Loyalty Program Data Privacy: What Happens When a Member Asks What You Hold?
31 Agosto 2026
David Schneider

In August 2026, Reece Rogers, a senior writer at WIRED, asked McDonald’s for a copy of the personal data held against his loyalty account. He received 515 pages.1

No law was broken. Rogers submitted the request through the McDonald’s Privacy Rights Center, exercising a right he holds as a California resident, and McDonald’s complied. There was no breach and no regulator. The company answered the question it was asked, and the answer became the story.

Loyalty program data privacy is usually discussed as a breach problem. Most loyalty teams have a breach response plan. Very few have read what their own system would send a member who asked to see everything.

What did McDonald’s disclose to a member who asked?

The file covered years of transaction history, loyalty points activity, every promotional offer sent to the account, and the codes Rogers had scanned during the McDonald’s Monopoly promotion, along with the prizes attached to them.

It also contained predictions. McDonald’s systems estimated that Rogers would visit 2.16 times over the following six weeks, spend an average of US$13.49 per order, and spend US$29.15 in total. The file ranked menu items by relevance to him, led by a large Diet Coke, and sorted him into behavioural categories describing the occasions on which he bought. His customer attrition likelihood, the modelled probability that he would stop visiting, was recorded as zero.

Rogers later told Marketplace that he had expected some level of data collection when he signed up, and had not anticipated it would be that extensive and granular. The predictive modelling surprised him most. He requested deletion of his data.2

A McDonald’s spokesperson told WIRED that the company takes data privacy and security seriously, that it uses information such as past purchases to deliver relevant deals, offers, and messages, and that customers retain the privacy choices set out in its privacy statement. Privacy specialists quoted in the coverage described the collection as fairly standard for large loyalty programs.

Which is the uncomfortable part for anyone running a program of similar size. The same request would produce a similar file.

Why is loyalty program data privacy different once data is aggregated?

Ari Ezra Waldman, a professor of law at UC Irvine, made the central observation in the coverage. A single data point, such as eating a particular burger, is unremarkable. Years of those points, run through predictive models, produce something a member experiences as personal in a way no single record does.

From the member’s side, accuracy about a member’s current situation builds trust, especially when the message carries some empathy. The problem starts when a message reveals something the member does not remember telling the brand. At that point the program needs to explain where the information came from, and many cannot.3

Predictive fields are what cause the trouble. Members generally accept a transaction history, because they were there for every line of it. A churn score is something they never knew existed and have no way to check. For more on how members weigh what they give against what they receive, see our article on the data bargain between brands and members.

How should a loyalty program prepare for a data access request?

The file a member receives is the clearest statement a program will ever make about how it treats them. Here are five steps a loyalty program should follow when preparing for a data access request, in the order worth doing them.

1. Assemble the file before a member does. Run an internal access request against a real, long-tenured member profile and read the output as a member would. This surfaces retention problems, orphaned fields, and predictive scores nobody remembered were being written.

2. Make retention defensible. Every field should map to a stated purpose and a defined retention period. In November 2020 the French data protection authority, the CNIL, fined Carrefour France €2.25 million after inspecting its loyalty program. Carrefour was holding data on more than 28 million customers who had been inactive for five to ten years, and had missed the statutory deadlines for responding to individual rights requests.4 Neither of those is a policy problem. Both are things a member finds out about by asking.

3. Be able to explain the predictive fields. Where a model influences which offers a member receives, the program should be able to say in plain language what the model does and which inputs it uses. Regulators are moving towards requiring that explanation, and a model nobody in the business can describe will not survive the question.

4. Document purpose limitation before monetisation. Record which data may be used to run the program, which may be used for advertising and analytics, and what consent supports each. In May 2026 the California Attorney General announced a US$12.75 million settlement with General Motors over the sale of driver location and behaviour data without adequate notice or consent, the largest penalty issued under the California Consumer Privacy Act to date and the first focused on data minimisation and purpose limitation.5 The constraint applies equally to loyalty. Data collected to run a program cannot be reused for something the member was never told about. Our article on loyalty program data as a commercial asset sets out the opportunity, and purpose limitation is what bounds it.

5. Give members self-service control. A member should be able to see what the program holds, take a copy, remove it, and check which permissions they have granted, without needing to contact support.

The last step costs something. Programs that make deletion easy see deletion rates rise, and the database can shrink in the short term. What they gain is a database of people who understand the exchange and accepted it, which is more accurate and far easier to defend when the rules change.

Most of this is decided long before anyone submits a request, at registration and onboarding, which we cover in our article on how to collect member data with intent.

What do members expect from a loyalty program on data privacy?

