Expert knowledge for digital decisions
Are Dynamic QR Codes GDPR Compliant?
Short answer
What Happens Technically When Scanning
The code contains a redirect address. When accessed, the server sees at least: IP address, timestamp, requested address, often also device type and language. The IP address is treated as personal data according to established case law.
A Permissible Setup
- Clarify Legal Basis. For pure reach measurement without recognition, a legitimate interest under Art. 6 (1) (f) GDPR is applicable. If recognition across devices occurs or profiles are created, consent is required.
- Shorten or Not Store IP. For the question "how often was scanned," a counter is sufficient.
- No Cookies Without Consent. If information is stored or read on the end device, § 25 TDDDG applies – then consent is needed, regardless of personal reference.
- Limit Retention. Delete raw data, keep evaluations aggregated.
- Transparency. The privacy policy must mention the measurement.
In Switzerland
The revised Data Protection Act (revDSG) applies there. The basic ideas are comparable, but the requirements for consent are less strict in parts. For offers that also target individuals in the EU, the GDPR is decisive anyway.
Summary for Practice
Counting how often a poster was scanned: uncritical with minimal storage. Tracking which person scanned which code when: requires consent.
This classification does not replace legal advice.
Key facts
- Critical Point
- IP address is generally considered personal data
- Possible Without Consent
- Aggregated counting without recognition
- With Consent
- Recognition, profile creation, cookies (§ 25 TDDDG)
Sources
All external claims are backed by traceable sources.- 01
-
02
§ 25 TDDDG – Schutz der Endeinrichtungen Bundesministerium der Justiz