Article · June 17, 2026

Heap and VWO under the PDPL: what to note about PII and consent

Heap and VWO under the PDPL: autocapture, PII, consent, cookie banners, evidence, and safe SME deployment.

consent.vn Editorial6 min read

Quick answer

Heap (autocapture analytics) and VWO (A/B testing) may trigger PDPL obligations because they automatically collect user behavior, which can capture PII or indirectly identifying data. Businesses should review purposes, classify data, design consent mechanisms, and store evidence as required.

How are Heap and VWO related to the PDPL?

Heap and VWO do not “automatically violate” anything, but how they are implemented often gives rise to personal data processing under the Personal Data Protection Law (Law 91/2025/QH15), expected to take effect 01/01/2026, replacing Decree 13/2023/ND-CP. If a tool collects every interaction, you must examine what it records, for what purpose, who can access it, and whether an appropriate legal basis is in place.

For SMEs, the common risk doesn’t lie in the name Heap or VWO, but in default configurations: autocapture of clicks, form fields, URLs, referrers, IPs, device IDs, session replay, and event properties. Just one form field containing an email/phone number, or a URL parameter exposing a customer ID, can create personal data that must be governed under the regulations.

How should “heap vwo product analytics experiment pdpl” be understood?

The phrase “heap vwo product analytics experiment pdpl” should be understood as: product analytics and experimentation tools are trackers that build user behavior profiles, so companies must determine which data is mandatory for operations, which data serves measurement/marketing, and which data is sensitive or can infer identity.

In practice in Vietnam, there are typically three situations:

  • An e-commerce website installs Heap to measure the funnel but accidentally captures search box content containing phone numbers.
  • VWO runs A/B testing on a registration form, but event tracking also reads the user’s prefilled values.
  • The product team exports data to a dashboard outside Vietnam without controlling cross-border data transfers as required.

If a tool creates data that can identify a person, or can be combined to identify a person, the company should treat it as personal data and handle it accordingly.

How do Heap and VWO create PII risks?

The main risk is “over-collection.” Heap tends to autocapture, so it can record more than is actually needed; VWO typically runs on live pages, so it can touch forms, CTAs, input content, and test data. Even if the objective is to optimize conversion, you must still ensure the principles of data minimization and purpose limitation as required.

Key areas to scrutinize:

  • Form fields: name, email, phone number, order code.
  • URL/query string: tokens, customer IDs, emails embedded in links.
  • Session replay: may reveal what users type if not masked.
  • Event properties: free-form content from textboxes, notes, feedback.
  • Metadata: IP, device, user ID, cookie ID, fingerprint, approximate location.

If you use analytics/experimentation tools for an e-commerce site, SaaS, or fintech, assume every tracker can create an “identifiable trace” and design for minimization from the outset.

ItemHeap (autocapture analytics)VWO (A/B testing)Typical PDPL obligations
ObjectiveMeasure behavior, funnel, retentionUX and conversion testingDefine processing purposes clearly
Common dataClicks, pageviews, forms, event propertiesVariants, events, form interactionMinimize and restrict access
PII riskHigh if everything is autocapturedHigh when testing on forms/live dataMask data, exclude sensitive fields
ConsentMay be required depending on purpose/cookiesMay be required depending on tracking/cross-siteDesign banners and record consent as required
Data transfersOften to external systemsOften to third-party platformsReview cross-border data transfers per regulations

Do businesses need user consent when using Heap and VWO?

Often it may be required, depending on the processing purpose and implementation. If it’s strictly for necessary operations, a different legal basis may apply; but when the tracker is used to deeply measure behavior, personalize, optimize marketing, or read cookies/device identifiers/IDs, you should design appropriate notice and consent mechanisms as required.

Important point: consent should not just be “continue browsing.” For websites in Vietnam, you should have a cookie banner or clear notice layer describing tracker groups, purposes, vendors, retention, and how to withdraw consent. Consent must be demonstrable, not just verbal.

  1. Map your trackers:

    list what Heap/VWO are collecting: pageviews, clicks, input, session replay, heatmaps, experiments, cookies, IDs.

  2. Classify data:

    flag which fields are PII, sensitive data, technical data, or inferential data that can identify someone.

  3. Configure minimization:

    turn off unnecessary autocapture, mask input fields, filter URL parameters, and block sensitive form fields.

  4. Design a consent banner:

    separate analytics, experimentation, and marketing; do not enable non-essential trackers by default.

  5. Store consent evidence:

    keep timestamp, banner version, user choices, and consent status per purpose.

  6. Vendor oversight:

    review DPA, subprocessors, storage locations, cross-border transfers, and access logs.

  7. Set up an incident process:

    if data is exposed, quickly assess impact and notify a data breach within 72 hours of detection as required.

What is a safe way for SMEs to deploy Heap and VWO?

The key is “measure without over-collecting.” For SMEs, the most practical approach is: enable trackers only on necessary pages, disable capturing of input content, use a pseudonymous ID if you need to link events, and avoid sending raw PII to third-party platforms.

Example: a shop uses VWO to test a “Buy now” button. There’s no need to send emails, phone numbers, or order data in events. Variant ID, a cleaned page URL, the click event, and a conversion flag are enough. If you want to analyze by user, use an internal hashed/pseudonymous ID per your policy.

If the product team wants to use Heap to understand drop-off in a sign-up form, configure masking for all input fields, remove query strings that contain customer IDs, and review sample sessions before wider rollout. This is where consent.vn often helps businesses set up cookie banners, store consent evidence, and manage DSAR more efficiently.

What if data leaks from Heap or VWO?

If an incident occurs, the company should activate the response process immediately, assess the scope of impact, isolate access, document the cause, and notify a data breach within 72 hours of detection as required. Serious violations may be subject to criminal liability; specific administrative penalties will follow the Government’s implementing decree when issued.

It can be used, but you must control collected data, processing purposes, cookies/IDs, masking, and consent mechanisms as required.
It often may be required if VWO uses cookies, device identifiers, or serves measurement/personalization beyond strictly necessary purposes.
Not always; it depends on purposes, data types, and the applicable legal basis under the regulations. Consult a lawyer if unsure.
Delete/obscure the data as soon as possible, review logs, fix URL filtering, and assess whether breach notification obligations arise.

Source: the Personal Data Protection Law (Law 91/2025/QH15), Decree 13/2023/ND-CP, Department of Cybersecurity and High-Tech Crime Prevention (A05) — thuvienphapluat.vn, bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started