procedure

Check a lawful-basis manifest

It tells you what you still owe. That is the point of it.

Every compiled channel plan carries a lawful-basis manifest: each data source used, the basis it relies on, the conditions attached to that basis, and any warnings raised while compiling. It exists so the answer to "where did this audience come from?" is a document rather than a conversation. The most important thing to understand before reading one is what it is not. It is an engineering artefact that records what remains to be done, not a compliance certificate — and the conditions in it are obligations on you.
steps
5
roughly
Fifteen minutes
things needed first
2
before you start

What you need first

  • A compiled plan for at least one channel
  • Knowing who in your organisation owns data protection decisions, because some conditions are theirs to satisfy
the procedure

5 steps

Every step carries the thing that goes wrong at it, in its own block. That is the part worth reading.

  1. step 01

    Check which channels are in scope at all

    Cinema and DOOH delivery involve no personal data — venue catchments, OpenOOH venue types, postcode polygons and dayparts — and the compiler records them as outside UK GDPR scope rather than leaving it to be inferred. Movement data is not in that list because none reaches the product: the Adsquare contract does not exist, so the screen-ranking list the compiler emits is empty.

    what goes wrong here

    Outside scope describes the delivery, not everything used to choose it. Cinema's manifest really is outside scope throughout, but a DOOH plan that references a consent-attested segment still carries that segment's basis, and the manifest names the provider that attested it. Read it rather than assuming both channels are clear.

  2. step 02

    Read the basis per source, not per campaign

    Different segments in the same plan can rely on different bases. The manifest records one per source: consent-chained, legitimate interests, or outside scope.

    what goes wrong here

    Per-campaign is the wrong granularity and is how a single non-compliant source hides inside an otherwise clean plan.

  3. step 03

    Read the conditions as a to-do list

    A consent-chained source attaches a condition that the supply chain must be framework-validated and the vendor attestation verified on connection. A legitimate-interests source attaches a condition that an assessment must be on file.

    what goes wrong here

    These are things you owe, not things already done. A manifest listing a condition is telling you the work is outstanding.

  4. step 04

    Read the warnings

    Low-confidence segment matches, unmapped geographies and excluded segments that could not be expressed natively all raise warnings that stay attached to the compiled plan.

    what goes wrong here

    A warning that a persona exclusion could not be expressed on a channel is the one most likely to matter to a brand-safety reviewer, because it means the exclusion is not enforced there.

  5. step 05

    Take it to whoever owns the decision

    The manifest is designed to be the thing you hand a DPO rather than a summary you write for them. It names providers, bases, conditions and warnings in one place.

    what goes wrong here

    What it will not do is make a judgement. Whether legitimate interests is appropriate for your processing is an assessment somebody has to make and document.

what you end up with

A written record of what made each targeting decision lawful, and an explicit list of the conditions still outstanding on your side.

45 minutes. Bring a real brief and we compile it live.

Talk it through

Questions

Does a lawful-basis manifest make me compliant?

No, and it is worth being blunt about that. It records which data was used, on what basis, and what conditions come with it — which is the raw material for a compliance argument rather than the argument itself. Our own review names turning these conditions into enforced launch gates as unfinished work. Nothing on this site claims UK GDPR compliance on your behalf.