GDPR and loyalty program: compliance checklist
Updated 2026-08-25
A loyalty program collects at least an identifier and a visit history: it is, within the meaning of the GDPR, processing of personal data. Good news: for a local business, compliance is a checklist of good practices, not a legal project.
This guide details what to check, what DimaCard provides, and what is your responsibility. General information — this is not legal advice.
Why a loyalty program is data processing
What you really collect
Even a “simple” loyalty card collects personal data: first name, email or telephone number, visit history, points accumulated, rewards unlocked. As long as this information relates to an identifiable person, the GDPR applies — regardless of the size of your business.
The basic principles
The GDPR is based on a base of principles: a clear purpose, minimization (collecting only what is necessary), a legal basis, a limited retention period and appropriate security. Each results in a concrete action in the checklist below.
The eight-point checklist
- Clear purpose: define why you are collecting (managing points and rewards), and do not divert the data for another use.
- Legal Basis: Identify your basis — program execution for operation, and consent for any marketing.
- Marketing consent: to send offers and notifications, obtain free, specific and revocable consent.
- Minimization: only ask for what is necessary — a first name and an email are often enough, there is no need to ask for the date of birth.
- Retention period: set a duration and purge inactive accounts; don’t keep data “forever”.
- Individual rights: be able to respond to requests for access, rectification, erasure and portability.
- Subcontractors: check where your service providers host and process data, and that a contract governs this.
- Documentation: keep a simple record of your treatments, adapted to the size of your activity.
Consent or legitimate interest: how to decide
The operation of the program (awarding points) generally relies on the execution of the program itself. Prospecting – offers, reminders, marketing notifications – is based on consent. Whenever you contact a customer again to sell them something, consent is the surest basis, and it should be able to be withdrawn as easily as it was given.
The rights of your customers
Your customers can request access to their data, its rectification, its erasure or its portability. Concretely: being able to find a customer's file, correct it, delete it or export it. A well-designed program makes these answers simple rather than painful.
What DimaCard provides
- Exportable (CSV) and deletable customer file, to respond to access, portability and deletion requests.
- Hosting in the European Union (Vercel / Supabase), and payment via Stripe.
- Anti-fraud QR + PIN to secure points against cheating.
- GDPR contact point: DPO can be reached at dpo@DimaCard.com.
These elements are aligned with our privacy policy. What is your responsibility remains: defining the purpose, collecting marketing consent, informing your customers and setting your retention periods.
What is your responsibility
Compliance is not entirely delegated: you decide what you collect and why. Before launching, write in one sentence the purpose of your program, choose your legal basis for marketing, and plan how to respond to a deletion request. These three reflexes cover most of the risk of a local business.
To go further on the Moroccan framework, read the guide to law 09-08 and customer data in Morocco. To discover the platform, consult the restaurant solutions page.
Conclusion
The GDPR is not an obstacle to the loyalty program: it is a framework of trust. A merchant who collects the minimum, collects consent for marketing and knows how to respond to a deletion request is already, in practice, well advanced. DimaCard provides the technical tools; the purpose and consent remain yours. If in doubt, seek legal advice.
Key Takeaways
- A loyalty program collects data linked to an identifiable person: this is processing of personal data subject to the GDPR.
- The checklist consists of eight points: purpose, legal basis, marketing consent, minimization, duration, rights, subcontractors and documentation.
- The functioning of the program relies on its execution; prospecting (offers, reminders) is based on revocable consent.
- DimaCard provides the tools: file export and deletion, EU hosting (Vercel / Supabase), Stripe payment and DPO to dpo@DimaCard.com.
- Purpose, marketing consent and retention periods are the responsibility of the merchant — this guide is not legal advice.
Frequently Asked Questions
Is a loyalty program subject to GDPR?
Yes. As soon as it collects data linked to an identifiable person (first name, email, visit history), it is processing of personal data subject to the GDPR.
Is consent required to send offers?
For marketing prospecting (offers, reminders, promotional notifications), yes: free, specific and revocable consent is the safest basis. The operation of the program itself relies on the execution of the program.
How long to keep customer data?
A duration limited to the purpose: the time of the program and associated obligations, with a purge of inactive accounts. There is no single duration valid for everyone; set yours and stick with it.
What to do if a customer requests deletion of their data?
Respond within the stipulated time and delete their file. DimaCard allows the deletion and export of the customer file to facilitate this response.
Does DimaCard host data in Europe?
Yes, hosting is provided in the European Union (Vercel / Supabase), with payment via Stripe. The GDPR contact is the DPO, at dpo@DimaCard.com. Find all the questions on the DimaCard FAQ.
Put it in place with DimaCard
Loyalty card in Apple & Google Wallet, included notifications, an independent loyalty prize wheel, and built-in referrals — starting at €39/month. The first paid subscription is covered by the 30-day commercial guarantee under the Terms.
See plans