EU, UK & DMA Paid Media Compliance Checklist 2025
EU, UK & DMA Paid Media Compliance Checklist 2025
Paid media compliance across UK GDPR, EU GDPR, and the Digital Markets Act (DMA) requires three parallel frameworks running simultaneously. Get one wrong and you're exposed to fines up to 4% of global annual turnover under EU GDPR, 4% under UK GDPR, or 10-20% under the DMA. This checklist breaks down every requirement by regulation, so your campaigns are clean before they go live.
What You'll Need Before Starting
Before working through the steps below, confirm you have the following in place:
- Legal entity clarity: Know whether you're targeting UK users, EU users, or both. Post-Brexit, these are separate regulatory environments with separate enforcement bodies (ICO for UK, lead supervisory authority for EU).
- Consent Management Platform (CMP): A compliant CMP (OneTrust, Cookiebot, Usercentrics, or equivalent) capable of granular consent capture by jurisdiction.
- Data Processing Agreements (DPAs): Signed DPAs with every ad platform you use: Meta, Google, LinkedIn, TikTok, and any DSP.
- Privacy policy: Reviewed by a qualified lawyer within the last 12 months, with separate sections for UK and EU data subjects if you serve both markets.
- Platform ad account settings audit: Access to privacy and data settings in each ad account.
Step 1: Map Your Data Flows by Jurisdiction
Before touching a single campaign setting, document where user data originates, where it's processed, and where it's stored. This is your compliance foundation.
For EU GDPR (Regulation 2016/679), personal data of EU residents must be processed under a lawful basis. For paid media, that almost always means consent (Article 6(1)(a)) or legitimate interest (Article 6(1)(f)), with consent required for tracking cookies and pixel-based retargeting. UK GDPR mirrors this structure but is enforced independently by the ICO under the UK's retained version of the regulation.
Practical step: Build a data flow map using a spreadsheet: column A lists the touchpoint (landing page, ad pixel, CRM sync), column B lists the data collected, column C lists the lawful basis, and column D identifies whether the user is EU or UK. Every row without a confirmed lawful basis is a live compliance gap.
Step 2: Configure Consent for Paid Media Tracking
Consent configuration is where most paid media teams fail. Pixels fire before consent is granted, retargeting audiences are built on unconsented data, and conversion signals are sent without a valid legal basis.
For EU users: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and soft opt-ins are invalid. Your CMP must block Meta Pixel, Google Tag, LinkedIn Insight Tag, and all other tracking scripts until the user explicitly accepts. Under the ePrivacy Directive (still the operative cookie law in the EU), this applies even when relying on legitimate interest for other data processing.
For UK users: The ICO's PECR (Privacy and Electronic Communications Regulations) governs cookie consent and mirrors ePrivacy requirements. Consent standards are functionally the same as EU requirements, but enforcement is separate.
| Requirement | EU GDPR + ePrivacy | UK GDPR + PECR | |---|---|---| | Consent for tracking pixels | Required before firing | Required before firing | | Legitimate interest for retargeting | Contested; ICO and EDPB advise consent | Contested; ICO advises consent | | Consent withdrawal mechanism | Must be as easy as granting | Must be as easy as granting | | Cookie banner pre-ticked boxes | Prohibited | Prohibited | | Data transfer to US ad platforms | SCCs or adequacy decision required | IDTA (UK equivalent) required |
Concrete example: A SaaS company running Meta Lead Ads into Germany and the UK must implement separate consent flows. The EU flow requires SCCs (Standard Contractual Clauses) to cover Meta's US data transfer. The UK flow requires an IDTA (International Data Transfer Agreement). One CMP configuration does not cover both.
Step 3: Audit Platform-Level Privacy Settings
Every ad platform has account-level settings that determine how your data is used. These are separate from your CMP and must be configured independently.
Meta: In Events Manager, enable Advanced Matching only for consented users. Set your data use limitations to exclude data from users who have not consented. Turn off Automatic Advanced Matching for EU/UK traffic if you cannot confirm consent at the pixel level. Use the GDPR toggle in your Meta Business Suite privacy settings.
Google Ads: Enable Consent Mode v2 (mandatory for EU traffic since March 2024). Without it, Google cannot model conversions for non-consenting users and your campaign performance data will be incomplete. Set ad_storage and analytics_storage to denied by default, updating to granted only on consent. For UK traffic, Google treats Consent Mode v2 as best practice but it is not yet mandated at the same level.
LinkedIn: Enable Insight Tag GDPR compliance mode in Campaign Manager. This delays tag firing until consent is confirmed. If you're running LinkedIn Lead Gen Forms, ensure your privacy policy URL is correctly linked within the form and is jurisdiction-specific.
TikTok: Enable Privacy Mode in TikTok Events Manager and use the Events API server-side for conversion signals, filtering out events from non-consenting users before they leave your server.
For a deeper dive into platform-specific setup, see our GDPR-compliant paid media agency guide.
Step 4: Apply DMA Rules if You Use Gatekeeper Platforms
The Digital Markets Act (DMA) applies to designated gatekeeper platforms: Google, Meta, Apple, Amazon, Microsoft, ByteDance (TikTok). If you're buying paid media through any of these platforms and targeting EU users, DMA compliance affects how you can use data and how the platforms must behave.
What DMA means for paid media buyers:
- Gatekeepers cannot combine personal data across services without user consent. Meta can no longer merge Facebook, Instagram, and WhatsApp data for targeting without explicit consent from EU users. This directly reduces audience breadth for retargeting.
- Interoperability requirements mean gatekeepers must allow third-party tracking and measurement tools to function. This is a net positive for advertisers using server-side tagging.
