What information the service actually handles

Consent in a retail proximity environment is the shopper's freely given, specific, informed and unambiguous agreement to receive location-based messages. Under UK GDPR and the Privacy and Electronic Communications Regulations (PECR), that standard applies whether the trigger is a Bluetooth beacon, an NFC tap or a QR scan. The technology changes the delivery mechanism, not the obligation.

A professional reviewing privacy-conscious analytics on a tablet
Illustrative example of aggregated analytics and privacy review.

For beacon-based notifications, consent typically begins inside a retailer's own app. The shopper must grant two separate permissions: location services at the operating-system level, and push notifications. Both are opt-in on iOS and Android, and neither can be bundled with broader terms of service or made a condition of using the app for non-location features such as checking a balance or browsing a catalogue.

QR and NFC routes simplify the consent picture because the shopper performs a deliberate physical action—scanning or tapping—to reach a web page. At that point, the relevant question shifts to whether the page sets tracking cookies or collects personal data, which brings its own consent requirements under PECR. The advantage is that no app installation stands between the shopper and the content, so the value exchange is immediate and visible.

A practical distinction worth understanding is the difference between device-level permission and campaign-level consent. Device-level permission allows the app to detect beacons and receive pushes. Campaign-level consent determines which types of message the shopper wants—offers, product information, queue updates, or none at all. Building both layers gives shoppers control and gives the retailer defensible records.

The Value Exchange

Shoppers grant consent when they perceive a clear benefit that outweighs the intrusion. In retail, that benefit usually takes one of three forms: immediate monetary value (a discount at the point of consent), useful information (stock availability for an item they are standing near), or convenience (skipping a queue). Vague promises such as "personalised experiences" rarely convert at the rates that specific, tangible offers do.

The timing of the ask matters as much as the offer. Requesting location and notification permissions on first app open—before the shopper has any reason to trust the brand—produces high refusal rates. Deferring the ask until the shopper is inside the store, near a relevant beacon zone, and has already received some value from the app (for example, a store map or product search) improves acceptance meaningfully, though exact figures depend on the retailer's circumstances and should be measured during a pilot.

Entrance-Zone Consent

Some retailers place a beacon at the shop door and trigger a welcome notification that includes the consent prompt. The logic is that the shopper is physically present and engaged. The risk is that a notification asking for permission before any value has been delivered can feel intrusive. A more effective pattern is to use the entrance beacon to deliver a genuinely useful message—today's offers, a store map link via QR—and follow up with the consent request after the shopper has interacted.

Aisle and Fixture-Level Consent

When a beacon is placed on a specific fixture or within a department, the triggered content can be highly relevant to the product the shopper is examining. Asking for consent in that context works because the value is obvious: "Tap to see reviews and stock for this item." If the retailer uses a web-based QR or NFC label on the fixture instead of a beacon, the consent question moves to the landing page's cookie banner rather than the app permission flow.

Queue and Till-Zone Consent

Queue-detection beacons can trigger a message offering the shopper a way to skip the queue, access a self-checkout guide, or receive a post-visit satisfaction survey. Consent requested in a queue context should acknowledge that the shopper's time is limited. A single-tap opt-in with a clear statement of what they will receive—and how to stop it—respects that constraint.

Till-Receipt and Post-Visit Consent

Printing a QR code on a till receipt that links to a consent page for future in-store notifications separates the consent moment from the shopping trip. The shopper can decide at leisure, without pressure. The limitation is that opt-in rates from receipt-based prompts are typically lower than in-the-moment asks, because the immediacy of the value exchange has passed.

Granular Consent Options

Rather than a single "accept all" toggle, offering shoppers a choice of notification types—offers only, product information only, queue alerts only—improves the quality of consent and reduces later opt-outs. It also produces cleaner data for campaign measurement, because each consent category maps to a distinct notification stream.

Withdrawing Consent

Every consent mechanism must include a clear, immediate withdrawal path. In an app, that means a visible settings screen where the shopper can toggle off location-based notifications without losing access to other app functions. For QR and NFC web journeys, it means an unsubscribe link in every message and a preference centre accessible from the original landing page. Under UK GDPR, withdrawal must be as easy as granting consent.

Proving the controls work in practice

Pre-Ticked Boxes and Bundled Consent

Pre-ticked consent boxes do not constitute valid consent under UK GDPR. Bundling location-notification consent with general marketing consent or app terms of service is similarly invalid. Each purpose must be separate, and the shopper must take a positive action to opt in.

Making Consent a Condition of Service

If a retailer's app offers features that do not require location data—such as checking a loyalty points balance or browsing an online catalogue—denying access to those features because the shopper refused location consent is likely to render the consent invalid. The shopper must have a genuine choice.

Vague Privacy Notices

A privacy notice that states "we use your location to improve your experience" does not meet the informed-consent standard. Shoppers need to know what data is collected (beacon identifiers, device advertising ID, timestamp), how it is used (triggering notifications, anonymised footfall analytics), who receives it, and how long it is retained. The notice should be written in plain language, not legal jargon.

Ignoring the Cookie Layer on QR and NFC Journeys

When a QR or NFC tap leads to a web page that sets analytics or advertising cookies, the retailer must present a compliant cookie banner before those cookies are placed, even though the shopper initiated the visit with a physical action. The physical tap does not substitute for electronic consent to cookies.

Low Opt-In Rates

Even a well-designed consent flow will not capture every shopper. Some will refuse location permissions at the operating-system level and cannot be reached by beacons at all. Others will grant permission but disable notifications. Retailers should plan for a realistic opt-in share—measured during a pilot—rather than budgeting or forecasting on an assumed rate. QR and NFC routes can reach shoppers who refuse app permissions, so a mixed-technology approach often yields broader coverage than beacons alone.

Consent Records

Retain evidence of what the shopper was shown, when they consented, which specific permissions they granted, and the method they used to withdraw. This record-keeping is a compliance requirement and should be built into the campaign management system from the start, not retrofitted after a pilot.

Key Checks Before Launching a Consent Flow

  • Is each consent purpose separated, with a positive opt-in action required?
  • Does the privacy notice explain beacon data collection in specific, plain terms?
  • Can shoppers withdraw consent as easily as they granted it?
  • Is the value exchange stated clearly at the point of the ask?
  • Are QR and NFC landing pages serving a compliant cookie banner before setting non-essential cookies?
  • Does the system log consent timestamps, versions of the notice shown, and withdrawal actions?
  • Has the flow been tested on both iOS and Android, including permission-denial paths?
  • Is consent requested at a moment when the shopper has already received some value, rather than at first app open?

For the next stage of planning—deciding how often to message shoppers who have opted in, and at what times of day—see the companion guide on notification frequency and timing.