f Follow 23.1M
Friday, Jul 10th 2026
4AM 64°F ☀️
7AM 64°F ☀️
5-Day Forecast
f Follow 23.1M
Friday, Jul 10th 2026
4AM 64°F ☀️
7AM 64°F ☀️
5-Day Forecast
DailyGmail
Buyline
| Buyline US Updated: 00:00 EDT

Associated Newspapers Ltd

Privacy & Cookies Policy (the “Policy”)
Last updated: 29 September 2025
Previous version: 29 July 2025

This Privacy & Cookies Policy sets out how Associated Newspapers Ltd (trading as DailyGmail) collects, uses, stores, shares and protects your personal data when you use our websites, mobile applications, newsletters, social media channels, paid subscription services and any other digital or print services we provide (collectively the “Services”).

This Policy also explains your legal rights under data protection laws including the UK GDPR, EU GDPR, California CCPA/CPRA, Brazilian LGPD and other applicable state privacy legislation across the United States.

By accessing or using our Services, you acknowledge you have read and understood this Policy. If you do not agree with our data handling practices, you must not use our platforms.

The data controller responsible for your personal information is Associated Newspapers Limited, a company registered in England with company registration number 84121. Our registered office is Northcliffe House, 9 Derry Street, London W8 5HY, United Kingdom.

Our VAT registration number is GB 243571174. We operate the DailyGmail website, mobile apps, print publications and associated digital brands including This is Money, Metro and The i paper.

We have appointed a dedicated Data Protection Officer who can be contacted via our privacy enquiries email address shown in section 18 of this Policy.

3.1 Information you provide voluntarily

  • Account registration details: full name, email address, date of birth, postcode, contact telephone number, chosen account password
  • Subscription payment data: billing address, credit/debit card details, payment transaction history, subscription tier preferences
  • User-generated content: public comments, reader letters, survey responses, competition entries, feedback messages sent to our support team
  • Marketing preferences: opt-in / opt-out selections for email newsletters, SMS alerts and targeted advertising

3.2 Automatically collected technical data

  • Device identifiers: IP address, browser type, operating system, device model, unique advertising IDs
  • Usage analytics: page visit timestamps, article reading duration, click tracking, video playback history, internal site search queries
  • Cookie and pixel tracking data: consent records, session cookies, persistent tracking cookies, third-party advertising pixel data

3.3 Third-party sourced information

We may receive supplementary demographic, marketing and audience data from regulated advertising partners, social media platforms and market research providers, where permitted by law.

We only process your personal data where one of the six lawful bases under GDPR applies:

  • Consent: Where you have explicitly agreed to us using your data for specific purposes such as marketing emails or targeted advertising.
  • Contract performance: Processing required to deliver paid subscriptions, fulfil competition prizes, or provide services you have signed up for.
  • Legitimate interests: For operational site analytics, fraud prevention, audience measurement, and limited direct marketing where your privacy rights do not override our business interests.
  • Legal obligation: Data processing required to comply with tax, financial reporting, court disclosure and regulatory media legislation.
  • Vital interests: Rarely used, only to protect your physical safety or the safety of another natural person.
  • Public task: Limited processing for journalistic, public interest news reporting purposes protected under media freedom exemptions.

We utilise collected personal data for the following core purposes:

  • Create, maintain and secure your user account, manage subscription billing, renewals and cancellations
  • Deliver requested newsletters, editorial content, subscription benefits and competition rewards
  • Respond to customer support enquiries, complaints and data rights requests submitted via our contact channels
  • Analyse website and app usage to improve article layout, site functionality, loading speeds and reader experience
  • Deliver relevant editorial recommendations and targeted advertising across our platforms and partner networks
  • Detect fraudulent payment activity, account hacking, spam abuse and harmful user-generated content
  • Comply with mandatory legal, tax and regulatory reporting requirements
  • Carry out market research, audience surveys and anonymised readership statistics analysis

Certain personal data fields are marked mandatory during registration, checkout or contact form completion. If you refuse to provide required information:

  • You will be unable to complete account creation or purchase a paid DailyGmail subscription
  • We cannot deliver newsletters, competition entries or respond to your support messages
  • Restricted site functionality including comment posting, video playback and subscriber-only content will be locked to you

Non-mandatory optional fields (such as demographic profiling information) can be left blank with no impact on core service access.

