Template · June 17, 2026
Template: Essential, analytics, marketing, personalization cookies
Template text for banners and preference centers: essential, analytics, marketing, personalization cookies; PDPL notes effective 01/01/2026.
Edit & copy
This is a reference template. Consult a legal advisor before using in production.
Quick answer
What is the template for essential, analytics, marketing cookie group descriptions?
This is a ready-made set of (short/long) descriptions for each common cookie group to plug into your banner and preference center. Under the rules, non-essential cookies (analytics, marketing, personalization) should only be set after obtaining consent; essential cookies may be enabled by default.
-
Essential group (Essential)
- Short description (banner): "Essential: Required for the website to function (login, cart, security). Cannot be turned off."
- Detailed description (preference center): "This cookie group enables basic functions such as page navigation, maintaining login sessions, shopping carts, load balancing, and protection against fraud. Not used for advertising or behavioral analytics. Disabling this group may cause the website to malfunction."
- Example cookies/providers: PHPSESSID, JSESSIONID, cart_id, csrf_token (1 session–1 day); Load balancer (e.g., AWSALB) (7 days).
-
Analytics group (Analytics)
- Short description (banner): "Analytics: Measure traffic and performance to improve the product. Only enabled with your consent."
- Detailed description (preference center): "We use cookies/similar technologies to count visits, events, and traffic sources in order to improve the experience. Where possible, we reduce identifiability (e.g., IP anonymization) and only deploy after you consent. You can withdraw your consent at any time in the preference center."
- Example cookies/providers: Google Analytics 4 — _ga (2 years), ga* (2 years), _gid (24 hours); Hotjar — hjSession* (30 minutes). Retention may vary by provider.
-
Marketing/Advertising group
- Short description (banner): "Marketing: Personalize ads and measure conversions across platforms. Only enabled with your consent."
- Detailed description (preference center): "These cookies/IDs help show relevant ads, measure campaign effectiveness, and avoid ad repetition. Data may be shared with advertising partners. Under the rules, we only activate these after your explicit consent, and you can turn them off at any time."
- Example cookies/providers: Meta Pixel — _fbp (90 days), fr (90 days); Google Ads — _gcl_au (90 days), _gcl_dc (90 days); TikTok Pixel — _ttp (13 months), _ttcid (13 months).
-
Personalization group (Personalization)
- Short description (banner): "Personalization: Remember choices (language, region) and suggest relevant content. Only enabled with your consent."
- Detailed description (preference center): "Helps remember your settings (language, currency), content you viewed, and display suitable recommendations. Not used to track you outside our website. Only activated with your consent and can be changed at any time."
- Example cookies/providers: locale (1 year), currency (30 days), last_viewed (7 days), recs_id (30 days).
Note: Cookie names/retention are examples; you must audit the actual inventory on your website/app.
How do I use this template for the banner and preference center?
Place the “short descriptions” in the banner (alongside toggle controls) and the “detailed descriptions” in the preference center. Under the rules, do not set/trigger non-essential tags before obtaining consent; allow users to withdraw consent easily.
Inventory & classify:
List all cookies/SDKs/tags in use; assign each to the 4 groups above, noting provider and retention.
Configure the banner:
Show 4 groups with short descriptions; keep the Essential group enabled by default, others off by default until users consent.
Tag firing conditions:
Apply a “consent=true” condition by group in your TMS (GTAG/GTManager, Segment...) before firing analytics/marketing/personalization tags.
Preference center:
Provide detailed descriptions, vendor lists, and allow changes anytime; record consent evidence (timestamp, banner version, choices).
Devices/SDKs:
For mobile SDKs (Firebase, Appsflyer...), delay initialization/collection until consent; synchronize choices between web–app if feasible.
Legal review:
Under the PDPL, obtain explicit consent for processing non-essential personal data; disclose purposes and data recipients. When purposes change, re-obtain consent.
What are the PDPL legal notes when using cookies?
Practitioner summary for SME/dev: cookies are technical tools; obligations arise when personal data is processed. Under the rules, non-essential cookies/IDs should only be activated after explicit consent; you must state purposes, data types, third parties, and retention.
- Effective date: the Personal Data Protection Law (Law 91/2025/QH15) takes effect on 01/01/2026, upgrading Decree 13/2023/ND-CP. Enforcement authority: Ministry of Public Security (A05).
- Consent: Do not set analytics/marketing/personalization cookies before consent; provide a mechanism to withdraw and manage choices.
- Sharing with third parties: If you use advertising/measurement platforms, disclose recipient lists, purposes, and legal bases as required; consider data processing agreements.
- Data breaches: If personal data related to cookies/IDs is leaked/exposed, notify within 72 hours as required.
- Penalties: Administrative fines apply under Government guidance; severe violations may lead to criminal liability.
- Specific tools: No tool is automatically “illegal”; obligations depend on implementation and actual data. Consult a lawyer when needed.
What is a prefilled example for a Vietnamese e-commerce website?
You can paste the following snippets directly into your CMP:
-
Essential (short): "Essential cookies keep login sessions, shopping carts, and security. Cannot be turned off."
-
Essential (long): "Ensure core functions such as checkout, fraud prevention, and load balancing. Not used for advertising or analytics. Example: PHPSESSID (session), csrf_token (1 day)."
-
Analytics (short): "Enable measurement of traffic, sources, and product performance. Only enabled with your consent."
-
Analytics (long): "Used to count pageviews, purchase events, and effective marketing channels. We configure reduced identifiability where feasible (e.g., IP anonymization). Example: _ga (2 years), _gid (24 hours), hjSession* (30 minutes)."
-
Marketing (short): "Helps personalize ads and measure conversions across platforms. Only enabled with your consent."
-
Marketing (long): "Supports delivery of relevant ads and measurement of campaign performance. Data may be shared with advertising partners as disclosed. Example: _fbp (90 days), _gcl_au (90 days), _ttp (13 months)."
-
Personalization (short): "Remember choices (language, region) and display relevant content. Only enabled with your consent."
-
Personalization (long): "Store language, currency, and viewed products to show suitable recommendations. Not tracking you outside this website. Example: locale (1 year), last_viewed (7 days)."
| Group | Enabled by default | Requires consent first | Example vendors | |
|---|---|---|---|---|
| Essential | Yes | No | Cart systems, payment gateways, load balancers | |
| Analytics | No | Yes | Google Analytics, Hotjar | |
| Marketing | No | Yes | Meta Pixel, Google Ads, TikTok Pixel | |
| Personalization | No | Yes | Product recommendation tools, A/B testing |
Need to automate the cookie banner, store consent evidence, and handle data subject rights requests (DSAR)? Consider consent.vn.
Source: the Personal Data Protection Law (Law 91/2025/QH15), Decree 13/2023/ND-CP, Ministry of Public Security (A05)
Access the full template library — no account needed.
Need more PDPL templates?