QR codes and UK GDPR
QR codes are not exempt from UK data protection law. If your code links to a form, tracks users, or sits beside a WiFi login, you should understand how UK GDPR and the Data Protection Act 2018 apply — in plain language, not legal jargon.
This guide is general information, not legal advice. For specific compliance questions, consult a qualified adviser or the ICO.
When GDPR is relevant
- Personal data collection — landing pages that ask for name, email, or phone
- Marketing lists — newsletter sign-up after scanning a menu QR
- Analytics — scan logs and device data (see tracking guide)
- Cookies — if the destination site uses non-essential cookies without consent
A QR that only opens a public PDF menu with no tracking on the PDF host may involve less personal data processing than a full marketing funnel — but your website analytics may still apply once they land on your domain.
Transparency matters
UK users expect clarity. Good practice:
- Link to your privacy policy from any form reached via QR
- State why you collect data (“book a table”, “join mailing list for offers”)
- Do not pre-tick marketing consent boxes
- Provide an unsubscribe path for email marketing (PECR rules)
WiFi QR considerations
Publishing a guest WiFi password on a poster is a business choice, not usually a GDPR form — but if you force portal sign-in with email capture, treat that as personal data processing. Read WiFi QR guide for network separation tips.
Restaurant and hospitality
Menu QRs became standard after 2020. ICO guidance evolves; focus on fairness, minimal data collection, and secure storage if you keep customer details. Allergen info on menus is a food safety matter separate from GDPR, but both build customer trust.
What Free-QR.co.uk does
We process account data, scan redirect logs, and billing information as described in our Privacy Policy. You remain responsible for what happens on your destination URLs — especially third-party booking or email tools.
Data export and deletion requests are available to account holders; admins can assist via support for GDPR enquiries.
Practical checklist for UK SMEs
- Publish an up-to-date privacy policy on your website
- Use HTTPS on all landing pages linked from QRs
- Only collect fields you actually need
- Register with ICO if required for your processing activities
- Train staff not to photograph customer IDs into personal WhatsApp groups — use proper systems
Building trust helps SEO and repeat business as much as checkbox compliance.
Ready to create yours?
Design and preview free on the homepage — no card required for your first live QR.
Create free QR See pricing