Template · June 17, 2026

PDPL-compliant cookie popup template for websites

PDPL-compliant cookie popup template: content, buttons, policy links, and ready-to-use copy for Vietnamese websites.

consent.vn Editorial6 min read

Edit & copy

This is a reference template. Consult a legal advisor before using in production.

Quick answer

If your website uses cookies, pixels, SDKs, or measurement tools, you should have a clear cookie popup that lets users accept/decline/manage preferences, with a link to your policies. Below is a content template and structure you can use right away to comply with the PDPL.

What is a cookie popup template?

A cookie popup template is a brief layer shown when users visit a website, explaining that the site uses cookies and giving them choices before activating non-essential cookies. Under the PDPL, the goal is not just to "notify" but to record and respect user choices as required by law.

What parts should a cookie popup include?

A good cookie popup should be short, clear, and immediately actionable. At a minimum, include the following five parts:

  1. Short title: states that the website uses cookies.
  2. 1–2 sentence description: states main purposes such as operation, measurement, and personalization.
  3. Action buttons: accept, decline, manage preferences.
  4. Policy link: leads to the Cookie Policy or Personal Data Protection Policy.
  5. Record choices: store the consent/decline status so you don’t ask repeatedly.
ComponentShould haveWhy it matters
TitleYesUsers immediately understand what the popup is about
Cookie purpose descriptionYesAvoids generic notices and helps prove transparency
"Accept" buttonYesAllows a clear choice
"Decline" buttonYesGives users a real option
"Manage preferences" buttonYesUseful if cookies are categorized by purpose
Policy linkYesPoints to detailed terms
Store proof of consentRecommendedSupports compliance checks when needed

How should a cookie popup notice be written?

Write simply and avoid heavy legal jargon. A good popup is usually just 2–3 lines with a clear set of buttons. For example:

  1. Identify the types of cookies used:

    list technical, analytics, advertising, and third-party embeds; only activate non-essential parts after receiving an appropriate choice in line with regulations.

  2. Write a short description:

    say the website uses cookies to operate, measure traffic, and improve the user experience; make it clear users can change their choices at any time.

  3. Design clear buttons:

    use "Accept all", "Decline", "Manage preferences"; avoid ambiguous buttons like "Agree" if no other options are provided.

  4. Attach policy links:

    link to the Cookie Policy and Personal Data Protection Policy so users can see details on data types, purposes, and data recipients.

  5. Store proof of choices:

    record the timestamp, status, and popup version; devs should implement this to easily demonstrate that notice was provided as required.

Ready-to-use cookie popup copy for your website

You can use the template below and adjust brand name, cookie types, and policy URLs.

Title: This website uses cookies

Body: We use cookies and similar tools to operate the website, analyze traffic, and improve the user experience. You can accept, decline, or manage each cookie group. See more in our Cookie Policy and Personal Data Protection Policy.

Buttons:

  • Accept all
  • Decline
  • Manage preferences

Links:

  • Cookie Policy
  • Personal Data Protection Policy
  • Contact support

Shorter mobile version: This website uses cookies for operation and measurement. You can accept, decline, or manage preferences. See the Cookie Policy for details.

What should you note if your website uses analytics or advertising cookies?

If you use Google Analytics, Meta Pixel, heatmaps, third-party chatbots, or similar SDKs, your cookie popup should not be a token notice. Under the regulations, these tools may trigger transparency obligations regarding purposes, data recipients, and mechanisms for users to choose. You should:

  • only enable non-essential cookies after obtaining an appropriate choice;
  • clearly state cookie groups and purposes;
  • have a policy page that is easy to read;
  • store choice logs for later verification;
  • review contracts with tool providers if data is shared.

For complex situations, consult a lawyer or your legal team before rollout.

Is a cookie popup enough to comply with the PDPL?

No. A popup is only one part. The PDPL requires businesses to address the entire flow of collecting, storing, sharing, and securing personal data. If a data breach occurs, the business must notify within 72 hours from discovery as required. The Personal Data Protection Law (Law 91/2025/QH15) takes effect from 01/01/2026, and the enforcement authority is the Ministry of Public Security, Department of Cybersecurity and High-Tech Crime Prevention (A05).

How should dev teams implement the cookie popup template?

Devs can implement on the principle that the banner appears before non-essential tags load, stores state in localStorage/server-side, and allows choices to be changed in the footer.

Suggested technical structure:

  • essential: always on, no consent popup needed;
  • analytics: only on after user consent;
  • marketing: off by default;
  • preferences: on according to user choice;
  • the "Manage preferences" button opens a detailed modal.

If you’re building an e-commerce website, SaaS, or a landing page with trackers, combine the cookie popup with a policy page and a mechanism to store proof of consent from the start to avoid rework later.

Recommended. If there is only an accept button, users have no real choice, and the business will struggle to prove it gave users control as required.
Yes, if you store the user’s choice and allow them to change it later. What’s important is not to enable non-essential cookies before an appropriate choice is made.
You should still consider a notice and choice mechanism, as measurement tools may involve personal or behavioral data. Review your configuration and policies.
Recommended. The popup is short, while the policy explains in detail the data types, processing purposes, retention periods, and how to contact you.

If you need help, consent.vn can help you standardize cookie banners, store proof of consent, and implement DSAR flows for stable use on Vietnamese websites.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP; Ministry of Public Security bocongan.gov.vn; thuvienphapluat.vn

Access the full template library — no account needed.

Need more PDPL templates?

Get started