Article · June 17, 2026
Braze customer engagement and PDPL: how to comply?
Using Braze for segmentation, push, in-app? How to handle marketing consent, customer profiles, and PDPL duties for Vietnamese businesses.
Quick answer
What is Braze customer engagement under the PDPL?
Braze customer engagement under the PDPL asks whether using Braze to manage customer profiles, segment audiences, and send push/in-app/email/SMS complies with the Personal Data Protection Law. The practical answer is: compliance depends on how you collect, store, share, and activate data, not merely on the tool itself.
If you use Braze to aggregate user behavior, build segments from purchase history, app opens, push clicks, or to synchronize data from a CRM/CDP, you are processing personal data under the law. That entails requirements for notices, clear purposes, data minimization, and consent management for each marketing channel.
Do customer profiles in Braze trigger PDPL obligations?
Yes. When you load data into Braze, businesses typically create or enrich customer profiles with fields such as phone number, email, device ID, in-app behavior, purchase history, and subscription status. These fields can be personal data, and in some cases can result in very detailed behavioral profiles.
The key point is that Braze is often used to unify data from multiple sources: app, website, POS, customer service, marketing automation. Therefore, the business must define the purpose of each data stream: transactional servicing, content personalization, marketing segmentation, or campaign measurement. Each purpose may require its own legal basis and notice under the regulations.
Does customer segmentation in Braze require consent?
It may, depending on the data and purpose. Segmentation to operate a core service can differ from segmentation for multi-channel marketing. If you use sensitive behaviors, infer deep preferences, or combine multiple sources for advertising/personalization, you should check the legal basis and evidence of consent.
A real-world example: a retail app groups “customers who purchase 3 times/month,” “customers who opened push but haven’t bought,” “customers with high order value” to send offers via push and email. Without transparent notice and appropriate consent for marketing purposes, the business will struggle to demonstrate that the processing is compliant.
| Situations in Braze | Common PDPL obligations | Practical tips | |
|---|---|---|---|
| Send push to remind about an order | Purpose notice, data minimization | Use only data necessary for the transaction | |
| Segmentation for marketing | Determine legal basis/consent as required | Separate consent by channel where possible | |
| Sync CRM to Braze | Control data sharing with vendors | Sign a data processing agreement with the vendor | |
| Track in-app behavior | Be transparent about tracking and profiling | Update the privacy notice, keep event logs |
How should multi-channel marketing consent be designed in Braze?
Design it per channel and per purpose, not as a single “consent to all” toggle. With Braze, businesses often run email, SMS, push notifications, in-app messages, and sometimes WhatsApp/Zalo OA via other systems. Each channel has different characteristics and risks, so consent capture should be separated accordingly.
In practice you should have: 1) consent for marketing via email; 2) consent for SMS/ZNS/push; 3) consent for behavior-based personalization; 4) an easy withdrawal mechanism. It’s important to record the timestamp, notice text, policy version, and consent source so you can prove it during audits.
Inventory data sources:
List all fields pushed into Braze from app, web, CRM, customer service, POS and identify which are mandatory and which are marketing-only.
Attach a purpose to each stream:
For every event/segment/campaign, specify the processing purpose: transaction, servicing, analytics, or marketing.
Separate consent by channel:
Create distinct checkboxes for email, SMS, push, in-app if you use them for multi-channel marketing.
Store consent evidence:
Record user ID, timestamp, consent text, capture source, IP/device if needed, and the applicable policy version.
Set up withdrawal mechanisms:
When users unsubscribe or opt out, sync this status to Braze immediately to stop sending on the right channel.
Control vendors and data transfers:
Review contracts, data flows, and storage locations; if there is cross-border transfer, handle it per the regulations.
Is Braze a tracker under the PDPL?
Braze can trigger obligations similar to a tracker/measurement SDK because it records app opens, clicks, sessions, campaign responses, and user behavior. You shouldn’t conclude the tool is “illegal”; instead, assess what it collects, whether it is covered by your notices, and whether it is used for profiling/marketing.
For example, if your app integrates the Braze SDK to learn how often users open the app and which CTAs they tap, then uses that data to personalize offers, you should update your privacy notice, manage consent, and check third-party data sharing per the regulations. If the data passes through infrastructure hosted outside Vietnam, the business should also review the related obligations.
What should businesses prepare before 01/01/2026?
The Personal Data Protection Law (Law 91/2025/QH15) is expected to take effect from 01/01/2026 and will replace Decree 13/2023/ND-CP. For Braze, the best preparation is to clean up data, standardize consent, and establish procedures for handling customer requests before the new law fully applies.
Three actions to take now: inventory data fields in Braze; rewrite the privacy notice to reflect your multi-channel marketing flows; and set up processes to respond to users’ access/deletion/consent-withdrawal requests. If you use Braze alongside a CRM/CDP, also check any bidirectional syncs to avoid “losing track” of consent in one system.
If your engineering team needs a quick implementation, consent.vn can help with a cookie banner, consent evidence storage, and internal DSAR flows—especially when you run trackers/SDKs and marketing automation tools in parallel.
- Yes, separate by channel and purpose, especially when used for marketing. This helps the business demonstrate consent more clearly under the regulations.
- It can, if you infer behavior, preferences, or customer value from personal data. In that case, review notices, legal bases, and user rights per the regulations.
- The business must check data transfer flows and related obligations under the regulations; consult a lawyer if your processing architecture is complex.
- Specific penalties will be set by the Government’s implementing decrees; serious violations may be subject to criminal liability.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP; Ministry of Public Security (A05) (thuvienphapluat.vn, bocongan.gov.vn)
Get started — no account needed.
Ready to comply with PDPL?