{"id":1235,"date":"2026-05-28T13:00:00","date_gmt":"2026-05-28T18:00:00","guid":{"rendered":"https:\/\/tolinku.com\/blog\/?p=1235"},"modified":"2026-03-07T03:35:05","modified_gmt":"2026-03-07T08:35:05","slug":"referral-program-compliance","status":"publish","type":"post","link":"https:\/\/tolinku.com\/blog\/referral-program-compliance\/","title":{"rendered":"Referral Program Compliance: Legal Considerations"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Referral programs pay people to recommend your product. That simple fact triggers a surprisingly broad set of legal requirements. In the US alone, referral incentives intersect with FTC endorsement guidelines, state sweepstakes laws, tax reporting rules, and privacy regulations. Internationally, you add GDPR, anti-spam laws, and country-specific promotional rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most teams launch referral programs without consulting legal, and most of the time nothing bad happens. But the consequences of non-compliance range from FTC warning letters to class-action lawsuits to regulatory fines. The cost of getting compliance right upfront is a fraction of the cost of fixing it after a regulator notices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide covers the major compliance areas for referral programs. This is engineering and operational guidance, not legal advice. Work with your legal team for your specific situation. For the general referral program framework, see <a href=\"https:\/\/tolinku.com\/blog\/building-referral-programs-that-work\/\">building referral programs that actually work<\/a>. For fintech-specific compliance, see the <a href=\"https:\/\/tolinku.com\/blog\/referral-program-fintech\/\">fintech referral program guide<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><img decoding=\"async\" src=\"https:\/\/tolinku.com\/blog\/wp-content\/uploads\/2026\/03\/screenshot-referrals-1772819416568.png\" alt=\"Tolinku referral program dashboard with analytics\">\n<em>The referrals page with stats cards, referral list, and leaderboard tabs.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FTC Endorsement Guidelines<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/federal-register-notices\/16-cfr-part-255-guides-concerning-use-endorsements-testimonials-advertising\" rel=\"nofollow noopener\" target=\"_blank\">FTC Endorsement Guides<\/a> require that material connections between endorsers and brands be disclosed. When a user shares a referral link and receives a reward for doing so, that&#39;s a material connection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What This Means in Practice<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When a user shares a referral link that earns them a reward, the share message should disclose the incentive. The FTC&#39;s standard is that the disclosure must be &quot;clear and conspicuous.&quot;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Compliant share message:<\/strong><\/p>\n\n\n\n<blockquote class=\"is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&quot;I use [Product] and love it. If you sign up with my link, we both get $10. [link]&quot;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Non-compliant share message:<\/strong><\/p>\n\n\n\n<blockquote class=\"is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&quot;Check out [Product]! [link]&quot;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second message doesn&#39;t disclose that the sharer receives a financial incentive for the recommendation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How to Implement<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><p><strong>Default share messages should include disclosure.<\/strong> When your app generates a pre-written share message, include language like &quot;we both get [reward]&quot; or &quot;referral link&quot; so the incentive is visible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Don&#39;t hide the incentive.<\/strong> If the share goes to a landing page, the landing page should also mention that the referrer earns a reward.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Social media shares need disclosure in the post itself.<\/strong> A disclosure buried in a link or on the landing page isn&#39;t sufficient for social media. The <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/com-disclosures-how-make-effective-disclosures-digital-advertising\" rel=\"nofollow noopener\" target=\"_blank\">FTC&#39;s .com Disclosures guide<\/a> provides specifics for digital advertising.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Enforcement<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The FTC has issued warning letters and fines for undisclosed paid endorsements. While most enforcement has targeted influencer marketing, the same rules apply to referral programs. The <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/cases-proceedings?search_api_fulltext=endorsement\" rel=\"nofollow noopener\" target=\"_blank\">FTC&#39;s Operation Full Disclosure<\/a> provides examples of enforcement actions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Privacy Laws<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">GDPR (EU\/EEA)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If your users include EU\/EEA residents, <a href=\"https:\/\/gdpr.eu\/\" rel=\"nofollow noopener\" target=\"_blank\">GDPR<\/a> applies to your referral program. Key requirements:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Consent for sharing.<\/strong> When a referrer shares a friend&#39;s contact information (email or phone number) through your referral system, you&#39;re processing that friend&#39;s personal data. You need a lawful basis for this processing, typically the referrer&#39;s legitimate interest, but you must also inform the referred person about the data processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Right to object.<\/strong> The referred person must be able to opt out of further communications. Your referral invitation email must include an unsubscribe mechanism.