Scenarios · Retail

A cross border retailer with a loyalty programme

Noorderlicht is a retailer with stores in six member states, a webshop, a loyalty programme of four million members, and a group service centre in Morocco that runs customer support. It profiles purchase history to personalise offers, buys a customer data platform as a service, and shares aggregated insight with suppliers. Its difficulty is not sensitivity but volume and choice: almost every question here has two lawful answers, and the register has to state which one was taken.

Who and what appears in this scenario

Each kind of record keeps the same mark throughout, so the same name always means the same thing.

Entity

  • Noorderlicht Retail BVThe controller, and the main establishment in the Netherlands.
  • Six national operating companiesLocal employers, separate controllers for staff data.
  • Noorderlicht Service Centre, MoroccoA group company acting as processor for support.
  • Kernel CDPThe customer data platform vendor, a processor.

Business unit

  • Retail stores, Webshop, Loyalty, MarketingOne unit per function, each with an owner.

Data subject set

  • Loyalty membersFour million members, profiled from purchase history.
  • Webshop customersBuyers without a membership.
  • Store employeesHeld by the national companies, not the group.

Processing activity

  • Loyalty membership administrationArticle 6(1)(b), performance of the contract.
  • Personalised offers from purchase historyArticle 6(1)(f), with a balancing test and instant objection.
  • Email and push marketingConsent recorded per channel.
  • Supplier insight reportingAggregated output only.

Assessment

  • Profiling at scaleArticle 35(3)(a), systematic evaluation of behaviour.

Transfer

  • Support and hosting outside the UnionOne record per destination.

Risk

  • Inference reveals something unexpectedProfiling that implies health or pregnancy.

Measure

  • Inference exclusion listCategories the model may not use.

Document

  • Legitimate interests assessmentThe balancing test behind the profiling.

Person

  • Sanne de VriesData Protection Officer, approver.
  • Marc PeetersLoyalty director, owner of the profiling activity.
  • Aicha BennaniService centre manager, owner of the processor relationship.

How it gets built

The shape of the organisation

Six countries means six establishments and one main establishment, which decides which authority leads. That answer belongs on the record, not in somebody's memory.

The context selector. Choosing an organisation and a business unit narrows every register beneath it.
The context selector. Choosing an organisation and a business unit narrows every register beneath it.

Entity: Noorderlicht Retail BV, main establishment

What is held
The controller, with the Netherlands recorded as the place of central administration and the Dutch authority as lead.
Why
Article 56 gives one lead authority where processing is cross border, determined by the main establishment. Recording it here is what makes the one stop shop claim evidenced rather than assumed.

Entities: six national operating companies

What is held
Each national company, with its role in the group.
Why
Local companies employ staff and run stores, so they process as part of the same controller for customer data but as separate controllers for employment. Splitting employment from customer processing early avoids a register that mixes the two.

Entity: Group service centre, Morocco

What is held
A group company acting as processor for customer support.
Why
Intra group does not mean internal. The service centre is a separate legal person outside the Union, so it needs a processor agreement and a transfer record.
Alternative
Binding corporate rules are the alternative to standard contractual clauses for a group that transfers constantly. They cost more to approve and less to operate; for a single service centre the clauses are usually proportionate.

The processing activities and their bases

The loyalty programme is one product to a customer and four activities to a register. Separating them is what allows one to be withdrawn without collapsing the others.

A processing activity, with the special category question answered first and the basis stated with its reason.
A processing activity, with the special category question answered first and the basis stated with its reason.

Processing activity: Loyalty membership administration

What is held
Enrolment, points and redemption, on Article 6(1)(b).
Why
Administering the scheme is performance of the contract the member entered. It does not need consent, and asking for it would suggest the points balance could be withdrawn.

Processing activity: Personalised offers from purchase history

What is held
Profiling of purchase history to select offers, on Article 6(1)(f) with a legitimate interests assessment and an unconditional objection route.
Why
Profiling for the retailer's own marketing can rest on legitimate interests where the balancing test holds and objection is honoured immediately under Article 21(2). The assessment is held as the legitimate interests assessment supplied with the subscription.
Alternative
Consent under Article 6(1)(a) is the alternative, and is the safer answer where the profiling reveals something the member would not expect, such as inferred pregnancy or health. Consent gives cleaner ground and a smaller audience; legitimate interests gives reach and a duty to make objection effortless. The register requires whichever is chosen to be evidenced, either by a consent record or by the balancing test.

Processing activity: Email and push marketing

What is held
Channel marketing, with consent recorded per channel, and the soft opt in for existing customers where national law allows it.
Why
The lawful basis under the Regulation and the consent required by the ePrivacy rules are separate questions, so the channel activity holds its own consent records rather than borrowing the profiling basis.

