Article · June 17, 2026

What happens if you skip a cookie banner under the PDPL?

Skipping a cookie banner risks losing consent evidence, PDPL noncompliance, and sanctions under guiding decrees.

consent.vn Editorial6 min read

Quick answer

Not implementing a cookie banner does not automatically mean a 'certain violation,' but you may lose evidence of consent, fail to demonstrate the purposes for collecting cookies, and increase the risk of being deemed non-compliant with the PDPL. If you transfer data or track users, you need mechanisms to inform, obtain consent, and store evidence.

What happens if you skip a cookie banner?

Skipping a cookie banner can make it hard to prove that users were informed and consented before cookies/trackers are activated, especially for advertising, analytics, remarketing, or behavioral collection cookies. Common consequences are loss of consent evidence, difficulty handling DSARs, risk of complaints, and scrutiny under the PDPL.

For e-commerce websites, ad-driven landing pages, SaaS with analytics, or apps/sites with tracking SDKs, a cookie banner is not just 'a popup.' It is part of your consent governance and proof-of-compliance mechanism.

What obligations does a cookie banner entail under the PDPL?

A cookie banner usually entails the following practical obligations:

  • Clearly disclose the types of cookies/trackers used: necessary, analytics, advertising, personalization.
  • State the purposes of processing: traffic measurement, experience optimization, remarketing, fraud prevention.
  • Let users choose: accept, reject, or configure by cookie category.
  • Do not activate non-essential cookies before having an appropriate legal basis.
  • Store evidence of consent: timestamp, banner version, the user's choices, IP/device ID if used for proof.
  • Provide a way to withdraw consent or change preferences.

The key point: under the rules, you must be able to prove that you processed data on a proper legal basis. Without a banner or consent logs, it is very hard to answer 'who consented, to what, and when' if asked.

Real-world risks if you skip the cookie banner

Consequences often don’t arrive immediately, but things can quickly 'fall apart' when an incident occurs.

ScenarioPractical riskCommon consequences
No cookie bannerCannot prove notice/consentLoss of compliance evidence, hard to explain during inspections
Banner exists but only an 'Accept' buttonConsent not explicit, may be deemed coercedCollected data may be contested for validity
Advertising cookies auto-enable firstCollection before a choice is madeRisk of violating data minimization and transparency principles
No consent logs keptCannot prove the user's choice historyHard to respond to complaints, DSARs, audits

Real-world example: an online shop runs Meta Pixel, Google Analytics, and a chatbot on the homepage. Without a banner and consent logs, marketing still gets numbers, but when a user asks 'what data are you collecting about me?' the company has no records to answer clearly. In a dispute, this is a major weakness.

Can you be penalized for not implementing a cookie banner?

You may be sanctioned under guiding decrees, but specific fine amounts are not fixed at this time. More importantly, serious violations may be subject to criminal liability under current law. Under the PDPL, the enforcement authority is the Ministry of Public Security — the Department of Cybersecurity and High-Tech Crime Prevention (A05).

In practice, the risks are not just 'a monetary fine.' Other consequences can be more severe:

  • being ordered to stop certain collection/measurement activities;
  • having to remediate, delete, or reconfigure tracking mechanisms;
  • loss of customer and partner trust;
  • difficulty passing security, compliance, or due diligence reviews during fundraising/M&A.

If you use cookies for advertising or profiling, treat this as a mandatory compliance item, not a 'nice-to-have later.'

When is a cookie banner practically mandatory?

As a matter of compliance practice, you should have a banner if your website/app does any of the following:

  • measure user behavior with analytics;
  • deploy advertising/remarketing pixels;
  • personalize content or ads;
  • share data with third parties;
  • track logins, sessions, devices, or click behavior.

If you only use truly necessary technical cookies for basic site operation, you should still provide clear notice. But for any non-essential cookie, the safe approach is not to activate it before an appropriate choice is made.

  1. Classify cookies/trackers:

    list each script, pixel, SDK, tag manager, and its purpose.

  2. Group them clearly:

    at minimum, necessary, analytics, advertising, personalization.

  3. Design a banner with real choice:

    allow accept/reject/configure, not just a single 'Accept' button.

  4. Block first, fire later:

    only activate non-essential cookies after the user has made an appropriate choice.

  5. Store evidence of consent:

    record timestamp, content version, choices, and consent source.

  6. Provide a reversal mechanism:

    let users reopen cookie settings and withdraw consent.

  7. Review periodically:

    whenever you add a pixel, A/B testing tool, or new chatbot, revisit the banner and logs.

What should SMEs do now?

If you are an SME, keep it lean but correct:

  • audit all cookies/scripts on the website;
  • remove unused tags;
  • update your privacy notice and cookie notice;
  • deploy a banner that logs consent;
  • check whether third-party vendors share data;
  • prepare processes to handle access/deletion requests.

If you use many marketing tools, prioritize a consent management mechanism that can prove the choice history. Consent.vn can help with the cookie banner, storing consent evidence, and DSAR workflows so dev/marketing teams can operate more easily.

Not every case is fined immediately, but you risk being seen as lacking proof that you provided notice and obtained consent as required, especially for advertising and behavioral tracking cookies.
Generally yes, because analytics involves tracking behavior and collecting access data. If used, you should clearly disclose the purposes and keep consent evidence as required.
Usually not sufficient if non-essential cookies/trackers run before the user makes a choice. The privacy policy is notice; the banner/consent mechanism is the operational consent step.
Necessary technical cookies may be handled differently from advertising cookies, but transparent notice is still recommended. Separate necessary from non-essential cookies clearly.

Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn ; Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; Ministry of Public Security (A05): https://bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started