Guide · June 17, 2026

Zapier, Make and the PDPL: How to transfer customer data correctly?

Guide to using Zapier, Make to transfer customer data under the PDPL: consent, security, cross-border transfer, practical checklist.

consent.vn Editorial7 min read

Quick answer

If you use Zapier or Make to push customer data between apps, under the PDPL you must check consent, processing purposes, security, logging, and cross-border transfer conditions. With personal data, risks usually don’t lie in the “automation” itself but in configuration, storage location, and sub-processors.

What is Zapier/Make automation for transferring customer data under the PDPL?

It means using no-code tools to automatically move customer data between CRM, forms, email, spreadsheets, ticketing, advertising, or chatbots. Under personal data protection rules, each such data flow can trigger obligations on notice, consent, security, access control, recordkeeping, and, if data leaves Vietnam, obligations related to cross-border data transfer.

Real-world example: a lead fills out a form on the website, Zapier pushes it to HubSpot, Make sends it to Slack so sales can close faster, and a copy is stored in Google Sheets. If the form collects phone number, email, purchase history, or care notes, you are processing personal data, not just “pushing text”.

Do you need to consider cross-border data transfers when using Zapier or Make?

Yes. If customer data is transferred, accessed, or stored on infrastructure outside Vietnam, you should treat it as a cross-border data transfer under the regulations.

Points to check before turning on automation:

  • Where the source and destination apps’ servers are located, and who can access them.
  • Whether Zapier/Make stores payloads, logs, histories, error traces, or attachments.
  • Whether data passes through a sub-processor, webhook, email parser, or temporary storage.
  • Whether there is sensitive data, children’s data, or strong identifiers.

If the answer is “yes” at any stage, the business should review the legal basis, notify users, and ensure a compliant transfer mechanism; consult a lawyer for complex cases.

Automation scenarioKey PDPL riskWhat to do
Website form -> CRMCollection beyond purpose, lack of noticeUpdate the privacy notice; add a separate consent checkbox if needed
CRM -> internal SlackExposing data to people without a need to knowHide/mask data, limit channels, enforce access control
CRM -> Zapier/Make -> foreign appCross-border data transferReview storage locations, processing contracts, and transfer records
Webhook -> Google SheetsProliferation of copies, hard to deleteStore only minimal fields; set deletion lifecycles

When do you need to obtain customer consent?

You should obtain consent when data is used for a new purpose outside the customer’s reasonable expectations, or when the law requires consent in a specific manner.

In practice with automation, common pitfalls include:

  • Collecting leads for consultation but automatically pushing them into multi-channel remarketing.
  • Taking form information to provide a quote but sending it to analytics/ads tools for purposes beyond the original.
  • Sending data to third parties for enrichment, scoring, or processing by an LLM without clear disclosure.

Pragmatic rule: your notice and consent must clearly state what data is transferred, to which systems, for what purposes, how long it will be stored, and whether it is transferred abroad.

  1. List all data flows:

    Diagram from intake to final storage: website, CRM, Zapier/Make, email, sheet, Slack, ads.

  2. Identify data types:

    Separate basic data, transactional data, sensitive data, and children’s data if any.

  3. Review processing and storage locations:

    Note where each app’s servers are located, and whether there are logs, backups, histories, or cached files.

  4. Confirm the legal basis:

    Mark which flows rely on consent, and which rely on contract performance or legal obligations.

  5. Design for data minimization:

    Transfer only necessary fields; avoid pushing internal notes, tokens, or attachments unless needed.

  6. Enable security by default:

    2FA, SSO, least privilege, secret management, masking, audit logs, safe retries.

  7. Keep evidence:

    Store consent form versions, timestamps, source IPs where appropriate, and workflow change logs.

How do you secure data when using Zapier and Make?

Security in automation isn’t just “use a strong password”. You must control data in transit, pending retries, and sitting in run histories.

Practical checklist:

  • Grant only the minimum necessary permissions for each Zapier/Make account.
  • Separate test and production environments.
  • Do not push sensitive data into unnecessary fields.
  • Mask information in Slack, email, and internal dashboards.
  • Disable or limit execution history if it contains real data.
  • Review API keys, webhook secrets, tokens, and rotation lifecycles.
  • Have an incident response process if automation sends data to the wrong recipient.

If an incident leads to exposure of personal data, the business must assess the impact, contain it, and notify the breach within 72 hours of discovery as required.

What should SMEs do before turning on automation?

Start with a short but sufficient checklist:

  • Have a clear privacy notice on your forms.
  • Include a separate consent checkbox when needed.
  • Have data processing agreements with relevant vendors.
  • Maintain a simple record of processing for each flow.
  • Have a data deletion policy when the customer opts out or the purpose ends.
  • Assign a responsible person to approve workflows before going live.

Example: an agency runs lead form -> Zapier -> Google Sheets -> Gmail -> HubSpot. Without controls, customer data can be spread across four places, each with different access. A safer approach is to store data only in the primary CRM, while other apps receive only minimal data such as name, email, and processing status.

What is a sample consent notice for automation?

You can use a short template like the following and adjust to your reality:

“We collect your full name, phone number, email, and consultation needs to contact you, provide quotes, and deliver customer service. Data may be processed through automation systems and related service providers, which may include cross-border data transfers in accordance with the law. You may contact us to request access to, correction or deletion of your data.”

This template is not sufficient for every situation, but it is a good starting point to embed in forms, landing pages, or popups.

They shouldn’t be framed that way. Under the regulations, the issue is whether the business meets its obligations for consent, notice, security, and cross-border data transfer.
Yes. If data is transferred to other systems or third-party providers, you should explain this in the privacy notice and have an appropriate consent mechanism.
Treat it as a cross-border data transfer under the regulations and review documentation, processing conditions, contracts, and security—consult a lawyer if the structure is complex.
Contain immediately, revoke access if possible, assess the exposure, and prepare to notify the data breach within 72 hours of discovery as required.

If you are designing a cookie banner, consent evidence storage, or a DSAR process for Zapier/Make flows, consent.vn can help you standardize this before scaling your automation.

Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; Ministry of Public Security (A05): https://bocongan.gov.vn

Get started — set up in 5 minutes.

Need help with PDPL compliance?

Get started