GDPR for Musicians: Collecting Emails at Gigs, Legally
2026-08-13 · 4 min read

An email list is the most valuable audience asset an artist can own. In the UK it's also regulated by two sets of rules, and the one people miss is the one that matters most.
General information, not legal advice. The ICO is the UK regulator and its guidance is the authoritative source.
GDPR and PECR do different jobs
- UK GDPR governs how you handle personal data: lawful basis, transparency, security, people's rights over their data.
- PECR — the Privacy and Electronic Communications Regulations — governs the sending of marketing messages.
Both apply. And here's the trap: legitimate interest is not an available basis under PECR for marketing email to individuals. Plenty of people document a GDPR legitimate-interest assessment, conclude they're covered, and are not — because PECR still requires consent or the soft opt-in.
What valid consent looks like
Consent must be specific (they agreed to hear from you, not from unspecified third parties), informed (they knew what they were agreeing to), and given by a clear affirmative action. Not pre-ticked boxes. Not bundled into something else.
And you must be able to demonstrate it. That means recording, per contact: the wording they agreed to, the date, and the mechanism — the sign-up form, the QR page, the paper sheet. A subscribe flag in your mailing platform is not evidence of consent; it's evidence that someone is on a list.
The soft opt-in
One narrow exception. If you obtained the address in the course of a sale or negotiation — someone bought a ticket or merch — you may market similar products or services to them without separate consent, provided you offered an opt-out at the point of collection and include one in every message.
It's genuinely useful for artists selling merch and tickets, and it's narrower than people assume. It doesn't cover an address written on a sheet at a gig by someone who bought nothing.
Running a lawful sign-up at a show
- Say what they're signing up for, at the point of signing. "Tour dates and new music from [artist]" on the sheet or the screen. That sentence is the wording you're recording consent against.
- Don't pre-tick anything, and don't make the list a condition of a competition entry unless that's clearly stated.
- Record when and how. A paper sheet should be dated and kept; a digital form should timestamp automatically.
- Include an unsubscribe in every message, and honour it promptly.
- Handle the data properly — don't leave a sheet of email addresses on the merch table, and don't share the list with promoters or other bands. That would be a separate processing purpose the fans never agreed to.
- A QR code to a sign-up page beats paper, because it captures the wording, the timestamp and the mechanism automatically — which is exactly what you have to be able to demonstrate.
Consequences and proportion
Enforcement against small artists is rare, and the point of this isn't fear. It's that the practices which make you compliant are also the practices that make a list *work*: people who knowingly opted in open your emails, and people who didn't mark you as spam, which damages your delivery to everyone else.
Capture it in a way that records itself
Musavise's fan list tool captures fans through a hosted sign-up page and QR code with the source and timestamp recorded per contact, keeps the list yours, and exports it whenever you want — no cap on how many fans you capture, and no charge for the capture. Which means the consent record exists as a byproduct of collecting the address rather than as a thing you'd have to reconstruct.
All of it lives in one free Musavise account — free means free, within honest limits, and your data exports whenever you want it. Create your free account; it takes about two minutes.
Stop reading about it — do it. Every tool mentioned here is free.
Get your free toolkit