Rules and ethics

ICO and UK GDPR duties for creator audience data in London

Influencer management agency data leads in London must follow UK GDPR, PECR and ICO rules on consent, subject access requests, cookies and children's data.

What to take away

  • An influencer management agency in London holds creator and audience data, so it must register with the ICO and pay the annual data protection fee.
  • UK GDPR requires a lawful basis for every processing activity, and consent records must show what was agreed, when and how.
  • Subject access requests from creators or audience members need a logged, repeatable process with a one month deadline.
  • PECR cookies and tracking rules sit alongside UK GDPR, and London campaigns aimed at children face stricter ICO expectations.
  • The ICO's enforcement action page shows the penalties for weak consent records and ignored subject access requests.

What counts as personal data in a London creator agency

London has the UK's largest cluster of influencer management agencies, talent agencies and brand-side creator teams. That density means more data flows, more sharing and more regulatory attention. The starting point is to know what you hold.

Creator data covers names, contact details, bank details, contracts, rates, audience insights and private messages. Audience data covers email lists, commenter handles, direct message threads, competition entries and analytics identifiers. Both are personal data when they can identify a living person.

The Data Protection Act 2018 sits alongside UK GDPR as the primary legal source for handling creator audience data, so London agencies should treat it as the base text for policies and training.

Some data is special category: health details in a creator's content, political views, sexual orientation or ethnicity. You need an additional condition to process it. Most agencies will not have one for routine campaign work.

Pseudonymous data still counts. A hashed email or platform ID linked to a campaign is personal data if you or a partner can re-identify the person. Do not treat it as anonymous.

Check how data protection duties apply to your roster before you map data flows. That review should cover creator contracts, audience lists and any research panels you run.

Lawful bases and consent records under UK GDPR

Every processing activity needs a lawful basis. The six options are consent, contract, legal obligation, vital interests, public task and legitimate interests. Pick one before you collect, not after.

For newsletter lists and remarketing, consent is usually the safest basis. For paying a creator under a management contract, contract is the natural basis. For fraud checks, legitimate interests may fit, but you must document the balancing test.

The ICO's UK GDPR guidance and resources set out how to choose and record a lawful basis for marketing and talent management. Use it as your reference when drafting privacy notices.

Consent records must show who consented, what they were told, when, and how they gave it. A screenshot of a checkbox is not enough. Keep the exact wording, the source and the timestamp.

Consent needs to be given freely, be specific, informed and clear. Pre-ticked boxes, silence and bundled terms do not count. Withdrawing consent must be as easy as giving it.

A simple consent record for a London agency looks like this:

Field Example
Subject ID creator_1042
Purpose weekly campaign newsletter
Notice version v3.2
Source website signup form
Timestamp 2026-09-01 10:14 BST
Withdrawal none

Review consent records every quarter. If a purpose changes, refresh the consent. If a creator leaves your roster, decide whether you still need their data and delete what you do not.

When you run audience research in England, keep the lawful basis and consent evidence attached to each dataset. That habit saves time during an ICO query or a subject access request.

Handling subject access requests from creators and audiences

A subject access request is a request from a person for a copy of their personal data. It can come by email, letter, social media message or verbally. You cannot charge a fee in most cases.

You must respond within one month. That period can be extended by two further months for complex requests, but you must tell the person why. Do not ignore a request because it arrives in an unusual channel.

Follow these steps:

  1. Log the request on the day it arrives, with the date, channel and requester details.
  2. Verify identity using proportionate checks, but do not ask for more than you need.
  3. Search all systems, including email, CRM, spreadsheets, messaging apps and backups.
  4. Redact third-party data and any exempt material before sending.
  5. Send the response in a common format and keep a copy of what you sent.

Creators often ask for their contract, rate history and messages with brand partners. Audience members usually ask for email records, comments and competition entries. Both are valid requests.

If you refuse or partly refuse, explain the exemption you rely on and tell the person they can complain to the ICO. The ICO's Enforcement action | ICO page shows what happens when agencies mishandle requests or delay responses.

Train account managers to forward any request to the data lead within one working day. Most breaches come from a request sitting in a personal inbox.

ICO registration and the data protection fee for London agencies

Most London agencies that process personal data must register with the ICO and pay the annual data protection fee. Registration is a legal duty, not a badge of honour.

The fee depends on your size and turnover. Tier 1 covers smaller organisations, Tier 2 covers larger ones, and Tier 3 applies to the largest. Check the current ICO fee table before you pay, because the tiers and amounts are updated.

