Answers / Loyalty programs

    How do I make my restaurant loyalty program GDPR-compliant?

    Written by PEKO Team.Last updated: 05/21/2026.

    Capture explicit opt-in at sign-up (not pre-ticked), document the lawful basis, give one-click unsubscribe in every message, honour deletion requests within 30 days, and keep a processing record. Modern loyalty platforms ship all five out of the box.

    Published: 05/09/2026

    GDPR doesn't ban restaurant loyalty — it just demands explicit, informed consent and clean data hygiene. Five things matter: (1) opt-in must be a positive action, never a pre-ticked box, (2) the lawful basis (usually 'consent' for marketing) must be recorded per-customer, (3) every outbound message must carry a one-click unsubscribe, (4) deletion requests must be honoured within 30 days, (5) a processing record must exist if you have 250+ customers.

    PEKO ships compliant defaults for all five — including granular consent (loyalty-only vs marketing), deletion API, and processing-record export.

    FAQ

    Does GDPR apply to Vietnamese restaurants with EU tourists?

    Yes — GDPR is extra-territorial. If you process EU residents' data, you're in scope regardless of where you operate.

    What's the fine for non-compliance?

    Up to 4% of global annual turnover or €20M, whichever is higher. In practice, regulators target wilful or large-scale violations; a small F&B operator with documented good-faith compliance is at low risk.

    Calculate your PEKO ROI

    Related

    People also read