We only disclose your personal data to third parties in limited, regulated circumstances:

7.1 Group companies

Data shared within our media group brands (This is Money, Metro, The i paper) for unified account management and cross-brand marketing where consent is held.

7.2 Service providers

Payment processors, cloud hosting platforms, email delivery services, fraud detection tools and customer support outsourcing firms, bound by strict data processing contracts.

7.3 Advertising and analytics partners

Anonymised or pseudonymised user behaviour data shared with ad networks, social media platforms and audience measurement tools for personalised advertising.

7.4 Legal disclosures

Data released to courts, police, tax authorities and regulatory bodies when legally compelled by valid court orders or statutory obligations.

7.5 Business transfers

In the event of a company sale, merger or acquisition, user data will form part of transferred business assets subject to ongoing data protection rules.

Some of our data processors and advertising partners operate outside the UK and European Economic Area (EEA), including the United States, Brazil, Australia and Canada.

When transferring personal data to countries without adequate data protection recognition by the UK ICO or European Commission, we implement formal legal safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission and UK Information Commissioner’s Office
  • Binding Corporate Rules (BCRs) for large multinational processing partners
  • Third-party service providers certified under the EU-US Data Privacy Framework or UK-US Data Bridge

Full copies of our data transfer agreements can be requested via our data protection contact email listed in section 18.

Where we operate co-branded campaigns, joint competitions or shared advertising tools alongside external partner companies, we act as joint data controllers alongside those third parties.

Joint controller agreements clearly define split responsibilities for meeting GDPR obligations, including responding to user data rights requests, maintaining data security and issuing privacy notices to participants.

For any joint processing activity, you may submit all data subject rights requests either to us or the partner joint controller, and both parties are legally obligated to resolve your enquiry within statutory response timescales.

Under UK and EU GDPR legislation you hold the following enforceable data subject rights:

  • Right to access: Request a full copy of all personal data we store relating to you, alongside a written explanation of our processing purposes.
  • Right to rectification: Demand correction of inaccurate, outdated or incomplete personal information held on your account.
  • Right to erasure ("right to be forgotten"): Request full permanent deletion of your account and all associated personal data, subject to legal retention exceptions.
  • Right to restriction of processing: Suspend our use of your data while we verify its accuracy or assess legitimate interest objections.
  • Right to data portability: Receive your account data in a machine-readable digital format for transfer to another data controller.
  • Right to object: Opt out of processing based on legitimate interests, including direct marketing emails and targeted advertising at any time, free of charge.
  • Right to withdraw consent: Revoke any prior consent you granted for marketing or tracking data processing, with immediate effect.

You may submit a GDPR rights request using our dedicated privacy contact channel shown in section 18. We will respond to valid requests within one calendar month.

Users residing in qualifying US states hold additional privacy rights under local consumer data statutes including California’s CCPA/CPRA, Virginia CDPA, Colorado CPA, Utah CPA and Connecticut CTDPA.

Key US state consumer rights:

  • Right to request disclosure of categories of personal data we collect, sell or share about you
  • Right to opt out of cross-device targeted advertising and third-party data "selling"
  • Right to permanent deletion of your personal consumer data
  • Right to non-discriminatory service access after exercising privacy opt-out rights
  • Right to authorise an authorised agent to submit data rights requests on your behalf

Do Not Sell My Personal Information requests can be submitted directly via our website footer link or our privacy support email address.

Visitors and subscribers located in Brazil are protected under the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, LGPD).

Your LGPD data rights mirror many GDPR provisions, with additional local requirements including:

  • Right to confirmation of whether we hold any of your personal data
  • Right to anonymisation, blocking or elimination of unnecessary personal data
  • Right to review automated decision-making logic used to serve personalised content or advertising
  • Right to lodge formal complaints with the ANPD (Brazilian National Data Protection Authority)

All LGPD requests submitted to our team will be managed in compliance with Brazilian data protection regulatory deadlines.

