QR codes and UK GDPR

Last updated 12 June 2026

QR codes are not exempt from UK data protection law. If your code links to a form, tracks users, or sits beside a WiFi login, you should understand how UK GDPR and the Data Protection Act 2018 apply — in plain language, not legal jargon.

This guide is general information, not legal advice. For specific compliance questions, consult a qualified adviser or the ICO.

When GDPR is relevant

  • Personal data collection — landing pages that ask for name, email, or phone
  • Marketing lists — newsletter sign-up after scanning a menu QR
  • Analytics — scan logs and device data (see tracking guide)
  • Cookies — if the destination site uses non-essential cookies without consent

A QR that only opens a public PDF menu with no tracking on the PDF host may involve less personal data processing than a full marketing funnel — but your website analytics may still apply once they land on your domain.

Transparency matters

UK users expect clarity. Good practice:

  • Link to your privacy policy from any form reached via QR
  • State why you collect data (“book a table”, “join mailing list for offers”)
  • Do not pre-tick marketing consent boxes
  • Provide an unsubscribe path for email marketing (PECR rules)

WiFi QR considerations

Publishing a guest WiFi password on a poster is a business choice, not usually a GDPR form — but if you force portal sign-in with email capture, treat that as personal data processing. Read WiFi QR guide for network separation tips.

Restaurant and hospitality

Menu QRs became standard after 2020. ICO guidance evolves; focus on fairness, minimal data collection, and secure storage if you keep customer details. Allergen info on menus is a food safety matter separate from GDPR, but both build customer trust.

What Free-QR.co.uk does

We process account data, scan redirect logs, and billing information as described in our Privacy Policy. You remain responsible for what happens on your destination URLs — especially third-party booking or email tools.

Data export and deletion requests are available to account holders; admins can assist via support for GDPR enquiries.

Practical checklist for UK SMEs

  1. Publish an up-to-date privacy policy on your website
  2. Use HTTPS on all landing pages linked from QRs
  3. Only collect fields you actually need
  4. Register with ICO if required for your processing activities
  5. Train staff not to photograph customer IDs into personal WhatsApp groups — use proper systems

Building trust helps SEO and repeat business as much as checkbox compliance.

Ready to create yours?

Design and preview free on the homepage — no card required for your first live QR.

Create free QR See pricing