
A grocery app that shaves a dollar off a gallon of milk does not feel like a data broker. The card lives in a phone. The perks feel personal. The trade seems obvious: a little browsing history for a coupon that actually applies to what someone buys.
That framing is starting to fall apart. Regulators, state legislatures, and privacy agencies are looking at what actually moves inside modern rewards programs, and a lot of it looks less like a punch card and more like a data pipeline.
When retailers pass loyalty data down that pipeline to third parties, the same rules that govern data brokers can quietly attach to the retailer that issued the card in the first place.
The Rewards Card Stopped Being a Rewards Card
The loyalty program used to be a simple bargain. A shopper handed over a name and an email, the store handed back discounts, and the data mostly stayed inside the store’s own marketing team.
Modern programs are built differently. Purchase history, app behavior, location pings, and household inferences get combined into profiles that are useful to many parties beyond the retailer. Some of that data funds the discounts. Some of it is sold to partners, advertisers, and analytics vendors whose interest in the shopper has nothing to do with cheaper milk.
A program that quietly monetizes purchase history is not really a loyalty program in the old sense. It is a data business with a coupon attached.
Where a Loyalty Program Becomes a Data Broker Problem
Data broker laws generally target businesses that collect personal information about people they do not directly deal with and then sell it to third parties. A retailer with a signed-up rewards member seems to sit outside that definition. The retailer has a direct relationship with the shopper, and the shopper agreed to the program.
The problem is what happens after that first handshake. Under Colorado’s regulations on loyalty programs, a retailer that wants to fund its rewards by selling a member’s purchase history to a data broker is engaged in a secondary use of the data and needs the consumer’s consent to do it. The regulation also expects up-front disclosure of which categories of third parties, including data brokers, will receive the information.
A retailer can run a rewards program without triggering broker-style obligations. The moment loyalty data is sold onward for purposes unrelated to the perks themselves, the retailer is doing something the law wants labeled, disclosed, and often separately agreed to.
The State Rules Are Getting Sharper, Not Softer
State legislatures have spent the last two years tightening the rules around who counts as a data broker and what they owe consumers. The trend is toward more registration, more disclosure, and stiffer penalties for sitting the process out.
- Registration and fees. Some states now require any business meeting the broker definition to register annually with a privacy regulator and pay a fee to appear on a public registry. Retailers that assumed loyalty operations were exempt are re-reading those definitions carefully.
- Centralized deletion. California’s Delete Act is standing up a single portal that lets a consumer ask every registered broker to delete their data in one request, with recurring deletion obligations after that.
- Bigger penalties. Newer statutes attach real money to noncompliance, including per-record penalties for sensitive data and daily fines for failing to register.
None of this is aimed specifically at rewards programs. It doesn’t have to be. The definitions are broad enough that a retailer selling purchase histories to third parties can end up inside them without ever thinking of itself as a data broker.
What Shoppers Can Actually Do About It
There is no clean way for an individual to audit what a rewards program does with their data. The disclosures are long, the partners are many, and the pipes are not visible from the app. A few habits still help.
- Read the loyalty terms, not the ad. The privacy notice attached to a rewards program is where secondary uses, third parties, and any data broker sharing are supposed to be listed.
- Use the opt-outs that exist. Most large retailers now offer a way to opt out of the sale or sharing of personal information. It is often buried, but it applies to loyalty data too.
- Send deletion requests. State portals and direct requests to a retailer can force a real deletion of the account and its history.
- Get help when something feels off. When a rewards program appears to be quietly reselling purchase data, or when opt-outs and deletion requests go nowhere, a consumer protection law firm can look at whether the retailer’s conduct actually matches what its own disclosures promised.
The Loyalty Program Is a Legal Category Now
The rewards card used to be a marketing tool. It’s turning into a regulated data channel, and the retailers that run one are increasingly on the hook for the same disclosure, consent, and deletion duties as the brokers they sell to.
For shoppers, the practical takeaway is smaller and more useful. A discount is not free. The price of it is written down somewhere in the program’s privacy terms, and it is worth knowing what that price actually is before scanning the card one more time.