When Personalization Starts Feeling Like Surveillance
Direct answer: A loyalty program should collect enough customer data to make participation useful, relevant and secure, but not so much that the customer would be shocked to see the complete profile. The right boundary is not defined by what technology can collect. It is defined by purpose, proportionality, transparency and genuine customer control.
Key Takeaways
- More customer data does not automatically create better loyalty.
- Personalization becomes uncomfortable when customers cannot understand why information was collected or how predictions are being made.
- India’s evolving data-protection framework makes clear purpose, limited collection and customer control increasingly important.
- Brands should measure trust and permission quality alongside redemptions, repeat purchases and engagement.
- The most useful loyalty data usually comes from verified actions, not from collecting everything available.
A 515-Page Surprise
In August 2026, WIRED senior writer Reece Rogers asked McDonald’s for a copy of the information connected to his loyalty account.
He expected order history, points and perhaps a record of the offers he had received. What arrived was a 515-page file.
According to Rogers’ first-person account in WIRED, the file contained detailed transaction records, locations, loyalty activity, offers and entries connected with McDonald’s Monopoly promotions. More strikingly, it included algorithmic predictions about his future behaviour.
The system estimated that he would visit 2.16 times over the following six weeks, spend an average of $13.49 per order and spend $29.15 in total. It reportedly assigned him a customer attrition likelihood of zero.
After seeing the extent of the information and prediction, Rogers requested that his data be deleted and wrote that he intended to stop eating there.
That is a remarkable loyalty outcome. A system designed to understand a customer more accurately ended up making the customer want to leave.
But this should not be read as a simplistic story about a failed loyalty program. McDonald’s operates one of the world’s largest loyalty ecosystems. The company reported nearly 210 million 90-day active loyalty users at the end of 2025 and almost $37 billion in annual systemwide sales to loyalty members across 70 markets. McDonald’s 2025 results provide the scale.
That is precisely why the WIRED story matters. It shows that even an effective and sophisticated loyalty system can approach an invisible boundary between relevance and intrusion.
The Uncomfortable Question Behind Personalization
Marketers have been taught to treat a complete customer profile as an unquestioned advantage.
Know what the customer buys.
Know when they buy it.
Know where they buy it.
Predict what they will buy next.
Estimate their risk of leaving.
Then choose the message, offer and reward most likely to influence the next action.
From the brand’s side, this sounds efficient.
From the customer’s side, the same process can sound very different:
How much do you know about me?
When did I agree to this?
What exactly are you predicting?
Who else receives the information?
Can I see, correct or delete it?
The difference between personalization and surveillance is often not the data itself.
It is the gap between what the company is doing and what the customer reasonably believes the company is doing.
What Is Useful Personalization?
Useful personalization employs data to deliver a clear benefit connected with the customer’s participation.
A shopper buys coffee every week and receives a relevant coffee reward.
A consumer scans an eligible pack and does not have to submit the same details again.
A dealer completes a training module and sees the next challenge appropriate to that product category.
A loyalty member chooses travel and entertainment as preferred rewards and sees more of those options.
The relationship is understandable.
The customer performs an action, the brand uses a reasonable amount of information and the customer receives recognizable value.
Personalization begins to feel like surveillance when the collection or inference becomes disproportionate to that visible benefit.
| Data Use | Possible Customer Benefit | Question the Brand Should Ask |
|---|---|---|
| Mobile number | Account access, OTP verification and reward delivery | Is every later communication covered by a clear choice? |
| Purchase and SKU history | Relevant rewards, replenishment reminders and easier service | How long is this history genuinely useful? |
| Location | Nearby availability or a location-specific benefit | Is precise or continuous location really necessary? |
| Engagement history | Fewer irrelevant messages and better timing | Can the customer change frequency and channel preferences? |
| Predicted traits or psychological characteristics | Potentially deeper personalization | Could this be explained comfortably and defended as proportionate? |
The RewardPort Useful Data Test
Before adding a new field, signal or prediction to a loyalty program, brands should apply five tests.
1. Visible Benefit
Can the customer identify what improves because this information is being used?
“ We use your preferred city to show nearby experiences” is understandable.
Collecting location without a visible customer benefit is much harder to justify as part of a loyalty relationship.
2. Appropriate Purpose
Is the information being used for the purpose the customer reasonably understood when providing it?
A mobile number supplied to deliver a cashback confirmation should not silently become permission for unlimited promotional messaging.
3. Limited Collection
Is this the smallest amount of data required to provide the benefit, verify the action or protect the program from abuse?
The discipline is to collect what is useful, not everything that is technically available.
4. User Control
Can the customer easily review preferences, change communication choices, withdraw permission or request correction and deletion where applicable?
Control should not be hidden behind multiple screens or depend on contacting an unknown department.
5. Explainable Inference
Could the brand explain the prediction to an ordinary customer without creating discomfort?
If a model labels someone as price-sensitive, at risk of leaving or likely to respond to a particular pressure tactic, the organisation should understand the inputs, intended use and possible harm.
