The loyalty programme is one of the most valuable commercial assets of physical retail and, at the same time, one of the areas where the most compliance errors concentrate: generic consents, commercial communications without a clear basis, transfers to partners without proper information and unsubscribes that take days to process.
This guide explains how to design and operate a loyalty programme with customer card under the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018) and art. 21 LSSICE (Spain's Law 34/2002) on electronic commercial communications.
Programme anatomy: differentiated processing operations
A loyalty programme is rarely a single processing operation. It usually combines a core and several optional layers, each with its own legal basis:
| Processing | Typical data | Legal basis |
|---|---|---|
| Enrolment and programme management | Identifying data, contact, card number, points. | Performance of contractual relationship (6(1)(b)) |
| Point accrual and redemption | Purchase history linked to the card. | Performance of contractual relationship (6(1)(b)) |
| Electronic commercial communications | Email, mobile phone; basic segment. | Consent (6(1)(a)) + art. 21 LSSICE |
| Profiling and personalised offer | Detailed history, frequency, average ticket. | Express consent (6(1)(a)) |
| Transfer to partners or group companies | Identifying and segment data. | Express, specific consent (6(1)(a)) |
| Aggregated statistical analysis | Anonymised or pseudonymised data. | Legitimate interest (6(1)(f)) with triple test |
Express consent by purpose
The fundamental operational rule of the programme is granularity of consent. A single "I accept the privacy policy" checkbox does not cover everything. Each purpose additional to the contractual core of the programme is presented with its own checkbox, unticked by default, with clear and specific text:
- Programme consent (enrolment, points, redemption, customer service): does not require a separate checkbox if executed as part of the programme contract. It does require clear information and acceptance of the general conditions.
- Consent to electronic commercial communications: separate checkbox, unticked by default. Text such as "I wish to receive offers, discounts and news of the programme by email/SMS".
- Consent to profiling for personalised offer: separate checkbox when profiling goes beyond basic statistical analysis and translates into relevant individualised offers.
- Consent to transfer to partners or group companies: separate checkbox and prior identification, at least by category, of recipients.
- Image consent if the programme includes draws, events or publication of winners: separate checkbox.
Each consent is revocable at any time without conditioning continued membership of the main programme. The customer can remain in the programme (accrue points, redeem them) and have withdrawn consent to commercial communications.
Commercial communications and the LSSICE
Art. 21 LSSICE requires prior express consent to send commercial communications by email, SMS and equivalent electronic channels. There is a complementary route in art. 21.2 LSSICE: to customers with a prior contractual relationship, the shop may send commercial communications on products or services similar to those already contracted, provided that each communication offers a simple and free objection mechanism.
Applied to the loyalty programme:
- To go beyond the similar product/service and send broader offers from the shop or cross-promotions with partners, differentiated express customer consent is required.
- Each commercial email includes in the footer the sender's identity, the unsubscribe mechanism (operational link) and, where applicable, reference to the alternative objection channel.
- Each commercial SMS includes a free unsubscribe keyword or operational link.
- The shop maintains a consent register with date, channel and exact wording shown to the customer when requesting it.
- Commercial calls for prospecting purposes to individuals are governed by art. 66.1.b of Spain's General Telecommunications Act (Law 11/2022): the customer must have expressly consented to receiving commercial calls.
Right to object and unsubscribe mechanism
The right to object (art. 21 GDPR) is one of the most relevant in marketing and loyalty. Operationally:
- Each commercial communication includes a simple and free unsubscribe channel that does not require access to a private area.
- Unsubscribes are processed immediately. The AEPD (the Spanish Data Protection Authority) usually assesses how quickly this happens: an unsubscribe that takes several days to take effect generates problems if sends continue in the meantime.
- The unsubscribe propagates to all systems: CRM, email marketing platform, SMS platform, app push notification tool if any.
- The customer may object to programme profiling while remaining enrolled: the programme must continue working in its basic mode (points, redemption) if the customer so wishes.
- Evidence of the unsubscribe (date, channel) is kept for the time necessary to evidence it.
