Loyalty data and GDPR: keep a useful record
Begin with the information needed to honour the reward. Give every additional field a purpose, a legal basis and a point at which it leaves the system.
Updated 29 September 2026 · 9 min read
Start the design of a loyalty programme with the reward record. Decide what you need to recognise the membership, award progress, correct an error and honour a completed card. Then examine every extra field. If you cannot explain what the programme would fail to do without it, leave it out of the first version and investigate the need before collecting it.
Use a short working document beside the programme specification. For each purpose, list the data, legal basis, people with access and retention rule. Keep the document close enough to daily operations that someone can use it when a guest asks for a correction or wants to leave. Treat the privacy notice as an explanation of that actual arrangement.
Begin with the law that applies to the business
The GDPR covers processing in the context of an EU establishment and, in specified circumstances, a business outside the EU offering goods or services to people in the Union or monitoring their behaviour there. Nationality alone is not that test. Read Article 3 before assuming that an English website or a visitor’s passport settles the question.
For a shop in Serbia, assess Serbia’s Zakon o zaštiti podataka o ličnosti, published in Službeni glasnik RS 87/2018. Article 3 sets out its scope; the Commissioner’s legislation index identifies the law. Assess GDPR separately if its scope conditions are met. Keep the two instruments distinct when writing instructions, especially their provisions on response deadlines.
A membership number can still be personal data
Under GDPR Article 4, personal data includes information about an identifiable person, including identification numbers and online identifiers. Recital 26 explains why replacing a name with a code does not necessarily make data anonymous. Serbia’s Article 4 likewise covers direct and indirect identification and defines pseudonymisation. Apply that distinction to the membership record you actually hold.
For design purposes, start by testing a member identifier, current progress, reward status and the limited transaction details needed to check awards and redemptions. Add an account-recovery contact only if your chosen recovery method needs it. Treat this as a candidate data set to justify, not a universal list of permitted fields. Include technical logs and exports in the discussion with your supplier.
The governing principle is necessity for a specified purpose: GDPR Article 5 requires data minimisation and limits retention, and Serbian Article 5 sets out corresponding principles. Ask what decision each field supports. A possible future promotion is a reason to consider a new purpose later, not a reason to collect a complete profile now.
Leave the unnecessary profile unbuilt
For a basic stamp scheme, challenge proposed fields for a home address, full birth date, employer, identity-document number or continuous location history. Write a specific justification before accepting any of them. If you later design a birthday reward, consider whether a day and month could serve that purpose without a year. Reassess the purpose and legal basis before introducing the new field.
Keep health information and other sensitive characteristics out of ordinary loyalty notes. GDPR Article 9 and Serbian Article 17 generally prohibit processing special categories, subject to their specified exceptions. As an operating recommendation, do not use a free-text loyalty field to record an allergy or infer a medical condition from an order. Deal with any separate service need through an appropriately assessed process.
Review screens as well as database columns. Decide what the person awarding a stamp needs to see, and restrict broader member searches and exports to appropriate roles. Do the same for printed lists and downloaded files. If a weekly review only needs totals, design that review around totals and check whether any small group still makes an individual identifiable.
Choose a legal basis for each purpose
Consent is one lawful basis, alongside others including contractual necessity, legal obligation and legitimate interests subject to the required balancing of rights. That follows from GDPR Article 6 and Serbian Article 12. Neither provision makes a chosen basis automatic merely because you call the service a loyalty programme.
Separate the purposes before choosing. Keeping the stamp balance, recovering access, analysing programme performance and sending offers should each have an explanation. If you propose contractual necessity for operating membership, check what is actually necessary to perform that contract. If you propose legitimate interests, document the interest, necessity and balancing assessment. Ask the adviser to examine the design you intend to run.
Where you rely on consent, it must be freely given, specific, informed and unambiguous; you must be able to demonstrate it and make withdrawal as easy as giving it. See GDPR Article 7, its Article 4 definition, and Serbian Article 15. GDPR Recital 32 expressly excludes pre-ticked boxes, silence and inactivity as consent.
Keep membership and promotional choices separate
My recommended starting design is a separate, unticked choice for each promotional channel you plan to use, with plain wording about the intended messages. Record the choice, its time and the wording shown. Offer a straightforward way to change it. Do not treat adding a card or receiving a stamp as proof of a separate promotional choice the person was never asked to make.
