Rules and ethics

How UK GDPR and ICO rules shape retail media audience data

UK GDPR retail media rules shape targeting, consent and data sharing. Here is how the ICO, PECR and the Data (Use and Access) Act 2025 apply.

What to take away

  • UK GDPR retail media audience data is governed by the UK GDPR and the Data Protection Act 2018, with the ICO as regulator.
  • Retailers need a lawful basis for loyalty and audience data; consent is common but not the only option.
  • PECR and ICO cookie guidance require consent for most retail media tracking and storage.
  • Data sharing between retailers, media owners and ad tech needs written agreements and due diligence.
  • Shoppers can make subject access requests; teams must respond within one month.
  • The Data (Use and Access) Act 2025 updates parts of the UK data regime, including ICO structure and research uses.

What UK GDPR and the Data Protection Act 2018 cover in retail media

Retail media runs on audience data: loyalty card records, transaction histories, browsing events and location signals. In the UK, that data is personal data when it can identify a person, directly or indirectly.

The UK GDPR sets the principles and the Data Protection Act 2018 provides the statutory basis, including the ICO's powers and the exemptions for journalism, research and crime.

The ICO publishes UK GDPR guidance and resources that retail media teams should treat as the starting point for any targeting plan.

The seven principles in a retail media context

Lawfulness, fairness and transparency: the shopper should not be surprised that their till data is used to sell ad space. Purpose limitation: data collected for a loyalty scheme cannot be reused for unrelated advertising without a lawful basis. Data minimisation: segments should be built from the fields needed, not the whole customer record.

Accuracy: targeting that depends on outdated purchase history can breach the accuracy principle.

Storage limitation: retention schedules should match the purpose, not the length of the contract. Integrity and confidentiality: access controls on the retailer's data clean room matter. Accountability: document decisions.

Special category data and retail media

Loyalty data can reveal health conditions through pharmacy purchases, or religious observance through food choices. That can create special category data, which needs an additional condition under Article 9. Most retail media teams avoid building segments that infer health or religion. If a campaign does, the lawful basis and the Article 9 condition must both be documented.

The ICO has fined organisations for inferring special category data without a condition. Treat any inferred health segment as high risk.

Children's data in retail media

Retail media audiences can include under-18s, especially in gaming, confectionery and back-to-school campaigns. The ICO's children's code applies to information society services likely to be accessed by children. Retailers and media owners should check whether their audience products fall within scope.

If they do, the best interests of the child become a primary consideration, and profiling for advertising needs extra care. Age assurance and separate consent flows are common controls.

The role of the IAB UK and industry standards

The IAB UK publishes guidance and standards for digital advertising, including transparency and consent frameworks. These are not law, but the ICO expects organisations to follow sector standards as evidence of accountability. The Advertising Standards Authority also covers ad content and targeting in some areas.

Aligning with IAB UK definitions helps when a campaign is reviewed by a client's data protection officer.

For a wider map of shopper data flows, start with the controller and processor roles before you design segments.

Lawful basis choices for retailer loyalty and audience data

Every processing activity needs a lawful basis under Article 6. The ICO's lawful basis guidance sets out six options and explains that the choice affects shopper rights.

Consent is the most familiar for retail media, but it is not always the best fit. Contract can cover the core loyalty scheme, but not ad targeting beyond it.

Legitimate interests can work for fraud prevention or network security, but it is harder to rely on for advertising that uses loyalty data. Legal obligation and vital interests rarely apply to retail media. Public task is limited to public bodies.

Consent as a lawful basis for loyalty data

Consent has to be given freely, be specific, informed and unambiguous. A single tick box at loyalty sign-up that covers all marketing is unlikely to meet the standard. The ICO expects separate choices for different purposes, such as email marketing, postal marketing and online ad targeting.

Withdrawal must be as easy as giving consent. If the retailer offers a discount in exchange for consent, the consent may not be freely given unless the discount is genuinely optional.

For retail media, consent is often the cleanest basis for cross-site tracking, but it requires ongoing preference management.

Legitimate interests for retail media

Legitimate interests can support some retail media activities, such as measuring campaign performance or preventing ad fraud. The three-part test requires a legitimate interest, necessity and a balancing exercise. The ICO expects a legitimate interests assessment (LIA) to be documented.

