Digital Business Cards and GDPR: A Practical Compliance Guide

| Updated | Compliance | Virtual Business Cards
How digital business cards sit within UK and EU GDPR, PECR, CCPA, the UAE PDPL and India's DPDP Act — plus honest answers on NFC security.
Digital business cards are compatible with GDPR, but compliance depends on how you use them. Sharing your own details is low risk. Capturing someone else's through a lead form makes you the data controller, so you need a lawful basis, a privacy notice, a retention period and a provider with a proper data processing agreement.
Key takeaways
- Handing over your own contact details creates almost no compliance burden; collecting someone else's through a form does.
- You are the controller for contacts captured through your card; your provider is normally a processor and needs an Article 28 agreement.
- In the UK and EU, business contact data is still personal data whenever a living individual can be identified, including addresses like firstname.lastname@company.com.
- UK PECR treats limited companies as "corporate subscribers" — you can email them without prior consent — but sole traders and unincorporated partnerships get consumer-level protection.
- California removed its B2B exemption on 1 January 2023, so business contacts there now have full CCPA rights.
- India's DPDP Rules were notified on 14 November 2025 with full enforcement from May 2027, and the regime is consent-first, with no legitimate-interest route for marketing.
- An NFC business card stores a URL, not your contact database. Losing one exposes a public web link, nothing more.
> This is general information, not legal advice. Data protection law is fact-specific and changes often. Nothing here creates a solicitor-client or attorney-client relationship. Before you rely on any of it for a real compliance decision, take advice from a qualified practitioner in the relevant jurisdiction.
Two very different data flows on one card
Almost every argument about virtual business cards and privacy collapses once you separate the two things a card actually does.
Outbound sharing. The other person sees your name, job title, work number and links. That data is yours, published deliberately, in a professional capacity. Your employer decides what appears, so the employer is the controller — but the risk is minimal because publication is the point. Inbound capture. They fill in a form on your profile so you can follow up. Now you are processing someone else's personal data, without them having chosen your systems or your retention policy. This is where the obligations live, and it is the part most buyers never think about.Controller or processor? Who is responsible for a captured contact
Under Article 4(7) of the UK and EU GDPR, the controller is whoever determines the purposes and essential means of processing. The EDPB's Guidelines 07/2020 (final version adopted 7 July 2021) makes the practical test clear: deciding why data is collected and the core decisions about how makes you a controller, even if a supplier operates the technology.
| Party | Typical role | Why |
|---|---|---|
| You / your employer | Controller | You decided to run a lead form, what fields to ask for, and what you do with the answers. |
| Your card provider | Processor | Hosts the profile and stores submissions on your documented instructions. |
| Provider's hosting and email vendors | Sub-processors | Engaged by the processor; must be disclosed to you and covered by equivalent terms. |
| Your CRM | Processor | Same analysis — you decide the purpose, the CRM stores it. |
| A provider that mines your leads for its own product | Controller in its own right | Article 28(10): a processor that determines its own purposes becomes a controller for that processing. |
That last row is the one to check in a contract. If a provider reserves the right to use captured contacts for its own marketing or model training, it is not acting purely as your processor, and your privacy notice is wrong.
Lawful basis for B2B follow-up in the UK and EU
There is no "B2B exemption" in the GDPR. The ICO is explicit that UK GDPR applies to business contact details whenever you can identify a living individual — a named person at a company, or an email address built from someone's name.
Two bases realistically apply. Consent is clean when the form itself is the point of contact: someone deliberately typed their details into your profile to hear from you. Record what they were told and when.
Legitimate interests (Article 6(1)(f)) is often the better fit for ordinary follow-up, and Recital 47 says direct marketing may be a legitimate interest. It is not a free pass. Document a three-part assessment — purpose, necessity, and a balancing test against the individual's rights — before you rely on it, and honour objections immediately.PECR is the rule that actually bites in the UK
GDPR governs whether you may hold the data. The Privacy and Electronic Communications Regulations govern whether you may send the email.
- Limited companies, LLPs, Scottish partnerships and government bodies are corporate subscribers. Under ICO guidance you do not need PECR consent to email or text them, but you must not disguise your identity and must give a valid opt-out address.
- Sole traders and unincorporated partnerships are treated as individual subscribers. You need consent, or the soft opt-in: details obtained during a sale or negotiations, marketing only similar products, and an opt-out offered at collection and in every message.
- Automated calls need consent from everyone, corporate subscribers included. Live calls must be screened against the TPS and CTPS.
The stakes rose sharply this year. The Data (Use and Access) Act 2025 lifted maximum PECR fines to UK GDPR levels — £17.5 million or 4% of global annual turnover — with effect from 5 February 2026. The same commencement introduced a narrower set of "recognised legitimate interests" and replaced the international transfer adequacy standard with a "data protection test".
The EU is not one rule
Article 13 of the ePrivacy Directive sets a similar soft opt-in, but implementation varies by member state and several are stricter than the UK. Germany requires consent for most unsolicited commercial email under its unfair competition law, with no corporate carve-out. Check the destination country's rule rather than assuming the UK position travels.
