You Might Be a Winner
        A blog from the attorneys of Verrill

        How Will The General Data Protection Regulation Affect Your Sweepstakes Across the Pond

        by Robert Laplaca on April 16, 2018

        As was made pretty clear last week from the 1,400 hours of Congressional testimony by Mark Zuckerberg, the USA may want to follow the lead of the EU and adopt laws similar to the General Data Protection Regulation (GDPR). For now, if you are running a sweepstakes or contest open to EU residents, here are some things you need to know about the GDPR.

        What is the GDPR? The GDPR is a comprehensive regulation concerning the collection and use of online personal data.

        When does it come into effect? The GDPR becomes effective May 25, 2018.

        Who is protected? The GDPR protects data collection from residents of the European Union. In a sweepstakes or contest, this is the entrant.

        Who is covered? Any person or entity that holds or uses personal data. For a sweepstakes or contest, this could be the Sponsor or an entity collecting entry or other information from the entrants.

        What is covered? Personal data, which includes anything that can be used directly or indirectly to identify a person, such as a name, photo, email or street address, posts on websites, and computer IP addresses.

        What to do for Sweepstakes and Contests?

        The GDPR does not contain any specific terms covering sweepstakes and contests. However, a Sponsor should be aware of three particular areas: having a GDPR-compliant privacy policy/website, obtaining proper consent, and proper data handling.

        Privacy Policy Compliance

        The Sponsor must have a GDPR-compliant privacy policy, clearly available to the entrant. The stated purposes of a privacy policy under the GDPR are transparency, consent and accountability. The topics to be covered in your privacy policy include: What personal information you collect; How and why you collect it; How you use it; How you secure it; Any third parties with access to it; If you use cookies; How users can control any aspects of this.

        The following information must be in your privacy policy: Contact information for your Data Controller; Whether you use data to make automated decisions; Whether providing data is mandatory; Whether you transfer data internally; Legal basis for processing data; Informing users of their 8 rights (The rights to be informed, to access, to rectification, to erasure, to restrict processing, to object, and regarding automated decision making and profiling).

        Consent

        When collecting any personal data online:

        1. The Sponsor can only collect what is necessary to administer the contest, such as name, address, phone or email, without obtaining specific consent.

        2. The Sponsor must provide the entrant with the specific option to opt-in to any use of the entrant’s personal data, besides using it for administration of the contest. (The Sponsor cannot use a negative option or require a person to opt-out.)

        3. The Sponsor must give the entrant the ability to opt-in to each specific use/purpose for which the data is proposed to be used, which must be stated separately, in easy to understand language.

        4. The Sponsor must inform the entrant that he/she can withdraw consent at any time and provide an easy method to do so.

        5. Without obtaining specific consent for use of a person’s personal data, the Sponsor can only use the personal data for the limited purpose for which it was given and must delete the personal data after its purpose is completed.

        Official Rules

        While the GDPR does not offer specific guidance for necessary disclosures in the Official Rules, the following paragraph may be sufficient for GDPR purposes:

        Privacy Notice for EU residents: The General Data Protection Regulation (GDPR) provides a number of protections for use of your personal data. Any personal data collected from you shall be subject to the Sponsor’s privacy policy located at the GDPR. The Sponsor will only use your personal data for the purposes of administrating this contest, unless you provide consent signifying your agreement to any other processing or use of your personal data. You can withdraw your consent at any time.

        One final note, the GDPR contains specific restrictions for obtaining consent and using data from persons under 16 years of age, including obtaining parental consent.

        Now, wasn’t that simple?

        You Might Be a Winner

        Promotion and sweepstakes laws vary widely across the fifty states and under federal regulations, creating complex challenges for today’s innovative marketers. This blog explores the latest updates and trends in promotion and marketing law, offering practical insights to help brands stay compliant while pushing creative boundaries. We’ll also discuss noteworthy, questionable, and groundbreaking promotional campaigns to encourage thoughtful discussion among marketing and legal professionals.

        Key Contacts

        Subscribe

        Looking for more great content? Subscribe for regular legal updates and information delivered right to your inbox.

        Firm Highlights

        Blog

        What is a Bonus for Purposes of ERISA?

        An ongoing dispute about a Department of Labor advisory opinion published last September raises a basic but unanswered question under the ERISA: What...
        Media Mentions

        Verrill Recognized by WMTW for Partnership Supporting Hunger Relief in Maine

        Verrill was recently featured in coverage by WMTW News 8 for its role in a collaborative effort to combat food insecurity across southern...
        Press Releases

        33 Verrill Attorneys, Across Four Offices, Recognized in the 2026 Chambers USA Guide

        BOSTON, Massachusetts, PORTLAND, Maine, WESTPORT, Connecticut, and WASHINGTON, D.C. – Verrill has been recognized as a Leading Firm in 14...
        Blog

        Will the Knicks Beat the Spurs? (Are Prediction Market Event Contracts Gambling?)

        For those of you who like to keep score, currently 18 states are engaged in litigation over prediction markets, such as Kalshi and Polymarket,...
        Alerts and Newsletters

        DOJ Announces Faster Review and Enhanced Enforcement for Benefits-Fraud FCA Matters

        On May 27, 2026, the U.S. Department of Justice (DOJ) Civil Division issued a new memorandum, “Accelerating Review and Enhancing Enforcement in...
        Alerts and Newsletters

        DOJ Announces Minnesota Health Care Fraud Takedown; Signals Intensified Medicaid Enforcement Nationwide

        On May 21, the Department of Justice (“DOJ”) announced a first-of-its kind Minnesota Health Care Fraud Takedown charging 15 defendants, including...
        Media Mentions

        Lauren Galvin Quoted in Massachusetts Lawyers Weekly on Arbitration and Anti-SLAPP Protections

        Verrill Partner Lauren Galvin was recently featured in a Massachusetts Lawyers Weekly article highlighting a notable Superior Court decision...
        Blog

        Section 530A Accounts: What Employers Should Consider Before Offering Contributions to “Trump” Accounts

        Section 530A accounts, commonly referred to as Trump accounts, have attracted attention since the enactment of the One Big Beautiful Bill Act in...
        Blog

        Navigating PBM Reform: Regulatory Changes, Market Shifts, and Practical Guidance for ERISA Fiduciaries

        Pharmacy Benefit Manager (“PBM”) arrangements have long relied on rebates with limited transparency into true drug costs. Recent regulatory and...
        Blog

        DOL’s Proposed Regulation on Selecting Alternative Investments: Broad Implications for 401(k) and 403(b) Plan Fiduciaries

        On March 30, 2026, the Department of Labor issued a proposed regulation purporting to implement an executive order to expand access to “alternative...
        Press Releases

        Verrill Welcomes Private Clients & Fiduciary Services Attorney Gracie Castle

        BOSTON, Massachusetts – Verrill is pleased to welcome Gracie Castle to the firm’s Private Clients & Fiduciary Services Group as an Associate,...
        Published Works

        Francesco De Vito Authors Article in the Journal of the American College of Mortgage Attorneys

        Verrill Partner Frank De Vito authored an article featured in the Spring 2026 issue of The Abstract, the journal of the American College of Mortgage...