Guide · June 17, 2026

Do promotional SMS need consent under the PDPL?

Do promotional SMS require PDPL consent? When opt-in is needed, risks of purchased lists, and the right approach for Vietnamese businesses.

consent.vn Editorial6 min read

Quick answer

Yes. For SMS/promotional messages, businesses typically must have a valid legal basis for processing; in practice, the safest is explicit consent (opt-in) before sending. Purchased lists are not automatically eligible. You need to check the data source, purpose, notice, and opt-out rights as required.

Do promotional SMS require PDPL consent?

Yes, in most situations businesses should treat explicit consent as a prerequisite before sending promotional SMS to individuals. The reason is that phone numbers, names, purchase history, and interaction behavior can all be personal data; using them for marketing is a specific processing purpose that must have a legal basis under the regulations.

If you send SMS to customers who have previously purchased, that still does not let you default to advertising every product. You need to check whether, at the time of data collection, you clearly notified a marketing purpose, whether the customer was given the opportunity to refuse, and whether what you send falls within the scope that was notified.

For SMEs, the safest approach is to design a clear opt-in flow: customers tick to agree to receive promotional messages, you log the time/source of consent, and there is always an easy way to unsubscribe.

Can purchased lists be used to send promotional SMS?

Purchased lists are not a “free pass” to blast SMS. You still have to check how that data was collected, whether the seller has the right to transfer it, and whether people on the list have consented to receive marketing from you specifically.

In practice, marketing consent is often tied to each recipient brand, each purpose, and each channel. A list that “agreed to receive messages” from provider A is not necessarily valid for brand B, especially when the advertising content changes or the recipient does not know their data was sold/shared.

If you use a purchased list, your business should require documentation proving data provenance, the notice content provided to data subjects, evidence of consent, and the terms governing data transfer. Without this dossier, compliance risk is very high.

How should opt-in for promotional SMS be done?

Opt-in should be an affirmative action, separate from general terms, and demonstrable. Do not bundle “agree to terms of use” with “agree to receive marketing”.

  1. Separate marketing consent checkbox:

    Do not pre-tick. The content should clearly state “I agree to receive promotional SMS/messages from [business name].”

  2. Record evidence:

    Log timestamp, IP, form/version, signup source, and the campaign or capture page.

  3. Specify content and frequency:

    For example: promotions, offers, product launches; avoid vague wording like “information updates”.

  4. Allow easy withdrawal:

    Add an SMS opt-out keyword, an unsubscribe link, or fast customer support processing.

  5. Check third parties:

    If you use an SMS gateway/CRM/agency, sign data processing terms and limit purpose of use.

Real-world example: a cosmetics shop runs a promotional landing page. The signup form should have two separate boxes: a required box to receive the discount code via SMS and an optional box to receive future promotional messages. If you only need to send the discount code for the current order, you should not “borrow” that phone number for next month’s ad campaign without appropriate consent.

If a customer has purchased before, can you send promotional SMS?

Do not interpret “has purchased” as automatic permission to advertise. A transactional relationship only gives you a basis to contact for fulfilling the order, after-sales service, reconciliation, and warranty. SMS marketing is a different purpose, which typically requires separate notice and a clear opt-out mechanism.

If you want to leverage past customers, review three points: whether marketing was notified when the phone number was collected; whether the customer opted in separately; and whether what you plan to send is within the scope they agreed to. If unsure, seek a fresh opt-in via email, web, app, or a message that confirms consent.

What should businesses note about penalties and breach reporting?

Specific fine levels will follow Government guidance decrees and are not fixed here. Serious violations may be subject to criminal handling. The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05).

If a list of phone numbers, a CRM file, or an SMS campaign is mis-sent or leaked, activate incident response immediately. Under the regulations, data breach notification must be made within 72 hours of discovery. This is especially important for marketing teams using multiple providers: SMS gateway, agency, chatbot, CDP, CRM.

Ready-to-use opt-in wording for promotional SMS

You can use this short template on a web/app form:

[ ] I agree to receive promotional SMS/messages, offers, and product information from [Business name]. I have read the notice on personal data processing and can withdraw consent at any time.

If used for an offline store, you can put this on the signup slip:

The customer agrees to allow [Business name] to use their phone number for the purpose of sending promotional messages, offers, and customer care as per the notice provided. The customer has the right to refuse at any time via [keyword/contact point].

Yes, for promotional messages you should obtain explicit consent before sending, or at minimum have an appropriate processing basis and provide full notice as required.
Purchased lists are not automatically valid. You need to check data provenance, evidence of consent, and whether the transfer complies with the rules.
You should not assume so. Purchasing only allows contact within the transaction scope; marketing typically requires separate notice and a clear opt-out mechanism.
Contain the incident, stop access, assess impact, log the incident, and notify the data breach within 72 hours of discovery as required.

If you are designing signup forms, cookie banners, or need to record consent for SMS/CRM/DSAR, consent.vn can help standardize this flow in a way that’s easy for marketing and dev teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15), Decree 13/2023/ND-CP, Ministry of Public Security (A05): https://thuvienphapluat.vn ; https://bocongan.gov.vn

Get started — set up in 5 minutes.

Need help with PDPL compliance?

Get started