European QR code platform: GDPR, DPP and enterprise compliance

European QR code platform: GDPR, DPP and enterprise compliance

A QR code scan generates personal data on every read. The platform behind the code records the visitor’s IP address, an approximate location derived from it, a device type, a timestamp and the destination served. Under Article 4(1) of the GDPR (General Data Protection Regulation, EU 2016/679), that combination relates to an identifiable natural person. The QR code platform becomes a data processor, the brand becomes the data controller, and the choice of platform becomes the part of a QR code programme that a European legal team will actually review. This guide covers what that review looks for, where the EU Digital Product Passport adds a second layer, and how to run the procurement so it takes weeks rather than quarters.

Unitag tracks 2.4 million scans daily across 189 countries. Over 40 million QR codes generated for brands including Bonduelle, Schneider Electric, and L’Oréal.

What a scan collects, and why the GDPR applies

The GDPR defines personal data as any information relating to an identified or identifiable natural person. A single field in a scan log can look anonymous. The combination rarely is. An IP address has counted as personal data since the Breyer ruling (CJEU C-582/14, 2016). The approximate location derived from that IP address is personal data. So is a device fingerprint when it is used to recognise a returning visitor across scans.

Every dynamic QR code platform collects some version of this on every scan, because scan analytics is a large part of what enterprises buy: which campaign drove the traffic, from which city, on which device. None of that is a problem in itself. It is a processing activity, and a processing activity needs a documented purpose, a lawful basis, a retention period and a contract. The compliance review exists to establish who holds the data, where it sits, and what the contract says.

One detail that regularly surprises marketing teams: the data is collected whether or not anyone looks at the dashboard. A dynamic QR code pointing quietly at an existing product page still produces a scan log, and the scan log is where the personal data lives.

The controller carries the choice of processor

Article 28 of the GDPR makes the controller responsible for choosing processors that offer sufficient guarantees. If the processor sits outside the European Economic Area, the controller has to justify the cross-border transfer lawfully, document it in the record of processing activities and disclose it in the privacy notice. That work lands on your legal team, whichever vendor causes it.

Worth naming who ends up in the room. A QR code platform is usually bought by marketing or marketing ops, and the personal data angle means the DPO and legal join the evaluation late unless someone invites them early. The evaluations that run smoothly are the ones where the invitation goes out before the shortlist is fixed, because the legal questions below can eliminate a vendor that marketing has already fallen for.

For US-owned providers, the bar is higher still. The Schrems II ruling (CJEU C-311/18, July 2020) invalidated the EU-US Privacy Shield and tightened the conditions for Standard Contractual Clauses. A US-headquartered platform falls within the scope of FISA Section 702, and that scope follows ownership: storing the data in a European data centre does not take a US parent company out of it. Legal teams respond with transfer impact assessments and supplementary measures, which take time and rarely leave anyone comfortable.

The EU-US Data Privacy Framework, adopted in July 2023, eased some of this, but only where the US provider is certified under the framework and only for the categories of data the certification covers. The enforcement stakes are real: the Irish Data Protection Commission fined Meta 1.2 billion euros in May 2023 on cross-border transfer grounds.

The practical consequence shows up in shortlists. European enterprises in regulated sectors tend to start with EU-hosted, European-owned platforms and widen the search only if the functional requirements cannot be met. It spares legal a transfer analysis, and it spares the project a quarter of elapsed time.

Five checks before you sign

The legal review of a QR code platform usually reduces to five questions. They are worth sending in writing to every shortlisted vendor:

  • Data residency. Scan logs and their backups sit in EU or EEA data centres, with no replicas in non-adequate jurisdictions. The vendor should be able to name the hosting provider and the legal entity that operates it.
  • The DPA. A Data Processing Agreement under Article 28(3), with a current sub-processor list covering the hosting provider, the CDN and any email or notification service, plus a committed notice period for sub-processor changes.
  • Retention. Scan-data retention that is configurable and tied to your documented purpose. A controller in pharma or finance may need far shorter retention than a controller in retail, and regulators expect the setting to follow the purpose.
  • Consent on hosted pages. If the code points to your own website, your consent banner does the work. If the platform hosts the destination itself, as with vCards (digital business cards) or campaign microsites, the platform has to serve a compliant consent mechanism.
  • Breach notification. Article 33 gives the controller 72 hours to notify the supervisory authority, so the processor’s contractual notice to you has to land well inside that window.