Registration details must be kept current. If your address, contact or processing purposes change, update the entry. A stale entry can lead to a fine.

Some processing is exempt, but the exemption is narrow. It does not cover routine marketing, audience lists or creator management. Assume you must register unless you have taken advice.

Put the fee renewal in the same calendar as your insurance and accounts. A missed renewal is an easy enforcement target.

Use the registration process to test your internal records. If you cannot describe your processing purposes clearly on the form, your records are not good enough.

Cookies, tracking and PECR duties in creator campaigns

PECR sits alongside UK GDPR and covers cookies, tracking pixels, email marketing and some phone marketing. The ICO's Guide to Privacy and Electronic Communications Regulations | ICO explains the rules for email, cookies and tracking in creator marketing.

The rules for cookies and similar technologies are strict. You need clear consent before setting non-essential cookies or pixels on a UK user's device. Analytics, advertising and social plugins usually need consent.

Consent must be specific and informed. A banner that only says "we use cookies" is not enough. Users must be able to accept or reject each category, and rejecting must be as easy as accepting.

Email marketing to individuals needs consent, unless you can rely on the soft opt-in. The soft opt-in applies where you obtained the details in a sale or negotiation and you offer an opt-out in every message. It does not cover bought lists.

Tracking pixels on creator content can collect data about audience members who never interacted with your agency directly. If you place those pixels, you are responsible for the consent and the notice.

Use a checklist before any London campaign goes live:

  • Consent banner tested on mobile and desktop.
  • Cookie categories listed with purposes and durations.
  • Reject option as visible as accept.
  • Pixel and tag audit completed.
  • Email consent records checked for the audience list.
  • Privacy notice links to the campaign landing page.
  • Children's audience screening completed.

If you buy audience data from a third party, check their consent records. The ICO expects you to do due diligence, and blame does not transfer with the list. Survey tools for UK audience data can help, but they do not remove your legal duty.

Children's data and vulnerable audiences in London briefs

Many London creator campaigns reach under-18s, even when the brief says otherwise. Toy launches, gaming, fashion, music and school-related content all attract younger audiences.

UK GDPR treats children's data as requiring special protection. The ICO's Children's information | ICO guidance sets out the expectations for creator content aimed at younger audiences.

Consent for children is harder to rely on. If you process a child's data for marketing, you generally need consent from a person with parental responsibility, and you must make reasonable efforts to verify that person.

Age assurance matters. Do not assume a platform's age gate is enough. If your campaign targets a channel with a young audience, document how you screen for age and what you do when a child signs up.

Design choices matter. Default settings should be high privacy, and you should not use nudge techniques to encourage children to weaken their privacy. This applies to apps, landing pages and competitions.

London agencies should also watch vulnerable adult audiences. If a campaign targets people with a known vulnerability, such as a health condition, the lawful basis and consent records need extra care.

Escalate any campaign aimed at under-18s to your data lead before the brief is signed. That single step prevents most children's data problems.

Common questions

Do London creator agencies need to register with the ICO? Yes, most do. If you process personal data for marketing, creator management or audience lists, you must register and pay the annual data protection fee unless a narrow exemption applies.

How long do we have to answer a subject access request? One month from receipt. You can extend by two further months for complex requests, but you must tell the requester and explain why.

Can we rely on legitimate interests for audience marketing? Sometimes, but consent is safer for email and tracking. If you use legitimate interests, document the balancing test and offer a clear opt-out.

What consent do we need for cookies on a creator campaign page? Clear, specific consent before non-essential cookies or pixels load. Users must be able to reject as easily as accept, and analytics and advertising cookies normally need consent.

What if a campaign reaches children? Apply the ICO's children's information guidance. Screen for age, use high privacy defaults and get parental consent where you process a child's data for marketing.

Where can we check ICO enforcement decisions? The ICO's enforcement action page lists fines and reprimands. Use it to test your own consent records, subject access request handling and cookie banners.

More in Rules and ethics

Rules and ethics

How ASA and CMA rules shape influencer contracts for British agencies

Influencer management agency contracts in the UK must embed ASA CAP Code and CMA disclosure duties, with clear clauses, sanctions risk and Copy Advice.

Rules and ethics

Protecting a creator brand name in the UK through Companies House and IPO

Influencer management agency founders in the UK should register at Companies House and file a UK trade mark at the IPO to protect creator and agency names.

Rules and ethics

Ofcom and IPA rules for talent agencies working with broadcasters

Influencer management agency duties under the Ofcom broadcasting code and IPA standards, from commissioning workflows to product placement disclosure and complaints.