Article · June 17, 2026
What is a Google Certified CMP and why does Google require it?
What a Google Certified CMP is, when Google requires it, and related PDPL duties for Vietnamese businesses.
Quick answer
What is a Google Certified CMP?
A Google Certified CMP is a Consent Management Platform that has passed Google’s certification program, commonly used to display a cookie banner, record user choices, and send consent/non-consent signals to Google’s advertising ecosystem. In short: it is the “consent management” layer between your website/app and ad tags, analytics, and remarketing pixels.
The key point is a CMP is not just a pop-up. A proper CMP must at least support: classifying processing purposes; allowing users to accept/decline; storing proof of consent; updating choices; and transmitting signals in the format Google requires in applicable regions.
For SMEs in Vietnam, this need typically arises when the website runs Google Ads, AdSense, GA4, Google Tag Manager, or ad SDKs in apps with traffic from the EEA/UK/Switzerland and some other territories depending on Google’s policies.
Why does Google require a certified CMP for Ads/AdSense in some regions?
Google requires a certified CMP to ensure consent signals are collected consistently and can be audited. The practical reason is that the ad ecosystem needs to know whether the user has agreed to cookies/personalized advertising before activating certain tags or transferring data to partners.
If you run Ads/AdSense and receive traffic from the applicable regions, Google typically cares not only about “is there a banner” but also about:
- whether consent is requested before setting cookies;
- whether users can reject as easily as accept;
- whether choices are stored and can be updated;
- whether the CMP passes the correct status to Google tags.
In reality, many Vietnamese websites that target only domestic customers are still affected because of international traffic, using a CDN, or stacking multiple third-party trackers. In such cases, if consent is misconfigured, you may face restricted ads, skewed measurement, or lost conversion data.
How is a Google Certified CMP different from a self-coded cookie banner?
A certified CMP differs from a “homegrown” banner in that it provides a system to store and synchronize consent and supports the integration standards recognized by Google. A self-coded banner may be sufficient to display a notice, but it often lacks critical components such as consent logs, policy versioning, detailed purpose management, or reliable signal transmission to tags.
| Criteria | Self-coded banner | Google Certified CMP | |
|---|---|---|---|
| Display cookie notice | May have | Yes | |
| Store proof of consent | Often missing | Yes | |
| Purpose-based categorization | Usually basic | Can be granular | |
| Transmit consent to Google tags | Depends on custom dev | Standards-based support | |
| Works across multiple legal regions | Hard to scale | Easier to standardize | |
| Misconfiguration risk | High | Lower if implemented correctly |
What should Vietnamese businesses do when using a Google Certified CMP?
You should treat the CMP as part of your compliance system, not just a marketing plugin. A minimum implementation should include:
Identify applicable regions:
Check where your traffic comes from, whether there is EEA/UK/Switzerland, and which tags are firing before the user consents.
Classify trackers by purpose:
Separate strictly necessary cookies, analytics, ad personalization, conversion measurement, remarketing.
Configure the banner in the correct order:
Do not fire non-essential trackers before consent where regulations require.
Store proof of consent:
Record timestamp, choices, notice/policy version, and how the user changes their preferences.
Test before go-live:
Use a clean browser, tag assistant tools, and network logs to verify consent signals flow correctly.
Review periodically:
When adding pixels, SDKs, affiliate scripts, or changing vendors, update the tracker map and banner.
Under Vietnam’s PDPL, remember that the Personal Data Protection Law (Law 91/2025/QH15), effective 01/01/2026, replaces Decree 13/2023/ND-CP. If your website/app collects data via cookies, fingerprinting, pixels, or ad SDKs, providing notice, obtaining consent, allowing withdrawal of consent, and storing proof are obligations that are likely to arise under the rules.
In other words, the CMP helps you handle the “consent touchpoint” on the interface, while the compliance documentation must be accompanied by a privacy policy, a data flow map, vendor contracts, and processes for responding to data subject requests.
Does a Google Certified CMP help meet Vietnam’s PDPL?
Yes, but not automatically. A CMP is just a tool for execution; whether you comply depends on how you configure and operate it. For example, if the CMP only has an “Accept all” button without an easy-to-see “Reject all,” or cannot store proof of consent, then from a risk management perspective it is still insufficient.
For Vietnamese businesses, especially small marketing + dev + legal teams, a practical approach is: use a certified CMP to standardize the banner and logging, while compiling a tracker list, checking the legal basis under the rules, and finalizing the process for when users withdraw consent.
If you are unsure about applicable regions, cross-border data transfer mechanisms, or how to design banners for multiple countries, consult a lawyer to avoid misunderstanding obligations.
If you need to implement a cookie banner, store consent evidence, or prepare DSAR processes for your website/app, consent.vn can be a starting point to help your dev and legal teams work together more smoothly.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — thuvienphapluat.vn; Department of Cybersecurity and High-Tech Crime Prevention (A05) — bocongan.gov.vn
Get started — set up in 5 minutes.
Deploy PDPL solutions for your business?