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data minimization.<\/strong> Only collect the minimum data needed for the referral. If you only need an email to send the invitation, don&#39;t also collect the phone number.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Right to erasure.<\/strong> If a referred person requests deletion of their data before signing up, you must comply. Delete the referral record and any personal data associated with it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CCPA (California)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\" rel=\"nofollow noopener\" target=\"_blank\">CCPA<\/a> gives California residents additional rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Right to know<\/strong>: Users can request what referral data you&#39;ve collected about them.<\/li>\n<li><strong>Right to delete<\/strong>: Users can request deletion of their referral data.<\/li>\n<li><strong>No discrimination<\/strong>: You can&#39;t exclude users from the referral program because they exercised their privacy rights.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">CAN-SPAM (US Email)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If your referral program sends emails (invitation emails, reward notifications), <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/can-spam-act-compliance-guide-business\" rel=\"nofollow noopener\" target=\"_blank\">CAN-SPAM<\/a> applies:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Emails must identify the sender clearly.<\/li>\n<li>The subject line must not be deceptive.<\/li>\n<li>Every email must include an unsubscribe mechanism.<\/li>\n<li>Unsubscribe requests must be honored within 10 business days.<\/li>\n<li>The email must include a physical postal address.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>&quot;Send to a friend&quot; features.<\/strong> If your app lets users send referral invitations via email through your servers, you (not the referrer) are the sender under CAN-SPAM. This means you&#39;re responsible for compliance, including unsubscribe handling.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CASL (Canada)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Canada&#39;s <a href=\"https:\/\/crtc.gc.ca\/eng\/internet\/anti.htm\" rel=\"nofollow noopener\" target=\"_blank\">Anti-Spam Legislation<\/a> is stricter than CAN-SPAM. You need consent before sending commercial electronic messages to Canadian recipients. The referrer&#39;s action of entering their friend&#39;s email constitutes &quot;implied consent&quot; in some interpretations, but the safest approach is to send a single invitation and not follow up unless the recipient consents.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sweepstakes and Contest Laws<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your referral program includes random elements (e.g., &quot;Refer a friend and get a random stock worth $5-$200&quot;), it may be classified as a <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/advertising-marketing-internet-rules-road\" rel=\"nofollow noopener\" target=\"_blank\">sweepstakes or contest<\/a> under state law.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Three Elements to Watch<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A promotion becomes a regulated sweepstakes when it has all three elements: prize, chance, and consideration. To avoid sweepstakes regulation:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Remove chance<\/strong>: Make rewards fixed, not random. &quot;$10 per referral&quot; is not a sweepstakes. &quot;A random stock worth $5-$200 per referral&quot; may be.<\/li>\n<li><strong>Remove consideration<\/strong>: If the referral requires significant effort (beyond just sharing a link), it might be considered &quot;consideration.&quot; Keep the required action minimal.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">State Registration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some US states (New York, Florida, Rhode Island) require sweepstakes to be registered before launch. If your referral program has a random element, check state-specific requirements or consult with a promotions lawyer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Tax Reporting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">US: 1099-MISC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the US, if a user earns more than $600 in referral rewards in a calendar year, you may need to issue a <a href=\"https:\/\/www.irs.gov\/forms-pubs\/about-form-1099-misc\" rel=\"nofollow noopener\" target=\"_blank\">1099-MISC<\/a> to that user and the IRS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Implementation steps:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Track cumulative referral rewards per user per calendar year.<\/li>\n<li>When a user approaches $600, notify them that tax reporting may apply.<\/li>\n<li>Collect a <a href=\"https:\/\/www.irs.gov\/forms-pubs\/about-form-w-9\" rel=\"nofollow noopener\" target=\"_blank\">W-9<\/a> (including SSN or EIN) from users before paying rewards above $600.<\/li>\n<li>Issue 1099-MISC forms by January 31 for the prior year.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If rewards are in-product credits<\/strong> (not cash), the IRS still considers them taxable income at fair market value. A $10 app credit has the same tax implications as $10 cash.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">International Tax<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Tax reporting requirements for referral rewards vary by country. In general:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Most countries tax referral rewards as income.<\/li>\n<li>You may have withholding obligations for international payees.<\/li>\n<li>Work with a tax advisor for cross-border reward programs.