Authors: Tran Thi Bao Tram – Lawyer, Nguyen Dinh Sac – Paralegal.
In business activities, especially on digital platforms, the collection, use and sharing of personal data of customers requires compliance with regulations on personal data protection and consumer rights protection. These requirements need to be considered by businesses throughout the process of providing products and services, from developing terms of use and privacy policies to establishing a mechanism for obtaining consent and resolving customer requests.
On the basis of the legal framework currently in force, this article by CDLAF Law Company Limited (“CDLAF”) analyze the responsibilities of enterprises in protecting personal data and consumers rights, forcusing on the effective conditions of consent, the legality of the terms of use, and the manner of implementation in practice. Though an analysis of the case involving Zalo, the article clarifies the legal risks and provides notes and recommendations to assist enterprises in establishing an appropriate compliance mechanism in their business activities.

1. Personal data protection regulations: responsibilities of the data controller and conditions of consent
According to Clause 7, Clause 8, Clause 9, Article 2 of the Law on Personal Data Protection 2025, the data controller is the agency, organization or individual that decides the purpose and means of processing; the data processor is the agency, organization or individual that performs the processing under a contract with the controller; the data controller and processor is the agency, organization or individual that both decides the purpose and means and directly processes it. Depending on the actual role in the process of processing personal data, the enterprise will be identified as the corresponding subject and bear the corresponding responsibilities and obligations in accordance with the law.
According to the provisions of the Law on Personal Data Protection 2025, in case an enterprise is identified as a controller or a data controller and processor, it is responsible for performing some of the following obligations:
- Apply measures to protect personal data and ensure the rights of data subjects;
- Collect and store the consent of the personal data subject;
- Organize data protection departments/personnel as prescribed;
- Clearly stipulate the responsibilities, rights and obligations to be complied with by the parties in agreements and contracts related to the processing of personal data as prescribed;
- Prepare, submit and archive dossiers of impact assessment of personal data processing as prescribed;
- Prepare, submit and archive dossiers of impact assessment of cross-border personal data transfers when there are activities of transferring personal data abroad as prescribed;
- Notice of violation of regulations on personal data protection.
It should be noted that in order for the collection and processing of personal data to be lawful, a data controller or a data controller and processor must obtain valid consent from the data subject. According to Articles 9, 10 and 11 of the Law on Personal Data Protection 2025, consent must be obtained prior to collection, except in cases where the law permits processing without consent, and must satisfy the following conditions, specifically:
- Vonluntary and informed: the data subject must give consent voluntarily with clear knowledge of the following information: the type of personal data to be processed, the purpose of processing, the data controller or the data controller and processor, and the data subject’s own rights and obligations.
- Clear and verifiable: consent is expressed in a clear, specific, printable or reproduced manner in writing including in electronic form or verifiable format.
In addition to satisfying the above conditions, the data subject’s consent must also ensure compliance with the following principles:
- The data subject must express consent for each purpose:
- It must not be accompanied by conditions that oblige the user to agree for purposes other than the content of the agreement;
- The consent is valid until the personal data subject changes such consent or as required by law;
- Silence or non-response shall not be deemed to constitute consent.
A data subject has the right to withdraw consent or to request restriction of processing; such withdrawal shall not have retroactive effect. Enterprises must also take note of the specific requirements applicable to advertising, social media, sensitive data, and children’s data.
For digital platforms, these requirements need to be reflected in both the content of the terms of use and the mechanism for obtaining, retaining, and managing consent. This is the basis for assessing compliance risks when businesses update the terms or expand the scope of user data processing.
2. Regulations on the Protection of Consumers’ Rights
In addition to the law on personal data protection, enterprises providing products and services to consumers must comply with the Law on Protection of Consumer Rights 2023. According to Clause 3, Article 3 of the Law on Protection of Consumer Rights 2023, consumer information includes personal information, the process of purchasing and using products and services, and other information related to transactions. According to the provisions of the Law on Protection of Consumer Rights 2023, enterprises have the following main obligations:
- Disclosure and obtaining consent: to clearly notify consumers of the purpose, scope of collection and use, retention period, and measures for protecting information; and to establish methods enabling consumers to select the scope of information they provide and to express their consent or refusal.
- Use within the permitted scope: where the purpose or scope of use is changed, to re-notify and obtain the consent of consumers; and to provide a mechanism for consumers to make choices regarding the sharing of information with third parties and the use of information for advertising and commercial activities.
- Ensuring security and consumers’ rights: to comply with applicable requirements when engaging a third party to process information; to give effect to requests to review, correct, update, delete, or cease the transfer of information; and to notify incidents in accordance with regulations.
The terms of use prepared by the platform can be identified as model contracts or general transaction conditions as prescribed in Article 23 of the Law on Protection of Consumer Rights 2023 and must comply with the provisions of Articles 24 to 27 of this Law. Notably, Clause 14, Article 25 of the Law on Protection of Consumer Rights 2023 does not allow business organizations and individuals to stipulate terms that stipulate that consumers must agree to the collection, storage and use of consumer information as a condition for entering into contracts, unless otherwise provided for by law. In addition, Clause 4, Article 25 of this Law also prohibits business organizations and individuals from unilaterally changing general transaction conditions without stipulating the right to terminate the contract.
Enterprises must make their terms publicly available, allow consumers a reasonable period to review them, publicly disclose the procedures for receiving and resolving feedback and complaints, and maintain appropriate mechanisms for vulnerable consumers. Accordingly, a user’s clicking “agree” does not automatically ensure the legality of all the terms; enterprises must ensure that both the content of the terms and the mechanisms for selection satisfy the requirements of law.
