Guide · June 17, 2026

What are the conditions for valid consent under the PDPL?

Learn the 4 conditions for valid PDPL consent: voluntary, specific, informed, clear, with invalid examples.

consent.vn Editorial6 min read

Quick answer

For consent to be valid under the PDPL, businesses must ensure four elements: voluntary, specific, sufficiently informed, and clearly expressed. If a checkbox is pre-ticked, the notice is vague, or multiple purposes are bundled into a single “Agree” button, it likely does not meet the requirements.

What are the conditions for valid PDPL consent?

Consent is only considered valid when users truly understand what data processing they are accepting, for what purpose, by whom, and whether they have the right to refuse or withdraw. Under the Personal Data Protection Law (Law 91/2025/QH15), businesses cannot “ask for it just to have it” and treat that as a sufficient legal basis.

In practice, for e-commerce websites, ride-hailing apps, SaaS or CRM, consent is often used for marketing, sharing data with partners, or collecting sensitive data. Therefore, the consent template needs to be designed as a standalone legal step, not buried inside dozens of pages of general terms.

When is consent considered voluntary?

Voluntary means users can choose to consent or not without being forced by unreasonable conditions. If refusing still results in being blocked from unrelated services, or if consent is presumed in order to continue using basic functions, voluntariness may be in doubt.

Real-world example: an appointment-booking app requires patients to consent to receive advertising from partners before they can book an appointment. This should not be considered voluntary, because advertising is not a necessary condition for providing basic healthcare services.

When is consent considered specific?

Specific means consent must be tied to each clear processing purpose, and cannot be lumped together as “consent to all activities.” Users must know which data will be used for customer care, which for marketing, and which for behavioral analytics.

Example: instead of writing “I consent to the Company processing personal data to improve the experience,” split it into:

  • Consent to receive promotional emails
  • Consent to share my phone number with the delivery provider
  • Consent to use cookies for behavioral analytics

The clearer the separation, the easier it is to prove the consent is for specific purposes.

When is consent considered informed?

Informed means that before users click agree, the business must provide at least information about processing purposes, data types, data recipients, retention period, data subject rights, and how to withdraw consent. If the information sits inside a policy that is too long, hard to understand, or hard to find, then in practice the user has not been adequately informed.

Poor example: a popup that only says “We use data to improve service quality” but does not specify which data, to whom, how long it is stored, or whether it is transferred abroad. This description is too generic and high-risk.

When is consent considered clear?

Clear means the act of consenting must express a definite, verifiable intent. Typically this is clicking an “Agree” button, ticking an unticked checkbox, or signing/e-confirming under a process with audit logs. Silence, continued scrolling, or default/assumed consent should generally not be used as the sole basis.

For digital products, the engineering team should retain the timestamp, policy version, consent content, and the source of the consent. This is very useful when demonstrating compliance, especially in the event of complaints or inspections by competent authorities.

  1. Separate each processing purpose:

    Don’t bundle advertising, partner sharing, and analytics into a single checkbox.

  2. Write a short, sufficient notice:

    State what data, for what purpose, who receives it, retention period, and the right to withdraw.

  3. Use clear affirmative action:

    Unticked checkbox, clearly labeled button, or a verifiable e-signature.

  4. Store proof of consent:

    Record the time, content version, IP/device where appropriate, and the consent status.

  5. Make withdrawal as easy as giving consent:

    Provide an unsubscribe for marketing, privacy settings, or a DSAR channel.

What are examples of invalid consent under the PDPL?

Below are common but high-risk patterns:

Scenario Why it may be invalid
Pre-ticked checkbox Does not reflect a clear expression of the user’s intent
“Agree to everything” in a single button Not specific to each processing purpose
Long policy with no summary Users have not been adequately informed
Requiring ad consent to use core services Indicates a lack of voluntariness
No way to withdraw consent Fails to meet proper consent management requirements

Another example: an e-commerce website only displays a banner saying “By continuing to use, you consent to our policy.” If this banner does not specify which cookies are necessary versus those used for marketing, and does not offer a refuse option, this is not a good consent pattern.

What should businesses do to avoid “illusory” consent?

If your business runs a website, app, or CRM, check three layers: the consent UI, the notice content, and the system for storing evidence. Many product teams only tweak the cookie banner and forget backend logs, making it impossible to prove consent during reconciliation.

A practical approach is to manage consent by channel: cookies on the website, marketing consent on signup forms, and a separate checkbox for sharing data with third parties. If you are building a dashboard or cookie banner, consent.vn can help you design a cleaner flow for consent evidence and DSAR.

Four elements: voluntary, specific, informed, and clear. Missing any of these four puts the consent at risk of not meeting the requirements.
It should not be treated as valid consent because the user has not clearly expressed intent. Leave the checkbox empty and require an active confirming action.
Not recommended. It’s better to separate by purpose to ensure specificity and easier proof.
Yes. Under the rules, businesses must allow easy withdrawal of consent and record that withdrawal.

Source: the Personal Data Protection Law (Law 91/2025/QH15) on thuvienphapluat.vn; Decree 13/2023/ND-CP on thuvienphapluat.vn; enforcement authority Ministry of Public Security (A05) on bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started