When does in-store analytics need consent rather than legitimate interest?
Consent is required once in-store analytics processes personal data for purposes that legitimate interest cannot carry, in particular special category data and marketing-driven uses 1.
Where legitimate interest is normally used
A legal basis is always needed for processing, and legitimate interest framed around security is the basis most commonly relied on for signage applications in retail and public environments 2. Analytics that stays identity-blind, meaning solutions that collect no personal information, is one way of measuring consumer interactions with in-store media while respecting privacy rules 3. Mature Wi-Fi-based in-store tracking systems track behaviour patterns anonymously, in line with data privacy laws like GDPR 4. A recurring difficulty is that collections of information in retail analytics are not always obviously personal information in the statutory sense 5.
Where consent is required instead
For some cases of direct marketing a different legal basis such as consent may be required, which precludes legitimate interest in that context 1. Processing of special categories for marketing, statistical or security purposes will in most cases require explicit consent from all data subjects under Article 9 (2) (a), though another exception in Article 9 could apply 1. Photographs fall under biometric data only when processed through a specific technical means 1. Storing behaviour patterns against a unique ID for each customer is done by asking for permission during the Wi-Fi login 4.
How consent is captured
- Opt-in at the start, where the visitor gives active consent via a pre-use screen, carries low GDPR risk provided consent is free, specific and revocable 2.
- A layered notice, a short on-screen message plus a QR code to the full privacy statement, works well for information kiosks in public spaces 2.
- Consented first-party data, such as email IDs, supports deterministic matching and targeting for brands 6.