GDPR Compliance Statement of Megri.com
Last updated: September 6, 2026
Megri.com respects the privacy and data-protection rights of its readers. This GDPR Compliance Statement explains how Megri.com approaches its responsibilities under the European Union General Data Protection Regulation, the United Kingdom General Data Protection Regulation and related data-protection laws.
In this Statement:
- EU GDPR means Regulation (EU) 2016/679.
- UK GDPR means the GDPR as incorporated into United Kingdom law.
- Personal data means information relating to an identified or identifiable living person.
- Processing includes collecting, recording, organizing, storing, using, sharing, altering or deleting personal data.
This Statement supplements our Privacy Policy. If there is any conflict, applicable data-protection law takes priority.
1. About Megri.com
Megri.com is an online digital publication producing news, features, guides, reviews, comparisons, opinions and other editorial content through its own editorial team.
For privacy questions and data-protection requests, contact:
Megri Legal Team
Email: legal@megri.com
Contact page: https://www.megri.com/contact
Home page: https://www.megri.com/
The Megri Legal Team is the contact point for GDPR-related enquiries. This Statement does not describe the Legal Team as a formally appointed Data Protection Officer.
2. Scope of This Statement
This Statement applies where the EU GDPR, UK GDPR or another relevant European data-protection law applies to Megri.com’s processing of personal data.
It may apply when an individual in the UK or EEA:
- Visits or browses Megri.com.
- Reads, searches, shares or interacts with content.
- Creates or uses an account, where available.
- Subscribes to a newsletter.
- Submits a comment or reader response.
- Contacts Megri.com.
- Submits a correction, privacy, copyright or legal request.
- Interacts with advertisements, sponsored content or affiliate links.
- Uses another Website feature involving personal data.
Some provisions of the GDPR may not apply to particular processing activities because of the nature, location or scope of the processing or because a lawful exemption applies.
3. Our Role as Data Controller
For personal data collected and used for Megri.com’s own Website, editorial, communication, security and administrative purposes, the publisher and operator of Megri.com generally determines why and how the information is processed and therefore acts as the data controller.
Certain service providers may process personal data on Megri.com’s behalf. These providers may act as data processors or, in some circumstances, as independent controllers under applicable law.
Third-party websites, advertising platforms and embedded services may determine their own purposes and means of processing. Their activities are governed by their respective privacy policies.
4. Data-Protection Principles
Where the GDPR applies, we aim to process personal data consistently with the following principles:
Lawfulness, Fairness and Transparency
Personal data should be processed under an appropriate legal basis and in a way that is fair and reasonably transparent.
Purpose Limitation
Personal data should be collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes unless permitted by law.
Data Minimization
We seek to collect personal data that is adequate, relevant and reasonably necessary for the relevant purpose.
Accuracy
We take reasonable steps to keep personal data accurate and, where necessary, current. Inaccurate information may be corrected or deleted where appropriate.
Storage Limitation
Personal data should not be retained in identifiable form for longer than reasonably necessary, subject to legal, security, editorial and recordkeeping requirements.
Integrity and Confidentiality
Reasonable technical and organizational measures should be used to protect personal data against unauthorized or unlawful processing, accidental loss, destruction or damage.
Accountability
We aim to maintain policies, practices and records appropriate to the nature and scope of our processing activities.
5. Categories of Personal Data
Depending on how you use Megri.com, we may process:
- Name and contact details.
- Email address.
- Username and account details.
- Password or authentication information in protected form.
- Newsletter and communication preferences.
- Comments and reader responses.
- Correspondence and enquiries.
- Correction, privacy, copyright and legal requests.
- Internet Protocol address.
- Browser and device information.
- General location derived from an IP address.
- Pages, articles and links viewed.
- Website searches and navigation activity.
- Cookie and similar technology identifiers.
- Advertising and affiliate interactions.
- Security, anti-spam and server-log information.
- Professional information voluntarily provided in an enquiry.
- Publicly available information used for editorial purposes.
- Other information you choose to provide.
Further details are available in our Privacy Policy.
6. Purposes of Processing
We may process personal data to:
- Operate and maintain Megri.com.
- Publish and deliver editorial content.
- Provide accounts and Website features.
