Need advice? Let's talk.

Get straightforward guidance from your broadcasting partner. Schedule a call to chat with the team about your radio station.

Book Demo

GDPR for Radio Stations: What You Need to Know

How UK and EU data protection law effects your radio station, and what to do about it.

Laura Shenton

by Laura Shenton in News

Last updated 28.09.2026

Gdpr Header2

The General Data Protection Regulation (GDPR) sets the rules on personal data privacy has changed and it can all seem a little confusing. We put together this guide of what you need to know and what actions you may have to take.

Key Takeaways

  • Document your data: Keep records of what personal data you hold, where it came from, and who you share it with.
  • Keep a privacy policy: Explain your lawful basis for processing, how long you keep data, and listeners' right to complain to the regulator, including for any station apps you publish.
  • Respect individual rights: Be ready to provide, correct, and delete personal data, and to respond to access requests within one month.
  • Get clear consent: Consent must be a freely given, specific opt-in that's separate from your terms, with an easy way to withdraw it, and mailing lists may need reconfirming.
  • Plan for breaches: Have procedures to detect, investigate, and report a data breach to the regulator when people's rights are at risk.

What is GDPR?

Image is a decorative illustration showing a grid of faces as the background and in the foreground is an EU flag with a padlock in the middle of the stars.

GDPR is a regulation that aims to protect people's personal data. In the UK, it sits alongside the Data Protection Act 2018 (DPA) as the UK GDPR, and both were updated by the Data (Use and Access) Act 2025. If you have listeners in the EU, the EU GDPR applies too. if you are in line with these rules act then you will have a lot less to worry about. However, it's worth checking that your policies are up to date.

What Should I Consider?

Information You Hold

Documentation is extremely important. Make sure you are documenting what personal data you hold, where you gained the information and where you are sharing that information. The GDPR means that you’ll have to keep records of processing activities, including when you share data with other companies.

Privacy Policies

Review your current Privacy Policy if you have one. Make sure you place any necessary changes before the GDPR comes into play, such as, explain your lawful basis for processing data, how long you will hold data and that your consumers have a right to complain to the ICO if they think there is an issue with the way you are handling data. In the UK, since June 2026, you must also have a process for handling data protection complaints. If you don’t have a privacy policy, you will have to make one by following this guide: Privacy Policy Guide.

Protecting Rights

Make sure you have covered all rights that your consumers have. This includes how you will delete personal data and how you will provide data electronically. The GDPR mentions the following rights for consumers:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • The right not to be part of automated decision-making, or profiling

For the most part, the GDPR covers most of the same rights as the DPA 1998 already did, but with a few enhancements on some.

Access Requests

The new rules regarding Subject Access Requests are as follows:

  • Most cases you won’t be able to charge for complying with a request.
  • You have one month to comply, which can be extended.
  • You can refuse or charge requests that are unfounded or excessive.
  • If you do refuse a request, you must state why and let them know they have a right to complain to the supervisory authority and to a judicial remedy, within one month.

Lawful Basis for Processing

It should be made possible to review the types of processing activities you carry out and to see your lawful basis for carrying out these activities. You need to document this in order to comply to GDPR.

Consent

Consent must be given freely, and made specific, informed and unambiguous. There must be a definite opt-in. It must be separate from terms and conditions, with a simple way provided to withdraw consent.

Children

If your radio station is one that is designed for children then this part will involve you. In the UK, the age where a child can give consent for themselves is 13 (in the EU this ranges from 13-16 depending on the country). If you offer a service to children below this age, you will need to make sure that consent is given from a parent or guardian on their behalf.

Data Breaches

Make sure to put procedures in place to be able to detect, investigate, and report a personal data breach. You must notify the ICO within 72 hours of becoming aware of a breach if it would result in a risk to their rights and freedoms, e.g. discrimination, defamation, financial loss, breach of confidentiality or any other severe risk.

Data Protection Impact Assessments (DPIAs)

Under the GDPR, DPIAs have been made mandatory in circumstances where data processing is likely to pose a high risk to consumers, for example:

  • New technology being deployed.
  • Processing a large amount of special data categories.
  • Processing is likely to significantly effect consumers.

What Can I Do?

Image is a decorative animation showing a man juggling balls and one laptop that represents data protection.

As an online radio station, there isn’t too much to worry about. If you have a mailing list for example, you will need to make sure your subscribers have opted in to receive it.

Make sure if you hold peoples personal data in any way, you have a Privacy Policy written out detailing all of the relevant information about how you store it, how it's deleted, any processing you do with the data, and what rights the individuals have. This includes submitting apps to iOS and Android, as both require the individual to provide their data when they download your app. You will need to write up a Privacy Policy for your apps, similar to how we've done it here.

Is GDPR affecting your radio station? Let us know in the comments below.