Article · June 17, 2026

OneSignal push under the PDPL: Are device tokens personal data?

OneSignal tokens and web/app push under the PDPL: when consent is needed, proof logging, and an SME compliance checklist.

consent.vn Editorial7 min read

Quick answer

OneSignal uses device tokens to send push notifications, so under the PDPL, tokens and data tied to a device/user may be personal data. If used for marketing, you need an appropriate legal basis, typically explicit, demonstrable consent, and you must manage opt-out rights.

What does OneSignal push notification mean under the PDPL, and why should businesses care?

Push notifications with OneSignal are not just “sending messages” but also personal data processing if you collect device tokens, browser identifiers, app IDs, or tie the action of opening a message to a specific user. For Vietnamese businesses, the question is not which tool you use, but what you collect, what you use it for, and what legal basis you rely on under the PDPL.

Real-world example: an e-commerce marketplace enables OneSignal to send a “9 p.m. flash sale” to people who previously viewed products. If the system stores subscription tokens, segments by behavior, and links them with an email/phone number, this is no longer merely anonymous messaging.

Are device tokens in OneSignal personal data?

They may be personal data under the PDPL if the token or related information can be used to identify, distinguish, or link to a specific individual. In practice, web/app push tokens often do not “speak a user’s name” by themselves, but they are a technical identifier to target a device or a user session.

Points to note:

  • Device tokens, push subscriptions, player IDs, device IDs may be personal data when linked with an account, email, phone number, or behavioral history.
  • Event data such as notification opens, clicks, unsubscribed can also create a behavioral profile.
  • If you sync OneSignal with a CRM/CDP, compliance risk increases because the data becomes more “identifiable.”

Under the Personal Data Protection Law (Law 91/2025/QH15), businesses should assess the role of each data type and the processing purposes before enabling tracking or segmentation.

When is consent required for marketing notifications?

If you use push notifications for advertising, promotions, upsell, cross-sell, or remarketing, treat this as marketing activity and design a clear consent mechanism per the rules. Do not assume that a user installing the app or granting browser permission equals blanket consent for marketing.

Common scenarios:

  • Transactional notifications: order confirmations, shipping status, password resets. These are service notifications and do not equate to marketing consent.
  • Marketing notifications: flash sales, upsell suggestions, personalized campaigns. Should have a separate opt-in.
  • Behavior-based push: cart abandonment, product views, returning to the app. If used to promote, assess the legal basis and the potential need for separate consent.

Best practice for SMEs is to separate at least two streams:

  1. Opt-in for service notifications.
  2. Separate opt-in for marketing notifications via push.

What should businesses do with OneSignal to reduce PDPL risk?

You don’t need to drop OneSignal; you need to design proper consent flows, store evidence, and make it easy for users to opt out. Below is a practical checklist for web/app.

  1. Identify processing purposes:

    clearly state whether you use push for transactional or marketing notifications, and whether you personalize.

  2. Split consent by purpose:

    create a separate checkbox for marketing; do not bundle with terms of use or an “agree all” button.

  3. Store proof of consent:

    record timestamp, consent text/version, capture source, and opt-in/opt-out status.

  4. Configure OneSignal to the right scope:

    sync only necessary attributes; avoid sending PII if not needed.

  5. Design easy refusal mechanisms:

    unsubscribe link, toggle off push in-app, or a preference center.

  6. Vet vendors and data flows:

    see where data goes, who processes it, whether there is cross-border transfer, and update internal records as required.

Example consent copy for an app:

“I agree to receive promotional offers and personalized content via push notifications from [Company name]. I can turn this off at any time in Settings.”

Example for web:

“Allow browser notifications for deals, new products, and cart reminders. I understand these are marketing notifications and I can opt out later.”

OneSignal push notifications and the PDPL: what to note about storage and data sharing?

When OneSignal receives a token or open/click events, treat that as part of the personal data processing lifecycle. This entails internal management obligations, not just toggling a feature on or off.

Points to check:

  • Whether you store tokens in your own systems, and for how long.
  • Whether tokens are synced with emails, phone numbers, or internal UIDs.
  • Whether staff access to the OneSignal dashboard is permissioned.
  • Whether you have a mechanism to delete tokens when users unsubscribe, delete their account, or withdraw consent.
  • Whether you record third-party vendors and the purposes of data sharing.

If a data leak occurs involving tokens, recipient lists, or targeting configurations, businesses should assess the impact and notify of a data breach within 72 hours of discovery as required.

Comparison table: service notifications vs marketing notifications via push

CriteriaService notificationsMarketing notifications
PurposeTransaction confirmations, shipping reminders, account securityPromotions, upsell, remarketing
Device tokenMay be used to send necessary notificationsMay be used to target marketing
Separate consent required?Depends on processing structure and internal policyShould have separate, clear consent
User opt-outOften affects service utilityMust have an easy-to-find opt-out
NotesShould not “mix” with marketingShould store evidence of consent

What should Vietnamese businesses do today?

If you’re using OneSignal for web/app, check these four items first:

  • Whether you separate service and marketing notifications.
  • Whether you have a dedicated consent form for push marketing.
  • Whether you store evidence of consent and opt-out history.
  • Whether you have reviewed token data, device IDs, and sharing flows with vendors.

For SMEs, a cookie banner or a preference center alone isn’t enough; you also need processes to record consent and handle DSARs, especially if push notifications are connected to email, a CRM, or a CDP. consent.vn can help you standardize cookie banners, store consent evidence, and DSAR workflows so your dev team can implement faster.

If you use push for marketing, you should have separate, clear, and demonstrable consent as required. For service notifications, assess according to the specific processing purpose.
Possibly. When a token, device ID, or player ID is linked with an account, email, phone number, or user behavior, it is often considered personal data depending on the processing context.
Not necessarily. The browser permission is only a technical permission to send notifications. If the content is marketing, you should still have consent or another appropriate legal basis under the rules.
You should check the opt-out flow, update the status immediately, and if the incident involves personal data or a misconfiguration causing risk, assess your incident-handling and notification obligations within 72 hours of discovery as required.

Source: the Personal Data Protection Law (Law 91/2025/QH15) thuvienphapluat.vn; Decree 13/2023/ND-CP thuvienphapluat.vn; Ministry of Public Security (A05) bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started