Guide
Influencer Marketing Basics
Brands
GDPR applies to influencer marketing wherever personal data is processed — shipping addresses and payment details for gifted products or fees, tracking-link click and IP data, and entrant data from giveaways. The brand is usually the data controller and needs a lawful basis under Article 6 for each use, plus a written data processing agreement (Article 28) with any platform or tool that processes that data on its behalf. This is a different law from ad-disclosure rules: GDPR governs how personal data is handled, not whether a post is labelled as an ad.
This is practical guidance from Make Influence, not legal advice. Use it as a checklist of what to consider — get the specific legal assessment of your own processing from a lawyer, particularly if you handle sensitive data or data about children.
Ad-disclosure rules — covered in their own article — govern whether a post has to be labelled as advertising. GDPR (the General Data Protection Regulation) governs something entirely different: how personal data is collected, stored, used and shared. The two rulebooks apply at the same time and independently of each other. A post can be correctly labelled as an ad and still involve a GDPR breach — for example, if entrant addresses from a giveaway are left unprotected in a spreadsheet with no lawful basis for holding them.
An influencer collaboration typically involves several distinct kinds of personal data, often handled by different parties:
| Situation | Personal data | Who typically processes it |
|---|---|---|
| Shipping a gifted product | Name, address, phone number | The brand or its logistics partner |
| Paying the influencer's fee | Bank details, tax/company ID, address | The brand's finance team or payment provider |
| A tracking link used in the collaboration | Cookie ID, click ID, IP address | The brand's tracking system or platform |
| A competition or giveaway run through the influencer | Name, email, sometimes address of entrants | The brand — and the influencer, if they collect entries first |
| Marketplace/insights data about the creator's audience | Aggregated demographic figures (rarely identifiable on their own) | The platform, e.g. Instagram's or TikTok's own Creator Marketplace |
The tracking row surprises a lot of people: the regulation's own definition, in Article 4(1), explicitly names an “online identifier” as an example of personal data, and an IP address is exactly that. The same applies to the cookies and click IDs that influencer tracking itself runs on — see how influencer tracking actually works for the mechanics behind the cookie and IP address that Make Influence itself retains for up to 30 days and 3 months respectively after a click.
Denmark's data protection authority, Datatilsynet, puts it this way: the controller decides why (for what purpose) and how (by what means) personal data is processed. A processor processes personal data on the controller's behalf — that is, on the controller's documented instructions — and may not use the data for its own purposes. What matters, per Datatilsynet, is always what is actually agreed and actually happens, not what the parties call each other.
| Scenario | Likely role |
|---|---|
| The brand ships a gift itself and keeps its own list of recipients | The brand is the controller |
| The brand uses an influencer marketing platform to manage fees, tracking and creator communication | The platform is typically a processor for the brand — it acts on the brand's instructions and may not use the data for its own purposes |
| An agency and the brand plan the campaign together, and both independently decide how entrant data is used | They may be joint controllers |
| An influencer makes their own content and runs their own account and their own followers | The influencer is normally neither a processor nor a controller for the brand — they're an independent actor for their own content |
If it's unclear, Datatilsynet points to three things: whether the arrangement actually concerns processing personal data (not just an ordinary service contract), whether the other party acts solely on instruction, and whether both parties can independently use the data for their own purposes — in which case you're unlikely to be in a processor relationship, and more likely joint controllers instead.
GDPR requires a lawful basis for any processing of personal data. In practice, three of the six bases in Article 6(1) come up repeatedly in an influencer collaboration:
| Purpose | Typical lawful basis |
|---|---|
| Shipping an agreed gifted product to the influencer | Necessary for the performance of a contract (Article 6(1)(b)) |
| Paying the fee and recording the payment | Contract, supplemented by a legal obligation (bookkeeping law) for the accounting record itself |
| Unsolicited outreach to an influencer the brand has no existing relationship with | Legitimate interests (Article 6(1)(f)) — requires an actual balancing test against the influencer's own rights |
| A competition or giveaway where followers submit their own name and email | Consent (Article 6(1)(a)) |
Worth noting: the tracking link itself — the cookie or click ID the commission calculation depends on — isn't automatically covered just because you have an Article 6 basis. Cookies and similar technologies are governed by a separate consent rule that, in Denmark, sits outside Datatilsynet's own remit and falls under the marketing and cookie rules overseen by the Danish Agency for Digitalisation (Digitaliseringsstyrelsen). In practice you typically need to satisfy two separate rulebooks when a tracking link involves a cookie: the GDPR basis for processing the click data itself, and cookie consent for setting the cookie in the browser in the first place.
