Template · June 17, 2026
Consent checkbox templates for website forms under PDPL
Consent checkbox copy for website forms: signup, contact, purchase. Ready-to-use, PDPL-compliant variants.
Edit & copy
This is a reference template. Consult a legal advisor before using in production.
Quick answer
What is consent checkbox copy for website forms?
Short answer: it’s the text next to a checkbox that tells users what personal data the business will collect and process, for what purposes, and how they can withdraw consent.
With the Personal Data Protection Law (Law 91/2025/QH15, expected effective 01/01/2026), businesses should design checkboxes that are clear, specific, and easy to understand. If you use web forms for signup, contact, or purchase, each purpose should have its own wording; avoid a single “agree to everything” checkbox for all purposes.
Quick templates for website forms
Variant 1 — account signup form
[ ] I consent to [Company Name] collecting and processing my full name, email, phone number, and account information to create and manage my account, support login, authenticate, and provide customer support, as described in the Privacy Policy.
Variant 2 — contact/consultation form
[ ] I consent to [Company Name] processing the information I submit in this form (full name, email, phone number, message content) to respond to my request, provide service consultation, and keep a record of the conversation, as described in the Privacy Policy.
Variant 3 — purchase/order form
[ ] I consent to [Company Name] using my full name, phone number, shipping address, email, and order details to process payment, deliver goods, issue invoices, provide after-sales support, and handle complaints, as described in the Privacy Policy.
Variant 4 — separate marketing opt-in form
[ ] I agree to receive promotional emails/SMS/Zalo messages, offers, and newsletters from [Company Name]. I understand I can withdraw my consent at any time by [withdrawal instructions].
How should you write consent checkboxes for easier compliance?
Short answer: write to cover four layers of information: what data, for what purposes, who processes it, and how the user can control it.
In practice, many web forms only say “I agree to the terms” but do not specify what data is collected or for what purposes. That approach creates ambiguity. Under the regulations, for each form you should at minimum separate into:
- one checkbox for processing data necessary to fulfill the user’s request;
- a separate checkbox for marketing, newsletters, remarketing, and sharing with third parties;
- a link to the Privacy Policy;
- a mechanism to store consent evidence.
| Form type | What to request consent for | Don’t do this | |
|---|---|---|---|
| Account signup | Create and manage account, authentication, customer support | Bundling marketing into the same checkbox | |
| Contact/consultation | Respond to the request, keep conversation history | Requiring advertising consent to submit the form | |
| Purchase | Process order, delivery, payment, invoicing | Bundling order data with consent to share with advertising partners | |
| Subscriptions | Email/SMS/Zalo marketing, offers | Using a pre-ticked checkbox |
Consent checkbox templates for signup, contact, and purchase forms
Short answer: below is copy you can paste into forms right away, but you still need to adapt it to your actual data and systems.
1) Account signup form
Required checkbox
[ ] I confirm I have read and agree to [Company Name]’s Privacy Policy. I consent to [Company Name] collecting and processing the personal data I provide to create an account, authenticate, operate the service, and support me when needed.
Optional marketing checkbox
[ ] I agree to receive product updates, offers, and newsletters from [Company Name] via email/SMS/Zalo.
2) Contact form
Required checkbox
[ ] I consent to [Company Name] processing the information I submit in this form to respond to my inquiry, provide consultation, or technical support, as described in the Privacy Policy.
Practical note: if the form is only for a callback request, you may not need a separate marketing checkbox. But if you later want to add them to advertising lists, you need a separate consent mechanism as required by the regulations.
3) Purchase form
Required checkbox
[ ] I consent to [Company Name] collecting and using my full name, phone number, delivery address, email, and order information to process the purchase, deliver goods, handle payment, issue invoices, and provide after-sales support.
Optional checkbox
[ ] I agree to receive information about similar products, offers, and promotions from [Company Name].
Which checkboxes should be required, and which should be optional?
Short answer: required checkboxes should apply only to data necessary to fulfill the user’s request; marketing, profiling, and sharing beyond what’s necessary should be optional.
If you force users to consent to advertising before they can submit a contact form, that is not a safe compliance design. A better practical approach is to:
- let the form work if the user consents only to what is necessary;
- separate the marketing checkbox;
- log the timestamp, wording, policy version, and source of consent.
Define each form’s purpose:
Signup, contact, purchase, or subscription forms must have distinct purposes; don’t use one piece of copy for all.
Limit data to what is necessary:
Only ask for data truly needed for the service. For example, a contact form should not require a home address if it’s not needed.
Write separate checkboxes:
Use one checkbox for ‘fulfilling the request’; separate checkboxes for marketing, remarketing, and partner sharing.
Link to the Privacy Policy:
The link must be prominent, work on mobile, and explain who processes the data, purposes, retention, and how to withdraw consent.
Store consent evidence:
Record timestamp, IP, user agent, the checkbox text version, and tick status so you can demonstrate compliance when required.
Do we need to store consent evidence?
Short answer: yes. If the business cannot demonstrate what the user ticked, when, and on which version, it will be hard to justify in case of complaints or inspections.
For SMEs and dev teams, the minimum you should do is:
- store
consent_text_version; - store
consent_timestamp; - store
form_idandpurpose; - store
user_idor an equivalent identifier; - store the opt-in/opt-out status;
- store the traffic/source if needed for reconciliation.
If you’re implementing a cookie banner, consent evidence storage, or DSAR processes, consent.vn can help you standardize logging and tracing to make operations easier.
- Keep it short but sufficient: what data, for what purpose, and a link to the privacy policy. Avoid overly generic wording like ‘agree to all terms’.
- Yes. The marketing checkbox should be separate from the checkbox needed to process the order, contact, or account.
- Not always one checkbox for everything, but if you collect personal data and process it beyond responding to the request, you should have appropriate notice and consent mechanisms per the regulations.
- Yes. You should store the timestamp, wording, policy version, and consent status to demonstrate when needed.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — https://thuvienphapluat.vn; Ministry of Public Security (A05) — https://bocongan.gov.vn
Access the full template library — no account needed.
Need more PDPL templates?