Guide · June 17, 2026
What consent do checkout/payment forms need under the PDPL?
Checkout/order form consent under the PDPL: essential order data only; separate consent for marketing; with practical templates.
Quick answer
What consent do checkout/payment forms need under the PDPL?
Short answer: ask only for what’s needed for the transaction; marketing requires a separate consent. For an order form, businesses can generally rely on the necessity to perform a contract to process full name, phone number, email, shipping address, invoicing details, payment method, and order status. But if you add checkboxes like “receive offers,” “subscribe to the newsletter,” or “agree to share with advertising partners,” that’s a different processing layer and should have its own consent mechanism.
The key is to separate essential order data from growth-related data. If you lump everything into a single “I agree to everything” checkbox, you risk being unable to prove that the customer separately consented to marketing as required. For SMEs, the best approach is to design a minimalist form, then add separate options for non-mandatory items.
Which data are essential for the order, and which are marketing?
Essential data are what you need to complete the order and provide the service the customer is requesting. Marketing is anything beyond processing that order.
| Data group | Examples in the form | Should this be considered essential? | Practical notes | |
|---|---|---|---|---|
| Order intake information | Full name, phone number, email, address | Yes | Used for confirmation, delivery, incident contact | |
| Payment information | Order ID, payment method, payment status | Yes | Limit storing card data if not necessary | |
| Invoicing | Company name, tax ID, billing address | Yes, if the customer requests an invoice | Ask only when truly needed | |
| After-sales support | Delivery notes, appointments, returns | Yes | Serves order fulfillment or after-sales obligations | |
| Marketing | Newsletter, remarketing, birthday offers | No | Should have a separate checkbox, not pre-checked | |
| Advertising sharing | Pixels/ad partners, CRM lists for lookalikes | No | Review each activity and disclose the purposes clearly |
A real-world example: an online cosmetics shop may need full name, phone number, and address to deliver the order. But if the form also includes an “agree to receive promotions via Zalo/SMS/email” box, it should not be pre-checked by default. For mobile users, a separate checkbox also helps reduce disputes when they say “I only wanted to place an order.”
How do you design a form without asking for unnecessary consent?
Start with the data minimization principle: ask only for what you are sure you will use to process the transaction. Then separate non-essential options into their own checkboxes, clearly describing who receives the data, for what purposes, and how the customer can withdraw consent.
List processing purposes before designing the form:
specify which purposes are for ordering, which are for marketing, and which are for internal analytics.
Split the form into two layers:
a mandatory layer for the order and an optional layer for marketing. Do not merge them into a single catch-all checkbox.
Hide or don’t display unnecessary fields:
for example, don’t ask for date of birth unless you have a clear purpose.
Write brief, specific language:
instead of “I agree to all policies,” use “I agree to receive promotional emails from [company name].”
Keep evidence of consent:
record the timestamp, consent text, form version, and IP/device if appropriate and per internal policy.
Make withdrawal easy:
every marketing email should include an unsubscribe link; for SMS/Zalo, have a clear opt-out process.
A workable approach for SMEs is to place the marketing checkbox at the end of the form, leave it unchecked by default, and leave it blank if the customer doesn’t opt in. Do not make “no marketing consent, no order” a condition, as that turns marketing consent into a pseudo-mandatory requirement.
Do I need separate consent for email/SMS/Zalo marketing?
Yes—separate by channel and by purpose if you actually use the data for marketing. Promotional emails, promotional SMS, Zalo OA broadcasts, or telesales calls are different contact methods; from a risk management perspective, the business should clearly describe each channel and avoid a very broad, bundled statement.
In practice, many disputes stem from forms that only have one generic checkbox like “I agree to receive information.” When customers complete a purchase and then get called repeatedly, it’s hard for the business to prove that this was clear consent for each channel and each purpose. If you only need to send order status notifications, that serves the transaction; if you send weekly promotions, ask for separate consent.
What if the form uses cookies, pixels, or a CRM?
You shouldn’t label a tool “illegal”; instead, determine what obligations it triggers under the regulations. Pixels, trackers, SDKs, or CRMs may require you to disclose tracking purposes, third-party data sharing, and, for some activities, implement appropriate consent mechanisms.
The most practical approach is to review each data flow: customer fills the form -> data goes into the CRM -> automated email is sent -> synced to advertising. At each step, identify the purposes, legal basis, and retention period. If your business has an ordering website, the cookie banner and a dedicated policy page should clearly state cookie types, purposes, and how users can manage their choices. If needed, consult legal counsel to finalize your implementation before running large campaigns.
Sample consent language for an order form
You can use the following short template to separate the order and marketing:
"I understand that [Company name] will process my full name, phone number, email, shipping address, and related information to confirm, deliver, take payment for, and support my order. I voluntarily agree to receive promotional [email/SMS/Zalo] from [Company name] and can withdraw at any time."
If you have multiple channels, split them into separate checkboxes:
- [ ] I agree to receive promotional emails
- [ ] I agree to receive promotional SMS
- [ ] I agree to be contacted via Zalo about promotions
For B2B orders, you may need a tax ID field and billing recipient details; still, keep the same principle: ask for data that serve the transaction, and obtain separate consent for data used for marketing.
FAQ
- You should clearly inform customers which data are used to process the order, delivery, and payment; marketing requires separate consent and should not be bundled.
- It’s not recommended. Marketing consent must be voluntary; if it’s a precondition for purchase, you risk failing to prove voluntariness under the regulations.
- Separate them if you use multiple marketing channels. The clearer you are by channel and purpose, the easier it is to prove appropriate consent.
- Yes. At minimum, keep the form content, submission time, policy version, and checkbox state to support audits, complaints, or DSAR handling.
If you’re building a checkout form, consent.vn can help you standardize cookie banners, store consent evidence, and set up DSAR processes from the start so you won’t have to rework them after running ads.
Source: the Personal Data Protection Law (Law 91/2025/QH15) thuvienphapluat.vn; Decree 13/2023/ND-CP thuvienphapluat.vn; Ministry of Public Security (A05) bocongan.gov.vn
Get started — set up in 5 minutes.
Need help with PDPL compliance?