When the Data Protection Commission closed 146 electronic direct-marketing investigations in 2024 and prosecuted eight companies for unsolicited communications, loyalty operators could be forgiven for assuming that enforcement was someone else's problem. It rarely is.
A loyalty program is a data collection engine. From the moment a member registers to the day they ask you to delete their account, you are collecting, storing, processing, and in many cases sharing personal data. The GDPR obligations at each of those stages are specific, and the DPC's active enforcement posture means that getting them wrong carries real consequences.
This guide covers everything an Irish marketing manager or DPO needs to know about GDPR compliance for loyalty programs. That means the lawful basis for each data point you collect, how to build a compliant sign-up flow, how long you can keep member data, how to handle rights requests, and where the DPC is actively looking. This is not legal advice; for specific situations, consult a qualified data protection professional.
A typical loyalty program registration form collects a lot: name, email address, phone number, date of birth, and postal address. Once the member is active, you add transaction history, purchase frequency, product preferences, and behavioural data from how they engage with your app or emails. Every single data point needs a documented lawful basis under GDPR Article 6.
The correct basis for core membership data is contractual necessity (Article 6(1)(b)). When a member signs up, they enter into a contract. Processing the data necessary to deliver that membership, including their contact details, transaction records, and points balance, is justified under the terms of that contract.
The mistake most brands make is stretching contractual necessity too far. Collecting a date of birth to verify age at a licensed venue is arguably necessary. Collecting it to send a birthday discount email is a marketing activity, and it requires a different lawful basis. The practical test for every data point is: would the program fail to function without this? If the honest answer is no, you need a separate justification.
The six lawful bases under GDPR Article 6 are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. For loyalty programs, the relevant bases are contract (for core membership operations), consent (for marketing and non-essential processing), and legal obligation (for records you must retain under Irish law, such as financial records). Legitimate interests can apply in some situations, but not for direct marketing communications, which we cover in the next section.
Documenting a lawful basis for each data point is not enough on its own. GDPR's accountability principle (Article 5(2)) requires you to be able to demonstrate compliance, not just assert it, and for loyalty programs that means maintaining a Records of Processing Activities (ROPA) register.
A ROPA entry for each category of personal data your program holds, name, email, transaction history, behavioural data, preferences, needs to record: the category of data itself, the lawful basis relied on, where the data originated (sign-up form, app, point-of-sale, third-party append), how long it is retained, and any third parties, including any outside the EEA, it is shared with. This is the same information a data inventory exercise produces, but a ROPA formalises it into a document the DPC can request and that your organisation can point to as evidence of accountability, rather than a claim.
Treat the ROPA as a living document, not a one-off compliance artefact. Update it whenever you add a data point, change a retention period, or bring on a new processor or partner.
Ireland's ePrivacy Regulations (SI 336/2011) sit alongside GDPR and govern electronic direct marketing independently. Under Regulation 13 of those Regulations, sending promotional electronic messages requires the affirmative consent of the recipient. According to the Data Protection Commission's guidance on electronic direct marketing, consent must be given in advance, freely given, specific, and informed. Pre-ticked boxes, silence, and inactivity do not constitute valid consent under those rules.
GDPR defines consent precisely: "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." For a loyalty program's marketing consent to hold up under scrutiny, it needs to satisfy all six characteristics that definition implies.
Freely given. Consent is not freely given if it is bundled with membership terms, if refusing it carries a penalty such as being denied access to the program, or if the member has no genuine choice. Joining the program and consenting to marketing are two separate decisions.
Specific. Consent must cover a defined purpose, not a blanket authorisation to use data "for marketing." Email, SMS, and partner communications each need their own clear opt-in where you intend to use all three.
Informed. The member needs to understand what they are agreeing to before they agree to it: who is collecting the data, what it will be used for, and how long it will be kept. A link to a lengthy privacy policy is not, on its own, sufficient.
Unambiguous. Consent requires a clear affirmative action, a ticked box, a pressed button, a verbal statement, not silence, inactivity, or a box the member had to actively untick.
Withdrawable. The member must be told, at the point of giving consent, that they can withdraw it at any time, and withdrawal must be exactly as easy as giving it was.
