Artificial Intelligence (AI) promises the hospitality sector a revolution for loyalty programs: hyper-personalised offers, improved customer loyalty and maximum sales. AI is able to analyse data and recognise patterns at scales that are humanly impossible. But how to ensure that this technology meets applicable regulations, such as the AI Act and the GDPR? How to balance innovation against legal compliance? In this article we will give you a number of practical tools for a compliant and future-proof use of this technology.
Data collection
From a marketing perspective, data is still gold. As a rule, marketeers therefore try to collect as many personal data about customers as possible; name and address details, spending patterns, customer communication, social media interactions, data obtained from third parties, data the customer personally provided, e.g. through a survey, etc. All these are very valuable data for a personalised digital marketing campaign.
However, in practice the actual collection of personal data is not that easy. An attractive loyalty program sometimes does the trick to convince (potential) customers to create an account and complete a list of personal data (20 items, if they also complete the optional fields). The customer then becomes a member. The idea of belonging to an exclusive ‘club’ often works well for customers, just as the prospect of a free hotel stay if they save up enough points.
Suppliers promise the hospitality sector several tools, which first divide customers into segments (e.g. ‘new customers’, ‘best customers’ and ‘intermittent customers’, but often a lot more specific) and then apply AI to these segments and generate a prediction (per segment) of customer behaviour. This prediction is used as a basis for hyper-personalised offers.
How to align such a working method with relevant regulations like the AI Act and the GDPR? Below, we will present a (non-exhaustive) list of some important compliance considerations.
Ground
If you base participation in a loyalty program on consent, please note that different processing activities are often taking place for different purposes. Individual consent must be asked for each individual purpose.
First, the various processing activities (and the accompanying purposes) should be distinguished, such as:
- Participation in the loyalty program;
- Dividing customers into segments;
- Sending personalised direct marketing messages.
A popular comment from marketing departments is that the more consent boxes must be ticked, the sooner (potential) customers will back out. Check carefully for each purpose whether another ground can be used, such as a legitimate interest. Sending personalised marketing messages must be based on consent in any case. Take care that the consent box is not a ‘mandatory field’; it cannot be a condition for participation in the loyalty program.[1]
Transparency
Article 13 of the GDPR applies to the personal data that are collected directly from customers. Make sure that the (online) privacy statement contains an understandable explanation of the loyalty program, which mentions the various processing activities, purposes and grounds. As far as the content of advertising texts is generated by AI and this qualifies as generative AI, the provider of the AI system is subject to a marking obligation. [2]
Data protection by design
The risk of applying AI to customer data is that customers often do not expect this. It should be avoided that personalised offers and the associated prices differ so much per customer that this has a discriminatory effect, or that a message is personalised to the extent of becoming too invasive. Personal data cannot be processed in a way that is unjustifiably detrimental, unlawfully discriminatory, unexpected or misleading to the data subject.[3]
Data minimisation
Only use data of loyalty members for direct marketing purposes that are in line with their expectations, such as their purchase history. Avoid web-scraping.
Automated decision-making
When a prediction about customer behaviour is generated through an automated decision, and a personalised ad is shown on the basis hereof, this will in most cases not be a decision that ‘significantly affects’ a person, as meant in Article 22 GDPR.
However, it may happen that the decision does significantly affect persons, depending on the specific characteristics of the case, such as:
- the intrusiveness of the profiling process;
- the expectations and wishes of the individuals concerned;
- the use of knowledge of the vulnerabilities of the data subjects targeted.[4]
In short: take care not to collect too many data on customers; bear in mind the expectations of customers; and avoid the use of special personal data or knowledge about vulnerabilities of data subjects.
Would you like to learn more about this topic? Please contact Elise Troll, counsel at Kennedy Van der Laan. Elise advises businesses and organisations in the field of privacy compliance, represents national and international clients in GDPR issues, and litigates in civil cases concerning privacy.
[1] Article 4 (11) GDPR.
[2] Article 50 (2) AI Regulation.
[3] EDPB Guidelines on Article 25 on Article 25 ‘Data Protection by Design and by Default’, 20 October 2020, para. 69.
[4] EDPB Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation (EU) 2016/679, 6 February 2018, p. 26.