GDPR and Giveaways: What UK and EU Brands Can Legally Collect From Entrants

Published on September 30, 2026
Updated September 30, 2026

A TikTok giveaway does not feel like a data collection exercise. It feels like a fun post that gets your comment section moving. But the moment someone comments to enter, hands over an email for an entry form, or gets DM'd to claim a prize, you are processing personal data, and GDPR does not care that the context was a giveaway rather than a checkout page. UK and EU brands running promotions are bound by the exact same rules that govern any other collection of personal information, and giveaways are actually one of the more common places brands get this wrong, because the whole thing feels too lighthearted to trigger serious data law.

This guide covers what you can actually collect from entrants, what needs a separate opt-in beyond simply entering, how long you are allowed to keep the data, and where UK and EU rules currently diverge now that the UK has made its own changes to how its version of GDPR works.

Two regimes, one shared foundation

UK brands and EU brands are technically working under two different laws now, even though both trace back to the same source. The EU's General Data Protection Regulation still applies directly across EU member states, enforced by each country's own data protection authority. The UK left the EU version behind after Brexit and now runs its own UK GDPR, sitting alongside the Data Protection Act 2018 and enforced by the Information Commissioner's Office.

For most of the day-to-day rules that matter to a giveaway, the two frameworks still line up closely: the same core principles, the same rules around consent, and largely the same expectations about data minimization. Where they have started to diverge is a newer development. The UK's Data (Use and Access) Act 2025 made a set of amendments to UK GDPR that took effect in stages through 2025 and 2026, and one change worth knowing about if you send entrant data anywhere outside the UK is that the UK replaced its old "essentially equivalent" test for international data transfers with a more flexible "not materially lower" standard. In practice this gives UK brands slightly more room when a tool or platform they use is based outside the UK, though a transfer risk assessment is still expected, just against a less rigid bar than before. The DUAA also introduced a handful of new lawful bases that skip the usual balancing test entirely, but those are narrowly limited to things like crime prevention and safeguarding vulnerable people, not ordinary commercial processing, so a giveaway does not get to rely on them.

If your giveaway only ever reaches UK entrants, UK GDPR and the ICO's guidance are what matters. If it reaches audiences in EU countries too, which is likely for anything running on TikTok, you are dealing with both regimes at once, and the safer approach is to comply with whichever rule is stricter on a given point rather than trying to run two separate versions of the same promotion.

The core principle: only collect what you actually need

Data minimization is the single idea that should shape every field you ask an entrant to fill in. The question for each piece of information you request is not "would this be useful" but "do I actually need this to run the giveaway."

For a straightforward comment-to-win TikTok giveaway, that usually means you need almost nothing beyond what TikTok itself already shows you: a username and a comment. You do not need an email address, a phone number, or a mailing address from every entrant just to run the draw itself. Those fields only become necessary once someone has actually won, at which point you need enough information to verify them and get the prize to them, typically a way to contact them privately and a shipping address if the prize is physical.

If your giveaway does run through an entry form rather than comments alone, the same logic still applies. Name and a way to contact the winner covers most needs. A birth date is only justified if age verification genuinely matters for your prize or your terms. A full postal address from every entrant, rather than just the eventual winner, is very hard to justify under data minimization, since the vast majority of entrants will never need to receive anything.

What lawful basis actually covers running the giveaway

People often assume that entering a giveaway is itself a form of GDPR consent, and that this consent then covers whatever the brand wants to do with the data afterward. That is not how it works, and it is the single biggest misunderstanding brands run into.

Administering the giveaway itself, verifying eligibility, drawing a winner, contacting them, delivering the prize, is typically covered by a lawful basis other than consent, most often the processing being necessary to perform the arrangement the entrant agreed to by accepting your published rules, or a legitimate interest in running the promotion you are already conducting. This is the housekeeping basis that lets a giveaway function at all.

Using that same entrant's data afterward for something else entirely, adding them to your marketing email list, using their details for future ad targeting, is a separate purpose, and a separate purpose needs its own lawful basis, almost always consent. This is the part that has to be freely given, specific, informed, and given through a clear affirmative action. A pre-ticked "yes, sign me up for emails" box does not count as valid consent under GDPR, and neither does treating giveaway entry itself as an implied yes to marketing.

Marketing consent has to be separate, not bundled

If you want to keep talking to entrants after the giveaway ends, the request for that has to stand on its own, separate from the entry mechanism, so entrants can say yes to one without being forced to accept the other. In practice this usually means an explicit, unticked opt-in checkbox or a clearly separate step, not a single box that says "by entering you agree to receive marketing," which tries to make one action cover two different purposes.

Consent also has to be genuinely easy to withdraw. If someone opts in to marketing during your giveaway and later wants out, the unsubscribe process needs to be roughly as simple as the sign-up was. A withdrawal process buried behind several steps, when signing up took one click, is itself a compliance problem, not just a customer experience one.

Publishing the winner's details

Announcing a winner is a normal, expected part of a giveaway, but the information you publish is still personal data, and GDPR still applies to it. The generally accepted safe approach is to publish only a first name or surname alongside a broad location, such as a county or region, and only when that combination would not reasonably let someone identify exactly who won. If your audience is small enough, or your winner's presence online is distinctive enough, that even a first name and general area would make them identifiable, publishing less, or asking the winner directly how they would like to be credited, is the safer path.

