The General Data Protection Regulation is the EU's data protection law. It applies whenever a business processes personal data of people in the EU or EEA, and a loyalty program is a textbook case: names, contact details, purchase history and messaging preferences are all personal data, and the merchant running the program is the data controller responsible for how they are handled.
For a wallet pass program, the moment that matters most is enrollment. That is where the lawful basis is established: the member is told what data the program collects and why, and gives consent or enters an agreement whose terms cover the processing. A flow like hosted onboarding captures that consent at signup, with the merchant's own wording, so membership starts on a clean legal footing rather than being backfilled later.
The regulation also grants members ongoing rights: to access the data held about them, to correct it, to withdraw consent, and to have their data deleted. A program has to be able to honor those requests, which in practice means knowing where member data lives, in the wallet platform, in the CRM, in the point of sale, and being able to act on it across those systems.
When evaluating a wallet platform, the GDPR questions are concrete: where is the data stored and processed, who is the processor, is there a data processing agreement, and what happens to member data if you leave. A platform built for European merchants should have direct answers to all four.

