Article · June 17, 2026
Taboola, Outbrain native ads under the PDPL: what to do?
Taboola, Outbrain and native ads under PDPL: cookies, tracking, prior consent, evidence logging, and an SME checklist.
Quick answer
What does “Taboola/Outbrain native ads under the PDPL” mean?
“Taboola/Outbrain native ads under the PDPL” refers to using content ad networks that attach trackers to personalize article recommendations, measure conversions, and optimize delivery. The issue is not “native ads” themselves, but which cookies, pixels, scripts, or SDKs are collecting what data, for which purposes, and whether prior consent is required.
Do Taboola and Outbrain cookies require consent before loading?
They may, if the cookies or trackers are used for behavior analytics, ad personalization, or sharing data with third parties. Under the PDPL, businesses should treat advertising/personalization trackers as a group that requires transparent notice and often prior consent before activation, unless an exception applies under the law. When unsure, ask counsel to review your data flows and consent documentation.
How do Taboola and Outbrain track user behavior?
Native ad platforms typically record impressions, clicks, reading time, pages viewed, device, truncated IP or browser identifiers to infer interests. For Vietnamese businesses, this means you are not just “embedding a related-articles widget” but also managing a data processing chain: cookie banner, consent logs, vendor list, data processing agreements, and a mechanism to withdraw consent.
What should businesses do to use native ads in compliance with the PDPL?
Follow this process before enabling Taboola, Outbrain, or similar native ad networks:
Inventory trackers:
List all scripts, pixels, cookies, SDKs from Taboola, Outbrain and related vendors on the website/app.
Classify purposes:
Separate necessary cookies, analytics, content personalization, advertising, conversion measurement.
Block before consent:
Do not load advertising/personalization trackers before the user opts in, if prior consent is required.
Update notices:
Clearly state who receives the data, processing purposes, retention period, and how to withdraw consent.
Keep evidence:
Record timestamp, banner version, user choices, and configuration change logs.
Review vendors:
Sign contracts with providers, clarifying controller/processor roles per your actual deployment model.
Set up an incident process:
If a data breach occurs, trigger assessment and notify within 72 hours from detection.
If you only embed a “related articles” widget, do you still need to worry about the PDPL?
Yes. Many teams think a native ads widget is just a “content block”, but in reality it may load from a third-party domain, set identification cookies, and send behavioral data back to an ad system. If the widget only shows static content, the risk is lower; if it personalizes based on behavior, you almost certainly need to treat it like an advertising tracker and manage consent accordingly.
Technical checklist for developers and SMEs
Here is a practical implementation checklist:
| Item | What to do | Practical notes |
|---|---|---|
| Cookie banner | Separate “necessary” and “advertising/personalization” groups | Do not enable ad scripts before an appropriate choice is made |
| Tag manager | Use rules to fire Taboola/Outbrain only after consent | Test refresh, logout, and preference-change cases |
| Consent log | Store user ID/anonymous ID, timestamp, banner version | Supports compliance audits and disputes |
| Privacy notice | Describe trackers, purposes, third parties, and how to withdraw | Keep it concise but specific |
| Vendor review | Identify where data is sent and how long it is kept | You may need a DPA/data processing agreement |
| DSAR | Prepare processes for access, deletion, and consent withdrawal requests | Integrate with CRM, analytics, and ad platforms |
What are the consequences of non-compliance?
Specific fines will be set by a Government guiding decree, so do not lock in numbers yet. In addition to administrative penalties under the guiding decree, serious violations may also incur criminal liability as provided by law. The relevant enforcement authority is the Ministry of Public Security, including the Department of Cybersecurity and High-Tech Crime Prevention (A05).
Any easy-to-apply examples for news or e-commerce sites?
Yes. For example, a news website uses Taboola to suggest “You may like” articles. If the cookie banner allows “Analytics” but “Advertising” is not enabled, the engineering team must ensure the Taboola script does not run until the user opts in. If the user declines, the widget can switch to a non-personalized version or static content, depending on your configuration and legal documentation.
- Not in every scenario, but if a tracker is used for advertising, personalization, or sharing data with third parties, you generally need to obtain consent before loading under the rules.
- Usually not. If a cookie serves personalization, measurement, or advertising, it should be separate from the necessary group and handled with its own consent.
- Yes, if you rely on a consent mechanism for trackers. You should keep logs of choices, banner version, and timestamps to demonstrate compliance.
- Within 72 hours from detection, under the data breach notification rules.
If you are auditing cookie banners or consent logs for Taboola/Outbrain, consent.vn can help design consent flows, evidence logging, and DSAR in an SME-friendly way.
Source: the Personal Data Protection Law (Law 91/2025/QH15) (https://thuvienphapluat.vn); Decree 13/2023/ND-CP (https://thuvienphapluat.vn); Department of Cybersecurity and High-Tech Crime Prevention - A05 (https://bocongan.gov.vn)
Get started — no account needed.
Ready to comply with PDPL?