Retail & Distribution

The loyalty programme is a data processing operation, not a promotion

Nextica Law & Tax puts in order the data a retail chain accumulates without noticing. The loyalty programme does not store a name: it stores purchase history, and cross-referencing it to decide which offer each person receives is profiling, with the safeguards of art. 22 of the General Data Protection Regulation. The head office and the franchisee sharing a customer base are usually joint controllers under art. 26 and need the arrangement that allocates who answers for what. Sending commercial communications has its own rule in art. 21 of Law 34/2002. And video surveillance of the shop floor and warehouse has its own in art. 22 of Organic Law 3/2018, with the information sign and the retention period almost nobody meets.

You have known what each customer buys for six years and never decided how long you would know it.

What's included

1. An inventory of what the chain actually keeps

card sign-ups, purchase history by receipt, returns, warranties, shop-floor and warehouse cameras, and data arriving from the online channel.

2. Separating purposes at sign-up

running the card is one thing and segmenting the history to send personalised offers is another, with its own basis and information.

3. Analysing the profiling

which decisions are made automatically about the person, what effect they have, and what safeguards must be offered.

4. A joint-controller arrangement between head office and franchisees where they share the customer base, allocating who informs, who handles rights requests and who notifies a breach.

5. Retention periods decided and applied

how long the purchase history of someone who never comes back is kept — the question nobody has asked.

6. Commercial communications by email and messaging under their own rule, and an unsubscribe that works first time.

7. Store and warehouse video surveillance with the information sign, camera placement and retention period, and its employment use handled separately.

THE CHAIN KNOWS MORE ABOUT ITS CUSTOMERS THAN IT DECIDED TO KNOW

Purchase history piles up on its own. What does not pile up on its own is the decision about what it is for and how long it is kept.

Cross-referencing purchase history to decide automatically which offer, price or condition each person gets, without the required safeguards: profiling with effects on the data subject has its own regime, with prior information, a right to human intervention and a right to contest the decision.

art. 22 of the General Data Protection Regulation

Head office and franchisees sharing the customer base with no joint-controller arrangement: where purposes and means are determined jointly, an arrangement allocating the roles transparently is required, and it releases neither party: the customer can exercise their rights against either one.

art. 26 of the General Data Protection Regulation

Cameras on the shop floor and in the warehouse with no information sign, no justified placement and no retention period: processing for security purposes has its own requirements, and using those images to monitor staff is a different processing operation that requires informing beforehand, not after the incident.

art. 22 of Organic Law 3/2018 on Data Protection and digital rights

Frequently asked questions

Does the loyalty card need consent, or is the contract enough?

Two things that usually share one tick box need separating. Running the card — accruing points, redeeming them, serving the member — is performance of the relationship with that person. Using their purchase history to segment them and send personalised offers is a different purpose and needs its own lawful basis and prior information. Putting it all into a single 'I accept the terms' box is what turns a routine inspection into a file: the problem is not holding the data, it is being unable to show what you said it would be used for.

We share the customer base with our franchisees. Who answers if there is a breach?

It depends on who determines the purposes and means, and if the two decide that together they are joint controllers. Art. 26 of the Regulation then requires an arrangement allocating the roles transparently — who informs the customer, who handles access or erasure requests, who notifies a breach and within what deadline — and making the essence of that allocation available to the data subject. What matters for the network is that the arrangement releases nobody: the customer can exercise their rights against either party, so the franchisee has to be ready to respond even where head office runs the system.

Equipo Nextica

Content reviewed by

Equipo Nextica

Dirección

Meet the team

Let's talk about your company.

Tell us your situation and we'll reply within 24 working hours.

Step 1 of 2

Your data is processed according to our privacy policy.