Skip to main content
Back to blogNews

GDPR and loyalty data: what a business must know

Published: May 20, 20266 min read2 views

A loyalty program cannot run without personal data — you need at least an identifier and purchase history. That puts the program inside GDPR scope from day one. This article is not legal advice, but it covers the questions every auditor asks in practice.

Legal basis: contract and consent are not the same

Running the program itself (accruing points, issuing rewards) usually rests on performance of a contract: the customer joined, the rules are public. Marketing messages — email, SMS, push with offers — need separate consent. The two must be separated both in the sign-up form and technically.

Consent must be provable

What matters is not the checkbox but the record: when, how and for what the customer consented, plus the ability to withdraw as easily as it was given. In practice that means a consent history in the system, not a single "I agree" line at registration.

Data minimisation

Date of birth, home address and national ID are almost never needed for loyalty. Every extra field is extra risk and fewer sign-ups. The practical minimum: one identifier (phone or email) and purchase history.

Retention periods

Data cannot be kept "indefinitely". Set a period that follows your business logic — for example, anonymise inactive members after 24 or 36 months — and state it in the privacy policy. The important part is that the period is actually enforced by the system, not only written in a document.

Export and deletion

Customers can request their data and ask for it to be deleted. For the business that means two technical requirements: structured export, and deletion that does not break accounting. The usual solution is to erase personal data while keeping anonymised transaction records for financial reporting.

A separate question when choosing a platform: can you export your own customer base at any time? If the answer is unclear, that is vendor lock-in risk, not just a legal detail.

Pre-launch checklist

  1. Program rules are public and readable.
  2. Marketing consent is separated from program participation.
  3. Consent history is recorded in the system.
  4. Retention periods are stated in the privacy policy.
  5. Data export and deletion actually work.
  6. A data processing agreement is signed with the platform vendor.

In Loyalty.lt, consent management and customer base export are standard parts of the partner portal. More on the business page.

BDARduomenų apsaugasutikimai
GDPR in Loyalty Programs: Consent and Data