Irish SME
Refer-a-Friend Scheme Rules: Reward the Friend Who Walks In, Not the Email You Send

Take a scenario that plays out, in one form or another, on plenty of small business websites every autumn. A mobile dog groomer in Mayo, booked solid through the summer, looks at a quiet November diary and decides to do something about it. Her best customers already rave about her. So she adds a box to the booking page on her website: "Know someone whose dog needs a tidy-up? Enter their email and we'll send them €10 off their first groom."
It works, at first. Within a fortnight, a few dozen addresses come in. The website fires off a cheerful email to each one, with her logo, her prices and a discount code.
Then one reply lands that is not cheerful at all. "Who gave you my email address? I never signed up for anything." A few weeks later, a letter arrives from the Data Protection Commission.
Nothing about her intentions was dodgy. She wanted what every small business wants: more customers who arrive already trusting her. The problem was one form field, and it is sitting on a lot of Irish websites right now.
Why She Was Right to Want Referrals
Before the law, the commercial case. Referrals are not a nice-to-have. They are probably the best-quality leads a small business ever gets.
Nielsen's global Trust in Advertising study, run across more than 40,000 consumers in 2021, found that roughly nine in ten people (88%) trust recommendations from people they know, more than any other channel [5]. That figure is global rather than Irish, and trust is not the same as buying. Still, nothing a business pays for comes close.
There is harder evidence on value, too. Researchers Philipp Schmitt, Bernd Skiera and Christophe Van den Bulte tracked around 10,000 customers of a German bank for almost three years and found that the average referred customer was worth at least 16% more than a comparable non-referred customer, partly because they stayed with the bank longer [6]. A bank is not a grooming van, and the authors themselves warn that the gap varies by segment. But the direction of travel is clear. People who come in on a friend's word tend to stick.
So the instinct was sound. You know what the trouble is, right? It is not the reward. It is who presses send.
What the Data Protection Commission Actually Says
The Data Protection Commission (DPC) has a short FAQ on exactly this question: can you ask customers for friends' electronic contact details as part of a refer-a-friend scheme and then market to them? The answer is blunt.
"It is an offence under the ePrivacy Regulations (SI 336 of 2011) to send an unsolicited marketing message to someone where there is no existing customer relationship. The onus is on the sender to show that the recipient has consented to the receipt of such messages. It is difficult to see how the operation of a 'refer a friend' facility could meet this requirement." [1]
Read that last sentence again. The regulator is not saying "be careful". It is saying the standard website version of the scheme is very hard to make lawful at all.

The three details that catch people out
Regulation 13 of S.I. 336/2011 is the rule underneath that FAQ [2]. Three parts of it matter for a small business:
- Text messages count. The Regulations define "electronic mail" to include SMS. Swapping the email box for a mobile number changes nothing.
- Every message is its own offence. Regulation 13(13)(b) says the sending of each unsolicited communication "constitutes a separate offence". Our Mayo groomer did not make one mistake. In principle, she made one per friend.
- The burden of proof sits with you. Under Regulation 13(14), if consent is disputed, it is for the business to establish that the person consented, not for the recipient to prove they did not.
On penalties, each offence carries a class A fine on summary conviction, which the Fines Act 2010 sets at up to €5,000, and on indictment a company can face up to €250,000 [2]. Most small cases never get near a courtroom, and I would not want anyone reading this in a panic. But the DPC is plainly busier on this front than it used to be. Its 2025 annual report records 275 electronic direct marketing investigations concluded, up 88% on the year before, plus 50 warning letters to companies over unsolicited marketing [3].
It works a bit like a hosting renewal email. Nothing happens for months, and then one annoyed recipient turns a friendly promotion into correspondence you have to answer.
"But My Customer Typed It In, Not Me"
This is the objection I hear most, and it is understandable. The groomer did not go looking for those addresses. Her customers volunteered them.
It does not help much. Regulation 13 applies to anyone who will "use or cause to be used" an electronic communications service to send the marketing message [2]. The website sent the email. The website belongs to the business. The customer supplied an address; the business did the sending.
The "existing customer" exception does not rescue it either. Irish law does let you email your own customers about similar products without fresh consent, under strict conditions, but that exception is about people who bought from you [2]. The friend never bought anything. There is no relationship to point to.
