GDPR-Compliant QR Code Generator
QR codes look harmless — but the moment they're scanned, the service behind them processes technical data. If you use QR codes to reach customers, you carry responsibility for that. This guide explains what actually matters — and how QRlogic implements it, concretely and verifiably.
Why is a QR code generator relevant to GDPR?
A QR code itself is legally neutral — it's just a visual pattern encoding information, usually a web address. The privacy relevance only arises from what happens server-side when it's scanned: the service running the QR code has to store the destination address to redirect at all. With dynamic QR codes, every single scan passes through a server that technically sees information such as IP address, timestamp, and device type.
This is exactly where it's decided whether a provider is GDPR-compliant: how long is this data retained, where are the servers located, and can the people scanning the code be identified in any way?
How QRlogic implements GDPR technically
Instead of generic marketing claims — here are the concrete, verifiable measures:
EU hosting, no transfer to third countries
The entire infrastructure runs exclusively in the EU: via Elestio (France) and on Hetzner hardware in Falkenstein, Germany. Elestio holds ISO 27001 and SOC 2 certifications. No data processing takes place outside the EU.
No cookies on scan
Scanning a QRlogic code sets no cookie whatsoever. As a result, no cookie banner is required for the people scanning your QR codes — something many providers only admit when asked directly.
Anonymized scan analytics
For the statistics feature, the IP address is anonymized before storage — the last block of the address is stripped before anything is written to the database. Tracing it back to an individual person is technically no longer possible.
Publicly available Data Processing Agreement (DPA)
For business customers, a DPA under Art. 28 GDPR is mandatory. With QRlogic, it doesn't need to be requested by email first — it's publicly available and automatically part of the Terms of Service. It contains the actual technical and organizational measures, not just generic boilerplate.
Self-hosted database — no additional third party
Many QR code services run on hosted cloud databases from US providers. QRlogic operates its own database, on its own EU infrastructure — there's no separate contractual relationship with an external database provider in the US.
Technical safeguards
Encrypted transmission (TLS/SSL), database-level access control (each customer sees only their own data), protection against SQL injection and cross-site scripting, plus automated, encrypted daily backups (AES-256, 180-day retention).
Clear deletion policy
QR code data, scan statistics, and uploaded files are automatically deleted once the associated subscription ends. A user account with no active subscription is automatically removed after three years.
What to check with any QR code provider
Whichever service you choose — these are the concrete points worth checking:
| Server location | Is a specific country/region stated, or does it stay vague ("cloud-based")? |
|---|---|
| DPA | Is it publicly available, or does it need to be requested first? |
| Cookies on scan | Are cookies set during the scan itself? |
| IP storage | Is the IP address anonymized, or stored in plain text? |
| Sub-processors | Are all services used named explicitly? |
| Retention periods | Is there a clear, documented statement of when data is deleted? |
Frequently asked questions about GDPR and QR codes
Do I need to do anything myself as a user of a QR code service?
Yes — you generally remain the data controller for the use case. Recommended: mention the service in your own privacy policy and review the provider's DPA.
Does my QR code poster need its own privacy notice?
Not necessarily directly on the poster — the information obligation is usually fulfilled via the privacy policy of the destination page or your company.
Are static QR codes less of a privacy concern than dynamic ones?
Yes, generally. A static QR code leads directly to the destination address without an intermediary server logging the scan. Dynamic QR codes, by contrast, technically route through the provider's server.
Do I need to obtain cookie consent for the QR code scan itself?
Not with QRlogic — since no cookies are set on scan, the consent requirement that would otherwise apply to tracking technologies doesn't come into play for the people scanning.
Is QRlogic suitable for business customers outside Germany too?
Yes — GDPR applies uniformly across the EU, not just in Germany.
Try it yourself
Create a QR code for free, no sign-up required — or take a direct look at our publicly available DPA.
.png)
.svg.png)

