Glossary

What is data controller?

The data controller is the organisation that decides why and how personal data is processed; in a loyalty programme this is the business running the programme, not the software vendor.

This distinction determines who owns the customer list. Because the business is the controller, its customer list belongs to it and can be returned on request to [email protected], and the platform may not use those customers for its own purposes. Any loyalty vendor that claims ownership of your customer data should be treated as a serious commercial risk.

Who is the controller in a loyalty programme?

The business running the programme. It decides which customers to enrol, what to collect, what the card does and when to message people, and those decisions are what make an organisation a controller.

The loyalty platform is a processor acting on the business's instructions. This allocation matters because the controller carries the obligations customers can enforce: providing information at collection, honouring access and deletion requests, and having a lawful basis for each purpose.

What does that mean in practice?

Four things the platform cannot do for you: obtaining consent at the counter, deciding your retention period, answering a customer who asks what you hold, and keeping copies of your customer list under control once returned.

The last is where small businesses most often fail. A CSV downloaded once and left in a downloads folder is personal data you control, and it sits outside whatever deletion flow your platform provides.

Can there be two controllers?

Yes: joint controllership exists where two organisations decide purposes together, and it carries its own requirements. For a standard loyalty deployment the business is the sole controller and the platform is a processor.

See also

  • Data processor: A data processor handles personal data on behalf of a controller and only under its instructions; a loyalty platform is a processor acting for the business that uses it.
  • GDPR consent: GDPR consent is the freely given, specific and recorded permission a business must obtain before processing an EU customer's personal data for a loyalty programme.
  • First-party data: First-party data is information a business collects directly from its own customers, such as a phone number given at the counter, and in a loyalty programme it is the asset the programme produces.

Further reading

Back to loyalty and wallet glossary