Article · June 17, 2026
What is IAB TCF? Should Vietnamese businesses adopt it for advertising?
Explains IAB TCF, when Vietnamese businesses need it for ads, and how to align with PDPL (Law 91/2025/QH15).
Quick answer
What is IAB TCF?
IAB TCF (Transparency and Consent Framework) is an industry standard issued by IAB Europe that helps websites and apps collect, encode, and transmit users’ consent choices to adtech vendors across the programmatic ecosystem.
TCF is widely used in Europe to meet transparency and consent obligations under the GDPR and ePrivacy. Technically, TCF generates a signal string (TC string) that expresses processing purposes, vendor privileges, and consent status so that SSPs, DSPs, and ad servers can read it and decide how to serve ads.
Is IAB TCF required in Vietnam?
Under current Vietnamese regulations, IAB TCF is not a legal requirement. Businesses need TCF when they have users in the EEA/UK or use advertising platforms/partners that require TCF for that traffic (for example, some platform policies require a certified CMP that supports TCF for EEA/UK).
For domestic traffic, businesses must comply with the Personal Data Protection Law (Law 91/2025/QH15) (effective 01/01/2026, replacing Decree 13/2023/ND-CP). The focus is to have a lawful basis for processing, obtain valid consent when required, be transparent about purposes, and keep evidence. When in legal doubt, consult a lawyer.
How does TCF relate to programmatic advertising?
TCF is the common language that programmatic components (CMPs, SSPs, DSPs, ad servers) use to understand user consent choices, thereby enabling or disabling cookies, measurement, personalization, and real-time bidding. For Vietnam traffic, many parties still accept custom setups; TCF helps standardize when working with international vendor networks.
| Criteria | IAB TCF | PDPL (Law 91/2025/QH15) in Vietnam | Ad platform CMP requirement for EEA/UK | |
|---|---|---|---|---|
| Nature | Industry technical and policy framework | Mandatory legal framework for data protection | Operational requirement under platform policy | |
| Scope | Primarily EEA/UK | Vietnam (replacing Decree 13/2023) | Applies to EEA/UK traffic on that platform | |
| Objective | Standardize consent signals, vendor transparency | Lawful basis, consent, transparency, security | Ensure partners collect consent under TCF | |
| Required outcomes | TC string, vendor/purpose lists | Transparency policy, consent records, DSAR, security | Certified CMP, emit a standards-compliant TC string | |
| When needed | Have EEA/UK users or a partner requires it | All personal data processing activities in Vietnam | When advertising to EEA/UK via the platform |
Practical deployment: PDPL-first CMP, enable TCF by region
A practical approach for businesses with multi-region traffic is an integrated CMP: PDPL-first for users in Vietnam, automatically enabling TCF for EEA/UK users per platform requirements.
Segment traffic by region:
Determine country from IP or app settings to branch CMP experiences for Vietnam and EEA/UK.
Choose a suitable CMP:
Prioritize a CMP that records consent evidence under PDPL (log timestamp, content, purposes) and supports TCF v2.2 for EEA/UK. If you use large platforms, check the list of certified CMPs.
Configure purposes and vendors:
For Vietnam, describe purposes clearly and plainly as required. For EEA/UK, map purposes and vendors to the TCF Global Vendor List.
Control storage:
Before consent, block cookies/IDs and advertising SDKs as needed by purpose. After receiving the signal, enable only the actions that have been permitted.
Keep consent evidence:
Store consent logs, policy versions, the UI presented, and the TC string (if applicable) as evidence; for audits by the Ministry of Public Security (A05) if needed.
Update transparency notices:
Your page/modal must state processing purposes, data types, recipients, retention, data subject rights, and how to submit access/deletion requests.
Test and monitor:
Use tag/SDK scanners to ensure no trackers fire before consent. Test integrations with SSPs/DSPs to read the TC string correctly.
Incident response:
Have a data breach response playbook and notify within 72 hours of discovery as required.
Example: A news app in Ho Chi Minh City monetizes through advertising. For Vietnamese users, show a PDPL-compliant consent banner and block measurement/personalization SDKs until consent is given. For users in France, enable a CMP that supports TCF v2.2 to generate a TC string for SSPs/DSPs to read; if a platform requires a certified CMP, activate the correct vendors.
Compliance risks and enforcement in Vietnam
PDPL is enforced by the Ministry of Public Security (A05). Specific fines will be set out in Government decrees; serious violations may be subject to criminal liability. Beyond consent and transparency, businesses need information security, access controls, and procedures to handle data subject requests. When a personal data breach occurs, regulations require notification within 72 hours of discovery.
Operationally: keep CMP change logs, assess ad vendor risks, and control cross-border data sharing. Do not assert that any tool or tracker is illegal; assess the obligations it triggers (consent, transparency, processor contracts, data transfers) and adjust your configuration.
If you need an out-of-the-box solution: consent.vn’s cookie banner stores consent evidence, supports PDPL purpose mapping, and generates a TC string for EEA/UK traffic.
Source: Luật 91/2025/QH15 (PDPL) https://thuvienphapluat.vn/van-ban/Thuong-mai/Luat-91-2024-QH15-Bao-ve-du-lieu-ca-nhan-589142.aspx; Nghị định 13/2023/NĐ-CP https://thuvienphapluat.vn/van-ban/Cong-nghe-thong-tin/Nghi-dinh-13-2023-ND-CP-bao-ve-du-lieu-ca-nhan-769105.aspx; A05 https://bocongan.gov.vn
Get started — set up in 5 minutes.
Deploy PDPL solutions for your business?