Skip to content

Using POS Data for Successful Marketing – with the GDPR in Mind

Anonymous reports, customer accounts and newsletters: how businesses use POS data for marketing – with the key GDPR and TKG rules for everyday practice.

BD
  • Bahram Davoodi
on Monday, 24 August 2026
Share:LinkedInXWhatsAppEmail
Using POS Data for Successful Marketing – with the GDPR in Mind

The most valuable marketing insights are often not found in expensive analytics tools – they are already sitting in your own POS system: Which products are bought most often? Which items regularly end up in the same basket? When are you busiest – and which customers keep coming back?

Analysed properly, this data helps you plan offers with more precision, understand customers better and build long-term customer relationships. However, as soon as POS data is linked to a specific person, data protection and the legal framework need to be considered from the very start.

In this article you will learn what POS data can do for your marketing and which basic data protection rules businesses in Austria should follow.

What POS data reveals about your business

Even without personal customer data, a modern POS system delivers valuable insights. Typical reports show, for example:

  • top sellers and slow movers in specific periods,
  • seasonal changes in buying behaviour,
  • products frequently bought together,
  • average basket values,
  • particularly high-revenue days and times,
  • differences between locations or sales areas.

Reports like these help you base decisions on more than gut feeling. Promotions can be scheduled for the times that actually fit, product combinations can be put together sensibly and staffing can be better aligned with peak hours.

A café might discover, for example, that coffee and cake are ordered together particularly often on Friday afternoons. Instead of launching a random discount campaign, it can turn this into a limited Friday offer and then use its POS data to check whether the promotion actually worked.

Distinguishing anonymous reports from personal data

As long as a report is genuinely anonymous and allows no conclusions to be drawn about individual persons, the focus is primarily on business insights.

Things look different once purchases are linked to a customer account, a loyalty card, an email address or any other identifiable person. The information then counts as personal data, and the requirements of the GDPR (DSGVO) must be observed.

Pseudonymised data also generally remains personal data if it can still be attributed to a person using additional information. And if the purchase frequency, interests or favourite products of individual persons are analysed automatically, this may also constitute a form of profiling.

From POS reports to loyal-customer marketing

With customer accounts or loyalty cards, businesses can offer additional features, such as:

  • points and rewards programmes,
  • digital store credit,
  • individual discounts,
  • birthday promotions,
  • exclusive offers for regular customers,
  • information about suitable products or services.

The loyalty programme and marketing consent should be treated as two separate things. Joining a rewards programme does not automatically mean the person also wants to receive a newsletter or personalised advertising.

For every use of customer data, you therefore need to define the purpose for which the data is processed and the legal basis on which this happens. Depending on the specific use case, this could be, for example, performance of a contract, consent, a legal obligation or a legitimate interest.

The key data protection rules for everyday practice

1. Define a clear purpose

Data should only be collected for purposes that are defined in advance and easy to understand.

If you receive an email address solely for sending a digital receipt, you must not automatically use it for marketing messages as well. POS, accounting and marketing data should therefore be cleanly separated, both technically and organisationally.

2. Collect only the data you need

For a simple customer account, name and email address may well be sufficient. Date of birth, phone number or address should only be requested if these details are actually needed for a specific feature.

The less personal data you collect, the lower your administrative effort and your data protection risk.

3. Inform customers transparently

Already at the point of data collection, it should be clearly explained:

  • which data is processed,
  • what the data is used for,
  • on which legal basis the processing takes place,
  • how long the data is stored,
  • who has access to it,
  • which rights the data subject has.

An easily accessible privacy policy can provide this information. A bare link without a clear explanation of the specific processing, however, is not always enough.

If processing is based on consent, that consent must be given freely, on an informed basis, unambiguously and for a specific purpose. Pre-ticked checkboxes should not be used.

For newsletters, a double opt-in process is recommended in practice. The sign-up is only confirmed once the person has clicked a link in a confirmation email. This makes the consent easier to prove and reduces the misuse of other people's email addresses. The Austrian data protection authority (DSB) has already dealt with a case in which a missing double opt-in process was assessed as an insufficient data security measure.

5. Follow the rules for marketing emails

In Austria, electronic direct marketing generally requires prior consent.

For existing customers, § 174 Abs. 4 TKG 2021 (Austrian Telecommunications Act 2021) provides an exception under narrow conditions. It can be relevant in particular where the contact details were collected in connection with a sale or a service, only the business's own similar products or services are advertised, and the person concerned can object easily and free of charge both at the time of data collection and in every message.

Whether this exception applies in a specific case should be examined carefully. The mere fact that someone has bought something once does not automatically permit every form of email marketing.

6. Make unsubscribing and objecting easy

Every marketing message should contain a clearly visible, free and straightforward way to unsubscribe – in practice usually via a working unsubscribe link.

If a person objects to the processing of their data for direct marketing, their data may no longer be used for that purpose. This right to object also applies to profiling to the extent that it is related to direct marketing.

7. Enable access, rectification and erasure

Among other things, customers can request information about which personal data concerning them is being processed. It must be possible to correct inaccurate data.

Erasure can also be requested. That does not mean, however, that all information may always be removed immediately. Statutory retention obligations, for example for certain accounting or business records, can stand in the way of complete erasure.

The POS system, or the customer management connected to it, should therefore be able to distinguish between data that must still be retained by law and data that may no longer be used for marketing purposes.

Putting it into practice: start small and controlled

You do not need complicated marketing automation to get started. A clear, step-by-step approach makes more sense:

  1. Start by analysing anonymous POS reports.
  2. Define a simple, easy-to-understand customer programme.
  3. Document consents and objections in a traceable way.
  4. Begin with a few relevant customer segments.
  5. Derive promotions from actual purchase data.
  6. Measure the success of every promotion by revenue, basket value or repeat-purchase rate.

A first segmentation could, for example, distinguish between new customers, regular loyal customers and customers who have been inactive for a longer time. In each case, however, you should always check whether the specific processing is permissible under data protection law and whether the persons concerned have been informed transparently.

Conclusion

Marketing with POS data means guessing less and responding more to actual buying behaviour.

Anonymous reports already help you improve your assortment, promotions and staff planning. Customer accounts and rewards programmes open up additional opportunities for long-term customer loyalty – but they also bring data protection responsibilities with them.

If you define clear purposes, collect only the data you need, document consents properly and reliably honour objections, you create a solid foundation for sustainable loyal-customer marketing.

We would be happy to show you how your POS system, customer management and marketing processes can work together – in a free initial consultation with Lonio.

Note: This article is for general information only and does not replace legal or data protection advice. The legal assessment depends on the specific business model, the data used and the marketing measures in question. For a binding review, please consult a qualified legal or data protection advisor.

Ready to modernise your POS?

See how Lonio fits your business in a free, no-obligation call.