QR Codes and GDPR – What You Need to Know if You Use Them for Business
QR codes are everywhere these days – on restaurant menus, advertising posters, product packaging, office receptions, and event materials. Most organisations use them without much thought – yet QR codes and GDPR is a topic that affects everyone who uses them for business purposes. Because using QR codes may involve the processing of personal data, often in ways you may not be aware of.
What is a QR code and how can it be used?
A QR code (Quick Response) is a graphic information carrier – a pattern that a mobile device camera can read. The technology has existed since 1994 – developed by a Japanese subsidiary of Toyota for automotive logistics – but its mass consumer adoption accelerated sharply during the COVID-19 pandemic and has not slowed since.
The graphic can encode a website URL, but also contact details, text, a Wi-Fi password, ticket data, or a parcel identifier.
How are QR codes used in business?
The code contains personal data or is used to identify a person
Some QR codes contain personal data encoded directly in the graphic – a boarding pass with the passenger’s name and surname, a named event ticket, a loyalty card linked to a customer account. Others contain an identifier that is not personal data in itself, but a verification system links it to personal data in its database – such as a code for opening a parcel locker or activating a public transport ticket.
The code leads to a website
A QR code on a poster, packaging, event stand, business card, or restaurant menu – when scanned, opens a website, form, or downloadable file.
It is this type of code that this article focuses on, because the seemingly simple mechanism of taking a user to a destination can involve the processing of personal data and give rise to obligations for those who use QR codes in their business activities.
When does using a QR code that leads to a website mean processing personal data?
To redirect a user to the destination page, the scanning device sends technical data to a server. The data collected for this purpose includes at minimum:
- the device’s IP address,
- the date and time of the scan, and
- the device type and operating system.
In most cases, processing an IP address solely to serve the request of opening a page will not constitute the processing of personal data. It is worth noting, however, that an IP address may be recognised as personal data (CJEU judgment C-582/14, Breyer: a dynamic IP address constitutes personal data in relation to an entity operating an internet service, provided that entity has the legal or technical means to identify the user). Even if the IP address is anonymised or deleted after the request has been served, according to the position of some data protection authorities the processing of personal data still occurs (the mechanism is analogous to that described by the CNIL in its 2022 decision on Google Analytics: the full IP address is transmitted to the server before any further processing takes place – and it is precisely that moment of transmission that constitutes the processing of personal data). For most website owners who do not have the means to identify a user on the basis of an IP address, the mere receipt of an IP address for the purpose of serving a request will not constitute the processing of personal data.
If, beyond using the IP address solely to open the destination page, statistics are collected from the data gathered – for example, to determine the number of scans from a given city on a given day – or if additional data is collected or inferred about the person scanning, further processing of personal data occurs. The technology used in the operation of QR codes allows, among other things, the determination of an approximate location of the user, and – when combined with other available data – the inference of their precise location at the moment of scanning.
Who collects this data and who is the data controller?
The question of who is the data controller is determined by who decides on the purposes and means of processing the data of people who scan.
Data may be collected either directly by the server of the destination page or through an additional intermediary (e.g. a QR platform) and its server – depending on which solution the business uses.
If you use a code that leads directly to your website, without the involvement of external parties – the processing of data from visitors to your site takes place on your server and you are the data controller.
If you use an external party to generate and manage codes, the process works such that the data of the person scanning is first collected by the intermediary’s server, which then redirects the user to the destination page. In such a situation, the allocation of roles should be set out in the contract. Some QR platforms adopt in their documents a model in which the code owner is the controller – both in respect of the technical data collected during the redirect and the location statistics generated by the platform from the IP address. By accepting the terms of such a contract, a business takes on specific obligations, sometimes without realising it, because it does not connect the use of location statistics with the role of data controller in relation to the data of people scanning.
What to look for when deciding to use QR codes in business?
Additional tools for collecting statistics
A QR code leading directly to your website does not give you information about how many times it was scanned or from where. But if you use additional tools to collect such statistics, you become the controller of the data of visitors to your website – with all the obligations that entails.
Where and how you generate the code
If you use an external platform to generate codes – one you can log into and access statistics from – what matters is what obligations you take on by accepting the terms of that contract.
If you use an external provider – what does that provider do with the data?
A platform acting as an intermediary in the redirect may process the data of people scanning for its own purposes – including collecting additional data and sharing it with advertising partners and analytics networks. Such an intermediary, repeatedly collecting data from the same device across redirects for many different organisations, may be able to build a profile of a specific user’s interests, preferences, and regular times and places of presence. The person scanning a code is usually unaware that their data is reaching other parties and has no real opportunity to exercise their rights against them. For businesses using external platforms, this creates an additional dimension of due diligence: what data does the intermediary collect for its own purposes, to whom does it pass it on, and is it able to meet GDPR requirements?
💡 Worth knowing!
Before choosing an external QR platform, check in its legal documents:
- what data is recorded with each scan and whether the IP address is stored,
- whether the platform processes scan data for its own purposes,
- what role the platform assigns to the code owner in relation to the data of people who scan,
- whether the platform offers a DPA compliant with Art. 28 GDPR and whether a list of sub-processors is available,
- where the data is physically stored and whether processing takes place within the EEA,
- how long the platform retains scan data.
The answers should be found in legal documents – the privacy policy and DPA – not in marketing materials.
Summary
Using QR codes may involve the processing of personal data.
If a code contains personal data or is used to identify a person – the processing of personal data occurs at the moment the code is read. If a code leads to a website – processing may occur on the server of the destination page, and if you use an external QR platform – also on the intermediary’s server.
Simply redirecting a user to a page will not, in most cases, constitute the processing of personal data. The situation changes when you collect statistics from that data, use additional analytics tools, or use an external QR platform that processes the data of people scanning – including for its own purposes.
Key questions to ask before using a QR code in business:
- Does the code lead through an intermediary’s server – and if so, what obligations do you take on by accepting that platform’s terms?
- Do you plan to collect scan statistics – and if so, using what tools and on what legal basis?
- If you use an external QR platform – what does that provider do with the data of people scanning for its own purposes?
Before you use a QR code that leads to a website – make sure you know what obligations apply to you.
This article relates to EU law and is based on the legal status, case law, and practice applicable at the time of publication. It is intended as educational material and reflects the author’s personal opinion. It does not constitute legal advice.
Sources and further reading:
CNIL decision of 10 February 2022 on Google Analytics, https://www.cnil.fr/en/use-google-analytics-and-data-transfers-united-states-cnil-orders-website-manageroperator-comply/
Regulation (EU) 2016/679 (GDPR), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679
CJEU judgment of 19 October 2016, Case C-582/14, Patrick Breyer v Federal Republic of Germany, https://curia.europa.eu/juris/document/document.jsf?docid=184668&doclang=EN
EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR, https://www.edpb.europa.eu/system/files/2023-10/EDPB_guidelines_202007_controllerprocessor_final_en.pdf
EDPB Guidelines 1/2024 on processing of personal data based on Art. 6(1)(f) GDPR, https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202401_legitimateinterest_en.pdf