Whether on flyers, product packaging, or posters, QR Codes are indispensable in modern marketing. But be careful: While nearly all major international QR Code generators advertise “GDPR-compliant” seals, they systematically violate applicable law when scanned by European users.
For companies, corporations, and government agencies, this poses an incalculable liability risk. With our free GDPR Short URL Auditor, you can check in real time whether your current provider truly meets the strict requirements of IT security and data protection officers - or whether you’re at risk of receiving a warning letter.
Simply enter any short URL there or select one of the well-known providers from the list to start the live test.
GDPR QR Code Auditor Test ResultThe “Compliance Badge” Dilemma: Why Marketing Promises Are Often Deceptive
Anyone looking for a QR Code generator will come across prominent banners from nearly all major international providers that read “DSGVO-compliant” or “GDPR-compliant.” But if you look at the technical reality - that is, the path a user’s data actually takes at the moment of scanning - a completely different picture emerges.
The problem: Many providers claim to be compliant because they manage their customers’ data properly. What they often fail to mention or ignore is the routing infrastructure. As soon as a European user scans a QR Code, their IP address (which is personal data under the GDPR) is transmitted to the routing server. If this server is located in a third country without an adequate level of data protection, or if tracking cookies are set without consent, a data protection violation has already occurred.
An Overview of the Reality: Popular QR Code Services (QR Planet, bit.ly, Uniqode, etc.) Undergo a Technical Audit
| Provider / Service | GDPR-compliant | Reality: Company headquarters | ePrivacy Act
| Hosting Provider
| Reality: Data processing & Redirection |
|---|
| QR Planet | ✅ | Austria (EU) | ✔ Complies
| ✔ Hetzner (Germany)
| Server infrastructure entirely in Germany (Hetzner). No persistent tracking cookies during the redirect.
|
| Uniqode (formerly Beaconstac) | ❌
| USA (Uniqode Phygital Inc.) | ❌ unauthorized cookies
| ✔ AWS (Germany)
| The data infrastructure routes requests through U.S. servers without recognized DPF adequacy decisions |
| QR Code Tiger (qr1.be) | ❌
| Singapore (QRTIGER PTE. LTD.) | ✔ Compliant
| ✖ DigitalOcean (US)
| The redirection servers operate in a third country without specific EU adequacy decisions |
| Bitly | ❌
| USA (Bitly, Inc.) | ❌ Unauthorized cookies
| ✖ Bitly (US)
| Relies heavily on U.S. infrastructure and frequently sets analytics cookies during short URL redirection before the user gives consent. |
The Two Most Common GDPR Pitfalls with Short URLs and QR Codes
When analyzing the links in your current campaigns, you should pay particular attention to these two critical points, which international providers almost always get wrong:
- Illegal Transfer to Third Countries (Server Jurisdiction): If the servers processing the redirection are located outside the EEA (European Economic Area) and no agreement such as the EU-U.S. Data Privacy Framework applies, the transfer of the user’s IP address is prohibited without the scanner’s explicit prior consent.
- Cookies Without Consent (ePrivacy Directive): If a tool sets a persistent tracking or analytics cookie during the fraction of a second it takes to forward data, this directly violates the EU Cookie Directive (ePrivacy). After all, at that point, the user has not yet had any opportunity to click on a cookie banner.
How Does the Auditor Work? The 3 Pillars of Data Protection
Our tool takes a close look at the target URL and evaluates the provider based on three key pillars of data protection law:
1. Hosting Jurisdiction (Where is the server located?)
The auditor identifies the IP address behind the short URL and determines the country where the server that handles the redirection is located.
- Why this is important: If the server is located outside the EU (e.g., in the U.S.), the user’s metadata (such as their IP address) is immediately transferred to a third country when the QR Code is scanned. Without legal safeguards, this constitutes a serious violation of the GDPR.
- The exception: If the server is operated by a U.S. company, that company must have joined the EU-U.S. Data Privacy Framework (DPF) in order to legally receive data from Europe.
2. Company Status (Where is the provider located?)
Here, the tool checks where the provider has registered its principal place of business.
- Why this matters: Ideally, the provider is based in the EU. If it’s based outside the EU, things get more complicated. This is particularly critical when it comes to U.S. providers.
- The U.S. Problem (CLOUD Act): U.S. companies are legally required to grant U.S. authorities (such as the FBI or the NSA) access to their data upon request - worldwide, regardless of whether the server is physically located in Frankfurt, Dublin, or Oregon. This ability to access data secretly directly conflicts with the GDPR.
3. EU-Cookie-Richtlinie / ePrivacy-Richtlinie (Werden ungefragt Cookies gesetzt?)
This test checks whether the server places cookies in the user's browser or loads tracking scripts without permission during the redirection process.
- Why this is important: According to the ePrivacy Directive, storing information on a user’s device without their prior, active consent (opt-in) is strictly prohibited. If a provider sets a tracking cookie simply by forwarding data without the user’s consent, this constitutes a direct violation of the law.
Understanding Test Results: When the Test is Considered Passed
After the analysis, the auditor will provide you with a clear result. There are two possible outcomes:
- Green Light (100% compliant): The provider passes all three tests.
- Red Light (disqualifying criterion): At least one of the three tests fails. In this case, you should urgently verify whether you can use this provider for your campaigns in a legally compliant manner.
Outcome Scenarios: GDPR-Compliant or at Risk
1. Hosting Jurisdiction
✅ The routing server's infrastructure is located within the European Economic Area (EEA).
❌ The routing server processes requests outside the European Union (without recognized safeguards).
2. Company Status
✅ The provider is based in the EU, or the non-European company holds active certification under the EU-U.S. Data Privacy Framework (DPF) or uses recognized Standard Contractual Clauses (SCCs).
❌ Because the company is based in the U.S., it is subject to the CLOUD Act (risk of access by U.S. authorities) or operates in third countries (such as Singapore) without having agreed to the necessary contractual safeguards (SCCs) with its customers.
3. EU Cookie Directive / ePrivacy Directive
✅ No unauthorized cookies or tracking scripts were found during the redirect.
❌ Non-compliant. An attempt was made to place a tracking cookie on the user's device before the user gave consent.
Why You're in Good Hands with QR Planet
As a European provider based in Austria, we develop and operate our QR Code infrastructure in accordance with the “Privacy by Design” principle:
- Without exception, our servers are located in highly secure European data centers.
- We are an Austrian company and are thus not subject to the U.S. CLOUD Act. We do not share any data with foreign intelligence agencies.
- Our standard tracking for redirects is 100% cookie-free. We respect your customers’ privacy from the very first second.
Take the test now and put your current QR Code service provider through its paces:
Sources