Programs & enrollment

GDPR

The EU's data protection regulation, which governs how loyalty programs collect member data, the consent captured at enrollment, and members' rights over it.

The General Data Protection Regulation is the EU's data protection law. It applies whenever a business processes personal data of people in the EU or EEA, and a loyalty program is a textbook case: names, contact details, purchase history and messaging preferences are all personal data, and the merchant running the program is the data controller responsible for how they are handled.

For a wallet pass program, the moment that matters most is enrollment. That is where the lawful basis is established: the member is told what data the program collects and why, and gives consent or enters an agreement whose terms cover the processing. A flow like hosted onboarding captures that consent at signup, with the merchant's own wording, so membership starts on a clean legal footing rather than being backfilled later.

The regulation also grants members ongoing rights: to access the data held about them, to correct it, to withdraw consent, and to have their data deleted. A program has to be able to honor those requests, which in practice means knowing where member data lives, in the wallet platform, in the CRM, in the point of sale, and being able to act on it across those systems.

When evaluating a wallet platform, the GDPR questions are concrete: where is the data stored and processed, who is the processor, is there a data processing agreement, and what happens to member data if you leave. A platform built for European merchants should have direct answers to all four.

How enrollment works on Stell
Next step

See what this looks like on a pass.

The definition is the short version. The next pages show it on the terminals merchants already run, and the merchants running it.