All Digital Rewards has called on HR teams to examine how digital gift card and employee reward programs handle personal information. Its October 14, 2025 guidance discusses names, email addresses, payment details and, in some wellness programs, health-related participation data.
The company recommends reviewing rewards vendors’ compliance evidence and restricting internal access by role. It also describes an HR Compliance Checklist covering SOC 2, PCI DSS, HIPAA and GDPR, and identifies HITRUST in its wider discussion of assurance frameworks.
These frameworks address different risks. The PCI Security Standards Council describes PCI DSS as technical and operational requirements for protecting payment account data. Its scope concerns entities storing, processing or transmitting relevant card data, or affecting that environment; use of the term gift card alone does not determine which requirements apply.
Health-information rules also depend on program structure. U.S. Department of Health and Human Services guidance explains that identifiable health information in a wellness program offered through a group health plan is protected by HIPAA. An employer’s direct program outside a group health plan is not automatically covered by HIPAA, although other laws may govern its information.
Employee consent is another area requiring care. The UK Information Commissioner’s Office says consent is often unsuitable where the employer–employee power imbalance prevents a freely made choice. An employer must identify an appropriate lawful basis for its actual processing rather than assuming that every reward transaction requires, or can rely on, explicit consent.
ADR’s checklist is therefore a starting point for examining a vendor and program, rather than evidence that one certification resolves every obligation. The article’s practical emphasis is on understanding the information involved, who can access it and the scope of the vendor’s supporting documentation.