Check a lawful-basis manifest
It tells you what you still owe. That is the point of it.
- steps
- 5
- roughly
- Fifteen minutes
- things needed first
- 2
What you need first
- A compiled plan for at least one channel
- Knowing who in your organisation owns data protection decisions, because some conditions are theirs to satisfy
5 steps
Every step carries the thing that goes wrong at it, in its own block. That is the part worth reading.
- step 01
Check which channels are in scope at all
Cinema and DOOH delivery involve no personal data — venue catchments, OpenOOH venue types, postcode polygons and dayparts — and the compiler records them as outside UK GDPR scope rather than leaving it to be inferred. Movement data is not in that list because none reaches the product: the Adsquare contract does not exist, so the screen-ranking list the compiler emits is empty.
what goes wrong hereOutside scope describes the delivery, not everything used to choose it. Cinema's manifest really is outside scope throughout, but a DOOH plan that references a consent-attested segment still carries that segment's basis, and the manifest names the provider that attested it. Read it rather than assuming both channels are clear.
- step 02
Read the basis per source, not per campaign
Different segments in the same plan can rely on different bases. The manifest records one per source: consent-chained, legitimate interests, or outside scope.
what goes wrong herePer-campaign is the wrong granularity and is how a single non-compliant source hides inside an otherwise clean plan.
- step 03
Read the conditions as a to-do list
A consent-chained source attaches a condition that the supply chain must be framework-validated and the vendor attestation verified on connection. A legitimate-interests source attaches a condition that an assessment must be on file.
what goes wrong hereThese are things you owe, not things already done. A manifest listing a condition is telling you the work is outstanding.
- step 04
Read the warnings
Low-confidence segment matches, unmapped geographies and excluded segments that could not be expressed natively all raise warnings that stay attached to the compiled plan.
what goes wrong hereA warning that a persona exclusion could not be expressed on a channel is the one most likely to matter to a brand-safety reviewer, because it means the exclusion is not enforced there.
- step 05
Take it to whoever owns the decision
The manifest is designed to be the thing you hand a DPO rather than a summary you write for them. It names providers, bases, conditions and warnings in one place.
what goes wrong hereWhat it will not do is make a judgement. Whether legitimate interests is appropriate for your processing is an assessment somebody has to make and document.
A written record of what made each targeting decision lawful, and an explicit list of the conditions still outstanding on your side.
What else you might need to do
45 minutes. Bring a real brief and we compile it live.
Talk it throughQuestions
Does a lawful-basis manifest make me compliant?
No, and it is worth being blunt about that. It records which data was used, on what basis, and what conditions come with it — which is the raw material for a compliance argument rather than the argument itself. Our own review names turning these conditions into enforced launch gates as unfinished work. Nothing on this site claims UK GDPR compliance on your behalf.