We only retain your personal data for the minimum period necessary to fulfil the purposes we collected it for, as follows:

  • Active subscriber accounts: Full account data retained for the full duration of your subscription term, plus 7 years post-cancellation for tax and financial record compliance.
  • Free registered accounts: Account data stored for 36 months from your last site login, after which inactive accounts are flagged for automatic deletion.
  • Marketing contact data: Retained until you submit an unsubscribe or opt-out request.
  • User comments and editorial content: Published reader content may be archived indefinitely for journalistic public interest purposes, even after account deletion (your name can be anonymised on request).
  • Cookie technical data: Session cookies expire when you close your browser; persistent tracking cookies expire after a maximum of 12 months.

When you submit an account deletion request, we erase all recoverable personal data within 30 days, save for mandatory legal retention exceptions.

Our website, subscription services and digital platforms are intended for general adult audiences aged 16 years and older.

We do not knowingly collect or intentionally solicit personal identifiable information from users under the age of 16. If we become aware we have received data from a child under 16 without verified parental consent, we will immediately delete all such records.

If you are a parent or legal guardian and believe we hold data belonging to your minor child, please contact our data protection team via the contact details in section 18 to request full removal.

We deploy cookies, pixel tags, local storage identifiers and device tracking tokens across all our websites and mobile applications to operate core site functionality, measure audience engagement and deliver personalised advertising.

Categories of cookies we use:

  • Necessary cookies: Mandatory for account login, subscription checkout, security fraud protection and cookie consent preference storage — cannot be disabled.
  • Analytics cookies: Measure page traffic, article read times and user navigation patterns to improve site performance.
  • Marketing cookies: Track cross-site browsing behaviour to serve tailored adverts and editorial recommendations.
  • Social media cookies: Embedded sharing widget tracking linked to X, Facebook, Instagram, YouTube and LinkedIn platforms.

You can fully adjust your cookie consent preferences via the pop-up banner displayed on your first site visit, or clear stored browser cookies manually through your device settings at any time.

We maintain robust technical, administrative and physical security safeguards to prevent unauthorised access, loss, alteration or unlawful disclosure of your personal data:

  • End-to-end TLS encryption for all website browsing, account login and payment checkout traffic
  • Encrypted cloud database storage with role-based staff access permission controls
  • Regular automated vulnerability scanning and third-party independent penetration testing of our web infrastructure
  • Mandatory data protection training for all internal employees with access to user personal records
  • Secure anonymisation of raw analytics data used for internal readership reporting
  • Formal data breach response protocols with mandatory ICO notification procedures in the event of a security incident

Whilst we deploy industry-standard protective measures, no internet-based data transmission or digital storage system can be guaranteed 100% secure against unknown cyber threats.

We reserve the right to revise and update this Privacy & Cookies Policy periodically to reflect changes in our data processing practices, new legal regulatory requirements or platform service feature updates.

All material changes to the Policy will be clearly highlighted on our website homepage and within logged-in user account dashboards ahead of the revised terms taking effect. Minor administrative amendments will only be updated on this page with a new "Last updated" date marker.

Your continued use of DailyGmail services after an updated Policy publication date constitutes acceptance of the revised data privacy rules. We encourage you to review this page every 3 months to stay informed of adjustments.

Data Protection & Privacy Enquiries

For all GDPR, CCPA, LGPD data subject rights requests, cookie policy questions or privacy complaints, email our dedicated data protection team at privacy@dailygmail.co.uk

General Customer Support

For subscription billing, account technical faults and editorial feedback: community@dailygmail.co.uk

Registered Postal Address

Associated Newspapers Limited
Northcliffe House
9 Derry Street
London W8 5HY
United Kingdom

Regulatory Complaint Route

If you are dissatisfied with our response to your privacy request, you hold the right to submit a formal complaint to your local data protection authority (the UK Information Commissioner’s Office for UK residents).