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Financial Regulations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For fintech apps, referral programs face additional regulations. See the <a href=\"https:\/\/tolinku.com\/blog\/referral-program-fintech\/\">fintech referral program guide<\/a> for details on:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>KYC requirements for reward recipients<\/li>\n<li>Anti-money laundering (AML) considerations<\/li>\n<li>State-specific rules for financial product promotions<\/li>\n<li>FINRA approval for investment-related referral promotions<\/li>\n<li><a href=\"https:\/\/www.ecfr.gov\/current\/title-12\/chapter-II\/subchapter-A\/part-230\" rel=\"nofollow noopener\" target=\"_blank\">Regulation DD<\/a> (Truth in Savings) if rewards could be classified as interest<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Terms and Conditions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every referral program needs published terms and conditions. Include:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Eligibility<\/strong>: Who can participate? (Age requirements, geographic restrictions, one account per person)<\/li>\n<li><strong>Reward details<\/strong>: What&#39;s the reward, when is it paid, and what&#39;s the qualifying action?<\/li>\n<li><strong>Limits<\/strong>: Maximum referrals per user, maximum reward per user per year.<\/li>\n<li><strong>Fraud clause<\/strong>: The right to revoke rewards and ban accounts for fraud. See the <a href=\"https:\/\/tolinku.com\/blog\/referral-fraud-prevention\/\">referral fraud prevention guide<\/a>.<\/li>\n<li><strong>Modification clause<\/strong>: The right to change or end the program at any time.<\/li>\n<li><strong>Tax responsibility<\/strong>: Statement that users are responsible for their own tax obligations.<\/li>\n<li><strong>Disclosure requirement<\/strong>: Reminder that referrers should disclose the incentive when sharing.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Make the terms accessible from the referral sharing screen and link to them in the referral invitation email.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Compliance Checklist<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use this checklist when launching or auditing your referral program:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>FTC Compliance<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Default share messages disclose the incentive<\/li>\n<li>Landing page mentions referrer&#39;s reward<\/li>\n<li>Terms and conditions are published and accessible<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Privacy<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Referral invitation emails include unsubscribe mechanism<\/li>\n<li>Privacy policy covers referral data collection and processing<\/li>\n<li>Deletion requests can be fulfilled for referral data<\/li>\n<li>Data minimization: only collecting necessary data<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Tax<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cumulative reward tracking per user per year<\/li>\n<li>W-9 collection process for users approaching $600 (US)<\/li>\n<li>1099-MISC issuance process for qualifying users<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Promotions Law<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>No unregistered sweepstakes elements (or state registrations filed)<\/li>\n<li>Clear rules for random\/variable rewards<\/li>\n<li>Terms include eligibility, limits, and modification rights<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Email<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CAN-SPAM compliance for invitation emails<\/li>\n<li>Physical address in email footer<\/li>\n<li>Unsubscribe mechanism in every email<\/li>\n<li>Unsubscribe requests honored within 10 days<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For setting up your referral program, see the <a href=\"https:\/\/tolinku.com\/docs\/user-guide\/referrals\/\">referral documentation<\/a>. For the complete framework, see <a href=\"https:\/\/tolinku.com\/blog\/building-referral-programs-that-work\/\">building referral programs that actually work<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Keep your referral program legally compliant. Navigate FTC guidelines, financial regulations, privacy laws, and tax requirements for referral marketing.<\/p>\n","protected":false},"author":2,"featured_media":1234,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"Referral Program Compliance: Legal Considerations","rank_math_description":"Keep your referral program legally compliant. Navigate FTC guidelines, financial regulations, and privacy laws for referral marketing.","rank_math_focus_keyword":"referral program compliance","rank_math_canonical_url":"","rank_math_facebook_title":"","rank_math_facebook_description":"","rank_math_facebook_image":"https:\/\/tolinku.com\/blog\/wp-content\/uploads\/2026\/03\/og-referral-program-compliance.png","rank_math_facebook_image_id":"","rank_math_twitter_title":"","rank_math_twitter_description":"","rank_math_twitter_image":"https:\/\/tolinku.com\/blog\/wp-content\/uploads\/2026\/03\/og-referral-program-compliance.png","footnotes":""},"categories":[13],"tags":[129,20,113,312,36,44,45],"class_list":["post-1235","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-growth","tag-compliance","tag-deep-linking","tag-growth","tag-legal","tag-privacy","tag-referral-programs","tag-referrals"],"_links":{"self":[{"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/posts\/1235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/comments?post=1235"}],"version-history":[{"count":3,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/posts\/1235\/revisions"}],"predecessor-version":[{"id":2279,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/posts\/1235\/revisions\/2279"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/media\/1234"}],"wp:attachment":[{"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/media?parent=1235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/categories?post=1235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tolinku.com\/blog\/wp-json\/wp\/v2\/tags?post=1235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}