blog

Wallet notifications and GDPR: transactional, marketing and consent

Transactional or marketing: which consent Apple Wallet and Google Wallet notifications need, and how to collect it.

Wallet notifications and GDPR: transactional, marketing and consent
Published on
21.11.2025

Updated October 2, 2026.

Apple Wallet and Google Wallet notifications are a highly visible channel: they land on the lock screen, like a text message from the brand. Before using them, you need to know which ones are service messages and which ones are marketing, because the consent required is different. For how they work technically (triggers, limits, geolocation), see our complete guide to wallet notifications.

What customers control in their wallet

Each pass is a separate object in the Wallet app. For each pass, customers can turn automatic updates, notifications and contextual display (for example the card appearing when entering a store) on or off. They can also turn off all Wallet notifications in their phone settings.

Pass notification settings in Apple Wallet
Global Wallet notification settings in iOS

These settings are not marketing consent: they only control delivery on the device. Consent must be collected in the brand's own journeys.

On the channel side, Apple Wallet only notifies when a pass is updated: for a promotional message, you update a dedicated field. Google Wallet can also notify from a message added to the pass, up to three per pass per day (Google documentation).

Transactional vs marketing notifications

Transactional notifications (service-related)

They stem from the performance of a contract, such as joining a loyalty program or buying a ticket, and are necessary to deliver the service.

  • "You've earned 50 points."
  • "Your concert starts tomorrow at 8 pm."
  • "You have 3 entries left."

Legally, they fall under contract performance (GDPR Article 6(1)(b)): no marketing consent is needed, but customers must be informed beforehand.

Important: a prospect who downloads a pass without signing up to a service is not covered by this basis. Any proactive notification they receive is direct marketing.

Marketing notifications (prospecting)

They promote a product or service with no direct link to an ongoing contract:

  • updating a promotional field to announce an offer;
  • a Google Wallet message "20% off the new collection".

They require explicit marketing opt-in, separate from service consent (GDPR Articles 6(1)(a) and 7). Some national exceptions exist, such as messages to existing customers about similar products, and must be assessed case by case.

Collecting and proving consent

  • Where: at sign-up (website, app, store), for example with The Wallet Crew enrolment forms, or on the pass download page.
  • How: two separate choices, service and marketing, stored as independent flags. No single "wallet notifications" checkbox.
  • Proof: keep the timestamp, collection channel, wording shown and privacy notice version, as well as withdrawals.

Privacy policy

It should state that a wallet pass can generate notifications, separate service and promotional messages, list the main triggers and expected frequency, and explain how to turn them off.

Best practices for brands

  1. Classify every notification: transactional or marketing.
  2. Update legal documents (privacy policy, terms).
  3. Use a specific opt-in for promotional notifications and filter sends accordingly.
  4. Add a link in the pass to a preference center, so customers can opt out of marketing only without deleting the card.
  5. Test the full journey: capture, update, notification and opt-out.

The Wallet Crew's role

The Wallet Crew lets you segment sends by consent status and keep purposes separate. The platform acts as a processor: the brand remains responsible for the legal basis, consent collection and customer information. Learn more: consents and GDPR documentation, wallet notifications guide, notifications platform.