Guide · June 17, 2026
What to do when storing customer chat history under the PDPL?
Guide to storing customer chats on Messenger, Zalo, live chat under the PDPL: purposes, retention, sensitive data, key cautions.
Quick answer
What is storing customer chat/message history under the PDPL?
It is when a business collects, records, stores, and retrieves the content of exchanges with customers via Messenger, Zalo, live chat, email chat widgets, or an integrated CRM. Under the rules, this constitutes processing of personal data if the messages contain information that can identify a user such as name, phone number, address, orders, purchase history.
For SMEs, this need usually stems from customer care, order confirmation, complaint handling, staff training, or evidencing transactions in disputes. The key is not 'whether to store', but how to store for the right purposes, within the right scope, and with controls.
For what purposes may a business store chats?
Businesses should only store chat history for specific, lawful purposes that can be explained to customers. For example:
- confirming and tracking orders;
- handling returns, warranty, complaints;
- measuring customer service quality;
- reconciling transactions, preventing fraud;
- keeping evidence of communications in case of disputes.
If you store 'for future marketing convenience' without clear notice, that is a compliance risk. With tools like bots, live chat, or a CRM, state the purposes from the start so users understand what their data will be used for.
Define retention purposes:
Specify each purpose such as customer support, warranty, reconciliation, or protecting legal rights. Do not lump all reasons together.
Give notice at the point of collection:
Display a short notice in Messenger, Zalo OA, live chat, or the chat-start form about logging and the retention period.
Classify data in chats:
Separate regular data from sensitive data; set rules to prevent staff from freely copying screenshots outside the system.
Set retention periods:
For example, keep 12 months for customer support, 24 months for disputes/reconciliation if there is a real need; when expired, delete or anonymize.
Limit access rights:
Only customer support, managers, and legal (if needed) may view; enable audit logs to know who opened which conversation.
Handle customer requests:
Prepare processes to search, export, delete, or restrict processing when customers request it under the rules.
How long should customer chat/message history be retained under the PDPL?
There is no single number that applies to all businesses. Under the rules, the retention period must be aligned with the processing purposes and the business’s actual needs; you cannot keep data indefinitely just because 'data is useful'.
Practical approach for SMEs:
- Pre-sales support chats: short retention, usually only enough to handle arising complaints;
- Chats related to orders, payments, warranties: longer retention because reconciliation and dispute resolution may be needed;
- Marketing or general advisory chats: set clear time limits and review periodically;
- Content no longer valuable: delete, anonymize, or move into a controlled archive.
If your live chat/CRM has a default 'store forever' setting, configure your own retention policy. Letting 'the system keep everything forever' is a common risk in product/ops teams.
How to handle sensitive data within conversations?
If messages contain sensitive data, you must exercise greater caution because the risk to privacy is higher. Common examples in chats with customers:
- health information, medical records, visit history;
- financial data, accounts, transactions;
- ID documents, images of the Citizen ID card (CCCD);
- information about children and family;
- content reflecting personal opinions, legal status, or private life.
In practice, many online sellers ask customers to send images of their Citizen ID card, prescriptions, or bank cards via chat 'for convenience'. This needs control because the chat content may contain both sensitive data and identifying data.
What to do:
- limit which staff can view conversations containing sensitive data;
- enable encryption in transit and at rest if the system supports it;
- mask fields that are not necessary;
- do not reuse sensitive data for other purposes without an appropriate basis under the rules;
- instruct staff not to ask customers for information beyond what is necessary.
What to watch for on Messenger, Zalo, and live chat?
Different tools, but the legal obligations are largely the same: the business still decides the purposes and means of processing for the part under its control.
| Channel | Common risks | What to do | |
|---|---|---|---|
| Messenger | staff take screenshots, forward freely | internal rules, limit access, store on company systems | |
| Zalo | syncs a lot of customer data into OA/CRM | check integration configurations, admin permissions | |
| Live chat | automatically logs all content and IPs | cookie/log notice, set a retention policy, audit logs | |
| Integrated CRM | data pulled across many departments | assign access roles and delete per the data lifecycle |
If you use a tracker, chatbot, or live chat plugin, don’t rush to conclude the tool is 'illegal'. Identify what obligations it triggers: notice, consent, recording evidence of consent, managing third parties, and ensuring system security.
A minimal process to store chats correctly
Small businesses can adopt the following minimum steps:
- Write an internal policy: Define purposes, retention periods, who can access, and how to delete.
- Update customer notices: State clearly that chats are logged, the purposes, contact channels, and how customers can request data support.
- Set retention: Automatically delete or anonymize on a schedule.
- Protect access: MFA, role-based access, access logs, separate test environments from real data.
- Handle incidents: If chats/personal data are exposed, by rule you must notify of a data breach within 72 hours of discovery.
When should you consult counsel or conduct deeper reviews?
You should review more carefully if your business:
- sells in healthcare, finance, education, insurance;
- uses chatbots/AI to summarize or score customers;
- shares chat logs with agencies, outsourced call centers, SaaS providers;
- stores images, audio, or ID documents in conversations;
- has customers in multiple countries or data is transferred abroad.
The PDPL is the Personal Data Protection Law (Law 91/2025/QH15), expected to take effect from 01/01/2026, replacing Decree 13/2023/ND-CP. Enforcement is handled by the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05). Specific penalties will follow the Government’s guiding decree, and serious violations may be subject to criminal liability.
- Not always; you need to assess the purposes and legal bases under the rules. That said, you should still give clear notice of chat logging and keep evidence of consent when required.
- Yes. If the chat content is linked to an identifiable person, the business is processing personal data and must manage it under the PDPL.
- Not recommended. Retention must match the purposes and real needs; implement deletion or anonymization on a schedule.
- That’s a high-risk situation because it may contain sensitive data. Limit access, protect it more strictly, and only use it when truly necessary under the rules.
If you need a cookie banner template, chat notice template, or a DSAR process for CRM/live chat, consent.vn can help standardize them so your dev and customer support teams can implement faster.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — thuvienphapluat.vn; A05 — bocongan.gov.vn
Get started — set up in 5 minutes.
Need help with PDPL compliance?