What UK Coffee Shops Can Legally Collect for Loyalty Under GDPR (And What to Skip Entirely)
A UK coffee shop can legally collect a customer's name, email, phone number, and purchase history for a loyalty program under two lawful bases: legitimate interest or contract. What it cannot do is send marketing texts or emails using that same data without meeting the requirements of PECR, and it cannot collect anything from the "special category" list (health data, biometrics, racial or ethnic origin) without that customer's explicit agreement to that specific use. Most loyalty programs that get flagged by the ICO aren't collecting too little data. They're collecting the right data and then using it the wrong way, usually for marketing they never got permission to send.
TL;DR
Names, emails, phone numbers, and purchase history can be collected under legitimate interest or contract, no separate consent needed for core loyalty admin.
Marketing emails and texts to loyalty members need to follow PECR rules. Explicit opt-in consent is the default requirement, though a "soft opt-in" exception can allow marketing to existing customers about similar products or services without it, provided they were given a clear chance to opt out when their details were collected and in every message since.
Special category data (health, biometric, racial origin) requires explicit consent and has no place in a standard stamp card or points program.
Data minimisation GDPR principles mean you only collect what the program actually needs, not what might be "useful someday."
Inactive accounts can't sit in your database forever. Storage limitation means dormant loyalty data eventually gets deleted or anonymised.
About the Author: This article is written by the team at meed, a digital loyalty platform built for independent cafes and coffee shops that runs enrollment, points tracking, and reward redemption without needing a customer's phone number, address, or app download to get started.
What Personal Data Can a Coffee Shop Legally Collect for a Loyalty Program?
Standard personal data, meaning names, email addresses, phone numbers, and purchase histories, can be collected under UK GDPR using legitimate interest, provided the collection passes a balancing test weighing your business need against the customer's rights. This covers the basics: who's enrolled, what they've bought, how many stamps or points they have. It does not automatically cover marketing use of that same data, which sits under a different set of rules entirely.
Special category data is a separate tier altogether. Health information, biometric identifiers, and racial or ethnic origin all require the customer's explicit, informed consent before you touch them. There is no version of a coffee shop loyalty card that needs any of this. If your sign-up form asks for date of birth beyond a simple "are you over 18" checkbox, or anything resembling a health question, you've wandered into territory the program doesn't need and the law treats with far more scrutiny.
What Is "Legitimate Interest" and Why Does It Matter for Loyalty Programs?
Legitimate interest is a lawful basis for processing data when a business has a genuine, necessary reason for it that isn't overridden by the customer's fundamental rights and freedoms. Think of it as a permission slip that's automatically valid for the boring, expected parts of running a program: tracking that someone has nine stamps, not ten, and knowing which drink triggers their free one.
Where it stops working is electronic direct marketing. Legitimate interest or contract covers the mechanics of the loyalty program itself, but PECR governs when you can email or text someone for marketing purposes. The default is explicit opt-in consent, but PECR also includes a "soft opt-in" exception: if a customer's details were collected in the course of a sale or negotiation for a sale, a business can send marketing messages about similar products or services without separate opt-in consent, as long as the customer was given a clear opportunity to opt out at the time their details were collected and is given that same opportunity in every message afterward. Skipping this distinction, or assuming every loyalty sign-up automatically permits marketing outreach, is one of the most common ways small hospitality businesses end up out of compliance, not through malice, but through not checking which rule actually applies to their situation.
What Does Data Minimisation GDPR Actually Require in Practice?
Data minimisation under GDPR means collecting only the data that's adequate, relevant, and limited to what's necessary for the stated purpose, nothing gathered "just in case." For a coffee shop, this is a genuinely useful filter to run every field on your sign-up form through. Ask of each one: does the loyalty program stop working without this?
A name and a way to identify the account, yes. A home address, almost never. Applying data minimisation isn't just a compliance checkbox, it's also lighter operationally. Less data collected means less data to secure, less to justify in a privacy notice, and less risk if something does go wrong down the line. A program that only holds a name, an email, and a stamp count is a smaller target and a simpler one to explain to a customer who asks what you're doing with their information.
A Quick Filter for Every Field on Your Sign-Up Form
Name - needed to identify the account, keep.
Email or phone - needed to link the wallet card or app entry to a person, keep.
Purchase history - needed to track rewards earned, keep.
Date of birth (full) - rarely needed beyond age verification, question it.
Home address - almost never needed for a loyalty program, skip.
Health, biometric, or ethnicity data - requires explicit consent and has no operational purpose here, skip entirely.
What Must Be Included in a Coffee Shop's Privacy Notice?
