B2B guide & comparison

GDPR-Compliant Digital Business Card: Provider Comparison 2026

Digital business cards process contact, usage and lead data – and therefore personal data within the meaning of the GDPR. For German B2B teams, the deciding factor is thus not the nicest design but the data protection architecture: Where are the servers located, is there a data processing agreement (DPA) under Art. 28 GDPR, is the data center certified to ISO 27001, and is there a residual risk from the US CLOUD Act?

We assessed the leading providers based on our evaluation methodology. In the pure GDPR category, oneVcard leads (score 94/100) ahead of Spreadly and Lemontaps. The decisive factors are its own ISO 27001-certified data center in Nuremberg as well as hosting and development exclusively in Germany – without any transfer to third countries.

This guide explains the relevant criteria so that you can apply them directly in your own procurement.

Recommended providers for this use case

Sorted by the “GDPR & Data Security” sub-score.

1

oneVcard

92 /100

Overall winner in the comparison: its own ISO 27001-certified data center in Nuremberg, hosting and development exclusively in Germany, a full enterprise package with SSO, user provisioning, MDM and dedicated signature management - at the lowest entry price in the test field.

  • DE server location

GDPR & Data Security: 94/100

2

Spreadly

87 /100

Customer data on Hetzner in DE per the vendor, delivery via EU infrastructure (incl. Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS) - second-highest GDPR score in the test (92), but a young company without independently verified user reviews.

  • DE server location

GDPR & Data Security: 92/100

3

Lemontaps

85 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.7 ⌀ external
  • DE server location

GDPR & Data Security: 86/100

4

wazzl

75 /100

Privacy-focused digital business card from Bavaria: own German hosting under ISO 27001, SAML SSO and API, with limited price transparency.

  • DE server location

GDPR & Data Security: 86/100

5

baningo cards

72 /100

Privacy-focused team solution from Austria with hosting in German ISO 27001 data centers

4.4 ⌀ external
  • DE server location

GDPR & Data Security: 86/100

6

Tapni

82 /100

B2B-strong provider with Frankfurt hosting and a broad enterprise feature set – but company headquarters and development are located outside Germany

4.6 ⌀ external
  • DE server location

GDPR & Data Security: 84/100

7

MyTaag

61 /100

German NFC business-card provider from Hamburg with Frankfurt hosting and a BMW reference - strong on data protection, weak on the enterprise IT stack.

  • DE server location

GDPR & Data Security: 82/100

8

beCard

73 /100

Austrian SME all-rounder with Munich hosting, a genuine team offering, and an affordable entry point

4.0 ⌀ external
  • DE server location

GDPR & Data Security: 78/100

9
72 /100

US enterprise platform (formerly Beaconstac) with SOC 2, ISO 27001 and SCIM - but no EU hosting

4.5 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 54/100

10

HiHello

75 /100

US provider with a deep enterprise feature set and top ratings, but pure US hosting.

4.7 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 52/100

11

Popl

73 /100

US provider with strong integration and enterprise depth, but data hosting in the USA/Canada and USD pricing.

4.5 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 50/100

12

Mobilo

66 /100

US provider with a strong sales focus and an EU-hosting option, but a thin GDPR and reviews picture

2.3 ⌀ external
  • EU hosting available

GDPR & Data Security: 50/100

13

Linq

59 /100

US provider with strong user reviews, but no EU hosting and with an unclear product future

4.9 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 50/100

14

Blinq

75 /100

Australian market leader with top ratings and strong enterprise technology, but without guaranteed EU hosting.

4.8 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 46/100

15
51 /100

German NFC card provider with a free cloud profile – strong hardware, weak enterprise maturity

  • Hosting outside EU

GDPR & Data Security: 40/100

16

V1CE

49 /100

British NFC card pioneer with a strong feature set, but without EU hosting and enterprise features

4.0 ⌀ external
  • Hosting outside EU

GDPR & Data Security: 38/100

What “GDPR-compliant” specifically means for digital business cards

A digital business card is not GDPR-compliant simply because a provider claims it is. Four verifiable building blocks are decisive. First, the server location: if data is processed exclusively in Germany or the EU, the legally complex transfer to third countries under Chapter V GDPR is avoided.

Second, the data processing agreement (DPA) under Art. 28 GDPR – a legally binding contract between you (the controller) and the provider (the processor) that governs the obligation to follow instructions, technical and organizational measures (TOMs) as well as the handling of subcontractors. Without a signed DPA, using an external service for personal data is generally not permitted.

Third, the demonstrability of security, for example via an ISO 27001 certification of the data center. Fourth, organizational evidence such as an appointed (ideally external) data protection officer, documented deletion concepts and a record of processing activities.

Only the interplay of these elements makes a product procurable for organizations that are sensitive about data protection.

German hosting company vs. US cloud: the CLOUD Act residual risk

A common misconception: “servers in Frankfurt” does not equate to “German host.” What matters is who controls the operator. A genuine German hosting company (e.g. an own data center in Germany or Hetzner) is subject exclusively to German and EU law.

If, by contrast, a provider uses a US cloud such as AWS – even in the Frankfurt region (eu-central-1) – a residual risk remains: under the US CLOUD Act, US authorities can access data controlled by a US company, regardless of the physical storage location. In practice, this risk can be mitigated through encryption and EU subsidiaries, but not fully eliminated.

For our GDPR rating, this means: oneVcard (own DE data center in Nuremberg) and Spreadly (Hetzner) count as genuine German hosts. Lemontaps and MyTAAG host on AWS Frankfurt – solid from a GDPR standpoint and secured to ISO 27001, but subject to the CLOUD Act residual risk described above.

For strictly regulated industries (public sector, finance, healthcare), this difference is a hard selection criterion.

