Rules and ethics
Part of The five kinds of authority a retail media launch must satisfy before release
Mapping shopper data through retail media, from device consent to controller roles
Retail media data protection explained through shopper-data maps, device consent, controller roles, risk assessment and current UK regulator source checks.
Retail media data protection starts with what happens to shopper information between collection and the advertising report. Map those operations before selecting a lawful basis or accepting a supplier agreement. This guide addresses retailer and marketplace advertising data, using UK requirements relevant to an England operation.
Sources were examined on 6 September 2026. The workflow is general information rather than legal advice, and it offers no assurance that a particular audience or technology is compliant. A qualified UK privacy specialist must review the actual design and the current amended law.
Describe each use of shopper information
Separate purchase-record collection from audience construction, matching, advert selection and campaign measurement. For each operation, name the input, recipient, purpose and retention decision. Avoid one combined description such as improving shopping where the real activity is choosing paid product adverts.
The ICO's data protection principles guide explains purpose limitation and data minimisation under Article 5. Use those principles to question whether the proposed fields are necessary and whether the intended advertising use fits the stated collection purpose.
Ask the reviewer to assess lawful basis for each personal-data purpose. If the supplier describes a match key as anonymous, require evidence for that description. A technical label should not decide the legal assessment, and this guide has not examined a dataset or anonymisation method.
Inspect device activity independently
The ICO advertising guidance says consent is required for advertising storage and access technologies. Advertising measurement can fall within the advertising consent without a separate consent request when intrinsically linked; unrelated later purposes need separate consideration under that guidance.
Document the technologies involved, what the shopper is told and how the preference reaches the relevant recipient. Inspect refusal and withdrawal paths as proposed validation work. Do not record them as successful tests until a competent person has actually performed and documented them.
Contextual selection should still have a technical inventory. The question is whether storage or access occurs for advertising, not merely whether the sales team calls the placement contextual. Account-based and server-side operations also need to appear in the wider personal-data map.
Determine who controls the operation
Under the ICO's data-sharing explanation, joint controllers need an Article 26 arrangement explaining agreed responsibilities. Ask who decides why the audience is built and how it is used; do not settle the role from an invoice description.
For a processor, UK GDPR Article 28 requires contractual processing details and instructions. Check that these describe the actual advertising service. Flag independent supplier reuse for review instead of hiding it in an unrestricted improvement clause.
Assess risk and objections
The ICO DPIA guidance requires an assessment where processing is likely to pose high risk to individuals. Record the screening reasoning for audience matching and profiling, including the information used and the people affected. A completed supplier questionnaire alone is not that reasoning.
For direct marketing, the right to object also covers related profiling. Design the request route so an objection reaches the audience operation, rather than only the retailer's email system. Preserve enough operational evidence to establish what action was taken.
Prepare a reviewable data record
Attach the data map, proposed notices, role assessment, risk screening and retention schedule. Mark international access, sensitive inferences or uncertain anonymisation for specialist attention rather than assuming they are permitted. These are review prompts, not findings about an existing retailer.
Some ICO sources carry DUAA update notices. Recheck them against the amended UK framework and relevant commencement before launch. The next step is a documented privacy decision for the named operation, with unresolved questions retained and no shopper-level transfer authorised merely by completion of this guide.