Skip to content
All articles

GDPR and loyalty cards: what a Belgian shop has to get right

A loyalty card creates a customer database, app or no app. Here are the six decisions to make before you enrol your first member, and the Belgian trap that has already cost a shopkeeper a fine.

A loyalty card is a customer database

The moment a card ties a purchase to a person, you are processing personal data. A first name and an email address are enough. Add visit history and you hold something more revealing than it looks: how often someone comes in, at what time, and what they buy.

None of that is forbidden. The GDPR asks you to know why you collect it, to say so, and to keep no more than you need. The good news for a neighbourhood shop is that the genuinely binding obligations are few, and most are settled once, when you open the programme.

Two activities, two legal bases

The common mistake is treating the card as one thing. It is two, and they do not rest on the same legal basis.

The card itself, counting stamps or points so you can honour the reward you promised, is performance of the contract the customer entered into when they joined. You do not need consent to count someone's stamps: they asked you to.

Promotional messages are direct marketing. An unsolicited email or text to a private individual needs prior consent that is freely given, specific and provable. The Belgian Data Protection Authority has published a full recommendation on the legal bases for direct marketing, and it is worth the half hour it takes to read.

Marketing consent has to be separate from enrolment

In practice: one action to join the programme, and a second, unticked box to accept offers. If the customer has to accept marketing in order to get the card, consent is not freely given, so it is not valid.

That is exactly what the Belgian authority held against the shopkeeper in the eID case: no alternative was offered, so the consent was not consent.

Keep a record of who agreed to what, and when. If a complaint lands, proving consent is your job, not the customer's job to disprove it.

What the customer must be told at sign-up

The information has to arrive at the moment of collection, not three screens later. It fits in a few lines: who you are, what you collect, why, how long you keep it, who you share it with, and how someone contacts you to exercise their rights.

A link to your privacy policy on the sign-up screen, plus one readable sentence at the counter, is enough for a shop. What is not enough: a poster nobody reads and nothing in writing.

How long to keep the data

The regulation sets no period. It asks you to set one and stick to it. For a loyalty programme, inactivity is the simplest yardstick: delete a member who has not scanned anything for, say, twenty-four or thirty-six months.

Write it into your policy and then actually run it. A period you announce and never enforce is worse than a long one you own, because it puts you in contradiction with your own document.

Your loyalty platform is a processor

If you use a platform to issue the cards, it processes your data on your behalf. You are the controller, it is the processor, and Article 28 requires a written contract between you, usually called a DPA.

Ask for it before you sign. Check at minimum where the data is hosted, who the sub-processors are, what happens at the end of the contract, and how quickly the provider tells you about a breach. A supplier with no published DPA is leaving you to carry a risk that is not yours alone.

Customer rights, and what they change at the counter

A member can ask for access to their data, correction, deletion, and can object to direct marketing. That last right is unusual: it is absolute, and no reason has to be given. If someone asks to stop receiving offers, it stops, even if they keep the card.

Practically you need two things: a contact address somebody actually reads, and the ability to delete a member without deleting your accounts. The rest is organisation, not law.

The Belgian trap: an identity card is not a loyalty card

This is the part missing from every French-language guide written for France, and it is the part that costs money in Belgium. Scanning a customer's eID to create or retrieve their loyalty card has already earned a Belgian shopkeeper a sanction.

The authority's reasoning was direct. Sex and date of birth were not necessary for the purpose, so data minimisation was breached. The national register number is not there to be used as a lookup key for a customer file. And because no alternative was offered, the consent was not freely given.

If you want to identify a member in two seconds at the counter, use an identifier you generate yourself: a QR code on a wallet pass, a member number, a barcode. Those are data you created for this purpose and can erase. A national register number is neither.

A compliant loyalty programme, for a shop, comes down to six decisions: separate the card from the marketing, collect distinct and traceable consent, inform people at sign-up, set a retention period, sign a DPA with your provider, and never use an identity card as the identifier. This article is orientation, not legal advice: for a specific situation the Belgian Data Protection Authority publishes sector guidance, and specialist advice is money well spent.

All articles

Issue your first digital loyalty card this week.

Start your first digital loyalty card with a 14-day free trial — or drop your email and we will send a two-minute setup walkthrough.

14-day free trial. No credit card needed.