Glossary
What is gdpr consent?
GDPR consent is the freely given, specific and recorded permission a business must obtain before processing an EU customer's personal data for a loyalty programme.
For loyalty this means two things in practice. First, the customer must actively agree at enrolment rather than being added silently, which matters particularly when a staff member is typing the number on their behalf. Second, the business, not the loyalty platform, is the data controller: the customer list belongs to the business, and the platform processes it under instruction.
When is consent required?
For marketing messages, always. For operating the loyalty card itself, the lawful basis is normally performance of a contract or legitimate interests, because the customer asked to join a scheme that cannot run without an identifier.
| Message | Type | Needs marketing consent? |
|---|---|---|
| Here is your loyalty card | Service | No |
| You have 8 of 10 stamps | Service | No |
| Your reward is ready | Service | No |
| 20% off this weekend | Marketing | Yes |
| We miss you: come back | Marketing | Yes |
What makes consent valid?
It must be freely given, specific, informed and unambiguous, and the business must be able to show it was obtained. A pre-ticked box is not consent, and neither is a customer's silence.
Where a staff member enters a number on the customer's behalf, consent is given verbally and the system must record that it happened, when, and for what. "Can I text you your loyalty card?" is sufficient wording; what matters is that the answer is captured.
What about the ePrivacy rules?
Electronic marketing is governed by ePrivacy rules as well as GDPR (PECR in the UK, national equivalents across the EU) and they generally require prior consent rather than legitimate interests. This is the layer most often missed by businesses that assume holding a number lawfully also permits texting it.
See also
- Data controller: The data controller is the organisation that decides why and how personal data is processed; in a loyalty programme this is the business running the programme, not the software vendor.
- Data processor: A data processor handles personal data on behalf of a controller and only under its instructions; a loyalty platform is a processor acting for the business that uses it.
- First-party data: First-party data is information a business collects directly from its own customers, such as a phone number given at the counter, and in a loyalty programme it is the asset the programme produces.
Further reading
GDPR and loyalty programmes: what a small business must do
The practical compliance checklist for running a digital loyalty programme in the EU: lawful basis, consent for marketing, retention limits and data subject rights.
Loyalty programmes that do not need a customer app
Why asking customers to install an app destroys loyalty enrolment, and how wallet cards deliver the same benefits without the download.