Documented. You must be able to show what a member consented to, what they were told, and when and how consent was given, on demand and without delay.
One limited exemption is worth understanding. If a company collected an email address during a product or service sale, and gave the customer a clear opt-out at the point of collection, it may contact that customer about similar products or services for up to 12 months without fresh consent. This exemption is narrow, and loyalty operators who rely on it without checking whether their communications genuinely meet the "similar products" test are taking a compliance risk.
Legitimate interest (Article 6(1)(f) GDPR) cannot substitute for consent where the ePrivacy Regulations require it. The EDPB's 2024 guidelines on legitimate interest, published at edpb.europa.eu, confirm this position: where electronic marketing consent is required under national ePrivacy law, legitimate interest cannot be used to bypass that requirement.
The practical implication: transactional loyalty messages (points credited, reward expiry alerts, account statements) are justified under the membership contract. Promotional messages require explicit opt-in consent. Your marketing consent architecture must reflect that distinction, and your email platform must be configured to enforce it.
The sign-up flow is where most loyalty programs either get GDPR right or build in problems they will be correcting for years. GDPR Article 13 requires that at the point of data collection you disclose your identity as data controller, the purposes and lawful basis for each processing activity, who else will receive the data, retention periods, and that the member has the right to lodge a complaint with the DPC.
Marketing consent must be collected separately from acceptance of membership terms and conditions. A single checkbox that covers both is not valid because consent must be specific. If you want consent for email marketing and also for SMS marketing, those must be two distinct, unticked opt-in boxes.
Three things to build into the flow: a clearly worded statement that core membership data will be processed to administer the program under the contract; separate unticked opt-in boxes for each marketing channel; and a link to a full privacy notice that names every third party (including technology providers and reward partners) who will process member data.
One detail that catches brands out: you must retain a record of consent, including when it was given, through which mechanism, and what the member was shown at the time. If a member disputes whether they opted in to marketing emails, you need to be able to demonstrate what they agreed to and when. No record means no defence.
For every member, your consent record should be able to show:
- What they consented to
- What they were told at the time (the version of the form or notice shown)
- When consent was given
- How consent was given (online form, in-store, app, or phone)
- Any subsequent changes, including updates, withdrawals, and re-consent
These records need to be stored securely and be queryable quickly. If a member submits a subject access request and asks to see their consent history, or the DPC asks the same question during an investigation, you need the full record ready immediately, not reconstructed after the fact.
GDPR's storage limitation principle (Article 5(1)(e)) requires personal data to be kept for no longer than necessary for the purposes for which it was collected. The DPC expects documented retention schedules that specify the period, the trigger for deletion, and the basis for each retention decision. Vague timelines such as "as long as required" do not meet the standard.
For loyalty programs, three situations apply. Active members: data can be retained for the duration of active membership because the contract justifies it. Inactive members: once a member stops engaging, the basis for retaining them in an active marketing audience weakens. The widely observed practice is to trigger a re-consent process or deletion after 12 to 24 months of inactivity. Post-closure: when a member closes their account, core membership data should be deleted. Transaction records may be retained where a specific legal obligation exists (such as Revenue requirements), but that justification must be documented and the retention limited to the minimum necessary period.
A point that creates risk for many operators: if consent is the only lawful basis for processing a member's data and they withdraw that consent, you must stop processing and delete the data, unless a separate, independent lawful basis justifies continued retention.
Many Irish loyalty programs still hold member data collected before GDPR took effect in May 2018, often via opt-out mechanisms, terms bundled with membership, or consent records that do not meet the current documentation standard. That legacy data cannot be relied on for marketing, whatever the original sign-up said.
A re-consent campaign is the correct fix. Contact affected members through existing channels, explain the new consent standard in plain terms, and invite them to actively opt in. Members who do not respond within the defined window should be suppressed from further marketing, not deleted outright, but not communicated with either until they re-consent or the retention period for their data lapses.
Re-consent is also a commercial opportunity, not just a compliance exercise. According to research from the Chartered Institute of Marketing, opt-in rates from well-designed re-consent campaigns can reach 30-50% of the original list, a smaller but far more commercially useful audience than a large, disengaged legacy database. Brandfire has helped a number of brands work through re-consent campaigns as part of broader loyalty program reviews, and the exercise regularly doubles as a natural moment to refresh preferences and re-engage the membership base.