What about the softer version, where the website opens the customer's own email app with a pre-written message? The DPC FAQ does not address it directly. The UK regulator, the ICO, applies rules drawn from the same EU ePrivacy directive, and its guidance takes a firm line: if you actively encourage people to pass your marketing on, you are likely to be "instigating" those messages, and "you don't need to give an incentive for it to count as instigating" [4]. ICO guidance does not bind an Irish court. I would still treat it as a strong signal of how a European regulator reads this, and I would not build a promotion on the hope that Ireland reads it differently.
The Referral Scheme That Works
The fix is simpler than the problem. Flip the direction of travel. Instead of your website contacting the friend, the friend contacts you.
That one change removes the unsolicited message from the equation entirely. Nobody receives marketing they did not ask for. The friend arrives because a real person, in their own words, at a time of their own choosing, told them you were good.
| Scheme design | Who contacts the friend | Risk under the ePrivacy rules |
|---|---|---|
| "Enter your friend's email and we'll send them an offer" form | Your website | High: the DPC says this is hard to make lawful |
| Pre-written "share by email or text" button you actively push | The customer, on your script | Uncertain: UK regulator treats this as instigating |
| "Who recommended us?" box on your booking or enquiry form | The friend contacts you | Low: no unsolicited message is sent |
| Personal referral code, or printed cards, the customer hands on in their own way | The customer, in their own words | Low: you are not scripting or sending anything |
The last two rows are where the value is. Neither needs clever software. Both need your website to do its job properly: a clear referral page explaining the offer, and a form field that captures the name of whoever sent the new customer in.
What the groomer should have built instead
Rewind the scenario. Same quiet November, same loyal customers, different website.
She adds one optional field to her booking form: "Did someone recommend us? Tell us who, and we'll both say thanks." She writes a short page on her site explaining the deal: €10 off for the new customer's first groom, €10 off the next groom for the person who recommended them. At the van door, she hands regulars a couple of printed cards with the referral page address on them.
She never sees a single friend's email address until that friend decides to book. No complaint letter. No awkward reply. And, as a bonus, she gets a clean record of which customers actually send her business, which a pile of harvested addresses never told her.

Setting Up a Lawful Referral Offer on Your Website
This is the part most owners can deploy in an afternoon. Keep it to four moves.
- Publish a referral page. One page that states the reward, who qualifies, when it is applied and when it expires, so neither side is left guessing about the terms.
- Add a "Who recommended us?" field. Put it on the booking, enquiry or checkout form, keep it optional, and never ask for the friend's contact details in any other box.
- Verify the rewards manually. Match each named referrer to a real customer before applying the credit, because a free-text field will attract the odd chancer.
- Update your privacy notice. Say that you record who referred a new customer and use that only to apply the reward, and ask your solicitor if you are unsure about wording.
A note on that last step, because it is where people overstate things. Moving to a "friend contacts you" model removes the unsolicited-marketing problem. It does not remove every data protection obligation. You are still recording a link between two people, and GDPR transparency still applies to that. The burden drops a lot. It does not drop to zero.
Two more cautions. First, do not tell the referrer what their friend bought or spent. "Thanks, your friend booked" is fine; "your friend spent €240 on a full groom and a nail trim" is a privacy complaint waiting to happen. Second, keep referral rewards completely separate from reviews. Paying people for referrals is one thing; rewarding them for leaving a review is a different legal question entirely, and the two should never share a promotion.
Where This Approach Falls Short
In fairness, the lawful version has a real cost, and it is attribution.
When your website sends the email, you know exactly who referred whom. When the friend contacts you, you are relying on them to remember and type a name. Some will not bother. Some will spell it three different ways. Some will say "a woman at the dog park". You will under-count your referrals, and a few loyal customers will quietly miss rewards they earned.
There are partial fixes. Personal codes help, since a short code printed on a card is harder to garble than a surname. Asking the question again at the first appointment catches a few more. But none of them gives you the perfect tracking the email form promised. That is the trade you are making: slightly messier data in exchange for a scheme you never have to defend to a regulator. I think it is an easy trade.
And one honest concession on tools. If you run a large subscription or e-commerce business with thousands of customers, a dedicated referral platform with fraud checks and automated code issuing can genuinely earn its fee, provided it is configured so that customers share codes themselves rather than handing over friends' addresses. For a groomer, a café, or a three-person accountancy practice, a form field and a well-written page do the job at no extra cost.
