HARCHAtelier
Skip to main content
HARCHAtelier
Sign inPricing
Request a demo
← Back to blog
Regulation

GDPR and Media Monitoring: A Compliance Guide for European Comms Teams

Monitoring brands is lawful; profiling named individuals is a very different story. What GDPR actually requires from media monitoring, the French, Belgian and Swiss specifics, and the seven-point compliance programme we recommend.

CD
Camille Duvernay
Data Protection & Compliance Lead, Harch Atelier
September 4, 2026·12 min read

The question arrives weekly from French, Belgian and Swiss comms teams discovering our platform: is media monitoring compatible with GDPR? The short answer is yes — when it is designed to be. The long answer is this guide: what the regulation actually imposes on a team that monitors media, where the real risk zones sit, and how to structure a compliance programme that stands up in front of a regulator rather than a salesperson.

A framing note first: this guide is an operational reading by a practitioner, not legal advice. Your context — status, country, data processed — deserves your counsel's analysis.

What GDPR actually says to media monitoring

GDPR applies to the processing of personal data, not to the news in general. Reading Le Monde, watching the RSS feed of a business daily, or archiving articles published on a news site does not in itself fall under the regulation: these are published journalistic works, and the European framework broadly protects the freedom to receive and communicate information. Brand monitoring — following what the media write about a company, a product, an organization — is the legitimate core of the profession and typically rests on legitimate interest, documented and proportionate.

The boundary moves as soon as the target becomes a person. Measuring sentiment towards a bank and measuring sentiment towards its CEO are two very different processings: the second constitutes a systematic evaluation of an identified natural person — sometimes profiling in the regulation's sense — and requires a solid legal basis, an explicit purpose, and most often an impact assessment. This is where comms teams inadvertently put themselves at risk.

The three risk zones of a monitoring apparatus

1. Sentiment on named individuals

Following the media coverage of an executive quoted about their company is a classic, defensible use; building a reputation barometer on journalists, trade unionists, activists or whistleblowers is a full personal-data processing, with heavy obligations. Our design rule at Harch Atelier is radical: the platform measures brands, not people. Individuals appear only as article authors or quoted spokespeople, never as scored entities.

2. Automated collection of public content

Public data remains personal data. The French doctrine on automated extraction of publicly available data — developed notably by the CNIL in its guidelines on web scraping — reminds us that a page's being public does not neutralize purpose, minimization, or the information of data subjects. A monitoring apparatus that indiscriminately ingests social profiles and nominative comments beyond what its purpose justifies exposes itself to sanctions. Monitoring press sources through their public feeds is the most sober path.

3. Retention and access

The most underestimated risk is trivial: a monitoring database that grows indefinitely, browsable by interns, containing years of nominative articles and internal notes. Defined retention periods, actual deletion, access logging, per-client segmentation: it is unglamorous, and it is exactly what a regulator checks first.

France, Belgium, Switzerland: the specifics

JurisdictionAuthorityWatch-points for media monitoring
FranceCNILDetailed doctrine on automated collection of public data; a track record of controls on reputation-management tools; exemplary sanctions for excessive profiling.
BelgiumAPD / Data Protection AuthorityDense ecosystem of agencies and public-affairs consultancies; the DPA has sanctioned surveillance of public figures; watch in-house social monitoring tools.
SwitzerlandFederal Data Protection and Information CommissionerRevised framework in force since 2023: principles close to GDPR for actors serving the EU; Switzerland is not bound by the regulation, but groups active on the European market align their processing in practice.
Operational view, not exhaustive; frameworks keep evolving.

For a team based in Brussels, Geneva or Paris, the structuring point is the same: GDPR applies as soon as the establishment is in the Union or the processing targets people located there — and monitoring practices inherited from the paper press-clipping era must be rebuilt with minimization rules in mind.

