The era of “trading benefits for data” is over!

Insights
The era of “trading benefits for data” is over!
Posted on: 24/12/2025

    Many businesses have been choosing the model of collecting and exploiting personal data based on the principle of exchanging benefits for the right to use data - the data giver and the data recipient are happy. However, behind that seemingly reasonable exchange mechanism is a significant legal risk for businesses.

     

    Many enterprises choose a model of collecting and exploiting personal data based on the principle of exchanging benefits for the right to use such data. Source: The Saigon Times

     

    Give discount codes to customers, invite customers to sign up for a loyalty program or ask users to tick "I agree" or "I agree in full" and then download or continue using the application... are ways businesses use to exchange customer information, access to shopping history, and collect data on users' browsing behavior. In these situations, users often unconsciously share data to receive gadgets or incentives, and businesses also have their own intentions for collecting that data.

    Vietnam's legal framework for personal data protection currently does not prohibit enterprises from operating business models in the direction of providing benefits in exchange for the right to collect and process users' personal data as mentioned above. However, the principles and regulations on personal data protection stated in current legal documents have stricter regulations on the protection of personal data. Accordingly, enterprises as controllers, or data controllers and processors, must ensure core legal obligations, such as ensuring the rights of users (data subjects), where "consent" is a key condition to start collecting and processing data[1].

    Vietnam's requirements and international experience

    Many legal systems place "consent"  as the foundation of personal data processing. According to the European Union's General Data Protection Regulation (GDPR), the processing of personal data is only lawful when at least one of six conditions is met: (1) with the consent of the data subject, (2) performance of a contract, (3) compliance with a legal obligation,  (4) to protect the vital interests of the data subject or other individual, (5) to perform a task in the public interest/to enforce the authority of a state agency, (6) for the legitimate interests of the data processor[2]. In particular, consent is only valid when it is given freely, concretely, clearly communicated and expressed through the user's confirmation action[3]. Singapore's Personal Data Protection Law maintains a similar stance when it requires businesses to collect valid consent and ensures that users have the right to withdraw consent at any time[4]. It can be seen that the provisions of Vietnam's law on personal data protection are quite similar to the principles of international law.

    A number of recent practical cases show that the competent authorities for personal data protection in the world tend to strictly handle violations of the obligation of consent and transparency.

    Typically, the case related to the dating app Grindr in Norway[5]. On December 13, 2021, on the basis of a complaint by the Norwegian Consumer Council, the Norwegian Data Protection Authority (Datatilsynet) reviewed and concluded that Grindr had shared user data - including GPS location, IP address, age, gender, and information about the user's use of the app with advertising partners without a valid legal basis under the GDPR.

    In conclusion, although Grindr does collect user consent, these consents are considered invalid because users are not provided with sufficient information about data sharing with third parties (Grindr's advertising partners). This violates the GDPR's requirement for transparency and the standard for "valid consent". As a result, Grindr was fined around 6.5 million euros. Such cases show that data processing models based on economic interests cannot replace the requirement for explicit and transparent consent and must strictly comply with the provisions of relevant laws.

     

    Source: The Saigon Times

     

    Agree but need to be transparent

    In Vietnam, some of the risks related to collecting consent that businesses often encounter when exchanging benefits for the right to use users' personal data can be mentioned as follows:

    Processing personal data without clear and complete notification of the type of data and purpose of processing

    Many businesses, when notifying and collecting user consent, only mention the type of data and the purpose of processing, such as "collected to improve service quality", "improve user experience". However, in fact, the collected data is used for different purposes, such as classifying customers or sharing data with analytical partners for market research... This risks violating the principle of consent of data subjects in accordance with the law on personal data protection[6]. To limit legal risks, when collecting consent, businesses need to clearly list the type of data and the purpose of collection. For example, when a supermarket collects the customer's full name, gender, year of birth, phone number and e-mail when registering for a loyalty program, the customer in return receives  a discount voucher when purchasing goods at the supermarket, in the consent collection form, the business needs to present the specific purpose of processing such as "using information to manage the membership account and verification of loyalty benefits", "contact customers to send information about promotions and offers for members", "analyze shopping behavior to improve service quality for loyal customers"...

    Forcing the user to "agree in full" by attaching a condition that requires consent for purposes that are unrelated to or different from the content of the agreement

    Forcing users to "consent in full" is understood as the establishment of terms of use or privacy policies in the direction of combining various purposes of data processing into a single consent option instead of allowing users to choose each purpose individually. In particular, the enterprise sets the condition that users can only receive benefits or continue to use the service if  they accept consent for all purposes, including secondary purposes or not directly related to the provision of the core service.

    Attaching unnecessary additional purposes such as sharing data to third parties that make consent no longer voluntary may  be considered as depriving the element of freedom of consent as required by personal data protection legislation[7],  at the same time, it leads to the risk that enterprises cannot prove the validity of consent in case of disputes or when inspected by management agencies.

    Using data for a new purpose without re-asking for consent

    Even with initial consent, enterprises must still re-obtain consent if they want to expand the purpose of processing to avoid the risk of violating the principle of collecting consent for each purpose[8]. For example, the  bank collects the customer's personal data for the purpose of loan appraisal but then uses this data to send e-mails promoting linked insurance products without asking for consent. This is an act of using beyond the scope of the original collection purpose.

    In short, to ensure the legality of applying the "exchange of benefits for data" model, businesses need to pay attention to collecting valid consent of data subjects before conducting any processing activities. Strictly complying with this principle not only helps businesses minimize legal risks but also contributes to building trust and credibility for customers in the context of increasing personal privacy.

    Lawyer Nguyen Ngoc Tra My

    HM&P Law Firm

    Read more: Qua rồi thời ‘đổi lợi ích lấy dữ liệu’!


    [1] Article 9 of the Law on the Protection of Personal Data

    [2] Article 6 GDPR

    [3] Article 7 GDPR

    [4] Article 13, Article 14 of the PDPA

    [6] Point a, Clause 2, Article 9 of the Law on Environmental Protection

    [7] Point b, Clause 4, Article 9 of the Law on Environmental Protection

    [8] Point a, Clause 4, Article 9 of the Law on Personal Data Protection