The question arrives weekly from French, Belgian and Swiss comms teams discovering our platform: is media monitoring compatible with GDPR? The short answer is yes — when it is designed to be. The long answer is this guide: what the regulation actually imposes on a team that monitors media, where the real risk zones sit, and how to structure a compliance programme that stands up in front of a regulator rather than a salesperson.
A framing note first: this guide is an operational reading by a practitioner, not legal advice. Your context — status, country, data processed — deserves your counsel's analysis.
What GDPR actually says to media monitoring
GDPR applies to the processing of personal data, not to the news in general. Reading Le Monde, watching the RSS feed of a business daily, or archiving articles published on a news site does not in itself fall under the regulation: these are published journalistic works, and the European framework broadly protects the freedom to receive and communicate information. Brand monitoring — following what the media write about a company, a product, an organization — is the legitimate core of the profession and typically rests on legitimate interest, documented and proportionate.
The boundary moves as soon as the target becomes a person. Measuring sentiment towards a bank and measuring sentiment towards its CEO are two very different processings: the second constitutes a systematic evaluation of an identified natural person — sometimes profiling in the regulation's sense — and requires a solid legal basis, an explicit purpose, and most often an impact assessment. This is where comms teams inadvertently put themselves at risk.
The three risk zones of a monitoring apparatus
1. Sentiment on named individuals
Following the media coverage of an executive quoted about their company is a classic, defensible use; building a reputation barometer on journalists, trade unionists, activists or whistleblowers is a full personal-data processing, with heavy obligations. Our design rule at Harch Atelier is radical: the platform measures brands, not people. Individuals appear only as article authors or quoted spokespeople, never as scored entities.
2. Automated collection of public content
Public data remains personal data. The French doctrine on automated extraction of publicly available data — developed notably by the CNIL in its guidelines on web scraping — reminds us that a page's being public does not neutralize purpose, minimization, or the information of data subjects. A monitoring apparatus that indiscriminately ingests social profiles and nominative comments beyond what its purpose justifies exposes itself to sanctions. Monitoring press sources through their public feeds is the most sober path.
3. Retention and access
The most underestimated risk is trivial: a monitoring database that grows indefinitely, browsable by interns, containing years of nominative articles and internal notes. Defined retention periods, actual deletion, access logging, per-client segmentation: it is unglamorous, and it is exactly what a regulator checks first.
France, Belgium, Switzerland: the specifics
For a team based in Brussels, Geneva or Paris, the structuring point is the same: GDPR applies as soon as the establishment is in the Union or the processing targets people located there — and monitoring practices inherited from the paper press-clipping era must be rebuilt with minimization rules in mind.
The seven-point compliance programme
- Register every monitoring apparatus in your processing inventory, with a purpose stated in one intelligible sentence.
- Document the legal basis — most often legitimate interest — with the corresponding balancing test.
- Ban person-scoring: measure organizations, not individuals; if executive tracking is genuinely necessary, limit it strictly to their public function.
- Run an impact assessment as soon as the apparatus profiles, crosses or evaluates people at scale.
- Set differentiated retention periods — articles, aggregated metrics, internal notes — and actually enforce them.
- Contract with vendors under Article 28: a data processing agreement, an identified data location, known sub-processors.
- Train the teams: GDPR risk is rarely born in the tool, almost always in the improvised use a rushed employee makes of it.
What this changes about the tool's architecture
Compliance is not a legal varnish applied after the fact: it is designed in. At Harch Atelier, it shaped precise engineering choices — sentiment is measured at brand level and aggregated, never as an individual profile; sources are public media feeds, not private spaces; European customer data is hosted in the Union with access logging; and the processing documentation is part of delivery, not of dissertation. A European buyer should ask these questions of any vendor, and expect precise answers.
Compliance done well is not a brake on monitoring — it is what makes it durable: an apparatus you can show a regulator is an apparatus you can show a client, a journalist and a board. European comms teams that have internalized this treat data protection as a design requirement, and sleep better through their crises — which are numerous enough to fill the nights without that.