As Loyalty Consultants we have observed that members are becoming less willing to share. The 2026 EY Loyalty Market Study, based on 1,505 responses from US consumers collected in November 2025, found comfort with sharing personal data with loyalty programs fell from 55 per cent in 2024 to 52 per cent in 2025 and 48 per cent in 2026, the first time it has sat below a majority across the study’s three-year history. Discomfort rose from 13 per cent to 22 per cent over the same period.6

The reasoning has shifted too. Privacy is still the most common concern, though EY records fears about data being sold or leaked easing year on year. Close to a third of those who were uncomfortable simply did not expect to get anything out of it.

Loyalty & Reward Co’s Empowered Customer Mandate™, detailed in the 3rd edition of Loyalty Programs: The Complete Guide, sets out nine expectations that shape how consumers evaluate the brands they engage with. Two govern the disclosure question directly. The first is Protect my data: I will share if you earn it, improve my experience, and let me control it. The eighth is Prove I can trust you: my trust resets with every experience.

The readiness assessment attached to the model asks three questions a program can answer today:

  • Do we give members granular, self-service controls over what data we collect and how it is used
  • Is every data collection touchpoint paired with a clear value exchange the member can see
  • Can members view, export, and delete their personal data from our loyalty platform without contacting support

Taite, writing in Harvard Business Review in January 2026, described this as a trust loop, in which disclosure drives value and value drives further disclosure. The loop is fragile, and one failure can collapse it.7 A disclosure file is one of the few moments a member gets to audit the exchange for themselves.

In summary

Preparing for a data access request is a fast way to find out how well a program is governed. Loyalty & Reward Co work with program operators to review how member data is collected, governed, and used, and whether the value exchange holds up when a member asks to see everything held about them. Our loyalty program audit covers data governance alongside program design, commercial performance, and member experience. Get in touch to discuss a review.

Frequently asked questions

What is a data subject access request?

A data subject access request is a formal request from an individual asking an organisation for a copy of the personal data it holds about them. Privacy regimes including the GDPR, the California Consumer Privacy Act, and the Australian Privacy Act give individuals this right. Organisations must respond within a defined statutory period, which varies by jurisdiction.

What is a loyalty program data strategy?

A loyalty program data strategy sets out what member data a program collects, why it collects it, how long it retains it, who may access it, and what value the member receives in exchange. It covers governance, consent, retention, security, and member-facing controls, and it operates alongside the privacy policy rather than being replaced by it.

How long should a loyalty program retain member data?

Only for as long as the data serves the purpose for which it was collected. Privacy regimes require deletion of data no longer necessary for its stated purpose, and inactive member records are a common area of exposure. Programs should set a defined retention period for each field and review it against actual use.

What is the difference between zero-party and first-party data?

First-party data is collected by observing member behaviour, such as purchases, page visits, and email opens. Zero-party data is information a member intentionally and proactively shares, such as stated preferences, interests, and purchase intentions. Zero-party data requires no inference, arrives with the member’s active awareness, and tends to be more accurate.

Can a brand sell loyalty program member data?

That depends on the jurisdiction, the consent obtained, and the purpose for which the data was originally collected. Purpose limitation rules under the GDPR and the California Consumer Privacy Act restrict repurposing data for uses unrelated to those disclosed at collection. Program operators should obtain specialist legal advice in each market in which they operate disclosed at collection. Program operators should obtain specialist legal advice in each market in which they operate.

Referencias

1.      Rogers, R., 2026, ‘McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There’, WIRED, August 2026.

2.      Marketplace, 2026, ‘How the McDonald’s mobile app compiled a 515-page dossier on one reporter’, American Public Media, 21 August 2026.

3.      Shelper, P., in press, Loyalty Programs: The Complete Guide, 3rd edition, Loyalty & Reward Co.

4.      Commission Nationale de l’Informatique et des Libertés, 2020, ‘Carrefour: fines of €2,250,000 and €800,000’, CNIL, November 2020.

5.      Office of the Attorney General of California, 2026, ‘When it comes to data privacy, consumers must be in the driver’s seat’, May 2026.

6.      EY, 2026, 2026 EY Loyalty Market Study: Exploring the gap between performance and experience.

7.      Taite, 2026, ‘5 Psychology-Backed Principles for More Effective Personalization’, Harvard Business Review, January 2026.

<a href="https://loyaltyrewardco.com/author/david-schneiderrewardco-com-au/" target="_self">David Schneider</a>

David Schneider

David is a Loyalty Director at Loyalty & Reward Co, the leading pure-play loyalty consulting firm. Loyalty & Reward Co design, implement, and evolve award-winning loyalty programs for global brands. David has worked in global advertising and media roles for over seventeen years with a focus on CX. He has delivered award-winning work for brands such as BMW of North America, Toyota Motor Corporation Australia, Anytime Fitness, Suncorp and GSK. David applies his skills across all aspects of the business, including loyalty program design, strategy development, customer experience, lifecycle management and the effective collection and use of data.

Lea las últimas opiniones de nuestros expertos

Hable con nosotros

¿Necesita un mejor programa de lealtad? ¿Quiere aprovechar nuestra experiencia? ¡Hable con nosotros!