The moment you launch a loyalty program, you start processing personal data. It isn’t a formality solved by a checkbox in the sign-up form – but it isn’t a reason to panic either. The obligations are finite and can be met in an afternoon.

This article is a practical overview of what has to be in order. It is not legal advice; for a more complex operation, or whenever you are unsure, talk to a lawyer.

Who is responsible for the data: you, not your vendor

The most important thing first, because everything else follows from it.

In a loyalty program the business is the controller of personal data (it decides why and how the data is processed) and the system vendor is the processor (processing it only on the business’s instructions). That relationship has to be backed by a data processing agreement under Article 28 GDPR.

In practice this means:

  • Responsibility towards the customer and the regulator sits with the business, not the vendor.
  • The vendor has to assist you when a customer exercises their rights.
  • Without a processing agreement in place, the whole processing operation breaches GDPR – even if everything else is right.

At Walio the processing agreement is part of the terms of service, so it comes into existence with the account. If you are choosing a different vendor, check this first; if they don’t have one, keep looking.

Does this apply to paper cards as well?

The most common misconception here is that GDPR is a matter of apps and digital systems.

What counts is whether you process personal data, not what you use to do it. A card with ten boxes for stamps and nothing else holds no personal data – that case is simple. But the moment you keep a notebook of names and phone numbers alongside it, or write the customer’s name on the card itself, the same rules apply as to any digital system: legal basis, the duty to inform, retention periods, customer rights.

The difference is that on paper you meet them by hand, and usually worse. A notebook under the counter cannot evidence when consent was given, nor delete it on request without rewriting the page. The paper card vs. Walio comparison takes this from the practical side.

Processing personal data has to rest on one of the grounds in Article 6 GDPR. In a loyalty program you meet two of them in practice, and it is essential not to mix them up.

Issuing and running the card – performance of a contract

When a customer asks for a loyalty card, they enter into a relationship with you: they collect stamps and you give them a reward for them. Processing the data needed to make that work rests on performance of a contract (Art. 6(1)(b)).

You do not need consent here, and asking for it is a mistake – it would lead to the absurd conclusion that when the customer withdraws it, you have to delete their card along with stamps they never lost.

Sending customers offers, campaigns and push notifications about promotions is a different matter. That is not necessary to run the card, so it requires consent (Art. 6(1)(a)) – freely given, specific and demonstrable.

Three rules follow:

  1. Marketing consent must be separate from card registration. Not one checkbox for both.
  2. It must not be a condition of getting the card. “You can have the card only if you agree to newsletters” invalidates the consent.
  3. It must be as easy to withdraw as it was to give, and you must be able to show when it was given and what for.

An operational reminder (“one stamp to go until your reward”) sits on the edge – it is closer to a service message about running the card. A commercial offer (“20% off everything today”) is marketing and shouldn’t go out without consent.

Collect less than you can

The minimisation principle says you should process only the data necessary for the purpose. For a loyalty card that means less than most forms ask for.

What you genuinely need: a card identifier and a record of stamps or points. That’s all. A card in Wallet works without a name.

What makes sense if you actually use it: e-mail or phone (contact for rewards and marketing), first name (for addressing them), day and month of birth (a birthday greeting).

What not to collect: national ID numbers, addresses, a full date of birth including the year, unless you have a specific reason. Special categories of data – health, dietary restrictions as an expression of religion – have no place in a loyalty program at all.

A good test: for every field in the form, say out loud what you will do with that piece of data next month. If the answer is nothing, delete the field.

How long to keep the data

GDPR sets no specific retention periods, but it forbids keeping data longer than necessary. For a loyalty program a simple rule works well:

  • Active card: for as long as the customer uses it.
  • Inactive card: set a period (commonly 24 to 36 months since the last visit) and delete or anonymise the data once it passes.
  • Marketing consent: keep the record of it even after withdrawal, so you can carry the burden of proof.

What matters is that the period is written down and followed. A database that has only ever been added to for ten years is a problem in itself.

What you have to tell the customer

Before collecting the data, the customer has to know (Art. 13 GDPR) who the controller is, what you collect the data for, on what legal basis, how long you keep it, who you pass it to and what rights they have.

It doesn’t have to be on the card or on a table stand – a link to your privacy information, typically on your website, reachable from card registration, is enough. One page in plain English, not five pages of legalese.

Customer rights and what they mean day to day

Customers have the right to access their data, to rectification, erasure, restriction of processing, portability and objection. You have one month to respond.

Two things tend to surprise people:

  • The right to erasure is not absolute. When a customer asks for deletion but you hold records you are required to keep under accounting rules, you delete only what you are not required to keep.
  • A request can be made verbally at the counter. Give your staff one sentence for where to send such a customer – typically the business’s e-mail address.

Where the data is stored

Customers and regulators alike ask where the data goes. The answer has to be traceable in your privacy information, and it should include the sub-processors your vendor uses (hosting, e-mail, payments, Apple and Google for the card itself).

Any transfer outside the European Economic Area needs a legal basis – a European Commission adequacy decision, or standard contractual clauses. This is a question for your vendor and the answer should be immediate; if they don’t have one, treat it as a warning sign.

Two duties people forget

Records of processing activities (Art. 30). The exemption for organisations under 250 employees sounds like relief, except it does not cover processing that is not occasional – and a loyalty program is regular. So assume the record is required. In practice it is one table: purpose, categories of data and of data subjects, legal basis, retention period, recipients and transfers outside the EEA. It fits on a page and is written once.

A data protection officer. Here the answer for an ordinary venue is simple: you don’t need one. A DPO is mandatory for public authorities and where the core activity is large-scale systematic monitoring or processing of special categories of data. A café or salon running a loyalty program falls outside that.

Pre-launch checklist

  • A data processing agreement with the vendor (Art. 28 GDPR)
  • A legal basis set separately for running the card (contract) and for marketing (consent)
  • Marketing consent separated from registration and demonstrable
  • Collected data limited to what you actually use
  • A defined and observed period for deleting inactive cards
  • Privacy information reachable from card registration
  • A process for handling a customer request within one month
  • An overview of sub-processors and processing locations
  • A record of processing activities under Art. 30

When all of that holds, the loyalty program is sound on data protection – and it is an argument towards your customers too. A guest database under your own control, rather than on someone else’s platform, is easier to defend in this respect than collecting contacts through social networks.

How Walio handles processing is described in the privacy policy and in the terms of service.