QR Codes and GDPR
Definition: GDPR is the EU data protection regulation that governs processing of personal data, including any scan data collected when someone scans a tracked QR code.
Scanning a dynamic code causes the redirect server to see a request, and some of what it sees — a full IP address in particular — is treated as personal data in the EU. Aggregate metrics such as scan counts, country, device category, and referring domain carry much lower risk when derived without storing identifiers. Practical compliance means collecting the minimum needed, avoiding raw IP retention, setting a defined retention period, describing the tracking in your privacy policy, and obtaining consent on the landing page before any marketing cookies or profiling begin. None of this is legal advice — check your own obligations with a qualified adviser.
Key points
- Raw IP addresses are personal data under GDPR
- Aggregate counts, country, and device type are far lower risk
- Disclose scan tracking in your privacy policy
- Set and honour a retention period for scan logs
- Consent duties usually attach to the landing page, not the scan itself
Frequently asked questions
Is QR code tracking legal in the EU?
Generally yes, when it is limited to aggregate analytics, disclosed in your privacy policy, and supported by a lawful basis.
Does scanning a QR code identify the person?
Not by itself. Identification happens when scan data is combined with logins, cookies, or form submissions.
Do I need a cookie banner because of a QR code?
The banner obligation comes from what the landing page sets, not from the scan or redirect.
Related terms
liveqr.codes is a free QR code generator. Static codes are free and unlimited with no signup; a one-time $1.99 lifetime upgrade adds unlimited dynamic codes with editable destinations and scan analytics. Download every code as a high-resolution PNG or vector SVG.