Together, these five questions create a simple V.A.L.U.E. discipline:
V — Visible Benefit
A — Appropriate Purpose
L — Limited Collection
U — User Control
E — Explainable Inference
Why This Matters Especially in India
India’s Digital Personal Data Protection Act, 2023 and the notified Digital Personal Data Protection Rules, 2025 place greater emphasis on clear consent, specified purpose, data minimisation, security, accountability and individual rights.
The Rules use a phased commencement timetable. Brands should therefore verify which provisions apply at the time of implementation rather than treating every requirement as having commenced simultaneously.
The official text is available from the Ministry of Electronics and Information Technology.
This is not only a legal issue.
It changes the commercial design of loyalty.
A program built on vague consent and constant data accumulation may technically generate more information while gradually weakening trust.
A program that clearly explains the exchange can generate less data but stronger permission.
That stronger permission is often more valuable because the customer understands why the relationship exists.
How Should Brands Redesign Loyalty Data Collection?
1. Map Every Collected Field
Include registration details, transactions, location, device information, campaign responses, inferred attributes and information received from partners.
2. Connect Each Field to a Customer or Operational Purpose
If the team cannot identify a current purpose, question whether the information should continue to be collected or retained.
3. Separate Participation From Broad Marketing Permission
Entering a promotion, receiving a reward and joining ongoing communications are not automatically the same decision.
4. Rewrite Notices in Ordinary Language
A customer should understand what is collected, why it is required and what will happen next.
5. Create a Preference and Control Layer
Let customers choose channels, frequency, reward interests and whether they want personalised recommendations.
6. Set Retention Rules
Loyalty data should not remain indefinitely merely because storage is inexpensive.
7. Audit Predictive Models
Review what is inferred, how it is used, whether it creates unfair treatment and whether the prediction can be explained.
8. Test Customer Reaction
Ask a simple question:
Would a reasonable member be surprised if this appeared in their personal data file?
The Metrics Loyalty Teams Should Add
Redemption rate, active membership, repeat purchase rate and customer lifetime value remain useful.
They do not reveal whether the program is building healthy permission.
Brands should also track:
- Consent acceptance and withdrawal rates
- Communication opt-out rates by campaign and channel
- Preference-setting completion
- Complaints concerning irrelevant or intrusive messaging
- Percentage of collected fields connected to a documented purpose
- Time taken to respond to data-access, correction and deletion requests
- Customer trust or comfort scores
- Incremental performance from personalization compared with non-personalized journeys
The final metric is particularly important.
If extensive profiling produces only a marginal improvement, the additional data and trust risk may not be worth it.
A Practical Example
Consider a packaged-food brand running a repeat-purchase program.
The brand needs a mobile number to create the account and send an OTP.
It needs purchase proof to confirm eligibility.
It may ask the customer to select reward interests so that cinema, merchandise, cashback or experiences can be presented appropriately.
It probably does not need continuous location access, unrelated browsing history or an opaque psychological profile.
After the first verified purchase, the customer can choose whether to receive reminders, participate in another challenge or stop communication.
The brand learns from real, permissioned actions while the customer retains control.
This produces a smaller customer profile.
It may also produce a better customer relationship.
The Real Loyalty Advantage May Be Restraint
For years, the loyalty industry has treated the complete customer profile as the ultimate asset.
The next competitive advantage may be different:
Knowing which information not to collect, which prediction not to use and which message not to send.
A customer who receives one relevant reward with a clear explanation may trust the brand more than a customer who receives ten perfectly timed offers without understanding how the brand knows so much.
RewardPort designs consumer, channel and partner engagement programs around verified actions, appropriate rewards and measurable outcomes.
The objective is not to build the largest possible customer file.
It is to use the right information to make participation more useful, secure and rewarding.
Planning or reviewing a loyalty or consumer-promotion program?
RewardPort can help assess the journey, verification method, reward architecture, permission points, fraud controls and measurement framework before launch.
Frequently Asked Questions
How much customer data should a loyalty program collect?
Only the information necessary to operate the program, verify qualifying actions, prevent abuse, deliver relevant value and improve the experience for purposes clearly communicated to the customer.
Is purchase history acceptable for personalisation?
Purchase history can support useful personalisation when the purpose is clear, the information is protected, retention is proportionate and the customer has appropriate choices.
Does joining a loyalty program mean agreeing to all marketing?
Program participation and ongoing promotional communication should be treated as distinct choices where required. Brands should avoid assuming that one action grants unlimited permission.
Can AI be used in loyalty programs?
Yes. AI can recommend rewards, identify likely needs, detect fraud and improve program decisions. Brands should understand the inputs, monitor outcomes and avoid predictions that are disproportionate, discriminatory or impossible to explain responsibly.
Is first-party data automatically privacy-safe?
No. First-party data describes where the information came from. It does not automatically make every collection method, purpose, inference or retention period appropriate.
What is the difference between personalisation and surveillance?
Personalisation provides a transparent and proportionate customer benefit. Surveillance is the feeling created when collection and inference exceed the customer’s expectations, understanding or control.
Should brands stop collecting customer data?
No. The objective is not zero data. It is useful, permissioned and accountable data connected with a clear customer or operational purpose.