This is also something to flag in your published rules before anyone enters, not something you spring on the winner afterward. Telling entrants upfront that a winner's name and general location may be shared publicly means nobody is surprised, and it gives you a cleaner basis for actually doing it. The guide on announcing a giveaway winner covers the practical side of doing this well once the data question is settled, and the walkthrough on verifying a giveaway winner is real is worth pairing with this, since verifying a winner privately before you publish anything about them keeps both your fraud check and your data handling contained to a single, controlled step.

How long you can keep entrant data

GDPR does not hand brands a specific number of days or months for how long giveaway data can be retained. What it requires instead is that you only keep personal data for as long as you actually need it for the purpose you collected it for, and that you have told entrants roughly what that period looks like.

For most comment-based giveaways, once the winner has been verified, contacted, and sent their prize, there is very little ongoing reason to retain data on every other entrant. A commonly used approach among brands running these kinds of promotions is to delete entrant records within a defined short window after the giveaway closes, often somewhere in the range of thirty to ninety days, unless there is a genuine legal reason to hold onto something longer, such as a tax or accounting requirement tied to a prize's value. Whatever window you settle on, state it in your privacy notice so entrants know what to expect, and actually follow it rather than letting old giveaway data quietly accumulate indefinitely.

Children and giveaways

If your audience includes or could plausibly include children, extra care applies before you use their data for marketing purposes specifically. Both UK and EU rules generally require a parent or guardian's consent before a child under thirteen can be marketed to through data collected online, and several EU member states set that threshold higher, up to sixteen, under their own national implementation of GDPR's age-of-consent provisions. Running the core mechanics of a giveaway is one thing, but folding entrants who may be minors into an ongoing marketing list without the right consent in place is a separate and much riskier step, and it is worth checking the age thresholds that apply in the specific markets your giveaway reaches before building any marketing follow-up into your plan.

International transfers: where your data actually goes

Every tool in your giveaway stack, from wherever you gather comments to wherever you store entrant details, sits somewhere, and where that somewhere is matters. If a tool you use to run the giveaway is based outside the UK or EU, moving entrant data to it counts as an international transfer, and both regimes expect you to have a proper basis for that transfer rather than assuming it is automatically fine because the tool is convenient.

For EU brands, the usual mechanisms are Standard Contractual Clauses built into the provider's terms, or relying on the provider's participation in the EU-US Data Privacy Framework where the destination is the United States. UK brands work from a similar toolkit, now assessed against the DUAA's newer "not materially lower" standard rather than the stricter test that applied before. In either case, the practical step is the same: check what data processing terms the tools in your giveaway actually offer before you build your process around them, rather than discovering the gap after entrant data has already been collected.

A practical checklist

Only ask entrants for what you actually need to run the draw itself, and only collect fuller details like an address once someone has actually won.

Keep the lawful basis for running the giveaway separate in your own head from the lawful basis for any marketing you want to do afterward, since they are not the same thing.

Make marketing opt-in a distinct, unticked action, never bundled into the entry step itself.

State in your published rules, before anyone enters, what will happen with a winner's data if they win, including whether their name and general location may be published. A set of official giveaway rules is the natural place to put this in writing alongside your other entry conditions.

Set and follow a real retention window for entrant data once the giveaway closes, and say what that window is in your privacy notice.

Check where the tools in your giveaway process actually store and transfer entrant data, and confirm they offer the safeguards your regime expects for anything based outside the UK or EU.

Treat any entrant who may be a minor with extra caution before adding them to anything beyond the giveaway itself.

Where this sits alongside the legal question you may have already checked

Data protection is a separate question from whether your giveaway is a lawful promotion in the first place. If you are running a UK audience specifically, the earlier guide on whether TikTok giveaways are legal in the UK covers the Gambling Act and CAP Code side of things, which sits alongside, not instead of, everything covered here. A giveaway can clear the gambling and advertising rules cleanly and still fall short on data protection if entrant information is collected without a proper basis or held onto for no defined reason, so treat both as separate boxes that both need checking, not one substitute for the other.

The bottom line

None of this makes running a UK or EU giveaway complicated in practice, it just means treating entrant data with the same care you would apply anywhere else in your business. Ask for less rather than more, keep marketing consent as its own clear step, be upfront about what happens to a winner's details, do not hold onto data longer than you need it, and know where the tools in your process actually send information. Get those habits in place once and every giveaway you run afterward inherits them for free.

Frequently Asked Questions

Does entering a giveaway count as consent to receive marketing emails?

No. Entry consent covers running the giveaway itself. Marketing needs its own separate, unticked opt-in.

What can I publish about a giveaway winner?

Generally, a first name or surname alongside a broad location, and only if that combination would not reasonably identify them. State this possibility in your rules before the giveaway starts.

How long can I keep entrant data after the giveaway ends?

GDPR sets no fixed number, but most brands delete entrant records within thirty to ninety days unless there is a genuine legal reason to keep them longer.

Do UK and EU GDPR still work the same way?

Mostly, yes, though the UK's Data (Use and Access) Act 2025 introduced its own changes, including a more flexible test for international data transfers.

Do I need parental consent to market to entrants who might be minors?

Generally, yes, under thirteen everywhere and under sixteen in several EU countries, before using their data for marketing purposes specifically.