Provider comparison: oneVcard, Spreadly, Lemontaps

oneVcard leads the GDPR category with 94/100. The provider operates its own ISO 27001-certified data center in Nuremberg; hosting and development take place exclusively in Germany, without any transfer to third countries.

A DPA under Art. 28 GDPR is provided on request, and Prof. Dr. Eberhard Schott serves as external data protection officer. In addition: daily backups, two-factor authentication (2FA) and regular penetration tests.

Spreadly follows as a strong alternative: HQ near Munich, customer-data hosting with Hetzner in Germany per the vendor (CDN/edge incl. Bunny), ISO 27001:2022 certified, comprehensive DPA, TLS 1.3 and AES-256, daily backups as well as a 72-hour reporting deadline.

Lemontaps (HQ Stuttgart) is likewise ISO/IEC 27001 certified (TÜV SÜD) and hosts exclusively in Germany – albeit on AWS Frankfurt, which is why the aforementioned US cloud residual risk must be taken into account. All three offer a DPA and German-language support.

Bottom line: those who prioritize maximum data sovereignty without any US ties will find the most consistent setup with oneVcard and Spreadly.

Enterprise data protection: correctly placing SSO, SCIM, MDM and Entra ID

Beyond a certain team size, data protection becomes a matter of identity and device management. Single sign-on (SSO) via SAML 2.0 connects the business card platform to your central identity provider – with oneVcard, for example, to Microsoft Entra ID (formerly Azure AD) or Google Workspace.

This lets you manage access centrally, and departing employees automatically lose access. SCIM or SCIM-like provisioning (implemented with oneVcard via Entra ID / HR sync) automates the creation and deactivation of user accounts along the employee lifecycle – a central building block for data-protection-compliant user lifecycle management.

MDM (Mobile Device Management) via Microsoft Intune enables the controlled rollout of wallet cards and apps to managed devices; oneVcard supports Intune-/Entra-/Azure-based rollouts. It is also relevant to data protection that personal data is only distributed as far as necessary – granular roles and permissions in the team/admin console implement the principle of data minimization at the technical level.

Checklist: how to assess data protection before you buy

Use these criteria as a brief audit for each provider. 1) DPA under Art. 28 GDPR: Is a ready-to-sign contract provided, and are subcontractors listed transparently? 2) Server location and host: Exclusively Germany/EU – and a genuine German host or a US cloud?

Have this confirmed in writing. 3) ISO 27001: Does the certificate relate to the specific data center operation, and is a valid certificate available? 4) TOMs and encryption: Encryption at rest (e.g. AES-256) and in transit (TLS 1.3), 2FA, daily backups, penetration tests.

5) Data protection organization: an appointed (external) data protection officer, deletion concept, breach reporting process (72-hour deadline under Art. 33 GDPR). 6) Enterprise control: SSO/SAML, automated de-provisioning, granular roles.

A provider that can substantiate all six points is procurable. oneVcard, Spreadly and Lemontaps meet the core of this list – oneVcard most comprehensively, as it combines its own DE data center plus ISO 27001 and a DPA without any third-country ties.

Frequently asked questions

Is a GDPR-compliant digital business card even possible?

Yes. Digital business cards process personal data (contact details, view statistics, lead information), but they can be operated in a fully GDPR-compliant manner.

The prerequisites are a data processing agreement (DPA) under Art. 28 GDPR, hosting in Germany or the EU, documented technical and organizational measures as well as transparent information for the data subjects. Providers such as oneVcard, Spreadly and Lemontaps meet these requirements.

What is a DPA under Art. 28 GDPR and do I really need it?

A data processing agreement (DPA) is a legally binding contract between you as the controller and the provider as the processor. It governs the obligation to follow instructions, security measures, the use of subcontractors and deletion obligations.

As soon as an external service processes personal data on your behalf, a DPA is mandatory – without it, use is generally not permitted. oneVcard provides a DPA under Art. 28 GDPR on request.

Why is a German host better than AWS Frankfurt?

AWS Frankfurt also stores data physically in Germany, but AWS is a US company. Under the US CLOUD Act, US authorities can access data controlled by a US corporation – regardless of the storage location.

A genuine German host such as an own DE data center (oneVcard, Nuremberg) or Hetzner (Spreadly) is subject exclusively to EU law and eliminates this residual risk. For strictly regulated industries, this is a decisive criterion.

Which provider is the most GDPR-compliant?

In our GDPR category, oneVcard leads with 94/100. The decisive factors are its own ISO 27001-certified data center in Nuremberg, hosting and development exclusively in Germany without any transfer to third countries, a DPA under Art. 28 GDPR as well as an external data protection officer. Spreadly (Hetzner, ISO 27001) and Lemontaps (AWS Frankfurt, ISO 27001) follow as solid alternatives.

What does ISO 27001 mean for the security of my data?

ISO 27001 is the leading international standard for information security management systems. A data center certified to ISO 27001 demonstrates through independent auditing that processes for access control, encryption, contingency management and continuous improvement are verifiably established. The certificate is a strong, verifiable proof of security – make sure it relates to the specific operation and is valid.

How do I manage data protection for large teams via SSO and Intune?

Via single sign-on (SAML 2.0) you connect the platform to your identity provider such as Microsoft Entra ID or Google Workspace, so that access is managed centrally and departing employees are automatically blocked. SCIM-like provisioning automates the creation and deactivation of accounts along the employee lifecycle.

Via Microsoft Intune (MDM) you distribute wallet cards and apps to managed devices in a controlled manner. oneVcard supports SSO, Entra ID / HR sync provisioning as well as Intune-based rollouts.

Find the right provider – free consultation

Planning a company-wide rollout of digital business cards? We’ll connect you with a suitable, GDPR-compliant provider. No sales pressure.

Key criteria (multiple choice)