Article · June 17, 2026

What is IAB TCF? Should Vietnamese businesses adopt it for advertising?

Explains IAB TCF, when Vietnamese businesses need it for ads, and how to align with PDPL (Law 91/2025/QH15).

consent.vn Editorial6 min read

Quick answer

IAB TCF is IAB Europe’s technical and policy framework for collecting and passing transparent consent signals for digital advertising. In Vietnam, TCF is not a legal requirement; businesses only need it when serving users in the EEA/UK or when an ad partner requires it. The domestic focus is PDPL compliance and consent governance.

What is IAB TCF?

IAB TCF (Transparency and Consent Framework) is an industry standard issued by IAB Europe that helps websites and apps collect, encode, and transmit users’ consent choices to adtech vendors across the programmatic ecosystem.

TCF is widely used in Europe to meet transparency and consent obligations under the GDPR and ePrivacy. Technically, TCF generates a signal string (TC string) that expresses processing purposes, vendor privileges, and consent status so that SSPs, DSPs, and ad servers can read it and decide how to serve ads.

Is IAB TCF required in Vietnam?

Under current Vietnamese regulations, IAB TCF is not a legal requirement. Businesses need TCF when they have users in the EEA/UK or use advertising platforms/partners that require TCF for that traffic (for example, some platform policies require a certified CMP that supports TCF for EEA/UK).

For domestic traffic, businesses must comply with the Personal Data Protection Law (Law 91/2025/QH15) (effective 01/01/2026, replacing Decree 13/2023/ND-CP). The focus is to have a lawful basis for processing, obtain valid consent when required, be transparent about purposes, and keep evidence. When in legal doubt, consult a lawyer.

How does TCF relate to programmatic advertising?

TCF is the common language that programmatic components (CMPs, SSPs, DSPs, ad servers) use to understand user consent choices, thereby enabling or disabling cookies, measurement, personalization, and real-time bidding. For Vietnam traffic, many parties still accept custom setups; TCF helps standardize when working with international vendor networks.

CriteriaIAB TCFPDPL (Law 91/2025/QH15) in VietnamAd platform CMP requirement for EEA/UK
NatureIndustry technical and policy frameworkMandatory legal framework for data protectionOperational requirement under platform policy
ScopePrimarily EEA/UKVietnam (replacing Decree 13/2023)Applies to EEA/UK traffic on that platform
ObjectiveStandardize consent signals, vendor transparencyLawful basis, consent, transparency, securityEnsure partners collect consent under TCF
Required outcomesTC string, vendor/purpose listsTransparency policy, consent records, DSAR, securityCertified CMP, emit a standards-compliant TC string
When neededHave EEA/UK users or a partner requires itAll personal data processing activities in VietnamWhen advertising to EEA/UK via the platform

Practical deployment: PDPL-first CMP, enable TCF by region

A practical approach for businesses with multi-region traffic is an integrated CMP: PDPL-first for users in Vietnam, automatically enabling TCF for EEA/UK users per platform requirements.

  1. Segment traffic by region:

    Determine country from IP or app settings to branch CMP experiences for Vietnam and EEA/UK.

  2. Choose a suitable CMP:

    Prioritize a CMP that records consent evidence under PDPL (log timestamp, content, purposes) and supports TCF v2.2 for EEA/UK. If you use large platforms, check the list of certified CMPs.

  3. Configure purposes and vendors:

    For Vietnam, describe purposes clearly and plainly as required. For EEA/UK, map purposes and vendors to the TCF Global Vendor List.

  4. Control storage:

    Before consent, block cookies/IDs and advertising SDKs as needed by purpose. After receiving the signal, enable only the actions that have been permitted.

  5. Keep consent evidence:

    Store consent logs, policy versions, the UI presented, and the TC string (if applicable) as evidence; for audits by the Ministry of Public Security (A05) if needed.

  6. Update transparency notices:

    Your page/modal must state processing purposes, data types, recipients, retention, data subject rights, and how to submit access/deletion requests.

  7. Test and monitor:

    Use tag/SDK scanners to ensure no trackers fire before consent. Test integrations with SSPs/DSPs to read the TC string correctly.

  8. Incident response:

    Have a data breach response playbook and notify within 72 hours of discovery as required.

Example: A news app in Ho Chi Minh City monetizes through advertising. For Vietnamese users, show a PDPL-compliant consent banner and block measurement/personalization SDKs until consent is given. For users in France, enable a CMP that supports TCF v2.2 to generate a TC string for SSPs/DSPs to read; if a platform requires a certified CMP, activate the correct vendors.

Compliance risks and enforcement in Vietnam

PDPL is enforced by the Ministry of Public Security (A05). Specific fines will be set out in Government decrees; serious violations may be subject to criminal liability. Beyond consent and transparency, businesses need information security, access controls, and procedures to handle data subject requests. When a personal data breach occurs, regulations require notification within 72 hours of discovery.

Operationally: keep CMP change logs, assess ad vendor risks, and control cross-border data sharing. Do not assert that any tool or tracker is illegal; assess the obligations it triggers (consent, transparency, processor contracts, data transfers) and adjust your configuration.

If you need an out-of-the-box solution: consent.vn’s cookie banner stores consent evidence, supports PDPL purpose mapping, and generates a TC string for EEA/UK traffic.

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started