QR Code Memorial Privacy and Security
QR code memorials are a beautiful way to link a physical grave to a rich online tribute — but a natural first question is: is it private and secure? Scanning a code in a public cemetery raises fair concerns about who can see the memorial and what happens to the family's data. This guide answers those questions clearly.
Can anyone who scans the code see everything?
Only if you choose to make it public. A well-designed platform puts you in control of visibility:
- Public — anyone who scans or finds the link can view the memorial. Good for well-known figures or when the family wants openness.
- Unlisted — only people with the link (or who scan the plaque) can view it; it won't appear in search.
- Private — restricted to invited family, sometimes behind a request-to-access step.
Who can add photos or messages?
Contribution controls are separate from visibility. Even on a public memorial, you can decide:
- Whether visitors may post guestbook messages at all.
- Whether new photos or memories require your approval before appearing.
- Whether only invited family can contribute.
Is my family's data protected?
This is where the choice of provider matters most. Look for:
- GDPR compliance — the platform must handle personal data lawfully and give you rights over it.
- EU-based hosting — where the data physically sits matters. Vidalem, for example, stores data on EU-based servers, which keeps it within the GDPR framework rather than on servers in other jurisdictions.
- Secure connections — the memorial should load over HTTPS so data in transit is encrypted.
- Clear data ownership — you should be able to export or remove content.
Does the QR code itself pose a risk?
The QR code is just a link — it doesn't store personal data. It simply points to the memorial's web address. The security of the memorial depends on the privacy settings and the platform, not the code. The one practical safeguard: use a provider that keeps the link fixed and controlled, so the code can never be redirected somewhere unintended.
Sensitive information: what to leave off
A memorial is public-facing by nature, so it's wise to avoid publishing:
- Exact home addresses of surviving family.
- Full dates that could aid identity fraud where relatives share a name.
- Anything the family would prefer to keep among close relations — those details can live in a private memorial instead.
Best practices for a private, secure memorial
Step 1: Set the right visibility
Choose public, unlisted, or private to match your family's wishes.
Step 2: Control contributions
Turn on approval for new photos and messages if you want to review them.
Step 3: Check where data is hosted
Prefer an EU-hosted, GDPR-compliant platform.
Step 4: Curate what you publish
Keep sensitive personal details off the public page.
Peace of mind
A QR code memorial can be as open or as private as your family wants, and — with the right provider — your data stays protected under GDPR on EU-based servers. That combination is what makes a scannable memorial both meaningful and safe. Vidalem is built around exactly these controls, so you can share memories with confidence.