Shoppers have the right to object to processing based on legitimate interests, and the retailer must stop unless it can show compelling grounds. For advertising that uses loyalty data, the balance often tips towards consent because the shopper would not expect it.

Contract and legal obligation

Contract can cover processing needed to run the loyalty scheme, such as issuing points and statements. It does not cover selling ad space. Legal obligation can cover tax and accounting records, and sometimes subject access request handling.

Neither basis is a good fit for building advertising audiences. Teams should map each processing purpose to one basis and avoid switching basis later without a valid reason.

Documenting the lawful basis

The accountability principle requires a record of processing activities (ROPA). For each retail media audience product, record the purpose, the data categories, the lawful basis, the recipients and the retention period. The ICO does not require a specific template, but it does expect the record to be accurate and up to date.

A ROPA that lists "marketing" as a single purpose will not survive scrutiny. Break it down by channel and by data source.

The controller, processor split should also be recorded, because it affects who answers a shopper's request.

Consent, cookies and storage under PECR and ICO guidance

PECR sits alongside the UK GDPR and covers cookies, similar technologies and electronic marketing.

The ICO's Guide to Privacy and Electronic Communications Regulations | ICO explains that storing information on a user's device, or accessing information stored there, requires clear and comprehensive consent, unless an exemption applies. For retail media, that means most tracking pixels, tags and device identifiers need consent before they fire.

The exemption for strictly necessary cookies is narrow: it covers things like basket functionality and security, not advertising.

What counts as consent under PECR

Consent for cookies must meet the UK GDPR standard: freely given, specific, informed and unambiguous. Implied consent, such as continuing to browse, is not enough. Pre-ticked boxes are not valid. The user must take a positive action.

The ICO expects consent mechanisms to be granular, so a shopper can accept analytics but reject advertising cookies. Withdrawal must be easy, and the choice must be remembered. Consent records should include what was shown, what was chosen, and when.

Cookie banners and retail media tags

A retail media campaign often involves tags from the retailer, the media owner and third-party ad tech. Each non-essential tag needs a consent signal before it loads.

Consent management platforms (CMPs) are common, but the ICO has warned that some CMPs design choices in a way that nudges users. The banner should not use dark patterns, such as a prominent "accept all" and a hidden "reject all".

The ICO's cookie guidance expects equal prominence for accept and reject options. Retail media teams should test the banner on mobile, where most retail traffic sits.

Storage and access beyond cookies

PECR applies to any storage or access on a user's device, not just cookies. That includes local storage, device fingerprinting, pixels and SDKs in apps. If a retail media product uses a mobile app, the same consent rules apply.

Server-side tagging can reduce the number of client-side tags, but it does not remove the need for consent if personal data is processed. The ICO has taken action against organisations that used fingerprinting without consent.

The consent or pay model

The ICO has looked at consent or pay models, where users pay a fee to avoid personalised advertising. The UK position is that consent must be freely given, and a fee can be acceptable if the alternative is genuine and the fee is not excessive.

Retail media teams should not assume that a paywall automatically makes consent valid. Document the assessment and offer a genuine choice. The ICO's guidance on consent under PECR remains the reference point.

Data sharing between retailers, media owners and ad tech

Retail media usually involves sharing audience data between a retailer and a media owner, or between a retailer and an ad tech platform. The ICO's Data sharing | ICO guidance sets out the key steps: identify the lawful basis, decide the roles, have a written agreement, and be transparent with shoppers.

A data sharing agreement should cover purpose, data categories, security, retention and the process for handling requests.

Controller and processor roles

In a retail media partnership, the retailer is often the controller of loyalty data. The media owner may be a controller for its own advertising purposes, or a processor acting on the retailer's instructions. The ad tech platform may be a joint controller or a processor, depending on how it uses the data.

The roles determine who is responsible for what, and they should be documented before any data moves. The ICO expects a clear allocation of responsibilities, especially for transparency and rights.

Data clean rooms and privacy enhancing technologies

Data clean rooms allow two parties to match audiences without sharing raw personal data. They can reduce risk, but they do not remove it. If the output still identifies individuals, the UK GDPR applies.

