B2B guide & comparison

GDPR-compliant digital business card: provider comparison 2026

Digital business cards process contact, usage and lead data, and therefore personal data within the meaning of the GDPR. For German B2B teams, the deciding factor is therefore not the most attractive design but the data protection architecture: Where are the servers located, is there a data processing agreement (DPA) under Art. 28 GDPR, is the data center certified to ISO 27001, and does a residual risk arise from the US CLOUD Act?

We assessed the leading providers using our evaluation methodology. In the pure GDPR category, oneVcard (score 94/100) leads ahead of Spreadly and Lemontaps. The decisive factors are an ISO 27001 certified data center in Nürnberg as well as hosting and development exclusively in Germany, without any transfer to third countries.

This guide explains the relevant criteria in a way that lets you apply them directly in your own procurement.

Recommended providers for this use case

Sorted by the “GDPR & Data Security” sub-score.

1

oneVcard

91 /100

Overall winner in the comparison: an ISO 27001 certified data center in Nürnberg, hosting and development exclusively in Germany, full enterprise package with SSO, user provisioning and dedicated signature management.

4.9 ⌀ external
  • DE server location

GDPR & Data Security: 94/100

2

Spreadly

88 /100

Customer data on Hetzner in Germany according to the provider, delivery via EU infrastructure (including Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS), second-strongest GDPR score in the test (92); comparatively young company (founded 2022).

4.4 ⌀ external
  • DE server location

GDPR & Data Security: 92/100

3

baningo cards

78 /100

Privacy-focused team solution from Austria with hosting in German ISO 27001 data centers

4.5 ⌀ external
  • DE server location

GDPR & Data Security: 87/100

4

Lemontaps

87 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.8 ⌀ external
  • DE server location

GDPR & Data Security: 86/100

5

wazzl

77 /100

Privacy-focused digital business card from Bavaria: in-house German hosting to ISO 27001, SAML SSO and API, with limited pricing transparency.

  • DE server location

GDPR & Data Security: 86/100

6

Tapni

82 /100

Strong B2B provider with Frankfurt hosting and a broad enterprise feature set, though headquarters and development sit outside Germany

4.6 ⌀ external
  • DE server location

GDPR & Data Security: 84/100

7

MyTaag

62 /100

German NFC business card provider from Hamburg with Frankfurt hosting and a BMW reference, strong on data protection, weak on the enterprise IT stack.

  • DE server location

GDPR & Data Security: 82/100

8

beCard

72 /100

Austrian SME all-rounder with München hosting and a genuine team offering

4.0 ⌀ external
  • DE server location

GDPR & Data Security: 78/100

9
75 /100

US enterprise platform (formerly Beaconstac) with SOC 2, ISO 27001 and SCIM, but without EU hosting

4.5 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 62/100

10

HiHello

76 /100

US provider with a deep enterprise feature set and top ratings, but purely US hosting.

4.7 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 60/100

11

Popl

75 /100

US provider with strong integration and enterprise depth, but data storage in the USA/Canada and USD pricing.

4.5 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 58/100

12

Mobilo

68 /100

US provider with a strong sales focus and an EU hosting option, but a thin GDPR and review situation

2.3 ⌀ external
  • EU hosting available

GDPR & Data Security: 58/100

13

Linq

62 /100

US provider with strong user ratings, but without EU hosting and with an uncertain product future

4.9 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 58/100

14

Blinq

76 /100

Australian market leader with top ratings and strong enterprise technology, but without guaranteed EU hosting.

4.8 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 54/100

15
49 /100

German NFC card provider with a free cloud profile; strong hardware, weak enterprise maturity

  • Hosting outside EU

GDPR & Data Security: 40/100

16

V1CE

50 /100

British NFC card pioneer with a strong feature set, but without EU hosting and enterprise features

4.0 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 38/100

What "GDPR-compliant" specifically means for digital business cards

A digital business card is not GDPR-compliant simply because a provider claims it is. Four verifiable building blocks are decisive. First, the server location: if data is processed exclusively in Germany or the EU, the legally complex third-country transfer under Chapter V GDPR is not required.

Second, the data processing agreement (DPA) under Art. 28 GDPR, a legally binding contract between you (the controller) and the provider (the processor) that governs adherence to instructions, technical and organizational measures (TOM) as well as the handling of subcontractors. Without a signed DPA, using an external service for personal data is generally not permitted.

Third, the verifiability of security, for example through ISO 27001 certification of the data center. Fourth, organizational evidence such as an appointed (ideally external) data protection officer, documented deletion policies and a record of processing activities.

Only the interplay of these elements makes a product procurable for organizations sensitive to data protection.

German hosting provider vs. US cloud: the CLOUD Act residual risk

A common misconception: "Server in Frankfurt" is not the same as "German hoster". What matters is who controls the operator. A genuine German hosting provider (for example an own data center in Germany or Hetzner) is subject exclusively to German and EU law.

If, on the other hand, a provider uses a US cloud such as AWS, even in the Frankfurt region (eu-central-1), a residual risk remains: under the US CLOUD Act, US authorities can access data controlled by a US company, regardless of the physical storage location. In practice this risk can be mitigated through encryption and EU subsidiaries, but not fully eliminated.

For our GDPR rating this means: oneVcard (a DE data center in Nürnberg) and Spreadly (Hetzner) count as genuine German hosters. Lemontaps and MyTAAG host on AWS Frankfurt, solid in GDPR terms and secured to ISO 27001, but subject to the described CLOUD Act residual risk.

For strictly regulated industries (public sector, finance, healthcare) this difference is a hard selection criterion.

Provider comparison: oneVcard, Spreadly, Lemontaps

oneVcard leads the GDPR category with 94/100. The provider hosts in an ISO 27001 certified data center in Nürnberg; hosting and development take place exclusively in Germany, without any transfer to third countries.

