Guide · June 17, 2026

Phone callback lead forms under PDPL: what do you need?

Guide to collecting phone numbers via lead forms for PDPL callbacks: legal basis, telesales consent, and proof retention.

consent.vn Editorial7 min read

Quick answer

If you use a lead form to collect phone numbers for PDPL callback consultations, you need to define the processing purpose, provide clear notice, have an appropriate basis for re-contacting, and retain evidence of consent. For calls/telesales, don’t just collect the phone number; record what was agreed to, the time, the form source, and how the user consented.

What is a PDPL phone callback lead form?

This is the situation where a business collects a phone number via a landing page, pop-up, chatbot, or sign-up form so staff can call back to consult on a product/service. Under PDPL, a phone number is personal data, so collecting, using, and sharing it internally with sales must have a clear purpose and proper notice to the user.

A real example: a clinic runs an ad for “book a free consultation,” and the user leaves a phone number. The sales team then calls back, messages via Zalo, adds the lead to the CRM, and sends an SMS. Each step creates its own compliance obligations; you can’t treat it as “just leave a number for easy contact.”

When can you use a phone number to call back for consultation under PDPL?

The practical rule is: only call back in line with a purpose the user has been informed of and agreed to, or under another appropriate legal basis under the regulations. For lead forms, design them from the start so users clearly understand they are consenting to being contacted for consultation, rather than collecting the number first and asking for permission later.

You should clarify at least these 4 points:

  • Why you collect the phone number: to call back for consultation, confirm an appointment, send a quote, or provide post-consultation care.
  • Who will use the data: sales, customer service, a call-center partner, or your internal CRM.
  • Through which channels you will contact: phone calls, SMS, Zalo, email.
  • How long you will retain the data: for example, 12 months from the last interaction, or per your internal policy.

If a subsequent purpose differs from the original—e.g., switching from “call for consultation” to “send weekly marketing”—you should obtain new consent or have a separate legal basis as required by the regulations.

What should a lead form display to reduce risk?

A good form is more than a checkbox. It must show users what data they are providing, to whom, and how they will be contacted. For PDPL phone callback lead forms, at a minimum include:

  • Required data fields: full name, phone number, consultation needs.
  • A link or short data-processing notice right next to the submit button.
  • A clearly written contact purpose: "Consultation, call back as requested".
  • A separate checkbox for marketing contact if you plan telesales beyond the consultation purpose.
  • A link to your personal data protection policy or a full notice.

Avoid bundling everything into a single checkbox like “I agree to all policies.” Operationally, separating consent for “call back for consultation” and consent for “receive promotions/telesales” is easier to evidence in case of disputes or audits.

  1. Define the processing purpose:

    State clearly whether the form is used to call back for consultation, schedule appointments, or provide post-consultation care. Don’t leave the purpose vague.

  2. Design a short notice:

    Display next to the form what data is collected, who will contact, via which channels, and how long you keep it.

  3. Split consent for telesales:

    If you want to make promotional/marketing calls, add a separate checkbox for agreeing to marketing calls.

  4. Retain evidence of consent:

    Record timestamp, IP, user agent, checkbox content, form version, and campaign source.

  5. Set up internal processes:

    Sales may only call leads with evidence of consent; have a mechanism to block numbers when users refuse.

  6. Recheck your CRM/CDP:

    Ensure form data isn’t automatically pushed into marketing lists without a proper basis.

How should you retain evidence of consent?

This is what many SMEs overlook. If later a user says “I never agreed to be called,” you must prove they entered the number themselves and saw the permission request.

Retain at least:

  • Time the form was submitted.
  • URL of the page/landing page.
  • The content displayed on the form at the time of submission.
  • Whether the checkbox was ticked.
  • Lead ID in the CRM.
  • Source/UTM or the advertising campaign.
  • Technical logs: IP, user agent, session ID if your system allows.

If you use a chatbot, pop-up form, or an in-app webview, also retain the version of the notice content and a screenshot of the interface. For telesales calls, have an outbound script: staff must restate the data source and reason for contacting, and record refusal cases.

Do telesales from lead forms require separate consent?

Yes, if the call is for marketing, promotion, or customer contact beyond what the user requested. Operationally, treat consent for “being called for consultation upon request” as different from consent for “receiving advertising/promotional offers.” Separating them reduces risk when processing data and avoids mixing customer care with telesales.

Example: a user fills out a form to “receive a quote for accounting software.” A sales call to advise on pricing matches the original purpose. But if you then place that number into a mass campaign to promote a new service package, you should have a separate legal basis under the regulations and, ideally, explicit prior consent.

What should you do to make lead forms safer in practice?

For SMEs, a simple but effective approach is to standardize from UX through CRM:

  • Provide a short, clear description right on the form.
  • Separate the consent for consultation from the consent for marketing.
  • Block submission when required fields are missing.
  • Push consent logs into the CRM together with the lead.
  • Have a policy to delete/hide data when the user opts out.
  • Train sales: do not copy numbers into personal spreadsheets.

If you use cookies, pixels, or trackers to measure conversions from the form, you also need to provide suitable notice about behavioral tracking and data collection as required by the regulations.

They should, especially if you want to prove the user was informed and agreed to being contacted. If you add telesales/marketing, split out a separate checkbox.
Yes. You should keep the timestamp, form content, lead source, and consent status to evidence your processing purpose.
Yes, if that internal transfer aligns with the notified purpose and has a basis under the regulations. Limit access rights and keep logs.
Stop contacting them immediately, update the refusal status in your system, and block the number from future campaigns. Have a process for handling consent withdrawal/opt-out.

If you’re deploying lead forms on web/app, consent.vn can help standardize the cookie banner, retain evidence of consent, and set up DSAR flows so your marketing team gets it right from the start.

Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn; Decree 13/2023/ND-CP: https://thuvienphapluat.vn; Ministry of Public Security (A05): https://bocongan.gov.vn

Get started — set up in 5 minutes.

Need help with PDPL compliance?

Get started