Guide · June 17, 2026
Are exit-intent email capture popups PDPL-compliant?
Learn PDPL rules for exit-intent email popups: be transparent, avoid coercion, store consent evidence, and do it right.
Quick answer
Are exit-intent email capture popups PDPL-compliant?
Yes, if the popup only collects email when the business meets transparency and consent obligations under the regulations. For “exit-intent” popups or “get an ebook/discount in exchange for email,” the key is not the tool, but how you design the personal data collection flow.
In practice, an email popup on a website in Vietnam typically touches three issues: the purpose of processing, the content of the notice to users, and the ability to retain evidence of consent. The Personal Data Protection Law (Law 91/2025/QH15) is expected to take effect on 01/01/2026, replacing Decree 13/2023/ND-CP. The enforcement authority is the Ministry of Public Security (A05).
If the popup only shows an email field and a “Submit” button without making clear what users will receive, from whom, and for what purpose, you are creating a compliance risk. Conversely, if the popup clearly states “subscribe to newsletters, materials, and offers via email,” links to the privacy policy, and logs time/IP/form version, it is much easier to prove compliance during a review.
What should an email capture popup disclose to be transparent about purpose?
Users should be told at minimum: why you collect the email, who the controller/processor is, what type of messages the email will be used for, whether it will be shared with third parties, and how they can withdraw consent or unsubscribe.
In an exit-intent popup, space is limited, so the notice must be short but sufficient. Practical examples:
- “Receive a PDF and product updates from consent.vn”
- “We only use your email to send the material you requested and related information”
- “See Privacy Policy”
A better approach is to show a short description in the popup and link details to a landing page or the privacy policy. With lead-gen forms, don’t lump multiple vague purposes like “news, promotions, customer care, partners.” Separate each purpose where possible.
Can the popup pre-tick consent or require an email?
You should not pre-tick a consent checkbox, and you should not make providing an email the sole condition for everything if it is not necessary for the actual purpose. Under the rules, consent must be a positive action, demonstrable, and tied to a specific purpose.
With exit-intent popups, two common mistakes are:
- The “I agree to receive emails” checkbox is pre-ticked.
- The close button is too hard to see, effectively forcing users to submit an email to exit.
If you offer a free ebook in exchange for an email, say plainly that this is the condition to receive the file, rather than hiding behind vague phrases like “to optimize your experience.” There should also be a clear “Decline” or “No, thanks” button. This not only reduces compliance risk but also improves data quality because only genuinely interested users will submit.
Define specific purposes:
State clearly whether the popup is for receiving materials, subscribing to a newsletter, or getting offers. Each purpose should have its own wording.
Write a short, clear notice:
Display a concise description directly in the popup, with a link to the privacy policy.
Design active consent:
Use an unchecked checkbox, or rely on the act of submitting the form to clearly indicate consent as required.
Store consent evidence:
Record timestamp, form content, privacy notice version, traffic source, IP or session ID.
Allow withdrawal and unsubscribe:
Every marketing email should include a visible unsubscribe link or clear opt-out instructions.
Check before launch:
Test on mobile/desktop, verify text, logs, and the data handling flow after submission.
How should you store consent evidence when running a popup lead form?
You should be able to record who consented, to what content, at what time, and via which interface/version. Many marketing teams overlook this because they focus solely on conversion rate.
A minimal log should include:
- Email submitted
- Submission time
- URL or landing page where the form appeared
- Popup content/version
- Checkbox/consent text at the time of consent
- Source/UTM or event ID
If you use a CRM, email marketing tool, or a third-party popup tool, check whether the system can export consent logs. If not, you can still run the campaign, but it will be difficult to prove validity during an audit. For SMEs, structured storage in a database or internal sheet is far better than keeping a plain email list.
Ready-to-use example of an exit-intent popup
You can refer to the short template below:
Title: Get free PDPL materials
Description: Enter your email to receive a PDF file and related updates from consent.vn. We only use your email for this purpose and you can unsubscribe at any time.
Checkbox: I agree to receive emails in accordance with the Privacy Policy.
Button: Send me the material
Secondary link: No, thanks
If you want to be safer, separate two checkboxes: one mandatory for receiving the material, and one optional for marketing emails. This is clearer when you need to deliver the file immediately and also want permission to send a newsletter afterward.
- You should include one if you use the email for marketing, newsletters, or purposes beyond immediately fulfilling the user’s request.
- Not necessarily. State who is sending, what type of content, and link to the privacy policy so users can understand before submitting.
- The law does not mandate a single log format, but businesses should keep sufficient evidence to prove consent as required.
- The business still needs to verify the processing purpose, the notice content, and the ability to store consent evidence. If the setup is complex, consult a lawyer.
How to run email capture popups with the least risk?
Treat the popup as a controlled data collection point, not just a conversion booster. The three most practical principles are: clearly state the purpose, give users an easy way to refuse, and retain sufficient consent evidence.
If your team uses multiple lead forms, standardize consent text, versioning, and logs before you scale. consent.vn can help you review cookie banners, store consent evidence, and set up DSAR flows that align with your existing marketing systems.
Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP: thuvienphapluat.vn; Enforcement authority A05: bocongan.gov.vn
Get started — set up in 5 minutes.
Need help with PDPL compliance?