A DPA under Art. 28 GDPR is provided on request, and Prof. Dr. Eberhard Schott serves as the external data protection officer. In addition: daily backups, two-factor authentication (2FA) and regular penetration tests.

Spreadly follows as a strong alternative: HQ near München, customer data held according to the provider at Hetzner in Germany (CDN/Edge including Bunny among others), certified to ISO 27001:2022, comprehensive DPA, TLS 1.3 and AES-256, daily backups as well as a 72-hour notification deadline. Lemontaps (HQ Stuttgart) is likewise ISO/IEC 27001 certified (TÜV SÜD) and hosts exclusively in Germany, though on AWS Frankfurt, which is why the mentioned US cloud residual risk must be taken into account.

All three offer a DPA and German-language support. Conclusion: anyone prioritizing maximum data sovereignty without a US connection will find the most consistent setup with oneVcard and Spreadly.

Enterprise data protection: correctly assessing SSO, SCIM, MDM and Entra ID

From a certain team size onward, data protection becomes a question of identity and device management. Single Sign-On (SSO) via SAML 2.0 connects the business card platform to your central identity provider, with oneVcard for example to Microsoft Entra ID (formerly Azure AD) or Google Workspace.

This lets you manage access centrally, and departing employees automatically lose access. SCIM, or a SCIM-like provisioning (implemented at oneVcard via Entra ID / HR sync), automates the creation and deactivation of user accounts along the employee lifecycle, a central building block for data-protection-compliant user lifecycle management.

MDM (Mobile Device Management) via Microsoft Intune enables the controlled rollout of wallet cards and apps to managed devices; such an MDM device rollout is, however, not publicly documented for oneVcard and should be confirmed with the provider before signing a contract; what is documented here is the Entra ID / Azure connection for SSO and user provisioning. It is also relevant for data protection that personal data is only distributed as far as necessary.

Granular roles and permissions in the team/admin console technically implement the principle of data minimization.

Checklist: how to check data protection before buying

Use these criteria as a short audit for each provider. 1) DPA under Art. 28 GDPR: is a signature-ready contract provided, and are subcontractors listed transparently? 2) Server location and hoster: exclusively Germany/EU, and a genuine German hoster or a US cloud?

Have this confirmed in writing. 3) ISO 27001: does the certificate relate to the specific data center operation, and is a valid certificate available? 4) TOM and encryption: encryption at rest (for example AES-256) and in transit (TLS 1.3), 2FA, daily backups, penetration tests.

5) Data protection organization: an appointed (external) data protection officer, a deletion policy, a notification process for data breaches (72-hour deadline under Art. 33 GDPR). 6) Enterprise control: SSO/SAML, automated de-provisioning, granular roles.

A provider that can substantiate all six points is procurable. oneVcard, Spreadly and Lemontaps meet the core of this list, oneVcard most comprehensively, because a DE data center plus ISO 27001 and a DPA without any third-country connection come together.

Frequently asked questions

Is a GDPR-compliant digital business card even possible?

Yes. Digital business cards process personal data (contact details, view statistics, lead information), but they can be operated in a fully GDPR-compliant way.

The prerequisites are a data processing agreement (DPA) under Art. 28 GDPR, hosting in Germany or the EU, documented technical and organizational measures as well as transparent information for the data subjects. Providers such as oneVcard, Spreadly and Lemontaps meet these requirements.

What is a DPA under Art. 28 GDPR and do I really need it?

A data processing agreement (DPA) is a legally binding contract between you as the controller and the provider as the processor. It governs adherence to instructions, security measures, the use of subcontractors and deletion obligations.

As soon as an external service processes personal data on your behalf, a DPA is mandatory. Without it, use is generally not permitted. oneVcard provides a DPA under Art. 28 GDPR on request.

Why is a German hoster better than AWS Frankfurt?

AWS Frankfurt also stores data physically in Germany, but AWS is a US company. Under the US CLOUD Act, US authorities can access data controlled by a US corporation, regardless of the storage location.

A genuine German hoster such as an own DE data center (oneVcard, Nürnberg) or Hetzner (Spreadly) is subject exclusively to EU law and eliminates this residual risk. For strictly regulated industries this is a decisive criterion.

Which provider is the most GDPR-compliant?

In our GDPR category, oneVcard leads with 94/100. The decisive factors are an ISO 27001 certified data center in Nürnberg, hosting and development exclusively in Germany without third-country transfer, a DPA under Art. 28 GDPR as well as an external data protection officer. Spreadly (Hetzner, ISO 27001) and Lemontaps (AWS Frankfurt, ISO 27001) follow as solid alternatives.

What does ISO 27001 mean for the security of my data?

ISO 27001 is the internationally leading standard for information security management systems. A data center certified to ISO 27001 proves through independent auditing that processes for access control, encryption, emergency management and continuous improvement are demonstrably established. The certificate is a strong, verifiable proof of security; make sure that it relates to the specific operation and is valid.

How do I manage data protection for large teams via SSO and Intune?

Via Single Sign-On (SAML 2.0) you connect the platform to your identity provider such as Microsoft Entra ID or Google Workspace, so that access is managed centrally and departing employees are automatically blocked. A SCIM-like provisioning automates the creation and deactivation of accounts along the employee lifecycle.

Via Microsoft Intune (MDM) you distribute wallet cards and apps in a controlled way to managed devices. oneVcard supports SSO as well as Entra ID / HR sync provisioning; an MDM device rollout via Intune is not publicly documented and must be confirmed with the provider before signing a contract.

Ad

Request a direct consultation with the test winner

Planning a company-wide rollout of digital business cards? Request a free, no-obligation consultation with our test winner oneVcard.

Key criteria (multiple choice)