Is Scanning Business Cards GDPR-Compliant?
· Updated · 9 min read · By the BizCardPro.AI team
This guide is general information, not legal advice. It cannot account for your jurisdiction, sector or the specific way you use contact data. Before relying on any position described here, consult a qualified data-protection practitioner in the relevant jurisdiction.
Is a business card “personal data”?
Yes. Under Article 4(1), personal data is any information relating to an identified or identifiable natural person. A card with a name, a job title, a direct line and a work email identifies a specific living person several times over.
The usual objection — “but this is B2B” — does not survive the text. Recital 14 excludes
information about legal persons: a company’s registered address or a generic info@ mailbox is
not personal data. The moment it concerns a named human, including at work, the GDPR applies.
There is no B2B carve-out.
Scanning is unambiguously processing — Article 4(2) covers collection, recording, structuring and storage. Nor does the household exemption in Article 2(2)(c) rescue you: a professional contact archive is not purely personal activity.
What is your lawful basis?
Every processing operation needs a basis from Article 6. For ordinary business networking the realistic candidate is legitimate interests, Article 6(1)(f) — the generally accepted position among practitioners, not a settled fact of law for every situation.
Regulators frame it as a three-part test:
- Purpose. Is there a genuine legitimate interest? Recital 47 states that processing for direct marketing purposes may be regarded as carried out for a legitimate interest.
- Necessity. Is the processing needed, with no less intrusive route? Storing details you were handed is proportionate; enriching the record from scraped sources is a harder question.
- Balance. Do your interests override the person’s rights and reasonable expectations? Recital 47 makes expectations central — and someone who gave you a card at a conference expects to be contacted.
Write the assessment down: Article 5(2) puts the burden of demonstrating compliance on you, and a one-paragraph assessment is the cheapest evidence you will ever produce.
Why not consent? Consent under Articles 4(11) and 7 must be freely given, specific, informed, unambiguous and as easy to withdraw as to give — a standard a handshake in a crowded hall does not meet. Claiming it anyway weakens you: if consent is your basis and it was invalid, you have no basis at all. Two limits: special category data under Article 9 needs more than Article 6, and scanning cards to build a resale list changes the balancing test entirely.
Who is the controller — you or the app?
This is the point most articles get wrong, and it decides everything else.
The controller (Article 4(7)) is whoever determines the purposes and means of processing — you, or your employer. You decided to scan the cards, what to keep, for how long, and who gets contacted. An app that extracts and stores them on your instructions is a processor (Article 4(8)).
So no vendor can be compliant on your behalf. Its practices feed into your compliance — Article 28 requires controllers to use processors offering sufficient guarantees, normally under a written contract — but the duties owed to the person on the card are yours. BizCardPro.AI’s privacy policy says it plainly: the cards you scan contain someone else’s details, and you are responsible for having the right to digitise and keep them.
Telling people you hold their data
Transparency is where card scanning most often falls short, because the obvious moment to give notice — the handshake — is the worst possible one.
Data obtained directly falls under Article 13, which expects notice at collection. Data obtained indirectly — a fishbowl, a colleague’s stack, an organiser’s list — falls under Article 14, the more workable of the two: Article 14(3)(b) allows the information to be given at the latest at the time of the first communication.
So your first email carries the notice: who you are, where you got their details, what you will use them for, how long you will keep them, and how to object or ask for deletion — one sentence plus a link to your privacy notice.
The rights on the other side of the card
The cardholder can ask you to access what you hold (Article 15 — including the card image), correct it (Article 16), erase it (Article 17), or object (Article 21). Under Article 21(1) you must stop unless you can demonstrate compelling legitimate grounds; under Article 21(3), objection to direct marketing is absolute — no balancing, no discretion. You generally have one month to respond.
When a request arrives, act on it everywhere: delete the contact and the card image from the archive and from every list, export and sending tool the record reached. A deletion that leaves a copy in a spreadsheet is not a deletion.
Retention: the quiet failure
Most card archives breach the storage limitation principle in Article 5(1)(e) through inertia — nobody deletes anything, so the pile grows forever. The law sets no number; it requires you to choose one and justify it. A defensible policy names a review window — eighteen or twenty-four months without interaction is a common choice — and deletes or anonymises what has gone quiet. The accuracy principle in Article 5(1)(d) points the same way: a card from four years ago is frequently just wrong.
GDPR is not the email-marketing rulebook
The GDPR governs whether you may hold and use the data. National electronic-marketing rules, derived from the ePrivacy Directive, govern whether you may send a marketing message. Conflating the two produces most of the bad advice on this topic.