Why Your Website Carries the Scheme
The part people miss about referrals is simple. The friend who hears about you rarely picks up the phone first. They search your name. We made the wider case for that in why word of mouth alone will not grow a business, and it applies doubly here: the referral page and the booking form are where a recommendation turns into a customer, or quietly dies.
A proper referral setup needs very little from your site, but it needs it to be solid. It needs full WordPress, so you can add an optional form field or a simple coupon plugin without asking a platform for permission. It needs a staging environment, so you can test the new booking form before you deploy it to production and discover mid-promotion that it is silently dropping enquiries. And it needs analytics you can read without a cookie banner getting in the way, so you can see whether anyone is actually visiting the referral page.
That is the kind of setup Web60 is built around. Full WordPress on Irish infrastructure, one-click staging, nightly backups, and privacy-first analytics that need no consent banner for the tracking itself, all inside Web60's €60-a-year all-inclusive plan. If a referral push is on your list before Christmas, the site to carry it can be built by describing your business to our AI builder, in about a minute.
Referral promotions also sit next to other marketing rules worth knowing. If you are tempted to bolt a prize draw onto it ("refer a friend and be entered to win a hamper"), read our note on the rules for running a giveaway in Ireland first, because that changes the promotion's legal footing again.
The Upshot
Referrals are still the best leads you will ever get, and nothing in Irish law stops you rewarding them. What the law objects to is your website messaging people who never asked to hear from you. Take the friend's email box off the form, put a "Who recommended us?" field in its place, and write one clear page about the reward. Then let your happiest customers do what they were always going to do, in their own words, at their own pace. The next person who books because of them will have come to you by choice.
Frequently Asked Questions
Is a refer-a-friend scheme legal in Ireland?
Yes, the reward itself is fine. What causes the problem is collecting a friend's email address or mobile number and then sending them marketing. The Data Protection Commission says it is difficult to see how a refer-a-friend facility that does this could meet the consent requirement in the ePrivacy Regulations. Schemes where the friend contacts you, and names the person who referred them, avoid that problem.
Can I email a friend my customer recommended if I only send one message?
One message is still an unsolicited marketing message. Under Regulation 13 of S.I. 336/2011, each unsolicited communication is a separate offence, and the business has to prove the recipient consented. Your customer cannot consent on their friend's behalf, so a single email does not change the position.
Does the existing customer exception cover referred friends?
No. The soft opt-in in Regulation 13(11) only covers people who bought from you, where you collected their details during that sale, you are marketing similar products, and you gave them a chance to opt out. A referred friend has not bought anything from you, so the exception cannot apply to them.
Can my customers share a referral code on WhatsApp or social media?
Customers sharing a code in their own words, on their own initiative, is generally fine. The grey area is when the business actively pushes pre-written messages for customers to forward. The UK regulator treats that as the business instigating the messages even without a reward. The safest approach is to show the code and explain the offer, and leave how they share it up to them.
What should a referral page on my website include?
State the reward for both people, who qualifies (for example, new customers only), when the reward is applied, any expiry date, and how the referrer is identified, such as naming them on the booking form. Keep it short and plain so there is no dispute later about what was promised.
Do I need to mention the referral scheme in my privacy notice?
It is good practice. You are recording that one customer referred another and using that to apply a reward, which is processing of personal data. A sentence in your privacy notice explaining this keeps you transparent. If you are unsure of the wording, check with your solicitor.
Sources
Eamon leads sales at Web60 and SmartHost, working directly with Irish business owners making the switch from cheap shared hosting to managed WordPress. With a background in enterprise technology sales — including Oracle and multiple Irish SaaS businesses — he understands the questions Irish SMEs ask before committing to a hosting platform. He writes about hosting comparisons, total cost of ownership, web design for Irish businesses, and how to evaluate what you’re actually buying.
More by Eamon Rheinisch →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
Take Your Own Website Photos Before the Clocks Go Back
Take your own website photos with your phone: the shot list, light and framing tips, and why to do it before the clocks go back on 25 October.
"Sold as Seen" Is Not a Defence. What Irish Law Asks of a Second-Hand Product Page
"Sold as seen" has no legal effect on an Irish consumer's rights. What the Consumer Rights Act 2022 actually asks of a second-hand product page.