The ICO has not published a clean room code, but its data sharing guidance applies. Teams should test whether the output is truly aggregated and whether re-identification is possible. Contracts should prohibit attempts to re-identify individuals.

Transparency and privacy notices

Shoppers should be told who will receive their data and why. The privacy notice should name the categories of recipients, such as media owners and ad tech providers. It should also explain the right to object and how to withdraw consent.

A generic notice that says "we may share data with partners" is not enough. The ICO has taken action against organisations for unclear privacy information. Retail media teams should review notices at least annually, and whenever a new partner is added.

Due diligence on ad tech partners

Before onboarding a new ad tech partner, check its data protection documentation. Ask for its role, its sub-processors, its retention periods and its security measures. Check whether it transfers data outside the UK and on what basis.

The ICO's data sharing guidance recommends a risk assessment. A short due diligence checklist is better than none. If the partner cannot answer basic questions, do not share personal data with it.

Subject access requests and shopper rights over retail media data

Shoppers have rights under the UK GDPR, including access, rectification, erasure, restriction, objection and portability. A subject access request (SAR) is the most common.

The ICO expects organisations to respond within one month, with a possible extension of two further months for complex requests. The response should confirm whether personal data is processed, and provide a copy of that data plus other information, such as purposes and recipients.

Retail media teams should know how to locate data held in ad tech platforms.

What a retail media SAR looks like

A shopper may ask what data a retailer holds about their loyalty account. They may also ask what segments they have been placed in, and who has received their data. The retailer must search all relevant systems, including the ad tech stack.

If data has been shared with a media owner, the retailer should tell the shopper about that recipient. The ICO's guidance on the right of access explains the process. Teams should log SARs and track deadlines.

Exemptions and limits

The UK GDPR and the Data Protection Act 2018 include exemptions, for example where access would prejudice crime prevention or where data relates to confidential references. These are narrow. A retail media team cannot refuse a SAR simply because the data is commercial.

If a request is manifestly unfounded or excessive, the organisation can charge a reasonable fee or refuse, but it must justify the decision. The ICO expects a case-by-case assessment.

Handling SARs across partners

If a retailer and a media owner are separate controllers, the shopper may need to make a request to each. If the media owner is a processor, the retailer is responsible for responding. The data sharing agreement should set out how requests are passed on and within what time.

A delay in the chain can cause a breach of the one-month deadline. Retail media teams should test the SAR process with a dry run before a campaign goes live.

Other shopper rights

The right to object is relevant to retail media that relies on legitimate interests. If a shopper objects, the retailer must stop processing unless it can show compelling grounds. The right to erasure can apply when consent is withdrawn.

The right to data portability is limited to data provided by the shopper and processed by consent or contract. Teams should map these rights to the systems that hold the data.

For a wider view of retail media law and commencement dates, check the primary sources.

International transfers and the Data (Use and Access) Act 2025

Retail media often involves ad tech providers based outside the UK, especially in the United States. International transfers need a lawful transfer mechanism, such as an adequacy regulation, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.

The ICO has published guidance on transfers, including the transfer risk assessment. The Data (Use and Access) Act 2025 makes changes to the UK data regime, including the ICO's structure and some research and law enforcement provisions.

The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 is the new UK data law. It reforms parts of the UK GDPR and the Data Protection Act 2018. It changes the ICO's governance, with a new structure including a board and chief executive.

It also updates rules on automated decision-making, research purposes and data sharing for public services. Retail media teams should check commencement dates, because not all provisions start at once. The Act does not remove the need for a lawful basis or for PECR consent.

What the Act means for retail media

The Act introduces a clearer framework for some legitimate interests processing, but it does not create a free pass for advertising. It also changes the rules on subject access requests in limited ways. Retail media teams should review their ROPA and their privacy notices against the new law.

The ICO will publish updated guidance as provisions commence. The Act also supports the ICO's new structure, which may affect how complaints and audits are handled.

International transfer mechanisms

For transfers to the US, the UK Extension to the EU-US Data Privacy Framework can provide a lawful basis if the recipient is certified. Otherwise, use the IDTA or the UK Addendum. A transfer risk assessment is required for most transfers.

The ICO expects organisations to consider the laws of the destination country and the sensitivity of the data. Retail media audience data can be sensitive when it reveals health or other special category data. Document the assessment and review it when the destination or the data changes.