"In a loyalty programme, almost all compliance is played out at the moment of enrolment and at the moment of unsubscribe. An enrolment form with separate checkboxes, an unsubscribe system that works the same day and a clean record of who consented to what and when is, in practice, 80% of the job."
Mario P. Talamillo · Managing Partner, Certix®
Art. 13 GDPR information at enrolment
At the time of enrolment, the customer receives the art. 13 GDPR information notice, integrated into the form (paper or digital) and stored as evidence of delivery. Minimum content:
- Identity of the controller (the company owning the shop, CIF, registered office) and DPO details if appointed.
- Specific purposes: programme management, point accrual and redemption, where applicable commercial communications, profiling, transfers.
- Legal bases: performance of the programme's contractual relationship for the core; consent for additional purposes.
- Categories of recipients: accountant, processors (programme platform, email marketing, customer service), and partners or group companies if consented to.
- International transfers where applicable (SaaS providers in the US or elsewhere: indicate Data Privacy Framework or another appropriate instrument).
- Differentiated retention periods.
- Customer rights and route to exercise them.
- Right to lodge a complaint with the AEPD.
Programme platform, CRM and processors
The loyalty programme usually relies on several technology tools acting as processors:
- Specific loyalty platform (card, points and redemption manager).
- CRM where customer data and history reside.
- Email marketing platform.
- SMS or push notifications platform.
- Payment gateway if the programme includes discounts applied to the transaction.
- External customer service centre if any.
For each: art. 28 GDPR contract with all required clauses (purpose, duration, nature, type of data, categories of data subjects, security measures, sub-processors, procedure for data return at service termination). Verify international transfers and, where applicable, valid mechanism (Data Privacy Framework, standard contractual clauses).
Retention of programme data
The retention policy is differentiated by block:
- Basic programme data: during the relationship and thereafter blocked during the periods of limitation of applicable civil actions (art. 1964 of the Spanish Civil Code) and tax periods where applicable.
- Purchase history linked to the card: during the programme's term plus applicable limitation periods.
- Commercial communications: while consent is in force. After revocation, the data is kept only in the exclusion list.
- Unsubscribes and revocations: for the time necessary to evidence them in case of complaint.
- The professional programme documents differentiated periods and proceeds to secure destruction at expiry.
Minimum loyalty programme checklist
- Art. 13 GDPR notice delivered at enrolment and kept as evidence.
- Separate checkboxes unticked by default for each additional purpose.
- Consent register with date, channel and wording shown.
- Simple, free and operational unsubscribe mechanism in each commercial send.
- Propagation of unsubscribes to all systems involved.
- Art. 28 GDPR contracts with programme platform, CRM, email marketing, SMS and other processors.
- Verification of international transfers with appropriate instrument.
- Differentiated retention policy by block.
- Processing entered in the RoPA.
Frequently asked questions
What legal basis does a loyalty programme use?
Programme management (enrolment, points, redemption) is covered by performance of the contractual relationship (6(1)(b) GDPR). Additional purposes (commercial communications, profiling, transfer to partners) require express consent (6(1)(a)). Legal obligation covers only specific aspects such as billing.
Can the shop send offers by email to programme customers?
Yes, with express consent (art. 21 LSSICE) or, in a prior contractual relationship, on similar products or services with a simple and free unsubscribe mechanism in every send (art. 21.2 LSSICE). The programme alone does not authorise commercial sending by default.
How is the right to object to communications exercised?
Through the simple and free unsubscribe link in each email, or keyword/link in each SMS. The unsubscribe is processed immediately and propagated to all systems. The customer may object to communications without losing programme membership.
Can the shop transfer data to partners or group companies?
Only with express, specific and independent consent for that transfer. A global consent is not enough. The shop identifies recipient categories and informs the customer in advance. Where the recipient is a processor, instead of a transfer there is an art. 28 GDPR contract.
This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.
Want to review your shop's loyalty programme?
At Certix we assign you a compliance expert specialised in the retail sector. No commercial intermediaries, no generic templates.
Talk to an expert