The practical reason for separating these flows is supported by Article 7(4): whether a service is conditional on consent to unnecessary processing matters when assessing freely given consent. Serbian Article 15 addresses that condition too. Have the rules for each communications channel checked separately before launch; a consent control alone is not a complete assessment of a campaign.
An objection to direct marketing must stop processing for that marketing purpose, including related profiling. That is the rule in GDPR Article 21(2)–(3) and Serbian Article 37. Build a way to stop promotions without accidentally deleting the reward balance. Keep a request to close the membership distinct from a request to stop offers.
Explain the arrangement before collecting the data
At collection, GDPR Article 13 requires information including who controls the data, purposes and legal bases, recipients, retention, rights and relevant transfers. Serbian Article 23 sets out the corresponding collection notice. Both should be read with their transparency provisions, GDPR Article 12 and Serbian Article 21. The notice must match the actual processing.
Put a short explanation beside the joining form and make the full notice easy to open before submission. Identify the business and a working contact address. Explain which fields are required, which are optional and what happens if a person declines an optional feature. Use the full notice for the necessary detail; avoid turning the short explanation into a promise of complete anonymity that the system cannot support.
Make leaving a process someone owns
Erasure is a qualified right. GDPR Article 17 and Serbian Article 30 cover grounds such as data no longer being needed, and consent withdrawal where no other legal ground remains. They also provide exceptions, including necessary retention for legal obligations or legal claims. Check the particular records; do not use a narrow exception to justify keeping the whole marketing profile.
- Record the request and receipt date, clarify its scope where needed, and assign someone to handle it.
- Verify identity proportionately. Match the request to the membership using an appropriate existing route where possible.
- Find the relevant records in the programme, mailing system, exports and supplier systems. Decide what must be erased and what has a documented reason to remain.
- Carry out the action, stop affected campaigns, address recipients and backups, and record the result.
- Reply clearly with what was done, any justified retention and the route for challenging the decision.
Under GDPR Article 12(3), information on action taken is due without undue delay and within one month. A necessary extension of two further months is possible for complexity or volume, with reasons notified within the first month. Serbian Article 21 instead specifies 30 days, with a possible additional 60 days on those grounds and notice within 30 days.
Do not demand an identity-document copy by default. GDPR Article 12(6) allows additional information necessary to confirm identity where reasonable doubts exist; Serbian Article 21 also addresses justified doubts. Choose a proportionate procedure. Train staff to pass a request to the responsible person rather than asking the guest to explain the law at the till.
Include the supplier and the copies
Where the shop determines the purposes and means, it is a controller; a supplier processing on its behalf is a processor. See GDPR Article 4 and Serbian Article 4. Processor arrangements require the safeguards and binding terms described in GDPR Article 28 and Serbian Article 45. Assess actual roles rather than assuming every supplier has the same role.
Ask for a demonstration of deletion across the service and a written explanation of backup handling. GDPR Article 19 and Serbian Article 33 address communicating erasure to recipients, with stated exceptions. Agree how restored backups will avoid reactivating erased memberships. Check transfer arrangements too: GDPR Chapter V and Serbian Articles 63–65 require a separate assessment of international transfers.
Set retention rules for each purpose and put them into operation. Restrict access, protect exports and test recovery procedures as practical measures against the risks you identify. The legal foundations are GDPR Articles 25 and 32 and Serbian Articles 42 and 50. Before launch, rehearse a correction, a promotional opt-out and a deletion request. Use what that rehearsal reveals to finish the programme.
Start with a clear data brief
Explore the loyalty programme with your collection rules, member choices and leaving process already defined.
See how Coteria worksSources
- Regulation (EU) 2016/679, GDPR — official text on EUR-Lex; Articles 3–7, 9, 12–13, 17, 19, 21, 25, 28, 32 and 44; Recitals 26 and 32 — eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Serbia, Zakon o zaštiti podataka o ličnosti, Službeni glasnik RS 87/2018 — official text on the Legal Information System of the Republic of Serbia; Articles 3–5, 12, 15, 17, 21, 23, 30, 33, 37, 42, 45, 50 and 63–65 — pravno-informacioni-sistem.rs/SlGlasnikPortal/eli/rep/sgrs/skupstina/zakon/2018/87/13/reg
- Serbian Commissioner for Information of Public Importance and Personal Data Protection — legislation index identifying the 87/2018 law — poverenik.rs/zastita-podataka-o-licnosti/