The second set diverges sharply by country. Germany requires prior express consent for email advertising under its unfair-competition law, and applies that to business recipients too — one of Europe’s strictest positions. The UK’s PECR draws the line differently: its consent rule for marketing email applies to individual subscribers, while corporate subscribers are treated more permissively — though sole traders and some partnerships count as individuals, and the right to object applies regardless. Passing the GDPR test does not mean you may send the message.
The same card in Asia
Japan — APPI
The Act on the Protection of Personal Information covers information about an identifiable living individual, so a meishi qualifies. Japan’s model is purpose-driven, not consent-driven: specify your purpose of use, do not exceed it without consent, and notify the person or publicly announce the purpose promptly after acquisition — a website privacy notice is the usual route. Consent becomes central when providing data to a third party and when transferring it overseas, unless the recipient country or the recipient itself meets an equivalent standard. The APPI also reaches foreign businesses supplying goods or services to people in Japan, and the EU and Japan recognise each other’s regimes as adequate.
China — PIPL
The Personal Information Protection Law, effective 1 November 2021, is the strictest of the four. First, there is no general legitimate-interests basis — PIPL lists its lawful bases (consent, contractual or HR necessity, legal obligations and a few others) and the GDPR’s Article 6(1)(f) is absent, so consent usually carries the load, with separate consent required for third-party provision, sensitive data and overseas transfers. Second, PIPL reaches outside China: it applies to processing abroad that targets people in China with products or services, or analyses their behaviour, and foreign handlers in scope must appoint a representative or establish an entity there. Cross-border transfers need a prescribed route — a Cyberspace Administration of China security assessment, certification, or the CAC standard contract — and the thresholds have been revised, so verify the current position.
Singapore — PDPA
The Personal Data Protection Act is the lightest-touch of the four, because of one carve-out. “Business contact information” — name, title, business telephone number, business address, business email and similar details, where not provided solely for personal purposes — is excluded from the PDPA’s main data-protection obligations, so a card handed over in a business context sits largely outside the consent, purpose-limitation and notification requirements. Two cautions: the carve-out follows the character of the information, not the setting, so a personal mobile written on the back is not business contact information; and separate Do Not Call provisions govern marketing calls and texts to Singapore numbers.
Hong Kong — PDPO
The Personal Data (Privacy) Ordinance works through six Data Protection Principles rather than lawful bases. DPP1: collection must be lawful, fair, necessary and not excessive, with the person told the purpose and the classes of transferees on or before collection. DPP2: accuracy, and no retention longer than necessary. DPP3: no new purpose without prescribed consent. DPP4: security. The distinctive feature is the direct-marketing regime in Part VIA — before using personal data in direct marketing you must tell the person, identify the kinds of data and classes of goods or services, provide a response channel, and obtain consent or an indication of no objection, then stop when asked. Non-compliance is a criminal offence. Note too that section 33, restricting transfers outside Hong Kong, has never been brought into operation.
A checklist for the trade-show floor
- Decide your lawful basis before the event, and write the paragraph.
- Note where each card came from — handed over, fishbowl, or organiser’s list. It decides whether Article 13 or Article 14 applies.
- Put the notice in the first email: who you are, where you met, what you will use the details for, how to opt out, plus a link to your privacy notice.
- Do not merge the badge-scan list into the same archive without checking what attendees agreed to.
- Set a retention rule now, apply it on a calendar, and make deletion a one-minute job.
- Separate the follow-up from the campaign — a same-week personal follow-up and a monthly newsletter are different processing activities with different rules.
What to look for in any scanning app
Because you are the controller, evaluate a scanner as you would any processor: where is the data stored, who else touches it, can you get it all back out, and can you delete it on demand?
For BizCardPro.AI, the privacy policy sets out the answers: data stored with established cloud infrastructure providers; card images sent to a third-party AI provider to extract the printed details; Stripe for payments; encryption in transit and at rest; per-account access rules so an archive is readable only by its owner. You can export everything as CSV, Google Contacts CSV or vCard, delete individual cards at any time, and request full account deletion from your registered email address, processed within 30 days. The provider is based in Hong Kong SAR — a fact you need for your own transfer analysis.
Demand that shape of answer from any scanner, including this one. It is not a compliance certificate: compliance is your obligation as controller.
The bottom line
Scanning business cards is lawful under the GDPR in the way most people do it — but because of what you do next, not automatically. Rely on legitimate interests and write down why. Accept that you are the controller. Put the notice in your first email. Pick a retention period and enforce it. Delete on request, everywhere, and treat a marketing objection as absolute. The other regimes differ: Japan wants your purpose declared, China consent and a transfer mechanism, Singapore steps back from business contact information, Hong Kong wants a specific opt-in.
And once more: this is general information, not legal advice. Take advice on your own situation from someone qualified to give it.
Frequently asked questions
Is scanning business cards GDPR-compliant?
