Template · June 17, 2026

Short PDPL-compliant cookie policy template

Short Vietnamese cookie policy template for SMEs, with fill-in blanks, PDPL-compliant and easy to deploy on websites.

consent.vn Editorial6 min read

Edit & copy

This is a reference template. Consult a legal advisor before using in production.

Quick answer

This is a short Vietnamese cookie policy template for SMEs, with fill-in blanks ready to publish on your website/app. It helps you describe cookie types, purposes, retention, third parties, and how users manage choices in line with personal data protection rules.

What is a short cookie policy template?

A short cookie policy template is a concise notice on your website that explains what the site uses cookies for, what choices users have, and what data the business collects/processes via cookies. For SMEs, the goal is to be clear enough for users to understand quickly, while still offering a link to a full version if needed.

When should SMEs use the short cookie policy template?

You should use it when your website has any tracking tools such as analytics cookies, advertising cookies, pixels, SDKs, a tag manager, or third-party chat/embedded tools. Under the rules, this may trigger obligations to provide notice, obtain appropriate consent, and allow users to change their choices.

Ready-to-use short cookie policy template

Below is the condensed version; you can replace the parts in square brackets:

COOKIE POLICY

Website/app: [Website/app name] Owner: [Company name] Contact: [personal data support email] Effective date: [dd/mm/yyyy]

1. What are cookies? Cookies are small files stored on your device when you access [website/app]. Cookies help the website function reliably, remember your preferences, and measure usage effectiveness.

2. What do we use cookies for? We use cookies for the following purposes:

  • Strictly necessary cookies: ensure the website operates, sign-in, cart, security.
  • Analytics cookies: measure visits, pages viewed, usage behavior.
  • Personalization/advertising cookies: remember choices and show more relevant content.

3. Which cookies may be used? Depending on the website configuration, we may use cookies from:

  • [Analytics system name]
  • [Advertising platform name]
  • [Chat/marketing tool name]

This list may change based on the actual technical configuration.

4. What data do we collect via cookies? Depending on the cookie type, data may include: IP address, device identifiers, browser, access time, pages viewed, click/tap behavior, and your choices on the website.

5. How can you manage cookies? You can:

  • Accept or reject non-essential cookies when visiting the website;
  • Change your browser settings to block/delete cookies;
  • Withdraw consent previously given for non-mandatory cookies, if our system supports it.

Note: disabling certain cookies may cause the website to not work fully.

6. Who do we share cookie data with? We may share cookie-related data with technical, analytics, advertising, or hosting providers, including [provider name], according to the applicable configuration and contracts.

7. How long are cookies stored? Cookie retention depends on the type of cookie. Some cookies last only for a browsing session, while others may be stored for [x days/months] to remember choices or for statistical analysis.

8. Changes to this cookie policy We may update this policy when technology, providers, or legal requirements change. The updated version will be published at [policy URL].

9. Contact If you have questions about cookies or personal data, please contact: [Department/Team name] [email] [address]

How to fill out the template for an SME website

  1. Fill in the website and company name:

    replace [Website/app name] and [Company name] with the correct legal entity information on the site.

  2. List the tools actually running:

    check whether you have GA4, Meta Pixel, Hotjar, Zalo chat, TikTok Pixel, HubSpot and include them in the cookie section.

  3. Group cookies:

    at minimum include strictly necessary, analytics, and advertising/personalization.

  4. State retention and choices clearly:

    describe how to accept/reject, how to change your mind, and the consequences of disabling non-essential cookies.

  5. Provide a clear consent mechanism:

    if there are non-essential cookies, the banner should allow rejecting on equal footing with accepting, and store proof of choices.

  6. Update when tools change:

    each time you add a new tracker/tag/pixel, review the policy and banner.

What should SMEs keep in mind to stay concise but accurate?

You don't need to write a lengthy document if your website only uses a few common cookies. What matters is that the content accurately reflects the system actually running, and is consistent across the banner, the policy, and the technical configuration. If you use third-party analytics/marketing tools, consider adding a consent management mechanism and logging proof of consent.

Is this template sufficient to publish on your website?

Yes, if your website uses only a simple set of cookies and you have filled in the actual information correctly. However, if there is cross-border data transfer, integration of third-party SDKs/software, or processing of sensitive data, you should review the entire policy and consent flow against the regulations; for complex cases, consult a lawyer.

CategoryShort templateFull version
Length1–2 screensMay include many detailed sections
Best forSMEs, simple websitesMany trackers, many providers
GoalEasy to read, easy to publishMore detail, supports internal review
Should includePurposes, cookie types, how to managePlus data transfers, storage, third parties, updates
Yes, if the site uses cookies beyond minimal technical cookies. If you have analytics, pixels, a chat widget, or advertising, you should have a clear policy.
Avoid overly generic wording. Under the rules, you should at least state what cookies are used for, which ones are necessary, and how users can manage them.
If you use non-essential cookies, you should provide clear, balanced choices between accept/reject and also store proof of the choice.
No. A cookie policy covers cookies/trackers specifically; a privacy policy is broader and covers personal data processing activities.

If you need a cookie banner template, consent logs, or a DSAR form to go with it, consent.vn can help standardize them under the same structure for easier technical implementation.

Source: the Personal Data Protection Law (Law 91/2025/QH15) (thuvienphapluat.vn); Decree 13/2023/ND-CP (thuvienphapluat.vn); Ministry of Public Security – Department of Cybersecurity and High-Tech Crime Prevention and Control (A05) (bocongan.gov.vn)

Access the full template library — no account needed.

Need more PDPL templates?

Get started