, does data go offshore, where are consent logs stored, in what format can you export evidence, do they support deletion/correction requests, and what is the SLA. Under the rules, if data is transferred or processed by third parties, the business must still control its responsibilities.
Real-world risks: why many banners are 'there but ineffective'?
Many companies attach a banner but let marketing scripts run before the user chooses. Example: a Vietnamese e-commerce site loads Facebook Pixel, Google Ads, Hotjar at page start; the banner only shows at the bottom while tracking already runs. In this case, having a banner does not necessarily fulfill transparency and consent-control obligations.
Also, if you cannot store consent evidence, then when complaints arise, it is very hard to prove what the user chose, at what time, and under which policy version. This is something both self-hosted and cloud must address with engineering and process.
Which model should Vietnamese SMEs choose?
If you’re an SME with an in-house dev team, few domains, and need cost control, self-hosting is reasonable—but someone must own logging, backups, and regular testing. If you’re marketing-driven, run many campaigns, and need fast go-live, cloud may suit you better because it reduces operational load.
Practical tip: choose cloud if you do not yet have a systematic way to retain consent evidence; choose self-hosted if you already have logging, audit trails, and tight banner/policy change management. Whichever you choose, ask your tech team to prove: which banner version was shown to whom, where consent is stored, and how quickly a report can be produced.
If needed, consent.vn can help you design the banner, store consent evidence, and set up DSAR flows in an audit-friendly way—not just “having a banner and calling it done.”
- Startups often fit cloud if they want quick deployment and lack a privacy engineering team. If you already have strong devs and want long-term savings, self-hosting may fit better.
- No. Cloud is just a tool. You still must configure it properly, retain consent evidence, manage retention, and control the provider under the rules.
- Yes, if you need to prove whether and when a user consented or declined. Not retaining evidence is a major risk in inspections or complaints.
- That’s a compliance risk. The banner must be paired with a mechanism to block non-essential scripts until the user chooses, except where permitted by law.
Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn ; Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; Ministry of Public Security (A05): https://bocongan.gov.vn
Get started — set up in 5 minutes.
Deploy PDPL solutions for your business?