On this page
- 01Short answer
- 02Does GDPR apply to social media marketing?
- 03What about photographs of customers and staff?
- 04Can you upload customer lists to advertising platforms?
- 05What rules apply to direct messages?
- 06What records should you keep?
- 07What happens if you get it wrong?
- 08What should you do if someone asks you to remove content?
- 09Next step
- 10Sources and further reading
- 11Frequently asked questions
Short answer
Social media marketing involves personal data, so UK GDPR applies. The four areas that catch small businesses are photographs of identifiable people, uploading customer lists to build advertising audiences, direct marketing messages, and keeping records of consent. None are difficult, but all require a decision made in advance.
- Photos of identifiable people need a lawful basis. Consent is usually cleanest for marketing.
- Uploading a customer list to a platform is processing personal data. You need a lawful basis and to tell people.
- Unsolicited marketing messages breach PECR. Consent must be specific and recorded.
- Keep records: who consented, when, to what, and how they can withdraw.
- Honour withdrawal promptly. It is a right, not a request.
Want your social media data practices reviewed? Message us on WhatsApp.
Chat on WhatsApp →Does GDPR apply to social media marketing?
Yes. UK GDPR applies whenever you process personal data, and personal data includes photographs of identifiable individuals, customer contact lists, and information about people who engage with your content.
The Information Commissioner's Office (ICO) is the UK regulator, and its published guidance on direct marketing is the primary reference for small businesses. Nothing here is legal advice; take professional advice on anything material to your business.
What about photographs of customers and staff?
If a person is identifiable, using their image in marketing is processing personal data and needs a lawful basis. For marketing use, consent is usually the most defensible choice for a small business, because the alternative bases are harder to argue.
Practically: ask, get a clear yes in writing, keep the message, and remove the image promptly if asked. For staff, put it in the employment paperwork and confirm again for anything prominent. For customers, a line in your quote or booking confirmation with an opt-out works well.
Can you upload customer lists to advertising platforms?
Sometimes, but not without thought. Uploading customer email addresses to create a custom audience is processing personal data and is a use most customers did not anticipate when they gave you their details.
You need a lawful basis, and your privacy notice must tell people that their data may be used this way. The ICO has been clear that transparency is the core requirement here. If your privacy notice does not mention advertising audiences, fix that before you upload anything.
We will review your consent wording and privacy notice alongside your social setup. Message us on WhatsApp.
Chat on WhatsApp →What rules apply to direct messages?
The Privacy and Electronic Communications Regulations (PECR) govern electronic direct marketing, and they apply to messaging platforms as well as email and text.
Unsolicited promotional messages to individuals require consent, which must be specific, informed and freely given. A person messaging you about a quote has not consented to receive marketing. Build lists only from explicit opt-ins, state what people will receive, and include a clear way to stop in every message.
What records should you keep?
Enough to demonstrate consent if asked: who, when, what they were told, and how they can withdraw. For a small business this is a spreadsheet, not a system.
Also keep a note of withdrawal requests and when they were actioned. The ability to show that a request was honoured within a reasonable period is the thing that matters if a complaint is ever made.
- Name or identifier, date, and what was consented to.
- The wording used when consent was obtained.
- How the person can withdraw, and a record when they do.
- A privacy notice that accurately describes what you do with data.
- A review date, annually, to check the records still match practice.
What happens if you get it wrong?
For most small business errors, the practical consequence is a complaint, a request to delete something, and reputational cost. The ICO has enforcement powers including fines, and it has taken action against organisations for unlawful direct marketing, though its approach to small businesses generally starts with guidance.
The bigger day-to-day risk is commercial. Being the business that used a customer's photo without asking, or messaged people who never opted in, damages trust locally in ways that are slow to repair.
What should you do if someone asks you to remove content?
Act promptly and without arguing about whether they are entitled to ask. Under UK GDPR individuals have rights over their personal data, including in marketing content, and a removal request from someone whose image or details you published should be treated as a request to be actioned rather than negotiated.
The practical sequence: acknowledge the same working day, remove the content from your own channels, check whether it was reused in ads or on your website, confirm back when it is done, and record the request and the date.
Remember that removal from your channels does not remove it from a platform's own copies or from anyone who saved it, and be honest about that rather than promising more than you can deliver. Withdrawing consent should be as straightforward as giving it was.
- Acknowledge the same working day. Do not debate entitlement.
- Remove from social, ads and website. Check all three.
- Confirm completion in writing and record the date.
- Be honest about what you cannot control.
Next step
Most of this is one afternoon of getting consent wording, a privacy notice line and a simple record sheet in place. It is far cheaper than fixing it afterwards.
Message us on WhatsApp for a review of consent, permissions and privacy wording across your social media.
Chat on WhatsApp →Sources and further reading
- Lawful basis for processing personal data · Information Commissioner's Office
- What is valid consent? · Information Commissioner's Office
- Electronic and telephone marketing under PECR · Information Commissioner's Office
Frequently asked questions
Do I need consent to post photos of customers?
If the person is identifiable, you need a lawful basis, and consent is usually the cleanest for marketing use. Get a clear written yes, keep the message, and remove the image promptly if the person later asks you to.
Can I upload my customer list to Facebook for ads?
Only with a lawful basis and transparency. Your privacy notice must tell people their data may be used to create advertising audiences. If it does not currently say so, update it before uploading anything.
Is it legal to send marketing messages on WhatsApp?
Only to people who have specifically opted in. PECR governs electronic direct marketing and covers messaging platforms. Someone messaging you for a quote has not consented to marketing, and every marketing message must include a clear way to stop.
What records do I need to keep for marketing consent?
Who consented, when, what wording they were shown, and how they can withdraw, plus a record of any withdrawal and when it was actioned. For a small business a spreadsheet is sufficient. Review it annually against actual practice.
Written by

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.