How the United States differs
The US flips the default. There is no general prior-consent requirement for commercial email: CAN-SPAM is an opt-out regime. You must use accurate headers and subject lines, identify the message as an advertisement, include a valid physical postal address, and offer a working unsubscribe mechanism honoured within ten business days. Penalties are set per email and adjusted annually for inflation.
State privacy law is where B2B data changed. California's CCPA, as amended by the CPRA, let its business-to-business and employee exemptions expire on 1 January 2023. Business contacts there now have the same access, deletion, correction and opt-out rights as consumers.
The CCPA applies to businesses meeting one of three thresholds: annual gross revenue above roughly $25 million (indexed), handling the personal information of 100,000 or more California consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
The California Privacy Protection Agency finalised new regulations in 2025 that phase in from now:
- Risk assessments — compliance required from 1 January 2026, with the first documentation filings due 1 April 2028.
- Automated decision-making technology — existing uses must comply by 1 January 2027.
- Cybersecurity audits — staggered by revenue: 1 April 2028 (over $100m), 2029 ($50–100m) and 2030 (under $50m).
Most other US state privacy laws — Virginia, Colorado, Connecticut, Texas, Oregon and the rest — do exclude data processed purely in a commercial or employment context. California is the outlier, and because it is the largest market, it sets the operational standard.
The UAE: PDPL without executive regulations
Federal Decree-Law No. 45 of 2021 has been in force since January 2022, but the Implementing (Executive) Regulations meant to flesh it out still had not been issued as of 2026. The practical consequence, as Chambers' 2026 UAE guide notes, is a cautious regulatory stance and limited enforcement — not an absence of obligations.
The law itself is recognisably GDPR-shaped: six processing grounds including consent, contract performance and legitimate interests, and eight data subject rights covering access, correction, erasure, portability and objection to solely automated decisions. Cross-border transfers require an adequate destination, a bilateral agreement, or a derogation. A DPO is required for systematic large-scale or sensitive processing.
Note the free zones. The DIFC and ADGM run their own regimes and are excluded from mainland PDPL coverage, so a Dubai firm's obligations depend on where it is licensed.
India's DPDP Act and the digital visiting card
India moved fastest of the four regions. The Digital Personal Data Protection Act 2023 finally became operational when the DPDP Rules were notified on 14 November 2025, opening an 18-month phased transition:
- Mid-2026 — consent manager registration and integration.
- 13–14 November 2026 — one-year mark; legacy data revalidation and the end of soft enforcement.
- 13–14 May 2027 — full enforcement, with penalties live.
Two features matter for anyone capturing leads through a digital visiting card in India. First, the Act is consent-first. Its "certain legitimate uses" carve-outs do not extend to commercial marketing, so the UK and EU legitimate-interests route is simply not available for that purpose. Second, notices must be available in English or any language in the Eighth Schedule to the Constitution on request — 22 languages.
Penalties run to ₹250 crore (about US$26 million at current rates) for the most serious failures. Cross-border transfers use a negative-list model: permitted except to countries the government specifically restricts.
Data minimisation, retention and residency
On the card itself. Publish what someone needs to contact you: name, role, employer, work number, work email, and the links that do a job. Leave off home addresses, personal mobiles and dates of birth. On the form. Name and email is usually enough; every extra field is data you must justify, secure and delete. Skip pre-ticked boxes entirely — they have never been valid consent. Retention. Set a period and automate it. Six to twenty-four months from last meaningful contact is a defensible starting point for B2B follow-up, provided you can explain the reasoning. Leads sitting untouched in an export folder from 2021 are a liability, not an asset. Residency. Ask where profiles and form submissions are stored. EU-to-UK transfers are straightforward: the European Commission renewed the UK adequacy decisions on 19 December 2025, valid to 27 December 2031, with a mid-point review after four years. Transfers elsewhere without adequacy need a mechanism such as standard contractual clauses plus a transfer risk assessment.What to ask a provider before you buy
| Ask for | What good looks like |
|---|---|
| Data processing agreement | Article 28-compliant DPA available without negotiation, covering purpose limitation, confidentiality, security, audit and deletion. |
| Sub-processor list | Published, with advance notice of changes and a right to object. |
| Hosting region | Named region, ideally selectable. "The cloud" is not an answer. |
| Deletion on request | Defined SLA for erasing a profile and its captured leads, plus confirmation in writing. |
| Security certifications | ISO 27001 or SOC 2 Type II, with the report available under NDA. |
| Admin controls | SSO, role-based access, and instant profile deactivation when someone leaves. |
| Breach notification | Contractual commitment to notify you without undue delay, so you can meet your own 72-hour clock. |
| Secondary use | Explicit contractual ban on using your captured contacts for the provider's own purposes. |
Compliance checklist by region
| Requirement | UK | EU | US (California) | UAE | India |
|---|---|---|---|---|---|
| Primary law | UK GDPR + DPA 2018 + PECR, as amended by DUAA 2025 | GDPR + national ePrivacy rules | CCPA/CPRA + CAN-SPAM | Federal Decree-Law 45/2021 (PDPL) | DPDP Act 2023 + DPDP Rules 2025 |
| Is B2B contact data covered? | Yes, if an individual is identifiable | Yes | Yes, since 1 Jan 2023 | Yes | Yes |
| Basis for marketing follow-up | Legitimate interests or consent; PECR governs the send | Same, but member states vary — several require consent | No prior consent; opt-out honoured in 10 business days | Consent or legitimate interests | Consent only |
| Privacy notice at capture | Required | Required | Notice at collection required | Required | Required, 22 languages on request |
| Deletion right | Yes | Yes | Yes | Yes | Yes |
| Cross-border rule | Data protection test (DUAA 2025) | Adequacy, SCCs or derogation | No general restriction | Adequacy or derogation | Negative list of restricted countries |
| Headline penalty | £17.5m / 4%; PECR now matches | €20m / 4% | Per-violation civil penalties | Administrative fines | Up to ₹250 crore |
Are NFC business cards safe? Cloning, hacking and lost cards
This is the security question buyers actually ask, and it deserves a straight answer rather than reassurance.