Every loyalty program operator needs working processes for five data subject rights, which are the ones most commonly exercised, or most operationally significant, in practice.
Under GDPR Article 15, any member can submit a subject access request and receive a copy of all personal data you hold about them, the purposes for which it is processed, the categories of recipients, and expected retention periods. You must respond within one calendar month. You may not charge a fee in most circumstances.
Under Article 16, members can request rectification of inaccurate or incomplete data. Your platform should ideally support self-service correction for common fields such as email address and phone number, rather than routing every change through customer service.
Under Article 17, members can request erasure of their data. You must comply where the data is no longer necessary for its original purpose, where consent has been withdrawn and no other basis applies, or where the processing was unlawful. You may decline an erasure request where you have a legal obligation that requires retention of the data, but you must communicate that reason clearly.
Under Article 20, members whose data is processed on the basis of consent or contract can ask to receive their personal data in a structured, machine-readable format (for example, a CSV export of transaction history and points balance). This applies to data they have actively provided.
Under Article 21, members can object to processing based on legitimate interest, including profiling for marketing purposes. Objections to direct marketing specifically must be actioned immediately, with no exceptions. There is no window for review or a business case for continuing to send that member promotional communications once they have objected.
Implementation note on withdrawal: a working unsubscribe link in every marketing email is the baseline, but it is not sufficient on its own. Members should also be able to see and change their consent settings directly through a member portal or app, without needing to contact customer service, in the same way they were able to opt in in the first place.
The operational gap we most often see: brands can process an access request in their CRM but leave member data sitting in an email platform, a third-party reward portal, or a data analytics tool. A rights request is only complete when the data has been addressed across every system where it exists.
The DPC is the EU's most active GDPR enforcer by total fine value. In 2024, it imposed administrative fines of more than €652 million across 11 finalised inquiry decisions. It received 11,091 new cases from individuals during the year, closed 146 electronic direct-marketing investigations, and prosecuted eight companies for unsolicited communications. Data breach notifications rose 11% to 7,781 compared to the previous year. Since GDPR came into force in 2018, the DPC has issued more than €3.5 billion in total fines, more than four times the value issued by the second-ranking EU supervisory authority. [Source: DPC 2024 Annual Report, dataprotection.ie]
The largest 2024 fines, €310 million against LinkedIn and €251 million against Meta, both related to how personal data was used for behavioural profiling and targeted advertising without a valid legal basis. If you are using member purchase history to build marketing profiles and relying on legitimate interest as your lawful basis, you are in territory the DPC has already acted on.
The 146 direct-marketing investigations the DPC concluded in 2024 were not limited to multinationals. The DPC investigates complaints at all scales. If your loyalty program is sending promotional emails to members who did not opt in, or to inactive members whose consent has lapsed, you have measurable exposure.
The LinkedIn and Meta fines above both trace back to large-scale profiling built without data protection considered up front. GDPR's answer to that pattern is Article 25: privacy by design and by default is a legal requirement, not best practice you can adopt when convenient. For a loyalty program, that means collecting only the data you genuinely need, applying access controls proportionate to sensitivity, and automating deletion once retention periods expire, all designed in at the brief stage rather than retrofitted later.
Where a new feature poses a high risk to members, large-scale behavioural profiling, biometric data, or AI-driven personalisation of offers, GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) before processing begins. A DPIA is a structured assessment documenting the privacy risks involved and the mitigations in place. Skipping a DPIA where one is required is itself a compliance breach, independent of whether any member is actually harmed. If your program is planning a profiling-driven personalisation feature or an AI recommendation engine, confirm with your legal or compliance team whether a DPIA is needed before development starts, not after launch.
Most loyalty programs involve third-party reward partners: voucher providers, gift card suppliers, cashback processors, or co-brand partners. Every data sharing arrangement requires proper governance before you transfer a single member record.
The first question is whether the third party is a data processor or a data controller. A processor handles member data on your behalf, under your instructions (for example, a technology platform running your loyalty app). A controller processes data for their own purposes (for example, a retail partner who wants to market to your members). The distinction determines which contractual obligations apply.
