UK GDPR After Brexit
Following Brexit, the UK retained its own version of GDPR (UK GDPR) alongside the Data Protection Act 2018. The requirements are substantively similar to EU GDPR but enforced by the UK Information Commissioner's Office (ICO) rather than EU supervisory authorities. For most retail businesses, UK GDPR and EU GDPR can be treated as equivalent in practical terms.
The key obligation: if you collect, store, or process personal data about customers or staff, you must have a lawful basis for doing so, must protect it appropriately, and must be able to respond to individuals' requests about their data.
What Customer Data Does Your POS Collect
A POS system with CRM and loyalty features typically holds: customer name, email address, phone number, purchase history (what they bought, when, how much), loyalty points balance, and potentially delivery address. Each of these is personal data under UK GDPR.
Email receipts — increasingly common — also involve collecting email addresses for transactional communication. Even if you only send receipts, you are processing personal data and GDPR applies.
Lawful Basis for Processing
You need a valid lawful basis for each type of processing. For most retail CRM purposes:
- Contract performance: Processing an order, fulfilling a delivery — lawful basis is contract
- Legitimate interests: Sending service-related communications to existing customers — may be lawful under legitimate interests, with a balancing test
- Consent: Marketing emails, loyalty scheme enrolment, profiling for personalisation — requires freely given, specific, informed, unambiguous consent
Consent for marketing cannot be bundled into terms and conditions or assumed from a purchase transaction. It must be a separate, positive opt-in — a clearly labelled checkbox that the customer actively ticks.
What Your POS Must Support
- Data access requests: A customer can request all personal data you hold about them. You must respond within one month. Your POS must be able to export all data linked to a specific customer record.
- Right to erasure: A customer can ask you to delete their data (subject to exceptions for legal/tax retention obligations). Your POS should support customer record deletion or anonymisation.
- Data portability: Customers can request their data in a machine-readable format (CSV, JSON). Your CRM export function must support this.
- Consent records: If marketing consent is collected through your loyalty sign-up, you must record when consent was given, what the customer was told, and have evidence they opted in. OneScale's CRM maintains consent timestamps and preference flags per customer record.
Data Retention
Personal data must not be kept longer than necessary for the purpose it was collected. A customer who has not made a purchase in five years and has not engaged with marketing communications has an arguable case that their data should be deleted. Set a retention policy (e.g., 3 years of inactivity triggers deletion or anonymisation) and enforce it automatically.
Consequences of Non-Compliance
The ICO can issue fines up to £17.5 million or 4% of global annual turnover (whichever is higher) for serious infringements. For a small retailer, enforcement at this scale is unlikely — but smaller fines, enforcement notices, and mandatory audits are realistic outcomes of customer complaints or data breaches that reveal non-compliant practices.
Conclusion
UK GDPR compliance for retail is less about avoiding large fines and more about building customer trust. Customers who understand how their data is used, who can opt out easily, and who are not bombarded with marketing they did not consent to are more loyal customers. Good data practice and good business practice align.