As soon as a shopkeeper sets up a loyalty card, they collect data about their customers: a first name, a phone number, sometimes an email, a history of visits. This information is valuable for building loyalty — but it comes with responsibilities framed by the GDPR, the European data protection regulation.
The word is intimidating, and many shopkeepers picture it as a legal mountain. In reality, the principles that apply to a loyalty card are few and mostly come down to common sense. This article presents them simply. For information only: it does not replace the advice of a legal professional, and for businesses outside France the official reference is your national data protection authority.
The basic principle: you are responsible for the data collected
From the moment you record a customer's first name, phone or email, you are processing personal data. The GDPR then considers the shopkeeper as the "data controller": it is up to you to ensure that this data is collected fairly, used for what was announced, and properly protected.
This does not mean you have to be a lawyer. The spirit of the regulation comes down to a few simple ideas: only collect what you genuinely need, say clearly what it will be used for, do not keep the data indefinitely, and let the customer take back control if they wish. A well-designed loyalty card respects these principles almost naturally.
Consent: the customer must know and agree
The central point is consent. When a customer signs up to your loyalty programme, they must understand what they are agreeing to: that you keep their information, that you track their visits, and — if that is the case — that you send them messages or offers.
This consent must be freely given and explicit. In practice, that means a clear notice at the moment of sign-up, and ideally a dedicated checkbox for sending marketing communications. The customer must be able to sign up to the card without being forced to agree to receive promotions: these are two distinct purposes.
Avoid vague wording or pre-ticked boxes. A simple sentence — "I agree to receive offers and news from [business name]" — next to a box the customer ticks themselves is healthier, and more respectful, than a long text nobody reads.
Only collect the data you need
The GDPR rests on a principle of minimisation: you should only collect the data genuinely necessary for your loyalty programme. The temptation is to ask for a lot — postal address, occupation, family situation — but every piece of data collected is data to protect and to justify.
For a loyalty card, the essentials usually come down to a first name and a means of contact (phone or email). The date of birth can be justified if you offer a dedicated perk. Beyond that, always ask yourself: "What will this information really be used for?" If the answer is unclear, do not collect it.
This restraint is not just a constraint: it inspires trust. A short sign-up form, asking only for the strict minimum, reassures the customer and increases your sign-up rates.
Customers' rights over their data
The GDPR grants the customer several rights over the data you hold. They can ask to see it (right of access), to correct it if it is wrong (right of rectification), to have it erased (right to erasure), and to stop receiving your marketing communications (right to object).
In practice, for a business, this means a customer must be able to ask you to remove them from your file, and you must be able to do so. Every marketing message must also include a simple way to unsubscribe — it is an obligation, not an option.
A good loyalty tool greatly facilitates these steps: finding a customer record, correcting it, deleting it or excluding someone from mailings should take a few clicks. If handling these requests forces you to dig through paper notebooks, you are exposing yourself needlessly.
Retention period and data security
Data is not kept indefinitely. The principle is to keep it for as long as necessary for the intended purpose, then to delete it or anonymise it. Data protection authorities provide benchmarks on this; a common practice is to consider that a customer who has become lastingly inactive no longer needs to appear in an active loyalty base. The idea to keep in mind: a customer file is not an eternal archive.
Security is the other side. Your customers' data must be protected against loss and unauthorised access. A notebook left on the counter or an unprotected file on a shared computer are concrete risks. A serious digital solution stores the data securely and limits access to authorised people.
If you have several employees, also think about who can see what. A cashier who scans the cards does not necessarily need access to the entire customer file: managing access is part of good data hygiene.
How a digital loyalty card simplifies compliance
Many of these principles, hard to maintain with a paper notebook, become simple with a digital tool designed for it. The sign-up form includes a consent notice and a dedicated checkbox for communications. Unsubscribing from a message is handled automatically. Customer records can be viewed, corrected and deleted in a few clicks.
This is what we set out to do with WePush.me: clear consent at sign-up, collection limited to useful data, differentiated staff access and the ability to respond quickly to customer requests. To see how this translates for a specific trade, you can read our page on the loyalty card for hairdressers.
This does not relieve you of your responsibility: you are the one who decides what data to collect and how to use it. But a good tool gives you the framework. If in doubt about your specific situation, the useful reflex remains to consult your data protection authority or a legal professional — this guide is only an introduction to the general principles.
Frequently asked questions
Is a loyalty card covered by the GDPR?
Yes. As soon as you record a customer's first name, phone or email, you are processing personal data, and the GDPR applies. The principles to respect are few: consent, limited collection, customer rights, retention period and security.
Is the customer's consent required for a loyalty card?
The customer must understand and agree that you keep their data. For sending marketing communications, explicit consent (for example a dedicated checkbox) is expected. Signing up to the card and agreeing to receive offers are two distinct things.
How long can a customer's data be kept?
The principle is to keep the data for as long as necessary for the intended purpose, then to delete it or anonymise it. Data protection authorities provide precise benchmarks. A loyalty file is not meant to keep lastingly inactive customers indefinitely.
Can a customer ask for their data to be deleted?
Yes. The GDPR grants the customer a right of access, rectification, erasure and objection. You must be able to remove a customer from your file on request, and every marketing message must include a simple way to unsubscribe.