Where the third party is a processor, GDPR Article 28 requires a written data processing agreement. That agreement must cover the subject matter, duration, nature and purpose of the processing, the type of personal data, and the obligations of the processor. This is not optional or aspirational. It is a legal requirement that the DPC can and does examine.
Where the third party is a joint controller, you need a joint controller agreement under Article 26, and your privacy notice must explain clearly what data goes to that partner and for what purpose. Under Article 13(1)(e), members are entitled to know specifically who receives their data. References in privacy notices to "trusted partners" or "selected third parties" are not sufficient under GDPR's transparency requirements. Name the specific entities, or at minimum, specific categories of recipients.
Before launch, or when reviewing an existing program, work through these areas systematically. At Brandfire, we use a version of this checklist when we audit a client's loyalty program ahead of a new season or a platform migration.
Data inventory. Have you mapped every data point you collect? Does each one have a documented lawful basis? Is that basis accurate, not assumed?
Consent architecture. Does your registration flow use separate, unticked opt-in boxes for each marketing channel? Do you store a record of each consent with a timestamp and the version of the form shown?
Privacy notice. Does your notice meet the Article 13 disclosure requirements? Does it name all processors and third-party controllers specifically?
Retention schedule. Is there a documented schedule covering periods, triggers, and bases for each data category? Is there a process for re-consent or deletion of inactive member records?
Rights processes. Do you have a process for subject access requests, erasure requests, and portability requests? Is there a named owner? Have you tested deletion workflows across all connected systems?
Data processing agreements. Do you have signed DPAs with every technology provider and reward partner who processes member data?
Marketing segmentation. Are promotional and transactional email audiences segmented in your platform? Are members who have not consented to marketing excluded from all promotional sends?
Data Protection Officer. Is a DPO formally required, based on the scale of your processing or use of special category data? If not legally mandated, has a senior individual been named with clear data protection responsibility, and the authority to act on it?
Getting GDPR right in a loyalty program is significantly easier when data compliance is designed into the architecture at the brief stage rather than retrofitted after a complaint arrives. The DPC's enforcement environment makes this a business risk question, not just a legal checkbox exercise.
We work with brands across energy, insurance, grocery, and telecoms to design and operate loyalty programs that meet Irish and EU data protection requirements from day one. If you are planning a new program or auditing an existing one, the Brandfire loyalty team can help you identify where the risks sit and how to address them before you go live. Contact us to start the conversation.
Does a loyalty sign-up form in Ireland need a separate marketing consent checkbox?
Yes. Under Ireland's ePrivacy Regulations and GDPR, marketing consent must be collected via a separate, unticked opt-in that is distinct from acceptance of membership terms. A combined checkbox is not valid consent because consent must be specific. Separate boxes for email, SMS, and phone marketing are required if you intend to use all three channels.
Can we rely on legitimate interest to send promotional emails to loyalty members?
No. Ireland's ePrivacy Regulations (SI 336/2011) require affirmative consent for electronic direct marketing. Legitimate interest as a lawful basis cannot override that requirement. The EDPB's 2024 guidance on legitimate interest confirms this position at the EU level.
How long can we keep a loyalty member's data after they close their account?
Core membership data should be deleted on account closure. Transaction records may be retained where there is a specific legal obligation (such as accounting records under Irish company law), but only for the period required by that obligation and documented in your retention schedule. Open-ended retention of post-closure data is not compliant.
What must a privacy notice say about third-party reward partners?
Under GDPR Article 13(1)(e), you must disclose specific recipients of member data. Generic references to "partners" or "selected third parties" are not sufficient. If a reward partner will process member data for their own purposes, that arrangement must be disclosed as a joint controller relationship and governed by a written agreement under GDPR Article 26.
What is the difference between a transactional loyalty communication and direct marketing under Irish law?
Transactional loyalty communications (points credited, reward expiry alerts, account statements) are justified under the membership contract and do not require marketing consent. Direct marketing is any communication designed to promote goods, services, or campaigns, and it requires opt-in consent under Ireland's ePrivacy Regulations, regardless of how the message is framed. A "programme update" email that promotes a new partner deal is direct marketing.