Building on the data minimisation point above, collecting less data only helps if customers actually know what you're doing with what you do collect. Under Articles 13 and 14 of UK GDPR, a privacy notice is a mandatory transparency document, not a nice-to-have. It must legally include your business's identity and contact details, the purposes and lawful bases you're relying on, how long you'll retain the data, whether it's shared with third parties, and what rights the customer has over their own information.
For a loyalty program specifically, this means being upfront that stamp tracking runs on legitimate interest while marketing messages are governed by PECR, and that these are handled differently, with marketing permission something a customer can opt out of independently of their loyalty enrollment. A privacy notice buried in dense legal text that nobody reads doesn't meet the transparency bar. It needs to be genuinely findable and understandable, ideally linked from the sign-up point itself, whether that's a QR code, a paper form, or a digital wallet card.
How Long Can a Coffee Shop Keep Loyalty Data?
A related but distinct question from what you collect is how long you're allowed to hold onto it. UK GDPR doesn't set a fixed number of months or years for loyalty data. Instead it enforces a storage limitation principle: you keep personal data only as long as it's genuinely necessary for the purpose you collected it for.
In practice, this means an inactive loyalty account, someone who hasn't visited in a long stretch and shows no sign of returning, can't sit in your system indefinitely on the logic that it might be useful one day. Eventually it needs to be deleted or anonymised. Setting a clear internal rule, for example reviewing accounts with no activity in the last 12 to 24 months, gives you something defensible to point to if the ICO ever asks how you're applying storage limitation rather than leaving it undefined.
What Happens If a Coffee Shop Gets This Wrong?
Stepping back from the mechanics, the consequences are worth being clear-eyed about. UK GDPR does not have a lighter penalty tier for small businesses based on employee count or revenue. Every business faces the same statutory maximums: up to £8.7 million or 2% of global turnover for standard violations, and up to £17.5 million or 4% of global turnover for the most severe. The ICO scales the actual fine to the specific case, and a single independent coffee shop is not going to be treated the same as a multinational chain in practice, but the legal ceiling doesn't discriminate by size.
The more realistic risk for a small operator isn't a headline fine, it's a complaint that triggers scrutiny you didn't need, or a customer who loses trust because a marketing text arrived without a clear opt-out ever having been offered. Getting the consent, legitimate interest, and PECR rules right the first time avoids both.
Frequently Asked Questions
Can a coffee shop collect a customer's date of birth for a loyalty program? Only if there's a specific reason, such as age verification for alcohol sales. Collecting full date of birth purely to enable a "birthday reward" is common practice but should be minimised to just the day and month where possible, consistent with data minimisation principles.
Does signing up for a stamp card count as consent to receive marketing texts? Not automatically. Loyalty program administration and marketing communication are covered by separate rules. Signing up for stamps covers the former under legitimate interest or contract. Marketing texts or emails are governed by PECR, which generally requires explicit opt-in consent, though a "soft opt-in" exception can apply if the customer's details were collected during a sale and they were given a clear opt-out option at collection and in every subsequent message.
Can a coffee shop collect dietary or allergen information for loyalty purposes? Allergen data can shade into special category data if it relates to a health condition, which requires explicit consent. It also isn't necessary for standard loyalty tracking, so most programs are better off leaving it out entirely.
How long should a coffee shop keep a customer's loyalty data after they stop visiting? UK GDPR doesn't set a fixed retention period, but the storage limitation principle requires deletion or anonymisation once the data is no longer necessary. Many businesses set an internal review point, such as 12 to 24 months of inactivity.
Is a digital wallet loyalty card more compliant than a paper punch card? Neither format changes the legal requirements, but digital programs typically make it easier to manage consent records, retention schedules, and privacy notices consistently, which supports compliance rather than replacing it.
Does a small, independent coffee shop face lower GDPR fines than a large chain? No. The statutory maximum penalties apply regardless of business size. The ICO scales actual fines to the case, but there's no separate legal tier for small businesses.
About meed
meed is a digital loyalty platform built for independent cafes, coffee shops, and small hospitality businesses that need a program running without app downloads, POS integration, or a data collection process heavier than it needs to be. Loyalty cards are stored in Apple Wallet or Google Wallet, enrollment happens through a QR code, NFC tap, or AI-powered receipt scan, and the free plan covers core loyalty features for up to 50 members without asking for more customer data than the program actually requires. For coffee shops weighing what to collect against what to skip, meed's structure is built around the same principle this article covers: collect what the loyalty mechanic needs, nothing more, and keep marketing permission separate from program enrollment.
Ready to run a loyalty program that stays on the right side of what it collects? Get started with meed.





Comments