A vendor that returns written answers on all five within a week has a compliance programme that actually runs. A long silence is also an answer. Keep the replies: they become annexes to the DPA and evidence in the record of processing activities, so the week spent collecting them is not overhead but documentation you would have had to produce anyway.

What procurement adds on top

Legal review is half the file. Procurement usually attaches a security questionnaire, and the same items appear on nearly every one: country of incorporation of the processor and its ultimate parent, the sub-processor list with locations, penetration test cadence, an ISO 27001 certificate or written evidence of equivalent controls, single sign-on support, and a right-to-audit clause with its scope.

Two habits make this stage faster. Ask for everything in writing, because verbal assurances do not survive personnel changes on either side. And read certificates rather than collecting them: an ISO 27001 certificate carries a scope statement, and the scope has to cover the service you are actually buying. How to read one honestly, including what to do when a vendor evidences controls without holding the badge, is a topic we cover in a separate article on ISO 27001 and QR code platforms.

Where the EU Digital Product Passport fits

The DPP (EU Digital Product Passport) is arriving under the ESPR (Ecodesign for Sustainable Products Regulation, EU 2024/1781), with a battery passport obligation landing in February 2027 under the EU battery regulation (EU 2023/1542). Batteries and textiles lead, and further product categories follow as delegated acts are adopted.

The passport itself carries product data: materials, durability, recycled content, repair information. That is regulatory data about an object. The scan that retrieves it is the same scan as above, with the same IP address in the same log, so a DPP programme inherits the full GDPR analysis of its QR code platform. This is why packaging and compliance teams increasingly sit in the same vendor evaluation as marketing.

Sector rules already in force preview the pattern. EU wine labelling has required electronic labels since December 2023 under regulation EU 2021/2117, and France’s loi AGEC (2020) pushes product transparency information onto digital supports. In both cases the industry answer was a QR code on the product, and in both cases the brands involved discovered that the labelling project and the data protection review were the same project. The DPP repeats this at a much larger scale.

Most DPP implementations are converging on QR codes carrying GS1 Digital Link, the GS1 standard that places the product’s GTIN inside a web address. The same standard sits behind GS1 Sunrise 2027: retailers will need to be able to accept QR codes carrying GS1 Digital Link at point of sale by the end of 2027, with 2D codes read alongside the barcode during the transition. The movement is broad and steady rather than sudden: 48 countries covering 88 percent of world GDP are piloting the 2D migration. There is no cliff edge here and no reason to rush a platform decision. There is a good reason to make one platform decision instead of two, because the code on the packaging and the code on the poster will end up governed by the same legal review.

Running a legal review of QR code platforms?

Hosting, contracts and multi-team governance, built for European enterprise evaluations.

See the enterprise offer →

How Unitag is set up for European buyers

Unitag has built QR code infrastructure since 2011 and serves around 1,000 clients, with scans arriving from 189 countries. The platform is EU-hosted and GDPR-compliant, and the company is European on both sides of the Channel: Unitag-QR LTD, the mother company, is registered in the United Kingdom, with a French subsidiary and offices in London and Toulouse. The team works in both French and English, which turns out to matter once a DPO in Paris and a procurement lead in Manchester are on the same call.

The UK side raises a question buyers ask often enough that we wrote a separate article on it: the United Kingdom holds an EU adequacy decision, so the structure stays simple for EU controllers. On governance, multi-country organisations run each brand or subsidiary as a sub-organisation with its own users and permissions, so a compliance reviewer sees defined roles rather than a shared login. And on standards, Unitag is a GS1 Solution Provider and holds the GS1 France Recommended badge, which is worth verifying on any vendor if the DPP or GS1 Digital Link appears anywhere on your 2027 roadmap.

Contract documentation for legal review sits with the enterprise plans. The fastest route through it is to bring your questionnaire to a demo and work through it point by point.

What to do now

Three moves take an evaluation from long list to signature without drama.

First, send the five checks above, in writing, to every vendor on the list, with a one-week deadline for written answers. The answers do double duty later as evidence in your record of processing activities.

Second, put the DPA templates in front of legal early and side by side. The DPA is where the real differences between platforms show up, and reading them in parallel is much faster than reading them in sequence.

Third, if the DPP or GS1 Digital Link sits on your 2027 roadmap, bring the packaging team into this evaluation now. A single platform decision covering marketing campaigns and product identification spares you a second procurement in eighteen months. When you reach the commercial stage, both sit on the same pricing page, and the enterprise plans add the SLA and support terms that a European legal review expects to find.

Bring your compliance checklist to a demo

We will walk through hosting, contracts and governance, question by question.

Book a demo →

Related articles