Article · June 17, 2026
Klaviyo email & SMS marketing under the PDPL: how to comply
Klaviyo stores data in the US and tracks behavior. Opt-in and data transfers under the PDPL: what should businesses prepare?
Quick answer
What is Klaviyo email and SMS marketing under the PDPL and why should businesses care?
Klaviyo is an email and SMS marketing platform that typically stores customer profiles, shopping behavior, website events, and opt-in status to automate campaigns. Under the Personal Data Protection Law (Law 91/2025/QH15), these data usually trigger obligations around notice, consent, purpose limitation, security, and cross-border data transfers if the servers/providers are located in the US.
For Vietnamese SMEs, the risk is not in “using Klaviyo” but in how you configure it: do the email/SMS collection forms clearly state the purpose, is tracking enabled before consent, is data shared with third parties in line with the rules, and can you retain consent history as evidence when asked?
Klaviyo and the PDPL: what obligations typically arise?
If you use Klaviyo for email & SMS marketing, the common obligations under the rules include:
- Provide notice and obtain appropriate consent when collecting emails, phone numbers, web browsing behavior, and purchase history for marketing.
- Separate purposes between order fulfillment, customer care, and marketing.
- Keep opt-in evidence: timestamp, source, consent content, IP/device if needed for proof.
- Manage cross-border data transfers if Klaviyo or related providers store/process in the US.
- Allow easy withdrawal of consent and opt-out in email/SMS.
- Have a process to handle data subject rights such as access, deletion, objection to marketing, and restriction of processing as required.
If you also use pixels, event tracking, or CRM sync with Klaviyo, check which data are directly identifying, which are behavioral, and whether you have an appropriate lawful basis for processing.
What issues arise with behavioral tracking in Klaviyo under the PDPL?
Behavioral tracking is often the most problematic because many companies enable events like Viewed Product, Added to Cart, Started Checkout, Placed Order by default and only think about consent later. Under the rules, you should not assume all tracking is merely “for internal purposes.” If the data are used for profiling, personalization, or marketing, the business must determine a processing basis and clearly inform users.
Practical example: a Vietnamese shop implements Klaviyo onsite tracking to see which products a visitor viewed, then sends cart reminder emails. If the cookie banner only has a generic “OK” and offers no appropriate choices for marketing tracking, that collection may lack a clear consent basis under the rules. In that case, the business should separate:
- tracking necessary for website/ordering operations;
- tracking for marketing/personalization;
- scripts that only run after obtaining appropriate consent.
How should you handle email and SMS opt-in with Klaviyo?
For email and SMS, the safe approach is to design opt-in for each channel and each purpose. Avoid bundling everything into a single checkbox if you will use it for different types of communications afterward.
Separate checkboxes by channel:
email marketing and SMS marketing should have separate checkboxes, not pre-ticked by default.
State the consent content clearly:
specify who is sending, what will be sent, over which channels, approximate frequency, and how to unsubscribe.
Keep consent evidence:
record the timestamp, form source, the content shown at the time of consent, and double opt-in status if any.
Sync into Klaviyo:
map the consent status to profile fields/tags so the system only sends to those who have opted in.
Enable easy withdrawal:
include an unsubscribe link in emails, use the STOP keyword in SMS where appropriate, and update the status immediately.
Review regularly:
check lists imported from CSV, landing page forms, pop-ups, and integrations with Shopify/WooCommerce/CRM.
What to note when transferring data to the US via Klaviyo?
If Vietnamese customer data are transferred to the US via Klaviyo, the business should treat this as a cross-border data transfer under the rules and prepare corresponding documentation. The key is not to rely solely on the provider’s terms of service, but to manage it from the business side: what data types are transferred, for what purposes, who the recipients are, retention time, protection mechanisms, and processes for handling data subject requests.
In practice for SMEs, you should maintain at least an internal dossier including: an inventory of data sent to Klaviyo, integration descriptions, your privacy notice, consent logs, and a contact responsible for providing explanations when the A05 or customers request them. The enforcement authority is the Ministry of Public Security — Department of Cybersecurity and High-Tech Crime Prevention (A05).
What checklist should businesses prepare before using Klaviyo?
The table below is a practical checklist for marketing, dev, and legal teams:
| Item | What to do | Practical tip |
|---|---|---|
| Privacy notice | State purposes for email/SMS, tracking, data sharing | Place a link right on the signup form |
| Consent logs | Keep evidence of consent | Record timestamp, source, content |
| Cookie/tracking banner | Categorize by purpose | Do not fire marketing tags before consent |
| Import data | Review sources of email/SMS lists | Do not import purchased/scraped lists from unknown sources |
| Unsubscribe | One-click opt-out | Sync immediately into Klaviyo |
| Data transfer | Record data transferred to the US | Keep recipient, purpose, and retention descriptions |
| DSAR | Have a process to respond to data requests | Export/delete/update as required |
Can violations involving Klaviyo be penalized?
Yes. Specific fines will follow the Government’s implementing decree; exact amounts are not fixed in the law yet. For serious violations, businesses may also face criminal liability as provided by law. Therefore, if you run email/SMS at scale or have multiple data flows from web, app, and CRM, review immediately before expanding campaigns.
If needed, consent.vn can help businesses design cookie banners, retain consent evidence, and DSAR processes for use with Klaviyo in a more practical way for SMEs.
- With email/SMS marketing and tracking for personalization, businesses should obtain clear consent under the rules; do not rely on vague blanket consent.
- If data are stored/processed on infrastructure in the US, businesses should treat this as a cross-border transfer and prepare documentation, notifications, and controls as required.
- Usually yes, if tracking serves marketing, profiling, or personalization. You need to categorize scripts and only run those requiring consent after the user agrees.
- Not enough if the system still syncs to CRM, CDP, or other tools. The business must update the opt-out status across all related flows as required.
Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn ; Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; Ministry of Public Security (A05): https://bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?