
Data Protection & NFC Business Cards
Digital Business Card and GDPR: What You Need to Know
Are digital NFC business cards GDPR-compliant? What applies to data storage, when consent is required, and which solution stays on the safe side.
Digital business cards via NFC are modern and practical β and anyone using them professionally will sooner or later ask: is this actually GDPR-compliant? The short answer: the card itself is not the issue. The complexities lie in the system behind it. This guide gives a realistic overview without causing unnecessary alarm.
What the card itself stores β and what it does not
An NFC chip stores nothing but a URL. No names, no email addresses, no device data, no cookies, no tracking. The chip is a passive data store: it outputs the link when a smartphone reads it β nothing more.
From a GDPR perspective, the card itself is entirely neutral. Personal data within the meaning of Art. 4 GDPR is not processed by the chip.
Where GDPR comes into play: the server behind the URL
When someone taps an NFC business card, the smartphone accesses the stored URL. This access automatically generates a log entry on the web server:
- IP address of the smartphone
- Timestamp
- Browser type and operating system (user agent)
An IP address qualifies as personal data under GDPR. This means: anyone operating a server that is accessed when someone taps is processing personal data β and must make this transparent in their privacy policy.
This applies to any website visit and is not specific to NFC. Anyone operating their own website faces the same situation.
When does it get more complex?
The data protection situation becomes more complex when additional services load on the profile behind the URL:
- Google Analytics, Meta Pixel, Hotjar: These services set cookies and create user profiles. They are GDPR-relevant and require either a consent banner or a privacy-compliant alternative (e.g. self-hosted Matomo).
- Embedded maps (Google Maps): Google Maps loads data from Google servers. This must also be covered in the privacy policy and may require consent.
- Contact forms: Anyone who fills in and submits a form is actively giving consent β this must be clearly communicated.
Keeping your digital profile lean β no tracking, no third-party scripts, only static contact details β lets you operate in a GDPR-compliant manner without a lot of infrastructure.
NFC business card vs. business card app: which is more privacy-friendly?
Many business card app providers collect far more data than necessary:
- Device identifiers (IDFA, GAID)
- Contact lists (if the app requests access)
- Location data
- Usage profiles (which profiles are accessed and when)
A simple NFC business card pointing to your own professional website or a minimal profile has a significantly smaller data footprint than an app-based solution. This is a genuine argument for NFC cards with your own profile rather than app platforms with opaque data policies.
Checklist: operating an NFC business card in a GDPR-compliant way
- Privacy policy linked on the profile (or accessible)
- Server logging mentioned in the privacy policy (IP, timestamp)
- Tracking services only used with valid consent (or avoided entirely)
- Google Maps, YouTube etc. only loaded after consent (or privacy-friendly alternatives used)
- Contact forms with clear consent wording
- Data processing agreement (DPA) in place with the hosting provider
Glastrix NFC business cards: what the card itself provides
Glastrix cards are hardware: UV-printed on glass, metal, wood, or bamboo, with an embedded NTAG215 chip. The card itself stores only the URL of the customer profile. What data that profile processes is entirely the customer's responsibility β Glastrix provides only the hardware card.
Anyone running their digital profile on their own domain with minimal third-party services can operate a Glastrix NFC business card in a GDPR-compliant and professional manner.
Frequently asked questions: NFC business cards and GDPR
Is an NFC business card compliant with data protection law?
The card itself (the chip) only stores a URL β no personal data. Data protection law only becomes relevant on the server behind the URL: when someone taps the card, they generate a server request with an IP address and browser data. This must be made transparent in the data protection policy of the profile. The hardware card itself is neutral from a GDPR perspective.
When is consent required for a digital business card?
Consent is required when personal data is actively processed when someone taps β for example, when the person must register or fill out a form. If you only display a digital profile (static page without cookies, without login), you can operate without consent β but you must technically ensure that no tracking cookies or third-party scripts are actually loaded.
How does an NFC business card differ from a digital business card app in terms of GDPR?
Apps often collect significantly more data: device identifiers, location, usage behaviour, contact lists. NFC business cards that point to a simple profile URL have a much smaller data footprint. It becomes critical when the profile provider loads tracking pixels, Google Analytics, or Facebook scripts on the profile β these are GDPR-relevant and must be declared in the privacy policy.
Do I need to link to a privacy policy on my digital business card profile?
If the profile is used in a business context and a connection to the server is established, a privacy policy should be accessible. This is not a rigid legal requirement for every single landing page, but it is recommended from a data protection perspective and is professional practice. Anyone using their own domain for the profile can link to the privacy policy in the footer.
What data does an NFC business card transmit when tapped?
The card itself transmits no data β it is only read. When the URL is accessed, the smartphone sends a standard HTTPS request to the server, which the browser and server software log: IP address, timestamp, browser type. This is technically unavoidable and is the standard for any webpage visit. Actual tracking cookies or user profiles are only created if the profile provider deliberately uses them.
WeiterfΓΌhrende Artikel
NFC Business Card β Privacy-Friendly Hardware
Glastrix cards are pure hardware. The chip stores only your URL β no data about your contacts. Produced in-house in Berlin-Kreuzberg.
URL only on the chip Β· No user data Β· No minimum order Β· Berlin
