Almost every argument about fan data collapses two different legal questions into one. They have different answers, and the answer changes by territory.
Two tracks, not one
The first track is direct marketing: email, SMS, anything addressed to a named person asking them to do something. That requires an opt-in, and the opt-in is locked to whoever the fan said yes to.
The second track is analytics and paid audiences: custom audiences, lookalike modelling, attribution, segmentation, market sizing. In the United States and most non-EU markets, this does not require a direct opt-in. It can run on legitimate interest, on an opt-out basis, with appropriate disclosure. Most of the operational value of fan data in those markets sits here.
The shortcut that does not work
A common move is to assume that naming the artist as a joint controller hands them a usable list. It does not. Joint control defines shared obligations over a shared dataset for one purpose. It does not give either party independent rights outside that purpose. Any use beyond the joint scope needs fresh consent.
In the EU, both tracks become consent
The two-track frame holds in the US and most non-EU jurisdictions. In the EU it does not, for two reasons.
First, the ePrivacy Directive acts as the controlling rule for anything that touches a user’s device. Storing or reading information on someone’s device needs prior consent, and legitimate interest is not a valid substitute. EU guidance finalised in 2024 extended this explicitly to tracking pixels, tracking links, and fingerprinting. The ad pixel firing on a ticket page sits squarely inside that scope.
Second, the Court of Justice of the EU ruled in 2023 that legitimate interest cannot justify processing personal data for personalised advertising. Regulators have applied the same reasoning to the businesses using the large platforms’ ad tools. A separate ruling on custom audiences held that sending hashed email addresses to an ad platform is a controller-to-controller transfer that needs consent, because hashing does not anonymise when the platform can match the identifiers against its own users.
Why this changes the artist’s position
The practical consequence is large. In the EU, the artist’s independent opt-in is no longer just the long-term play for email. It becomes the only lawful basis for the audience layer too. Custom audiences from ticket-buyer lists, pixel-based retargeting, lookalike seeding: none of it runs on legitimate interest in the EU.
That also flips the negotiation. A partner cannot lawfully run the pixel and custom-audience layer at scale without consent at the source. An artist who arrives with clean consent infrastructure is not asking for a concession. They are offering the only path to lawful targeting that exists. The ask is one opt-in covering two named uses, direct marketing and analytics, with the artist’s data entity as controller for both.


