The printed code processes nothing. It is a static pattern of squares, it decodes offline, and it is no more subject to data protection law than a phone number on a poster.
The redirect behind it is a different matter. The moment someone opens the decoded link, your server receives an IP address, a user agent, a timestamp, and usually a referrer. That is processing of personal data, and everything the GDPR attaches to processing attaches here: a lawful basis, a notice people can actually reach, a retention period, and a defensible answer about who else sees it.
This post covers what a scan actually generates and what each item requires. The broader picture for links is in GDPR for URL shorteners, and the cookie question specifically is in cookie consent for short links.
What a Scan Actually Produces
Decoding happens on the device with no network involved. Nothing has left the phone at that point, which is why the code itself is not the compliance question people assume it is.
Opening the link produces an ordinary HTTP request. The redirect sees the IP address, the user agent string, the time, and sometimes a referrer. A dynamic code adds one hop before the destination, so it is your server that sees this first, then the destination's.
An IP address is personal data in the ordinary case. The Court of Justice held as much in Breyer, and Article 4 defines personal data to include indirect identification. Two consequences follow that people resist: you do not have to know who someone is for the data to be personal, and aggregate counts do not launder it, because the aggregation happens after collection.
Which Lawful Basis
For counting scans, legitimate interests under Article 6(1)(f) is normally the right basis, and it is the one most campaigns should be using rather than a consent banner nobody reads.
That basis is not free. It requires a balancing test written down before the campaign: what the interest is (knowing whether the poster in the north entrance works), why it is necessary, what the impact on the individual is, and what you did to minimise it. Truncating IPs, keeping country rather than coordinates, and setting a short retention window are the mitigations that make the test come out in your favour.
Consent becomes necessary at a specific point, and it is worth knowing exactly where the line sits. Not for counting. Not for country-level aggregation. Yes for non-essential cookies set on the landing page, which is the ePrivacy rule rather than the GDPR one and applies regardless of your basis for the underlying data. Yes for building a profile that follows the person across sites, which is what a retargeting pixel on the destination does.
That distinction is the practically useful part of this whole area: scan counting and cross-site advertising are different activities with different rules, and treating them as one thing is what produces both over-collection and pointless banners.
What the Notice Has to Say, and Where
The poster cannot carry the privacy notice, and by the time the page loads the processing has already happened. So the notice lives on the landing page, reachable without hunting, and it has to be honest about a scan specifically rather than generically about the website.
The workable version says: scanning this code opens a page that records the visit, we record the time, approximate country, and device type, we do it to measure which placements work, on the basis of legitimate interests, we keep raw records for a short defined period, and here is who processes it for us.
Two things that regularly go wrong. A code that appears on physical material in one country while the landing page's notice exists only in another language is not meaningfully transparent. And a notice describing "our website" while the campaign is a shelf-edge sticker in a shop does not describe what actually happened.
Retention Is Where Most Campaigns Drift
Purpose limitation does the work here. A campaign report needs raw records for weeks; nobody needs the raw log of every scan from a 2024 poster.
The pattern that holds up: a short retention window on raw records, then aggregates kept indefinitely. Counts by day, by country, by code survive; the row containing an IP does not. That satisfies storage limitation without losing the numbers anyone will ever ask for.
It also answers the awkward question of subject access and erasure requests, because after the window there is nothing linkable left to hand over or delete.
Where the data physically sits matters too, and for EU campaigns it is the difference between a straightforward answer and a transfer assessment. EU data residency for marketing covers that, and Schrems II and tracking pixels covers what happens when the analytics tool is not in the EU.
When a DPIA Is Actually Needed
Rarely for a marketing code. A poster scan producing a page view and a counter is low-risk processing by any reading.
The threshold is crossed when scanning ties to an identifiable person rather than a count: a loyalty code linked to an account, a workforce code recording who was where and when, a code that combines with location data to build a movement pattern. Those are systematic monitoring, and Article 35 starts to apply. SOC 2 and HIPAA for link tracking covers the adjacent question of tracking in regulated contexts.
The other risk worth naming is not yours. A QR code hides its destination, which is exactly what makes quishing work. A code on your packaging that a stranger covers with a sticker becomes your reputational problem even though the processing was never yours, and the mitigation is a domain people recognise plus periodic checks that the codes in the field still resolve where they should.
Choosing a redirect that keeps scan data in the EU by default is the easiest of these decisions to get right: create a link on the free plan and check where the analytics for it live before the campaign goes to print.
Read the Cornerstone Series
This sits in the compliance cluster. Start with GDPR for URL shorteners for the redirect-level analysis, then cookie consent for short links for where consent genuinely applies. The trust page covers our own processing posture.
Related on the Blog
Veelgestelde vragen
Do QR codes fall under the GDPR?
The printed code does not, because a pattern of squares processes nothing. The redirect it points at does: resolving a scanned link means your server receives an IP address, a user agent, and a timestamp, and that is processing of personal data with everything the regulation attaches to it.
Is an IP address personal data under the GDPR?
Yes, in the ordinary case. The Court of Justice held in Breyer that a dynamic IP address is personal data for a website operator where lawful means exist to identify the person behind it, and the definition in Article 4 covers indirect identification. You do not have to be able to name someone for the data to be personal.
Do I need consent to count QR code scans?
Not usually for counting alone. Aggregate scan analytics without cookies or cross-site profiling can generally rest on legitimate interests under Article 6(1)(f), documented with a balancing test. Consent becomes necessary once you set non-essential cookies on the landing page or build profiles that follow a person across sites.
What has to be in the privacy notice for a QR campaign?
That scanning the code takes the person to a page which records the visit, what is recorded, why, on what lawful basis, for how long, and who else sees it. It has to be reachable from the landing page, because the poster cannot carry the notice and the scan has already happened by then.
How long can scan data be kept?
Only as long as the stated purpose needs. A campaign report justifies raw records for weeks, not years. The practical answer is a short retention window on raw logs plus indefinite aggregates, so the counts survive without the underlying identifiers.
Does a QR code on a product need a DPIA?
Rarely on its own. A scan that produces a page view and a counter is low risk. A DPIA becomes relevant when scanning is tied to an identifiable individual, used for systematic monitoring, or combined with location tracking, which is the pattern in loyalty and workforce use cases rather than in marketing posters.
Probeer Elido
Plak een URL, krijg een werkende korte link
Geen aanmelding nodig. Link blijft 30 dagen actief. Meld je aan om hem voor altijd te bewaren.
Gratis, geen aanmelding nodig · 2 per dag