Processing activity: Supplier insight reporting

What is held
Aggregated, non identifying reporting to suppliers.
Why
Recorded because the aggregation has to be evidenced. If the output can be reduced to an individual it is still personal data, and the activity would need a basis and a notice.
Alternative
Sharing member level data with suppliers is possible, but it makes the supplier a controller and requires a notice naming them. Most retailers should keep the aggregate and say so.

The customer data platform and the transfer

A bought platform is where retail registers usually go wrong, because the vendor is described as a partner and treated as neither processor nor controller.

The transfer register, with the safeguard and the assessment behind each destination.
The transfer register, with the safeguard and the assessment behind each destination.

Entity and agreement: Customer data platform vendor

What is held
A processor, with the data processing agreement, the subprocessor list and the authorisation terms.
Why
Article 28(2) requires authorisation of subprocessors and notice of changes. The platform's own subprocessors are recorded, so a change can be assessed rather than discovered.

Transfer: Support and hosting outside the Union

What is held
One transfer record per destination, with the mechanism, the assessment and the measures.
Why
One record per destination keeps the answer readable when one country's assessment changes and the others do not.
Alternative
A single transfer record covering the vendor as a whole is less work, and it fails the first time an authority asks about one country. Prefer the per destination record.

Assessment: Profiling at scale

What is held
An impact assessment covering systematic monitoring and evaluation of behaviour.
Why
Article 35(3)(a) applies to systematic and extensive evaluation, and four million profiled members is squarely within it. The assessment states the measures that limit inference and the ones that make objection immediate.

Rights and the operational reality

Volume makes the rights process the part that fails. The register is what makes it answerable inside a month.

The data subject requests register, with the statutory clock visible on each row.
The data subject requests register, with the statutory clock visible on each row.

Requests: erasure and objection at volume

What is held
Each request as a record, with the statutory clock running from receipt.
Why
An objection to profiling has to stop the profiling, which means the request has to reach the platform and the marketing channels. The links from the request to the activities and systems are what make that provable.

Retention: dormant members

What is held
A retention rule that closes and deletes dormant memberships, evidenced on completion.
Why
Article 5(1)(e) is the rule most often broken by a loyalty scheme. A dated, evidenced deletion is the only defence.
Alternative
Anonymising rather than deleting keeps the analytics and satisfies the storage limitation, provided the result genuinely cannot be re-identified. State which was done; do not describe deletion when the rows are only hidden.

How it gets maintained

A register is not finished when it is built. Three changes arrive at every organisation, and each one is absorbed the same way.

A new risk arrives

An analyst notices that the offer model has learned to promote maternity products from unrelated purchases, so an inference about pregnancy is being acted upon.

  1. 01Set the context band to Noorderlicht Retail BV and the Loyalty unit.
  2. 02Open Risks, press the plus button, and name the risk Inference reveals something unexpected.
  3. 03Describe the source, the inference and the effect on individuals in the Details tab.
  4. 04Move to Under assessment and rate both lenses. Harm to individuals is high; the effect on the organisation is reputational rather than financial.
  5. 05Choose reduce as the treatment, then link the measure Inference exclusion list and the activity Personalised offers from purchase history.
  6. 06Record the residual rating, send it to Sanne de Vries for approval, and set a six month review.

The profiling assessment now cites a rated, treated risk, and the exclusion list is evidenced rather than asserted.

The risk register on the data subject lens.
The risk register on the data subject lens.

A new processing activity starts

Marketing launches an in store beacon offer, sending an offer to the app when a member is near a shelf.

  1. 01Set the context band to the Retail stores unit.
  2. 02Open Processing activities, press the plus button and answer the special category question, then state the purpose and the basis.
  3. 03Cite the existing data subject set Loyalty members with Link a record; do not create a second member set.
  4. 04Record consent as the basis for the channel, and link the consent evidence in the Accountability tab.
  5. 05Open the Assessment tab. Location tracking of members at scale triggers screening, so link the existing Profiling at scale assessment or extend it.
  6. 06Move the activity to In use and confirm the new line in the record of processing.

One more activity, one more line in the Article 30 record, and no duplicate reference records.

The record of processing activities, produced from the activities in use.
The record of processing activities, produced from the activities in use.

A new data processor is engaged

The webshop moves its review moderation to an external agency in Serbia.

  1. 01Open Entities, press the plus button, choose the processor family and then the processor role, and record Serbia as the country.
  2. 02Create the data processing agreement in Documents from the supplied template and link it to the entity.
  3. 03Link the processor to the activity it serves from the Linked records band of that activity.
  4. 04Open Transfers and create a record for Serbia, stating the clauses and the transfer impact assessment.
  5. 05Re-read the risk on unexpected inference and raise a new one if the moderation gives the agency access to free text about individuals.

The new party is in the register with its agreement, its transfer and its risk, before the first review is moderated.

The transfer register, with the safeguard behind each destination.
The transfer register, with the safeguard behind each destination.

Try it

The demo site builds a register from a sentence. Describe an organisation like this one and it will draft the records, then leave you the gaps to close.