Shopper Ads

Rules and ethics

Part of The five kinds of authority a retail media launch must satisfy before release

Mapping shopper data through retail media, from device consent to controller roles

Retail media data protection explained through shopper-data maps, device consent, controller roles, risk assessment and current UK regulator source checks.

Retail media data protection starts with what happens to shopper information between collection and the advertising report. Map those operations before selecting a lawful basis or accepting a supplier agreement. This guide addresses retailer and marketplace advertising data, using UK requirements relevant to an England operation.

Sources were examined on 6 September 2026. The workflow is general information rather than legal advice, and it offers no assurance that a particular audience or technology is compliant. A qualified UK privacy specialist must review the actual design and the current amended law.

Describe each use of shopper information

Separate purchase-record collection from audience construction, matching, advert selection and campaign measurement. For each operation, name the input, recipient, purpose and retention decision. Avoid one combined description such as improving shopping where the real activity is choosing paid product adverts.

The ICO's data protection principles guide explains purpose limitation and data minimisation under Article 5. Use those principles to question whether the proposed fields are necessary and whether the intended advertising use fits the stated collection purpose.

Ask the reviewer to assess lawful basis for each personal-data purpose. If the supplier describes a match key as anonymous, require evidence for that description. A technical label should not decide the legal assessment, and this guide has not examined a dataset or anonymisation method.

Inspect device activity independently

The ICO advertising guidance says consent is required for advertising storage and access technologies. Advertising measurement can fall within the advertising consent without a separate consent request when intrinsically linked; unrelated later purposes need separate consideration under that guidance.

Document the technologies involved, what the shopper is told and how the preference reaches the relevant recipient. Inspect refusal and withdrawal paths as proposed validation work. Do not record them as successful tests until a competent person has actually performed and documented them.

Contextual selection should still have a technical inventory. The question is whether storage or access occurs for advertising, not merely whether the sales team calls the placement contextual. Account-based and server-side operations also need to appear in the wider personal-data map.

Determine who controls the operation

Under the ICO's data-sharing explanation, joint controllers need an Article 26 arrangement explaining agreed responsibilities. Ask who decides why the audience is built and how it is used; do not settle the role from an invoice description.

For a processor, UK GDPR Article 28 requires contractual processing details and instructions. Check that these describe the actual advertising service. Flag independent supplier reuse for review instead of hiding it in an unrestricted improvement clause.

Assess risk and objections

The ICO DPIA guidance requires an assessment where processing is likely to pose high risk to individuals. Record the screening reasoning for audience matching and profiling, including the information used and the people affected. A completed supplier questionnaire alone is not that reasoning.

For direct marketing, the right to object also covers related profiling. Design the request route so an objection reaches the audience operation, rather than only the retailer's email system. Preserve enough operational evidence to establish what action was taken.

Prepare a reviewable data record

Attach the data map, proposed notices, role assessment, risk screening and retention schedule. Mark international access, sensitive inferences or uncertain anonymisation for specialist attention rather than assuming they are permitted. These are review prompts, not findings about an existing retailer.

Some ICO sources carry DUAA update notices. Recheck them against the amended UK framework and relevant commencement before launch. The next step is a documented privacy decision for the named operation, with unresolved questions retained and no shopper-level transfer authorised merely by completion of this guide.

More in Rules and ethics

Rules and ethics

The five kinds of authority a retail media launch must satisfy before release

Retail media rules for UK planning: distinguish advertising codes, consumer law, shopper-data duties and contract controls before a reviewed 2027 launch.

Rules and ethics

Is the sponsored placement recognisable as an advert? Checks before a retail media booking

Retail media advertising checks for England cover paid placement labels, product claims, restricted categories and the evidence needed for specialist review.

Rules and ethics

The contract workstreams behind a retail media deal, from claims to consent handover

Retail media commercial contract workstreams for England, with a non-ranked inclusion method, authoritative evidence and limits for specialist negotiation.

Rules and ethics

A retail media disclosure policy that is reviewed on the rendered placement, not the spec

Retail media disclosure policy steps for England cover paid formats, advertising labels, legal distinctions, ownership and review of the rendered placement.