What is a GDPR-compliant loyalty card?
A GDPR-compliant loyalty card is a programme that collects only the data needed to recognise the customer and hand over their reward, that informs them clearly, that obtains separate consent before sending them offers, that sets a retention period and that binds the technical provider with a processing agreement. In Belgium, the Data Protection Authority (DPA) has clarified each of these points, in particular the use of the electronic identity card.
This guide is written for the merchant. It does not replace legal advice, but it cites the texts and decisions as available on 10 October 2026.
What data can you ask for?
The principle of data minimisation (article 5.1.c GDPR) limits data to what is necessary for the purpose. For a stamp card, the purpose is to recognise the customer and credit their visits.
| Data | Necessary for a loyalty card? | Note |
|---|---|---|
| First name or name | Yes | To recognise the customer and personalise the card |
| E-mail or phone number | Yes, one of the two | To send the card and handle recovery |
| Date of birth | No, unless a birthday offer | Optional, never mandatory |
| Postal address | No | Useless for a digital card |
| National register number | No | Use strictly regulated by law |
| Photo, copy of the identity card | No | Prohibited outside cases provided by law |
With Goodly, the customer leaves a name and an e-mail address on the sign-up page; the offers box is separate and never pre-ticked. That is the default setting, not an option.
The eID is not a loyalty card
Scanning the electronic identity card to create a customer card is a well-known Belgian practice, and now a well-regulated one.
The law. Article 6, §4 of the Act of 19 July 1991 on identity cards allows a merchant to read the eID only with the holder's free, specific and informed consent, and requires offering "an alternative mechanism to the use of the identity card" to customers who do not wish it. No copy, photocopy or electronic copy, may be taken outside cases provided by law (DPA, "eID, practical applications", consulted on 10 October 2026).
The 2019 decision. In decision 06/2019 of 17 September 2019, the DPA's Litigation Chamber fined a merchant €10,000 for requiring the eID to be read as the only way to obtain a loyalty card, with no alternative. The merchant read the name, address, photo and the barcode linked to the national register number: disproportionate to the purpose (article 5.1.c) and consent not freely given (article 7.4).
The Market Court, then the Court of Cassation. The Market Court annulled that decision on 19 February 2020, holding that since the complainant had not presented her card, no data had been processed. The Court of Cassation quashed that ruling on 7 October 2021: a person has the right to minimal processing of their data in order to obtain a service and may complain about a refusal of service tied to a disputed processing, even if their data was ultimately not processed (DPA, press release of 28 October 2021).
Freedelity, 2024. In decision 146/2024 of 28 November 2024, the DPA imposed corrective measures on Freedelity, a company that pools identity data read from the eID on behalf of retail chains: stop collecting card data that is not indispensable for the purposes pursued, reduce retention from 8 years to a maximum of 3 years from the last activity, and ensure that access to commercial benefits is not conditional on accepting additional processing (DPA, press release of 28 November 2024).
In practice: do not scan the eID for a loyalty card. A name and an e-mail are enough, and a card in the Wallet asks for nothing more.
Consent for offers: a separate box, never pre-ticked
Enrolling a customer in the programme and sending them promotions are two distinct processing operations.
E-mail. Article XII.13, §1 of the Code of Economic Law provides that the use of electronic mail for advertising is prohibited without the prior, free, specific and informed consent of the recipient. The Royal Decree of 4 April 2003 provides an exception for your existing customers, under three cumulative conditions: contact details obtained directly during a sale, advertising limited to your own similar products or services, and the possibility to object free of charge from the moment of collection. The DPA restated this framework in its recommendation 01/2026 on direct marketing, which replaces recommendation 01/2020 and integrates case law up to 15 December 2025.
Push notifications and Wallet. The same recommendation states that the channel used does not matter: a promotional notification on the card is direct marketing just like an e-mail. Treat it with the same consent.
Free and separate. Consent is not free if access to the card or the reward depends on it (recommendation 01/2026, section on free consent; Freedelity decision). A pre-ticked box is not consent (CJEU, Planet49, C-673/17, 1 October 2019). Every message must contain a simple way to object (article XII.13, §2), and the right to object to direct marketing is unconditional (article 21.2 GDPR).
Concretely, your form has two boxes: a mandatory box for the programme rules and the information notice, and an optional, unticked box for offers. The push notifications guide then explains how to stay useful without tiring people.
