# GDPR, consent and UGC

UGC shows identifiable people, so it is personal data under GDPR. A defensible programme records scoped permission, honours removal requests, and minimises what it holds.

By Rohin Aggarwal · 2026-01-18

The cookie banner is not a consent record. The DM that says 'yes you can use it' is not a consent record. The Instagram tag is not a consent record. None of the three would survive a regulator walking through your data on a site visit, and closing that gap is what the workflow below is for.

**Quick answer**

- UGC shows identifiable people, so it generally involves personal data under GDPR and similar laws.
- Copyright permission and data-protection consent are related but not the same thing.
- People retain rights over their personal data: including, in many cases, to have it removed.
- A defensible UGC programme records permission, honours removal requests, and minimises data.

UGC rights conversations usually stop at [copyright: who owns the photo](/blog/copyright-fair-use-ugc). But a customer photo or video also contains something else, an identifiable person, and under GDPR and comparable regimes that brings data-protection obligations alongside the copyright ones.

## Is UGC personal data?

An image of an identifiable individual is personal data. Publishing and storing it is processing that data. None of this makes UGC unusable, businesses process personal data lawfully every day, but it does mean a UGC programme has to be [built with data protection in mind](/blog/gdpr-ugc-compliance), not only copyright.

## Why do you need two permissions, not one?

Copyright permission says you may use the content. Data-protection law adds that the person should understand and agree to how their personal data is used, and keeps rights over it afterwards. A good rights request does both at once: it spells out what the content will be used for, which is exactly what informed agreement needs. Our [UGC rights and permissions guide](/blog/ugc-rights-and-permissions-guide) covers how to word a request that satisfies both at the point of collection.

## What does GDPR mean for UGC in practice?

- Be clear at the point of permission about how and where the content will be used.
- Keep a record of the permission, tied to the asset and the person.
- Honour removal requests, if a person asks for their content to be taken down, have a process to do it.
- Minimise: do not hold UGC, or the data around it, longer or wider than you need.

| Question | Copyright permission | Data-protection consent |
| --- | --- | --- |
| What it covers | The right to use the work | How a person’s data is processed |
| Who holds the right | The content creator | The identifiable individual shown |
| Can it be withdrawn? | Per the licence terms | Yes, including erasure in many cases |
| What you must keep | The licence record | Scoped consent + removal process |

_Copyright permission versus data-protection consent._

**The data rule:** Treat UGC as personal data, not just copyrighted content. Clear permission for use, record it, and be able to remove content on request.

> **How Idukki helps:** Idukki’s rights workflow records scoped permission against each asset and the creator, the documentation and control a data-protection-aware UGC programme needs, including acting on removal requests.

The harder edge case is when a creator deletes the original post after you have featured it. That is where holding your own copy and record matters: we cover it in [what happens to your gallery when a creator deletes the original](/blog/when-a-creator-deletes-the-original-post).

### Sources & notes
- [European Commission, GDPR overview](https://commission.europa.eu/law/law-topic/data-protection_en) — Personal data and processing obligations.
- [UK ICO, guidance on images and personal data](https://ico.org.uk/) — When images count as personal data.
- Note — Practical guidance, not legal advice, confirm with a data-protection specialist in your market.

- **30 days** — GDPR right-to-erasure SLA (End-to-end inc. CDN purges)
- **45 days** — CCPA deletion SLA (CPRA)
- **64%** — of brands fail withdrawal SLA on audit (Idukki research Q1 2026)
- **38%** — Median rights yes-rate (Idukki dataset)

_Compliance benchmarks across UGC programmes._

---
Canonical: https://idukki.io/blog/gdpr-consent-and-ugc
Tags: ugc, rights-management, gdpr, compliance