- Self-preferencing is restricted. Google cannot exclusively favor Google Analytics data in its ad targeting. This opens space for independent attribution tools.
- Article 5(2) consent obligation: Gatekeepers must obtain consent before combining personal data from their core platform service with data from other services for ad targeting purposes.
DMA enforcement is active. As of 2025, the European Commission has opened formal non-compliance proceedings against Meta, Apple, and Alphabet. Fines reach 10% of global annual turnover for a first violation and 20% for repeat violations.
Practical checklist for DMA compliance in paid ads:
- Confirm your CMP captures consent for cross-service data combination (not just cookie consent).
- Review your Custom Audience sources. Audiences built from non-consented data are non-compliant under DMA Article 5(2).
- Do not use Lookalike Audiences built from non-consented seed lists for EU campaigns.
- Document that your targeting inputs rely on first-party, consented data.
Step 5: Validate Your Retargeting and Custom Audience Setup
Retargeting is the highest-risk activity in paid media compliance. It processes behavioral data (pages visited, products viewed, time on site) that is inherently personal and requires a valid lawful basis.
For EU audiences: Retargeting via pixel requires prior consent. No exceptions. If a user did not accept tracking, they cannot be added to a retargeting pool. Your CMP must communicate consent status to your ad platforms in real time, either via Consent Mode signals (Google) or filtered server-side events (Meta CAPI, LinkedIn Conversions API).
For UK audiences: The same standard applies. The ICO's 2024 guidance explicitly states that behavioral advertising requires opt-in consent, not legitimate interest.
CRM-based custom audiences (customer lists uploaded to Meta or Google) require a separate lawful basis: the individuals on the list must have consented to their data being used for this purpose, or you must document legitimate interest with a completed Legitimate Interest Assessment (LIA).
If you're scaling campaigns across multiple European markets, our performance advertising agency team can audit your audience setup before launch.
Step 6: Set Up Compliant Conversion Tracking
Conversion tracking without consent compliance produces corrupted data and legal exposure simultaneously. The fix is server-side measurement with consent filtering.
Recommended setup:
- Implement Google Tag Manager Server-Side or a dedicated CDP (Segment, RudderStack) as your data layer.
- Filter conversion events at the server level: only fire events to ad platforms when a consent signal confirms the user accepted tracking.
- Use Conversion APIs (Meta CAPI, Google Ads Enhanced Conversions, LinkedIn Conversions API) as your primary measurement method. These are more durable than browser-based pixels and give you control over what data is transmitted.
- Enable Google Consent Mode v2 to allow modeled conversions for non-consenting EU users (Google's modeling fills the gap without using personal data).
- Implement hashed data only when sending customer match or enhanced conversion data. Never send raw email addresses or phone numbers.
For attribution modeling across this compliant data architecture, see our guide to paid media attribution models for startups.
Common Mistakes That Trigger ICO and DPA Investigations
- Firing pixels on page load before consent is granted. This is the single most common violation and is trivially detectable by regulators using browser dev tools.
- Using legitimate interest as a blanket justification for behavioral advertising. Both the EDPB and ICO have stated this does not meet the standard for intrusive tracking.
- Uploading CRM lists without verifying consent scope. The consent users gave for email marketing does not automatically extend to ad targeting.
- Running identical campaign setups for UK and EU without acknowledging post-Brexit divergence. UK GDPR and EU GDPR are separate instruments with separate enforcement.
- Ignoring DMA consent obligations for cross-service data combination when using Meta or Google audiences.
Does UK GDPR still apply post-Brexit?
Yes. UK GDPR is the UK's retained version of EU GDPR, incorporated into domestic law via the European Union (Withdrawal) Act 2018. It is enforced by the ICO independently of EU supervisory authorities. Substantive requirements are nearly identical, but enforcement, adequacy decisions, and data transfer mechanisms diverge.
What is the difference between EU GDPR and DMA for advertisers?
EU GDPR governs how personal data is collected and processed. The DMA governs the behavior of large platform gatekeepers, including how they use data for ad targeting. Both apply simultaneously. A campaign can be GDPR-compliant but DMA non-compliant if it uses audience data that gatekeepers have combined across services without consent.
Do DMA rules apply to advertisers or only to platforms?
DMA obligations fall primarily on gatekeepers, not advertisers. However, advertisers who instruct gatekeepers to use non-compliant data (for example, cross-service combined audiences without consent) may share liability exposure and will certainly see audience capabilities restricted as gatekeepers come into compliance.
Key Takeaways
- UK GDPR, EU GDPR, and the DMA are three separate compliance frameworks that apply simultaneously to most European paid media campaigns.
- Consent must be captured before any tracking pixel fires. Legitimate interest does not meet the standard for behavioral advertising in most EU and UK guidance.
- DMA rules restrict how gatekeeper platforms combine data for targeting, directly reducing retargeting pool size for non-consented EU audiences.
- Server-side conversion tracking with consent filtering is the only setup that is simultaneously compliant and measurement-complete.
- Fines under EU GDPR and UK GDPR reach 4% of global annual turnover. DMA fines reach 10-20% of global annual turnover.
Next Steps
If your campaigns are live in the UK or EU and you haven't completed a formal compliance audit against all three frameworks, the exposure is real and ongoing. GoScale Media works exclusively with European and EU-targeting brands on paid media that is compliant by design, not patched after the fact.
Talk to us about a compliance audit for your paid media setup before your next campaign goes live.
Unlocking Ad Potential for Brands Ready to Scale
Book a free strategy call and see how we can scale your paid media.
Book a Strategy Call