How long should you keep the data?
The GDPR sets no numerical period: article 5.1.e requires retention "no longer than necessary". The DPA's recommendation 01/2026 recalls that the period depends on the relationship: shorter for a prospect, longer for a regular customer, and always documented. In the Freedelity decision, 3 years after the last activity was retained as the maximum for a consumer file of retail businesses.
A simple rule for a business: set a period after the last visit, write it in your information notice, and apply it. With Goodly, end-customer data is kept as long as the card exists and deleted at your request from the dashboard, or at the customer's request; no automatic purge is done on your behalf. It is therefore up to you to decide and apply the rule, for instance once a year.
Who is responsible: you or your provider?
The GDPR distinguishes the controller, who decides purposes and means, from the processor, who acts on instructions (article 28). For your loyal customers' data, the merchant is the controller. The digital card provider is generally a processor, provided a written contract says so (article 28.3). Some network platforms declare themselves joint controllers with the merchant, which changes the allocation of obligations: read that clause of the terms before signing.
With Goodly, article 13 of the terms and conditions constitutes the processing agreement: Goodly processes end-customer data on your behalf, for the duration of the subscription, solely to provide the service, and sub-processors are listed in the privacy policy. The end customer receives an information notice linked from the sign-up page.
Your obligations remain yours: inform the customer (article 13), keep a processing register (article 30), answer access or erasure requests, and do not reuse the data for another purpose without a legal basis.
Merchant checklist
- Collect a name and an e-mail or phone number, nothing more by default.
- Never read or copy the eID for a customer card; offer an alternative if you use a reader for another legal purpose.
- Two boxes: programme rules (mandatory) and offers (optional, unticked).
- A readable information notice before sign-up, with the retention period.
- A processing agreement with your provider, or clarity on the joint controller role.
- A deletion rule for inactive cards, applied at least once a year.
- An unsubscribe option in every message.
For a shop or a food business, these seven points fit on one page and are set up in an afternoon. The guide creating a loyalty programme in Belgium covers the other aspects of the launch; Goodly's pricing includes the compliant form by default.
Frequently asked questions
Can I ask for the date of birth for a birthday offer?
Yes, if it is optional, explained (birthday offer) and never a condition for getting the card. If you do not run a birthday offer, do not ask for it.
Can I require consent to offers in order to give the card?
No. Consent would not be free (article 7.4 GDPR; DPA recommendation 01/2026; Freedelity decision). The card and its stamps must work even if the customer declines offers.
Can a merchant scan the eID if the customer agrees?
The law allows it with free, specific and informed consent, without a copy and with a mandatory alternative. The DPA found reading all the card's data disproportionate for a simple loyalty card. The safest course is still not to do it.
How long should I keep the data of a customer who no longer comes?
Set a period after the last visit, document it and apply it. The DPA retained a maximum of 3 years after the last activity in the Freedelity decision; a shorter period is possible.
Do I need the customer to sign something?
No. An online sign-up with a box ticked by the customer and an accessible notice is sufficient evidence, provided you can show when and to what they consented.
Is Goodly the controller for my customers?
No: you are the controller, Goodly is the processor (T&C, article 13). Create your card and the compliant form, the information notice and the separate consents are in place from the first sign-up.
Sources
- GDPR, articles 5.1.c, 5.1.e, 6, 7.4, 13, 21.2, 28 and 30.
- Act of 19 July 1991 on population registers and identity cards, article 6, §4; DPA, "eID: practical applications" (consulted on 10 October 2026).
- DPA, Litigation Chamber, decision 06/2019 of 17 September 2019 (€10,000 fine); DPA press release.
- Market Court, ruling of 19 February 2020; Court of Cassation, ruling of 7 October 2021; DPA, press release of 28 October 2021.
- DPA, decision 146/2024 of 28 November 2024 (Freedelity); DPA press release of 28 November 2024.
- DPA, recommendation 01/2026 on the processing of personal data for direct marketing (PDF, consulted on 10 October 2026); replaces recommendation 01/2020 of 17 January 2020.
- Code of Economic Law, article XII.13; Royal Decree of 4 April 2003 regulating the sending of advertising by electronic mail.
- CJEU, 1 October 2019, Planet49, C-673/17.
- Goodly, terms article 13 and privacy policy, §7.