The seven-point compliance programme

  1. 1Register every monitoring apparatus in your processing inventory, with a purpose stated in one intelligible sentence.
  2. 2Document the legal basis — most often legitimate interest — with the corresponding balancing test.
  3. 3Ban person-scoring: measure organizations, not individuals; if executive tracking is genuinely necessary, limit it strictly to their public function.
  4. 4Run an impact assessment as soon as the apparatus profiles, crosses or evaluates people at scale.
  5. 5Set differentiated retention periods — articles, aggregated metrics, internal notes — and actually enforce them.
  6. 6Contract with vendors under Article 28: a data processing agreement, an identified data location, known sub-processors.
  7. 7Train the teams: GDPR risk is rarely born in the tool, almost always in the improvised use a rushed employee makes of it.

What this changes about the tool's architecture

Compliance is not a legal varnish applied after the fact: it is designed in. At Harch Atelier, it shaped precise engineering choices — sentiment is measured at brand level and aggregated, never as an individual profile; sources are public media feeds, not private spaces; European customer data is hosted in the Union with access logging; and the processing documentation is part of delivery, not of dissertation. A European buyer should ask these questions of any vendor, and expect precise answers.

→
The three questions to ask your vendor
Where is the data hosted and processed? Does the scoring target organizations or people? What happens to my data at the end of the contract? Three vague answers equal one leak.
Indicative split of obligations in a compliant monitoring apparatus (illustrative)
7 points
programme
Minimization & purpose30%
Security & access25%
Contracting20%
Retention15%
Documentation10%

Compliance done well is not a brake on monitoring — it is what makes it durable: an apparatus you can show a regulator is an apparatus you can show a client, a journalist and a board. European comms teams that have internalized this treat data protection as a design requirement, and sleep better through their crises — which are numerous enough to fill the nights without that.

Tags
#GDPR#compliance#media monitoring#CNIL#Belgian DPA#Swiss FADP#communications#DPO#Europe
CD
Written by

Camille Duvernay

Data Protection & Compliance Lead, Harch Atelier

Camille runs Harch Atelier's data protection programme. She spent six years guiding Franco-Belgian scale-ups through GDPR compliance as a data protection officer.

Get your reputation audit →

A board-ready audit of how your company is perceived across 30+ media sources, 8 AI engines and the social conversation — in Darija, French and English. 5 minutes to request. 7 days to deliver.

Request my free audit →
Related articles

Keep reading.

Regulation12 min read

Regulatory Risk Radar: 12 Moroccan Regulators You Need to Monitor

BAM, AMMC, ANRT, ONSSA, ANAC, CNDP and six more — their 2026 priorities, recent actions, and the reputation risks they create for the companies they supervise.

Read →
Industry Analysis12 min read

Reputation Risk in Moroccan Banking: Why 2026 Is a Pivotal Year

BAM is tightening AML rules, fines are rising, and digital channels are amplifying every misstep. We map how the five largest Moroccan banks are positioned heading into 2026.

Read →
ESG11 min read

ESG Reporting in Morocco: From Compliance to Competitive Advantage

Loi 30-21 turns ESG disclosure into law for listed Moroccan companies. OCP's green ammonia and Bank of Africa's sustainable finance frame show how leaders are turning obligation into advantage.

Read →
Checking…
Initializing…
HARCH|Atelier

AI Reputation Intelligence — Africa & the French-speaking world.

atelier@harchcorp.com·+212 684 440 682
→ harchcorp.com
Navigation
ProductsSolutionsDecision AugmentationPricingRequest demoAbout
Products
Reputation Intelligence PlatformAPI & MCP IntegrationsInsight ReportsAdvanced DashboardsNewsletters & Briefings
Tools
★ Flagship Report 2026Harch 100 RankingRisk TrackerConsoleReport TemplatesInstitutional Audit
Resources
All resourcesFlagship Report 20262026 Media ReportCase studiesMethodologyFAQ
Company
About usCareersPartnersContactTrust CenterResilience MatrixLegal
8 francophone markets covered
FR
France
Paris · Lyon · Marseille
MA
Morocco
Casablanca · Rabat · Marrakech
BE
Belgium
Brussels · Antwerp
CH
Switzerland
Geneva · Lausanne · Zurich
QC
Quebec
Montreal · Quebec City
TN
Tunisia
Tunis · Sfax
LB
Lebanon
Beirut
SN
Senegal
Dakar
Building in Public, since 2026 · Casablanca, Morocco
Harch Atelier is a Harch Corp venture · Bank transfer