GDPR Loyalty Program: What You Need to Know About Customer Data
Every week without clear GDPR rules risks fines – but the requirements are straightforward.
GDPR and loyalty programs work better together than many shop owners fear. A digital stamp card processes personal data, but the rules are manageable. You need to handle five things: legal basis, separate marketing consent, customer information, deletion, and a contract with your provider. This article explains them clearly. It's not legal advice – if in doubt, have your setup reviewed.
What data does a stamp card collect?
Before thinking about legal bases, look at what's actually collected. With a typical Wallet stamp card, that's:
- Card ID: a random identifier that links stamps to the card
- Optional name or first name: for addressing on the card and in messages
- Optional birthday: only if you offer birthday promotions
- Stamp and redemption history: when was it scanned, when was it redeemed
- Technical data: Wallet registration of the device, timestamps, possibly device detection to prevent fraud
The data minimization principle (Art. 5(1)(c) GDPR) says: collect only what you need for the purpose. If you don't plan birthday offers, don't ask for birthdays. If a first name is enough, don't ask for a last name.
Legal basis: contract, consent, or legitimate interest
Every data processing needs a legal basis from Art. 6(1) GDPR. For loyalty programs, three are relevant:
| Processing | Legal basis | What it means |
|---|---|---|
| Collecting stamps, managing card, redeeming reward | Art. 6(1)(b) (Contract) | The customer participates in the program; processing is necessary to run it. No separate consent needed. |
| Marketing messages, promotions, offers | Art. 6(1)(a) (Consent) | Requires voluntary, informed, active agreement. Also subject to applicable marketing laws. |
| Fraud protection, technical security | Art. 6(1)(f) (Legitimate interest) | For example, device detection so no one stamps themselves unlimited times. Must be proportionate. |
The key point: Stamping and marketing are two different things. Anyone who creates the card can be stamped. Anyone who wants marketing must agree separately.
Marketing consent: separate, voluntary, unchecked
Most mistakes happen here. For marketing consent to be valid, it must be:
- Separate from program participation (no forced bundling, Art. 7(4) GDPR)
- Active: checked by the customer themselves (a pre-checked box is not consent – the European Court of Justice ruled this in Planet49)
- Informed: the customer knows what they're getting (for example, Wallet messages with offers)
- Revocable at any time, as easily as it was given
In practice: When creating the card, there's a required checkbox for the privacy policy and a separate, unchecked checkbox for offers and promotions. Customers get their card even if they don't check the second box.
Messages that are part of running the program (like "You now have 5 of 10 stamps" or "Your reward is ready") aren't marketing and don't need consent. "2 for 1 today only" is marketing. How such messages work technically is explained in Sending push messages to customers.
Disclosure obligations under Art. 13 GDPR
When collecting data, you must inform customers. The information must be easily accessible – a link on the signup page is enough. Required information includes:
- Name and contact details of the controller (you, the shop)
- Purposes of processing and the legal basis for each
- Recipients or categories of recipients (like your software provider as a processor, Apple and Google for Wallet)
- Storage duration or criteria for it
- Rights of the data subject: access, correction, deletion, restriction, portability, objection
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
A shop without its own website often faces a problem here: Where should the policy live? Some providers automatically generate an editable privacy policy per shop and host it. Customers see it when creating the card, and you don't have to write anything yourself.
Data subject rights: access and deletion
Customers can request information about what data you have on them (Art. 15) and demand deletion (Art. 17). You need two things for this:
- A way to find the customer: With a digital card, usually by name or card ID in your dashboard.
- A delete function: Either the customer deletes the card from their Wallet themselves, or you remove them in your dashboard. Deletion must be complete, including from histories and reports, unless retention obligations apply.
Also: data can't sit around forever. A sensible approach is to delete or anonymize cards that haven't been used for a long time after a set period. State the period in your privacy policy.
Data processing: the contract with your provider
If you use software for your loyalty program, the provider processes customer data on your behalf. Legally, you're the controller and the provider is the processor. Art. 28 GDPR requires a written contract – a data processing agreement.
It states what data is processed, that the provider only acts on your instructions, how they protect data, and which subprocessors they use (like hosting providers). Reputable providers present the data processing agreement for acceptance when you sign up. Also check the server location: hosting in the EU simplifies things significantly.
Self-check: Is your loyalty program GDPR-compliant?
- I collect only data I really need
- Marketing checkbox is separate, unchecked, and voluntary
- Privacy policy is linked when creating the card
- Customers can request information and deletion
- I have a data processing agreement with my provider
- My team knows customer data is confidential
If you can't check more than two boxes, you should make changes.
What happens if you do nothing
Without clear GDPR rules, you risk warnings from competitors or complaints to the data protection authority. Fines can be painful, even for small shops. More importantly: customers lose trust if they feel their data isn't protected. For comparison: with paper cards, most points disappear as long as you don't record personal information. Once a name is on the card, the same rules apply, but without a delete function and without a hosted policy. The comparison of both models is in Paper stamp card vs. digital stamp card.
Conclusion
GDPR and loyalty programs aren't contradictory: stamping runs on the contract basis, marketing needs a separate checkbox, customers are informed and can request deletion, and you have a data processing agreement with your provider. Important: this article isn't legal advice – review your specific setup. stampa handles the technical side for you, with separate marketing consent, auto-generated privacy policy per shop, and data processing agreement at signup. You can start free, up to 100 active customers, no credit card needed.