Are dynamic QR codes GDPR compliant?
Dynamic QR codes can be used in a GDPR-compliant way, but compliance depends on which data is processed, why it is processed, how long it is kept, how users are informed and whether cookies or other identifiers are used.
Explanation
A QR code itself is not simply compliant or non-compliant. The relevant issue is what data processing happens during the scan and on the destination page.
If the service processes information that can directly or indirectly identify a person, GDPR principles apply: purpose limitation, data minimisation, appropriate retention, security and transparency.
For cookies and similar technologies, some limited audience-measurement setups may qualify for exemptions only under strict conditions. Advertising pixels, retargeting and cross-site tracking generally raise additional consent and transparency requirements.
The exact legal obligations depend on the implementation and jurisdiction.
Concrete example
Counting aggregated scans to compare two posters is not the same processing activity as building individual marketing profiles and combining them with data from other websites.
Common mistake
A provider displaying the word GDPR does not make every possible use compliant. The actual configuration, purposes, recipients and retention rules matter.
This content follows Outilo's editorial guidelines.