Adequacy and future changes

The UK has adequacy regulations for the EEA, and the EU has adequacy for the UK. These can change. Retail media teams should monitor ICO announcements and the Department for Science, Innovation and Technology. If adequacy is withdrawn, alternative mechanisms are needed.

Contracts should include a change clause that allows the parties to update transfer terms. A yearly review of transfers is a sensible control.

ICO enforcement documents a retail media team should read first

The ICO publishes enforcement notices, fines, reprimands and audits. Reading them is the fastest way to understand the regulator's expectations.

Retail media teams should start with the ICO's Data Protection Act 2018 statutory basis, then read the enforcement actions that touch on advertising, cookies and data sharing.

The ICO's action against organisations for cookie non-compliance is directly relevant. So are decisions on lawful basis and transparency.

Enforcement themes in retail media

The ICO has repeatedly focused on consent for cookies, transparency in privacy notices, and the use of legitimate interests for advertising. It has also acted on data sharing without a lawful basis. Retail media teams should read the ICO's cookie enforcement outcomes and its guidance on consent.

The ICO's reprimands often set out practical steps, such as improving banner design or updating notices. These are useful templates for internal reviews.

A pre-campaign checklist

  • Confirm the lawful basis for each audience and each purpose.
  • Check that consent is collected before non-essential tags fire.
  • Review the privacy notice to name recipients and purposes.
  • Sign a data sharing agreement with each partner.
  • Complete a transfer risk assessment for any overseas ad tech.
  • Test the subject access request process end to end.
  • Record the ROPA entry and the legitimate interests assessment.

Worked example: a retailer and a media owner

A UK grocery retailer wants to sell sponsored product placements to a consumer goods brand. The retailer holds loyalty data. The media owner will run the campaign on the retailer's site.

The retailer is the controller for the loyalty data. The media owner is a processor for campaign delivery, but a controller for its own measurement. The parties sign a data sharing agreement. The retailer updates its privacy notice to name the media owner.

The media owner uses a data clean room to match audiences. The retailer checks that the clean room output is aggregated. The shopper can object, and the retailer has a process to stop using their data.

The campaign uses a consent management platform to collect cookie consent before tags fire. The retailer records the lawful basis as consent for targeting and legitimate interests for fraud prevention.

The media owner transfers data to a US ad tech provider under the UK Addendum, with a transfer risk assessment. The retailer tests a subject access request and confirms it can retrieve the shopper's segment data within one month.

Common questions

What is the lawful basis for retail media targeting? Consent is the most common basis for online targeting because it gives shoppers control. Legitimate interests can work for some activities, such as fraud prevention, but it is harder to justify for advertising that uses loyalty data.

Do retail media cookies need consent under PECR? Yes, most cookies and similar technologies need consent before they store or access information on a shopper's device. The strictly necessary exemption is narrow and does not cover advertising.

Can a retailer share loyalty data with a media owner? Yes, but only with a lawful basis, a written data sharing agreement and clear privacy information. The roles of each party must be documented, and shoppers must be told who receives their data.

How long does a retail media team have to answer a subject access request? One month from receipt, with a possible extension of two further months for complex requests. The response must cover data held across the ad tech stack, not just the loyalty system.

What changes with the Data (Use and Access) Act 2025? The Act reforms parts of the UK GDPR and the Data Protection Act 2018, changes the ICO's structure and updates rules on research and automated decision-making. It does not remove the need for a lawful basis or PECR consent.

Where should a retail media team start with ICO guidance? Start with the ICO's UK GDPR guidance and resources, then read the PECR guide, the data sharing guidance and recent enforcement actions. The ICO's cookie enforcement outcomes are a practical benchmark.

More in Rules and ethics

Rules and ethics

In-store retail media screens and UK planning rules for digital signage

In-store retail media screens UK planning rules: how the 2007 advertisement regulations, local council consent, ASA CAP Code and ICO CCTV guidance apply.

Rules and ethics

Scottish and Welsh retail media, devolved rules and bilingual campaigns

Scottish Welsh retail media devolved regulation shapes planning, language, signage and equality duties for campaigns across Scotland and Wales.