TL;DR for the DPO
Four findings that recur wherever there is a loyalty card: (1) invalid consent; (2) new purposes added over time without ever reassessing the processing; (3) legitimate interest invoked without adequate balancing; (4) data subject requests answered beyond the Art. 12(3) deadline.
The three points that matter
- Loyalty programmes grow by accretion: they start as point collection, then come profiling, personalised offers, purchase-behaviour analytics, partner sharing. Each layer is a new purpose that had to be assessed when it was added, not afterwards.
- Consent collected at sign-up does not cover what comes later. If the purpose changes, you either update the legal basis or collect fresh consent: silence is not a third option.
- Response deadlines are a measurable duty and the easiest to challenge: one month, extendable by two with justification. It is among the first things an authority checks, because it only takes looking at the dates.
What to do now, in practice
For clients with loyalty programmes, apps or communities: 1) reconstruct the timeline of purposes: what the programme did at launch and what it does today; 2) check each added purpose has its own legal basis and sits in the register; 3) reread the consent wording: if it is generic or bundled, rebuild it granular; 4) measure response times over the last six months: if you cannot state them, that is already a problem; 5) review sharing with commercial partners and the related agreements.
Why it matters for your clients
The case comes from Norway but the shape of the problem is identical in any retail chain with a loyalty card: features layered over the years on top of consent collected once. It is an audit you can propose concretely, with a clear scope and a verifiable outcome.
Official source:Datatilsynet (Norway) - decision following an audit of the Nordic entities of a retail groupLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free