It can be, and normally is, when done properly. A business card contains personal data, so scanning and storing it is processing under the GDPR — but ordinary B2B networking follow-up is generally accepted as lawful under the legitimate interests basis in Article 6(1)(f), provided you can pass the balancing test. What makes it compliant is the surrounding practice: telling the person where you got their details when you first make contact, keeping the data no longer than you need it, and honouring access, erasure and marketing objections promptly.
Do I need consent to scan someone’s business card?
Usually not, and consent is usually the wrong basis to rely on. GDPR consent must be freely given, specific, informed, unambiguous and as easy to withdraw as to give — a standard a handshake at a trade show does not meet. The realistic basis for ordinary business follow-up is legitimate interests under Article 6(1)(f), which the GDPR’s own recitals recognise can cover direct marketing. Separate national marketing rules may still require consent before you email or call, which is a different question from whether you may hold the data.
Who is the data controller when I use a business card scanner app?
You are — or your employer is. The controller is whoever determines the purposes and means of the processing, and that is the person or company deciding to scan cards and keep the contacts. A scanning app that processes those cards on your instructions is a processor. This is the point most articles get wrong: a vendor cannot be “GDPR-compliant on your behalf”. Its practices are one input to your compliance; the obligations owed to the cardholder remain yours.
How long can I keep scanned business cards under the GDPR?
There is no fixed period in the law. The storage limitation principle in Article 5(1)(e) requires that you keep personal data no longer than necessary for the purpose you collected it for, which means you must choose a period and be able to justify it. A common approach is to review contacts with no interaction after a defined window — say eighteen or twenty-four months — and delete or anonymise what is no longer a live business relationship. Indefinite retention “just in case” is the one answer that is hard to defend.
Can I email someone whose business card I scanned?
That is two separate questions. The GDPR governs whether you may hold and use their data; national electronic-marketing rules derived from the ePrivacy Directive govern whether you may send them a marketing message. Those rules differ sharply by country — Germany requires prior express consent for email advertising and applies that to business recipients too, while the UK’s PECR treats corporate subscribers more permissively than individuals. A genuine one-to-one follow-up to a conversation you actually had is a different thing from a bulk campaign, and should be written that way.
What do I do if someone asks me to delete their business card details?
Act on it, and do not make them repeat themselves. Delete the contact and the card image from your archive and from every list or export the record reached, then confirm in writing within one month. If they are objecting to direct marketing specifically, that right is absolute under Article 21(3) — there is no balancing test and no discretion to weigh your interests against theirs. If you need a minimal suppression record so they are not re-imported later, keep only what suppression actually requires.
Does the GDPR apply if my company is based outside the EU?
It can. Article 3 extends the GDPR beyond EU-established organisations to processing related to offering goods or services to people in the EU, or monitoring their behaviour there. Simply holding an EU contact’s card is not automatically enough to bring you in scope, but actively marketing to that person may amount to offering goods or services. If a meaningful share of your contacts are in the EU or UK, treat the question as live rather than assuming distance protects you.
How do Asian privacy laws treat business cards differently from the GDPR?
Japan’s APPI is purpose-driven: specify your purpose of use, notify or publicly announce it, and obtain consent before transferring data to a third party or overseas. China’s PIPL is the strictest and has no general legitimate-interests basis, so consent usually carries the load, with separate consent and a formal mechanism required for cross-border transfers. Singapore’s PDPA is the lightest, because “business contact information” is largely carved out of its main obligations. Hong Kong’s PDPO works through six Data Protection Principles and adds a prescriptive direct-marketing regime requiring notification and consent before you market to someone.
Is this article legal advice?
No. This is general information written for people who scan business cards, not legal advice, and it cannot account for your jurisdiction, sector, corporate structure or the specific way you use contact data. Data-protection law also changes. Before relying on any position described here, consult a qualified data-protection practitioner or lawyer in the relevant jurisdiction.
Keep reading
· 11 min read
Reading CJK Names on Business Cards: Order, Splitting and Romanization
Why 陳 is Chen in Beijing, Chan in Hong Kong and Tan in Singapore: how to read, split and romanize Chinese, Japanese and Korean names correctly.
Read the guide →· 10 min read
How to Import Scanned Business Cards into Outlook (vCard and CSV)
No Outlook plugin needed. The two file routes into Outlook contacts, a column-by-column field mapping table, and the encoding and delimiter traps to avoid.
Read the guide →· 8 min read
Vertical Japanese Business Cards (縦書き): Why Scanners Break on Them
Vertical 縦書き meishi read top-to-bottom, right to left — the opposite of what OCR assumes. What breaks, the 縦中横 trap, and how to capture them cleanly.
Read the guide →