If the brand uses a platform or tool that processes personal data on its behalf — for tracking, fee payouts or campaign management, for example — Article 28 requires a written data processing agreement (DPA), not just an ordinary vendor contract. The agreement has to fix, among other things:
The DPA is a separate legal document — it doesn't replace the collaboration contract with the influencer itself; see what to put in an influencer contract for the 12 terms that contract needs to cover on its own.
Many of the tools an influencer campaign relies on — tracking platforms, analytics tools, communication tools — are US companies. Since the European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023, personal data can be transferred to US companies certified under the framework without additional safeguards such as Standard Contractual Clauses (SCCs). If a vendor isn't certified under the framework, the transfer needs to rest on SCCs or another valid transfer mechanism instead. Always check whether a US platform or tool is actually certified before putting personal data into it.
GDPR's Article 8 sets 16 as the default age at which a young person can independently consent to an information society service — but member states may lower it, not below 13. According to comparative overviews of how member states have implemented this, Denmark has set the age at 13. Legislation is amended over time, so check the current Danish data protection act if this is decisive for your campaign. If a collaboration targets a younger audience — or the influencer's own following skews heavily under 13 — be especially careful about collecting data directly from children (e.g. via a competition) without parental consent.
The figures below are a made-up worked example to illustrate how the fine structure works — not a real case, and not a prediction of what any specific breach would cost.
GDPR's Article 83 sets two tiers of fines. The lower tier (Article 83(4)) goes up to EUR 10 million or 2% of annual global turnover, whichever is higher. The higher tier (Article 83(5)) — for breaches of the basic processing principles and data subjects' rights — goes up to EUR 20 million or 4% of annual global turnover, whichever is higher.
Take a hypothetical Danish brand with DKK 750 million (roughly EUR 100 million) in annual global turnover that commits a higher-tier breach. 4% of that turnover is DKK 30 million. But because the fixed cap of EUR 20 million (roughly DKK 149 million) is higher than DKK 30 million, the statutory ceiling that technically applies is DKK 149 million — not DKK 30 million — because the law uses whichever figure is higher. In practice, a supervisory authority never reaches the statutory ceiling for a first, quickly corrected mistake: Article 83(2) requires it to weigh eleven specific factors, including the gravity and duration of the breach, whether it was intentional or negligent, what steps the brand took to mitigate the harm, and whether the brand reported it voluntarily.
In our experience, GDPR gets overlooked in influencer campaigns most often because it doesn't feel like “real” data processing — it's “just” a shipping address for a gifted product, or a tracking link. But that's exactly the kind of processing the law covers. Our own approach to tracking — a cookie retained for up to 30 days and an IP address for up to 3 months — is a deliberate choice to hold as little as possible, for only as long as it takes to attribute a sale to the right creator, and no longer.
Usually not. The influencer typically creates their own content and runs their own account — they don't act on the brand's instructions in the GDPR sense. A data processing agreement is usually relevant with platforms and tools, not with the influencer themselves. The exception is if the influencer collects data on the brand's behalf, for example a list of competition entrants they then hand over — in that case, assess the role split on its actual facts.
Aggregated, non-identifiable figures — like a platform's own demographic insights — generally aren't personal data and fall outside GDPR. See how to verify an influencer's audience before you pay for what data is actually available.
There's no fixed statutory limit — retention has to be proportionate to the purpose (data minimisation and storage limitation). Make Influence's own model retains the cookie for up to 30 days and the IP address for up to 3 months after a click — see how influencer tracking actually works.
Yes, if the link sets a cookie or similar technology for anything beyond what's strictly necessary. That's a separate cookie-consent rule — not GDPR Article 6 itself — and in Denmark it falls under the rules overseen by the Danish Agency for Digitalisation. See Consent Mode and influencer tracking in the EU for what that consent actually has to satisfy, and what happens to your tracking data when it's declined.
Yes — GDPR applies to personal data about anyone, regardless of nationality, as long as the processing happens within the EU/EEA or is directed at EU/EEA residents. See how to pay international influencers for currency, invoicing and tax — a separate question from the data protection of the payment details themselves.
Make Influence
Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.
Book a demoCreate accountMake Influence
Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.
Create creator profileMore creator guidesMake Influence
Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.
See how it worksBrowse the Academy