What is on the chip. Very little. A standard NFC business card uses an NXP NTAG chip holding an NDEF record — in practice, a URL and nothing else. The chips used in cards are specified in a few hundred bytes of user memory, which we tabulate in our guide to what a virtual business card is. Your contact details, leads and analytics live on a web server. There is neither room for them on the card nor a mechanism to put them there, which is why a lost card is not a data breach. Can it be cloned? The URL can be copied to a blank tag, because a URL is public by design — anyone who taps your card can already read it, and could just as easily type it out. What cannot be duplicated is the chip's 7-byte UID, which NXP programs at manufacture. Cloning a card tag achieves roughly what photographing a paper card achieves. The real risk is rewriting, not cloning. An unlocked NTAG can be reprogrammed by anyone with a phone, pointing your card at a different address. This is the thing worth checking before you buy any NFC business card: ask whether the chip is locked, or protected by the 32-bit password authentication NTAG chips support. NXP chips also carry an ECC-based originality signature that lets software verify a genuine tag. Can it be read from across a room? No. NFC operates over a few centimetres and needs deliberate alignment. Neither iOS nor Android opens a link automatically — the phone shows a notification the user must tap. If you lose the card. Nothing sensitive is lost, because nothing sensitive was stored. Whoever finds it can visit a page you had already published. With a dynamic profile you can repoint or unpublish that page immediately — more than can be said for a dropped wallet of paper cards. For how the two delivery methods differ, see our comparison of NFC and QR code business cards.Frequently Asked Questions
Are digital business cards GDPR compliant?
The card is not compliant or non-compliant on its own; your use of it is. Sharing your own work details raises almost nothing. Capturing someone else's through a lead form makes you a controller, requiring a lawful basis, a privacy notice at the point of capture, a retention period, and a processor agreement with your provider.
Do I need consent to email someone who scanned my card?
In the UK, if they typed their details into your form you can usually rely on consent or legitimate interests, and PECR lets you email limited companies without prior consent. Sole traders need consent or the soft opt-in. In the US, no prior consent is needed but you must honour opt-outs within ten business days.
Is a business email address personal data?
Usually yes. The ICO's position is that UK GDPR applies whenever a living individual can be identified, which includes an address in the form firstname.lastname@company.com and a named person at a company. Generic addresses such as info@company.com are not personal data, though they are still covered by PECR marketing rules.
Can an NFC business card be hacked or cloned?
The chip holds a URL, not your data, so there is nothing valuable to steal. The URL can be copied to a blank tag, much as a paper card can be photographed. The genuine risk is an unlocked chip being rewritten to point elsewhere, which locking or password protection prevents. Ask your supplier which applies.
What happens if I lose my NFC card?
You lose a piece of plastic or metal carrying a public web address. No contacts, no leads and no credentials are stored on it. If your profile is dynamic, change or unpublish the destination and the found card becomes inert. Order a replacement without changing the details you have already shared.
Which countries' rules apply if my team is international?
Generally, the rules of the place where your data subject is, plus the rules of the place you are established. A London firm capturing a lead in Dubai should expect both UK GDPR and the UAE PDPL to be relevant. This is precisely the point at which general guidance stops being enough and local advice starts.
Getting this right without a legal department
Most of the burden here is procurement, not law. Choose a provider that will sign a proper DPA, publish its sub-processors and tell you which region your data sits in; write a short privacy notice for the capture form; set a retention period and automate it. That covers most realistic exposure for a small or mid-sized team.
Every profile across our full range is editable for life, which is also what makes correction and deletion requests straightforward to honour. When you are ready to connect capture to follow-up, our guide to CRM integration covers doing it without creating a second uncontrolled copy of everyone's data.
And once more, plainly: this article is general information, not legal advice. Take proper advice before acting on it.