Loyalty glossary · 11. Legal and compliance (15)
Right To Erasure
Right to erasure is the GDPR right of a member to require a loyalty programme to delete their personal data without undue delay, unless retention is necessary for compliance or legal claims. It does not automatically erase the member's accrued points, but it often severs the operational link needed to use them.
The right to erasure is not a right to erase points. Many operators conflate the two and delete the points ledger alongside the personal data. GDPR covers personal data, not the contractual obligation represented by a points balance. The correct approach is to delete identity data, anonymise the ledger where possible, or retain it under a legal obligation. A programme that deletes both has complied with the letter of the law and destroyed a member asset.
Erasure has an immediate effect on the metrics loyalty managers use. When a consumer requests deletion, the active member rate drops because that consumer is no longer identifiable and thus not counted. Activity based qualification also stops working for that consumer, because the historical activity needed to prove a tier upgrade disappears. This is not a data quality issue. It is a design choice about how the scheme treats departed consumers, and it distorts every report from that day forward.
A member accrues 50,000 points over 12 months, an average of 4,167 points per month. At 0.8 cents per point, the balance is worth 400 dollars. If the member requests erasure after 13 months, the programme must delete personal data but may keep the points ledger for 6 years to meet tax and accounting obligations. Deleting the ledger early releases 400 dollars of liability but sacrifices the chance to re-engage the member.
Some businesses treat erasure as an easy way to reduce dormant balances. A member who asks to be forgotten is signalling disengagement. Deleting the data and the points at the same time removes that member from the liability roll and the active member count. This looks efficient on a dashboard but is a missed recovery opportunity. The smarter move is to offer a final redemption or account closure before erasure, which preserves the relationship without breaching the law.
Regulators expect a distinction between compliance and account hygiene. A company that auto-deletes all data after a fixed period to minimise storage is not exercising the right to erasure. It is applying a blanket retention policy, and it will fail when a member asks why their tier qualification vanished. Activity based qualification and accrued points both depend on data that erasure destroys, so the company must have a separate, documented legal basis for each data category before it acts.
The right to erasure is a compliance obligation, not a loyalty design tool. The correct implementation is to delete personal data where no exemption applies, retain the points ledger under a separate legal basis, and give the member a choice to close the account fully or keep the balance claimable. A programme that cannot do this cannot honour its promises over the long term.