Article · June 17, 2026
Plausible, Fathom privacy analytics under PDPL: is consent needed?
Plausible and Fathom can still process personal data under PDPL. See when consent is needed, pros/cons, and safer implementation.
Quick answer
What are Plausible and Fathom privacy analytics under the PDPL?
Plausible and Fathom are often called privacy analytics because they do not use advertising cookies and reduce user identification. However, “cookieless” does not mean “no personal data processing” under the PDPL. If you measure pageviews, referrer, device, session duration, click events, or log IPs even when truncated, the system is still processing data that may relate to a specific individual or device.
For Vietnamese businesses, the right question is not “cookies or not,” but: what data is being collected, can it be linked to users, who is the controller/processor, and does the purpose go beyond internal measurement.
What data do Plausible and Fathom still process under the PDPL?
Both tools typically process some of the following data, depending on configuration:
- IP address or partially truncated/obfuscated IP
- User agent: browser, operating system, device
- Referrer: traffic source, referring page
- URL, pathname, click events, conversions
- Access time, frequency, sessions
- Technical browser data, language, screen resolution
If you enable event tracking tied to accounts, form submits, order IDs, email, phone number, or internal IDs, PDPL risk increases significantly because the data may directly identify users.
Is consent required when using Plausible or Fathom?
There is no “always yes” or “always no” answer for every configuration. Under the PDPL, businesses need to determine the processing purpose and an appropriate legal basis. For basic analytics, many teams choose to minimize data, remove direct identifiers, and only enable tracking after clearly informing users in the privacy notice and, if needed, via a consent banner.
In practice, if your website only measures aggregate usage, does not link events to personal identifiers, and is configured for data minimization, you may consider a “notice + opt‑out” model rather than requesting consent by default for all cases. But if analytics is combined with advertising, remarketing, identifiable A/B testing, or cross‑border data transfers under the vendor’s model, carefully evaluate consent requirements and transfer documentation under the PDPL.
Pros and cons of Plausible and Fathom from a PDPL perspective
| Criteria | Plausible | Fathom | |
|---|---|---|---|
| Level of “privacy‑friendly” | High; lean setup, less data | High; user‑friendly, minimalist | |
| Personal data may still arise | Yes, if IP, events, referrer, device are collected | Yes, if configured to track detailed behavior | |
| Ability to reduce reliance on cookie banners | Good | Good | |
| PDPL risk | Lower than traditional analytics but not zero | Similar; depends on configuration | |
| Fit for SMEs | Yes; easy for small and mid‑sized sites | Yes; suits marketing teams needing a simple dashboard |
A major advantage of these tools is reduced data collection, easier explanations to users, and generally less “consent fatigue” than cookie‑heavy analytics. The downside is that many teams mistakenly assume “no cookies = no legal considerations.” This can lead to inadequate notices, missing processing records, or enabling extra tracking beyond the original intent.
How to implement more safely under the PDPL
List the data actually collected:
check IP, referrer, events, device fingerprint, order ID, email, or any form fields being sent.
Minimize data:
disable unnecessary fields, avoid sending identifiers in analytics events, and shorten retention where possible.
Update your privacy notice:
state that you use Plausible/Fathom, the measurement purposes, data types, recipients, and retention periods.
Decide on consent per configuration:
if it’s minimal internal measurement, you may not need an ad‑tech‑style banner; if advanced tracking or cookies/IDs are used, obtain explicit consent.
Sign and keep records with the vendor:
review data processing terms, the parties’ roles, and any cross‑border transfer mechanisms.
Prepare a process for data requests:
who handles user requests to access, rectify, delete, object, or withdraw consent; by when; and with what tools.
Set up an incident process:
if logs or analytics dashboards are exposed, the business must notify the data breach within 72 hours of discovery as required.
Practical examples for SMEs in Vietnam
A D2C shop uses Fathom to measure traffic from Facebook, Google, and email campaigns. If it only looks at visits, referrers, and popular product pages, the risk is much lower than sending customer email addresses in a “purchase” event. But if the marketing team wants to attach orders to emails to calculate LTV directly in analytics, that system is no longer “just traffic measurement” and is closer to personal behavioral profiling.
Similarly, a SaaS using Plausible to measure a signup funnel can be safer if it only views the number passing through each step. But if account IDs are attached, the team needs to control internal access, set dashboard permissions, and standardize retention.
FAQ on Plausible, Fathom, privacy analytics, PDPL
- Not always. If you only use minimal analytics, do not use advertising cookies, and do not attach personal identifiers, notice requirements may be lighter. But you still need to assess the actual configuration and processing purposes under the rules.
- No. IP, user agent, referrer, events, and device data can still be personal data or data related to an individual depending on context.
- Typically lower in terms of collection and default settings, but not zero. Final risk depends on the data you send, how it’s stored, and how you inform users.
- You should still update the privacy policy, minimize data, and review whether consent is required. If there’s a log incident or exposed dashboard, handle it under your security process and notify as required within 72 hours.
If you’re standardizing a cookie banner, consent evidence storage, or DSAR workflows for sites using trackers/analytics, consent.vn can help your dev and legal teams streamline this work.
Source: the Personal Data Protection Law (Law 91/2025/QH15) and Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement authority Ministry of Public Security (A05) at bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?