3. Risks for enterprises when building a consent collection mechanism: Analysis of the Zalo case
At the end of December 2025, the Zalo application sent a notice requiring all account holders to update the new terms of service to continue using it. The new terms significantly expand the scope of collection and sharing of personal data, including basic data (phone number, full name, gender, family relationships, etc.) and sensitive data (citizen identification information, location, usage behavior, etc.). According to the display interface, users only have two options: (i) agree to all terms, including the content of personal data processing; or (ii) stop using the application — the system will automatically delete the account after 45 days if the user does not change his mind. This has been met with a strong reaction because of the potential risk of violating the law on contracts, as well as the regulations on personal data protection that are about to take effect (the Law on Personal Data Protection 2025 takes effect on January 1, 2026).
In January 2026, the National Competition Commission (Ministry of Industry and Trade) sanctioned VNG Group Joint Stock Company a total of VND 810 million for six violations of the law on consumer rights protection, and at the same time requested an end to the violation, review and complete the policy. The problem does not lie in whether Zalo is allowed to collect data or not, but in the way of obtaining consent: combining multiple processing purposes into one “agree to all”, linking the continued use of the service with the acceptance of the whole, and not allowing users to separate choices according to each purpose.
At the time Zalo updated the provisions (end of December 2025) and when issuing a sanctioning decision (January 2026), the Law on Personal Data Protection 2025 did not have a separate sanctioning decree. However, that does not create a sanction gap because the authorities invoke the Law on Protection of Consumer Rights 2023, because this law has sufficient provisions on the obligation to notify, collect consumer consent and corresponding sanctions.
From August 19, 2026, Decree No.330/2026/ND-CP takes effect and violations of consent have a specific penalty frame.
- The fine for each act is from 30 to 70 million VND for organizations. The level of VND 3 billion in Article 8 of the Law on Personal Data Protection 2025 is the general ceiling for other violations, not the default level for violations of consent. However, each act can be sanctioned separately, so the total fine increases rapidly when the consent mechanism has many design errors at the same time.
- Remedial measures are the biggest risk for enterprises. The Decree allows forcible destruction and deletion to the point where it is impossible to restore data collected and processed without valid consent, forced return of illegal revenues and confiscation of material evidences and vehicles. For businesses that build products, advertisements or analytics models on user data, having to delete collected data without valid consent can affect more than the fine.
- Such conduct may be subject to review by multiple authorities. Under the principles of application set out in Decree No. 330/2026/ND-CP, conduct falling within the field of personal data protection shall be governed by that Decree; where there are indications of a breach of obligations falling under another specialized area of management, the decree governing that field shall apply.
In addition to administrative sanctions, enterprises may also have to pay compensation for damages under civil law, face lawsuits from consumers or social organizations, and in serious cases may be considered for criminal liability under the Criminal Code.
4. Notes and recommendations for enterprises in the process of collecting and using personal data
The Zalo case illustrates a reality that many enterprises, especially those operating digital platforms, mobile applications, and online services, often overlap: personal data protection and consumer protection are not two separate fields but often overlap in the same behavior. Therefore, when building a consent collection mechanism, businesses need to pay attention to some of the following issues:
- Design a clear consent mechanism: obtain consent for each purpose, distinguish between required and optional data; avoid pre-selected boxes, aggregate multiple purposes, or force users to “agree to all”.
- Ensuring the right of choice: allow users to refuse data sharing and advertising and to withdraw consent easily; retain evidence of the time, content, and scope of consent given.
- Transparency when updating terms: make the content and effective date publicly available and allow a reasonable period for consideration; notify users and re-obtain consent where the purpose or scope of processing changes.
- Concurrent review of both legal frameworks: review privacy policies and terms of use against the laws on personal data protection and consumer protection, paying particular attention to prohibited terms.
- Completing procedures and records: designate a data protection focal point, prepare impact assessment dossiers, and establish procedures for handling requests and complaints and for responding to incidents within the prescribed time limits.
- Managing partners and protected groups: clearly allocate responsibilities in data processing contracts; put in place appropriate mechanisms for children and vulnerable consumers.
Enterprises should actively review and keep sufficient compliance records to serve the explanation when there is an inspection, examination or complaint.
Personal Data Protection & Consumer Protection Compliance Consulting Services at CDLAF
CDLAF supports enterprises — especially those operating digital platforms and applications that collect user data — to build a compliance framework that synchronizes both legal areas:
- Review and draft personal data protection policies and terms of service, ensuring simultaneous compliance with the Law on Personal Data Protection 2025 and the Law on Protection of Consumer Rights.
- Designing a mechanism for obtaining consent (consent mechanism) according to each purpose of data processing, meeting the requirements of transparency, specificity and the ability to choose users.
- Representatives of enterprises shall work and explain to the competition and consumer protection authorities and specialized agencies in charge of personal data protection when there is a request for review or complaints arise.
📩 BOOK A CONSULTATION WITH CDLAF’S LEGAL TEAM
Do not let procedural errors disrupt your business plans. Contact CDLAF today to receive a preliminary risk assessment from our team of Lawyers:
Hotline/Zalo: [+84 909 668 216]
Email: info@cdlaf.vn
Why choose CDLAF’s service?
- We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
- We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
- Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
- As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
- CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
- Strict information security procedures throughout the service performance and even after the service is completed.
You can refer for more information:
-
- Mechanism For Disputes Settlement, Protection Of Interests And Divestment Of Minority Shareholders
- Arbitrability: Notes For Enterprises When Choosing Arbitration As A Dispute Resolution Mechanism
- Defective Arbitration Clause: Handling Guidelines And Solutions For Enterprises
- Validity of Arbitration Agreements: Notes for Enterprises
- Estimating the Cost of Closing an FDI Enterprise – Why a Legal & Tax Health Check Is Needed Before Filing for Dissolution
