A loyalty programme collects personal data by definition: you cannot reward a repeat customer without recognising them. This is the practical checklist for doing that lawfully in the EU, written for an owner rather than a lawyer. It is general information, not legal advice.
What lawful basis covers a loyalty card?
Issuing and maintaining the loyalty card itself normally rests on performance of a contract or on legitimate interests, because the customer asked to join a scheme and you cannot operate it without holding an identifier.
Marketing is a separate question with a separate answer. Sending an offer to a customer who joined a stamp card is not covered by the basis that lets you count their stamps: it needs its own consent, captured separately and recorded.
Do I need consent to send loyalty messages?
You need consent for marketing messages, and you do not need it for service messages that the customer would expect as part of the scheme they joined.
| Message | Type | Needs marketing consent? |
|---|---|---|
| Here is your loyalty card | Service | No, it is what they asked for |
| You have 8 of 10 stamps | Service | No |
| Your reward is ready to claim | Service | No |
| 20% off this weekend | Marketing | Yes |
| We miss you, come back | Marketing | Yes |
The line is whether the message advances the scheme the customer joined or promotes something additional. When in doubt, treat it as marketing.
What must I tell customers at sign-up?
- Who is collecting the data: the legal entity, not just the trading name.
- What you collect and why: a phone number, to issue and update the card.
- How long you keep it, stated as a period rather than 'as long as necessary'.
- That they can ask for a copy or deletion, and how.
- Whether you use processors: an SMS provider and a wallet platform both count.
At a counter this cannot be a wall of text. The workable pattern is a short spoken line plus a link in the enrolment message to a full privacy notice.
How long can I keep the data?
You can keep loyalty data for as long as the customer is active in the scheme plus a defined dormancy window, after which you should delete or anonymise it.
Two to three years of inactivity is a commonly used window and is straightforward to defend, provided you apply it. A retention policy that exists only in the privacy notice is worse than none, because it documents the breach.
What about deletion requests?
You must be able to delete a customer's data on request, and the deletion has to reach every system holding it: the loyalty platform, the SMS provider's logs, and any list sitting in a spreadsheet.
That last one is where most small businesses fail. A CSV of customer numbers downloaded once and left in a downloads folder is personal data, and it is outside the deletion flow your platform provides.
What does Loonine handle for you?
Loonine acts as a processor for the customer data you collect: you remain the controller. The platform provides the deletion mechanism, a published subprocessor list, and a data processing agreement. What it cannot do is obtain consent on your behalf at the counter, that part is yours.
What does the ePrivacy rule add on top of GDPR?
Marketing by SMS is governed by the ePrivacy rules as well as GDPR (implemented as PECR in the UK and as national equivalents across the EU), and the practical effect is that electronic marketing generally requires prior consent rather than legitimate interests.
This is the point most often missed. A business can sometimes justify holding a customer's number on legitimate interests, and then assume the same reasoning covers texting them an offer. It does not: the marketing message needs its own opt-in, obtained before the first one is sent.
There is a narrow exemption in several jurisdictions for marketing your own similar products to an existing customer who was given an opt-out at the point of collection. It is narrower than it sounds, and relying on it for a loyalty programme where you could simply ask is a poor trade.
Wallet push notifications sit in a different position from SMS, because the customer installed a card and the notification is a change to that card. Treat promotional content pushed through the card as marketing anyway: the safer reading is also the one that keeps customers from deleting the card.
What must I write down?
Three records, and none of them needs to be elaborate for a small business.
- A record of processing: what data you hold, why, on what basis, who you share it with, and how long you keep it. A single page is usually enough.
- The consent record for each customer: that consent was given, when, for what, and how. Your platform should capture this automatically at enrolment.
- A data processing agreement with each processor: the loyalty platform, and any SMS provider you contract with directly.
Smaller organisations are exempt from some record-keeping obligations under GDPR, but the exemption is narrower than most people assume and does not apply where processing is regular rather than occasional. A loyalty programme is regular processing. Keeping the page is easier than establishing that you did not have to.
What happens if there is a breach?
A personal data breach that poses a risk to individuals must generally be reported to your supervisory authority within 72 hours of becoming aware of it, and the customers themselves must be told if the risk to them is high.
For a loyalty programme the realistic scenarios are a customer list left somewhere unprotected, a shared staff login, or an incident at your platform provider. The first two are yours to prevent: the third is why your processor agreement should oblige the platform to notify you promptly.
Preparation is mostly about knowing who decides. Write down who at your business is called, who contacts the regulator, and where the customer list lives. Seventy-two hours is not long to work that out from scratch.
Does this apply outside the EU?
The same shape of obligation now applies in most of the markets a loyalty programme will operate in, so a business running to GDPR standards is generally close to compliant elsewhere.
| Market | Regime | Practical difference |
|---|---|---|
| EU / EEA | GDPR + national ePrivacy | The baseline described above |
| United Kingdom | UK GDPR + PECR | Substantively similar; separate regulator |
| UAE | Federal Decree-Law on Personal Data Protection | Comparable in shape; consent and rights recognised |
| Other GCC | National laws, varying maturity | Consent and purpose limits broadly expected |
| United States | State-level, varies | Patchwork; California is the strictest |
Two rules keep a multi-market business out of trouble without tracking each regime separately. Run everything to the strictest standard you are subject to, and note that GDPR can follow your customers rather than your address: serving EU residents can bring you within scope regardless of where the business sits.
What is the minimum I should do this week?
- Add one sentence to the enrolment script asking permission to text the customer.
- Confirm your platform records that consent with a timestamp.
- Publish a short privacy notice and link it from the enrolment message.
- Write down a retention period and set a reminder to apply it.
- Delete every customer CSV sitting in a downloads folder.
- Get the data processing agreement from your loyalty platform and keep a copy.
That list covers the great majority of what a small loyalty programme is assessed on. This page is general information rather than legal advice, and a business operating across several jurisdictions should have a lawyer review the specifics.