This Privacy & Cookies Policy sets out how Associated Newspapers Ltd (trading as DailyGmail) collects, uses, stores, shares and protects your personal data when you use our websites, mobile applications, newsletters, social media channels, paid subscription services and any other digital or print services we provide (collectively the “Services”).
This Policy also explains your legal rights under data protection laws including the UK GDPR, EU GDPR, California CCPA/CPRA, Brazilian LGPD and other applicable state privacy legislation across the United States.
By accessing or using our Services, you acknowledge you have read and understood this Policy. If you do not agree with our data handling practices, you must not use our platforms.
The data controller responsible for your personal information is Associated Newspapers Limited, a company registered in England with company registration number 84121. Our registered office is Northcliffe House, 9 Derry Street, London W8 5HY, United Kingdom.
Our VAT registration number is GB 243571174. We operate the DailyGmail website, mobile apps, print publications and associated digital brands including This is Money, Metro and The i paper.
We have appointed a dedicated Data Protection Officer who can be contacted via our privacy enquiries email address shown in section 18 of this Policy.
We may receive supplementary demographic, marketing and audience data from regulated advertising partners, social media platforms and market research providers, where permitted by law.
We only process your personal data where one of the six lawful bases under GDPR applies:
We utilise collected personal data for the following core purposes:
Certain personal data fields are marked mandatory during registration, checkout or contact form completion. If you refuse to provide required information:
Non-mandatory optional fields (such as demographic profiling information) can be left blank with no impact on core service access.
We only disclose your personal data to third parties in limited, regulated circumstances:
Data shared within our media group brands (This is Money, Metro, The i paper) for unified account management and cross-brand marketing where consent is held.
Payment processors, cloud hosting platforms, email delivery services, fraud detection tools and customer support outsourcing firms, bound by strict data processing contracts.
Anonymised or pseudonymised user behaviour data shared with ad networks, social media platforms and audience measurement tools for personalised advertising.
Data released to courts, police, tax authorities and regulatory bodies when legally compelled by valid court orders or statutory obligations.
In the event of a company sale, merger or acquisition, user data will form part of transferred business assets subject to ongoing data protection rules.
Some of our data processors and advertising partners operate outside the UK and European Economic Area (EEA), including the United States, Brazil, Australia and Canada.
When transferring personal data to countries without adequate data protection recognition by the UK ICO or European Commission, we implement formal legal safeguards:
Full copies of our data transfer agreements can be requested via our data protection contact email listed in section 18.
Where we operate co-branded campaigns, joint competitions or shared advertising tools alongside external partner companies, we act as joint data controllers alongside those third parties.
Joint controller agreements clearly define split responsibilities for meeting GDPR obligations, including responding to user data rights requests, maintaining data security and issuing privacy notices to participants.
For any joint processing activity, you may submit all data subject rights requests either to us or the partner joint controller, and both parties are legally obligated to resolve your enquiry within statutory response timescales.
Under UK and EU GDPR legislation you hold the following enforceable data subject rights:
You may submit a GDPR rights request using our dedicated privacy contact channel shown in section 18. We will respond to valid requests within one calendar month.
Users residing in qualifying US states hold additional privacy rights under local consumer data statutes including California’s CCPA/CPRA, Virginia CDPA, Colorado CPA, Utah CPA and Connecticut CTDPA.
Do Not Sell My Personal Information requests can be submitted directly via our website footer link or our privacy support email address.
Visitors and subscribers located in Brazil are protected under the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, LGPD).
Your LGPD data rights mirror many GDPR provisions, with additional local requirements including:
All LGPD requests submitted to our team will be managed in compliance with Brazilian data protection regulatory deadlines.
We only retain your personal data for the minimum period necessary to fulfil the purposes we collected it for, as follows:
When you submit an account deletion request, we erase all recoverable personal data within 30 days, save for mandatory legal retention exceptions.
Our website, subscription services and digital platforms are intended for general adult audiences aged 16 years and older.
We do not knowingly collect or intentionally solicit personal identifiable information from users under the age of 16. If we become aware we have received data from a child under 16 without verified parental consent, we will immediately delete all such records.
If you are a parent or legal guardian and believe we hold data belonging to your minor child, please contact our data protection team via the contact details in section 18 to request full removal.
We deploy cookies, pixel tags, local storage identifiers and device tracking tokens across all our websites and mobile applications to operate core site functionality, measure audience engagement and deliver personalised advertising.
You can fully adjust your cookie consent preferences via the pop-up banner displayed on your first site visit, or clear stored browser cookies manually through your device settings at any time.
We maintain robust technical, administrative and physical security safeguards to prevent unauthorised access, loss, alteration or unlawful disclosure of your personal data:
Whilst we deploy industry-standard protective measures, no internet-based data transmission or digital storage system can be guaranteed 100% secure against unknown cyber threats.
We reserve the right to revise and update this Privacy & Cookies Policy periodically to reflect changes in our data processing practices, new legal regulatory requirements or platform service feature updates.
All material changes to the Policy will be clearly highlighted on our website homepage and within logged-in user account dashboards ahead of the revised terms taking effect. Minor administrative amendments will only be updated on this page with a new "Last updated" date marker.
Your continued use of DailyGmail services after an updated Policy publication date constitutes acceptance of the revised data privacy rules. We encourage you to review this page every 3 months to stay informed of adjustments.
For all GDPR, CCPA, LGPD data subject rights requests, cookie policy questions or privacy complaints, email our dedicated data protection team at privacy@dailygmail.co.uk
For subscription billing, account technical faults and editorial feedback: community@dailygmail.co.uk
Associated Newspapers Limited
Northcliffe House
9 Derry Street
London W8 5HY
United Kingdom
If you are dissatisfied with our response to your privacy request, you hold the right to submit a formal complaint to your local data protection authority (the UK Information Commissioner’s Office for UK residents).