- Authenticate users and protect accounts.
- Respond to enquiries and feedback.
- Review corrections and complaints.
- Process privacy, copyright and legal requests.
- Send newsletters and requested updates.
- Maintain communication preferences.
- Measure readership and content performance.
- Improve Website navigation, design and functionality.
- Deliver and measure advertising.
- Administer sponsored-content and affiliate arrangements.
- Detect spam, fraud, abuse and security threats.
- Diagnose technical problems.
- Maintain editorial, administrative and legal records.
- Enforce our Website policies.
- Protect our rights, readers, systems and property.
- Comply with legal and regulatory obligations.
- Establish, exercise or defend legal claims.
- Conduct journalism, reporting, commentary and public-interest publishing.
7. Legal Bases for Processing
The applicable legal basis depends on the information and the purpose for which it is used.
Consent
We may rely on consent when you:
- Accept non-essential cookies.
- Subscribe to optional newsletters or communications.
- Agree to a particular use of your information.
- Provide information for an optional feature.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing completed before consent was withdrawn.
Contract
We may process personal data when necessary to:
- Provide a service you requested.
- Manage an account or subscription.
- Fulfil our obligations under an agreement.
- Take steps at your request before entering into an agreement.
Legitimate Interests
We may rely on legitimate interests when processing is reasonably necessary for purposes such as:
- Operating and improving the Website.
- Understanding readership.
- Maintaining Website and account security.
- Preventing fraud, spam and abuse.
- Responding to ordinary communications.
- Maintaining editorial and business records.
- Protecting legal rights.
- Conducting appropriate editorial and publishing activities.
When relying on legitimate interests, we consider whether our interests are overridden by your interests, rights and freedoms.
Legal Obligation
We may process personal data when necessary to comply with a legal or regulatory obligation.
Legal Claims
We may process personal data where necessary to establish, exercise or defend legal claims.
Public Interest, Journalism and Freedom of Expression
Personal data may be processed for journalism, reporting, commentary, public-interest publishing, artistic or literary expression where permitted by applicable law.
8. Special-Category and Sensitive Data
Special-category data under the GDPR can include information concerning:
- Racial or ethnic origin.
- Political opinions.
- Religious or philosophical beliefs.
- Trade-union membership.
- Genetic or biometric identification.
- Health.
- Sex life or sexual orientation.
Megri.com does not generally request this information from ordinary Website visitors.
In limited circumstances, such information may be processed when:
- You have explicitly consented.
- The information has manifestly been made public by the individual.
- Processing is necessary for legal claims.
- Processing is permitted for journalism, freedom of expression or another substantial public-interest purpose.
- Another lawful condition applies.
Readers should not send sensitive personal data through ordinary email, public comments or unsecured forms unless it is necessary and appropriate.
9. Editorial and Journalistic Processing
Megri.com may process personal data for:
- News reporting.
- Journalism.
- Commentary.
- Reviews and analysis.
- Biographical content.
- Public-interest publishing.
- Editorial research.
- Corrections and archiving.
This information may come from official records, public statements, published interviews, research, public social media, company websites and other lawful sources.
Data-protection laws seek to balance privacy rights with freedom of expression and information. Accordingly, certain transparency requirements and individual rights may be restricted where a journalistic, artistic, literary, public-interest or freedom-of-expression exemption lawfully applies.
A request relating to published editorial content will be evaluated under applicable data-protection law and our Corrections Policy.
The GDPR does not necessarily require the removal of accurate and lawful editorial content merely because it is unfavourable or no longer preferred by the person concerned.
10. Cookies and Electronic Communications
Megri.com may use cookies and similar technologies for:
- Essential Website operation.
- Security.
- Account sessions.
- Preference storage.
- Analytics.
- Performance measurement.
- Embedded content.
- Advertising.
- Affiliate attribution.
Where required by applicable law, non-essential cookies will not be placed or accessed until valid consent has been obtained.
You may manage cookie preferences through the consent controls provided on the Website. You may also adjust browser settings, although doing so may affect Website functionality.
For information about cookie categories, purposes and durations, review our Cookie Policy.
11. Newsletters and Direct Communications
We may send newsletters or promotional communications where:
- You have provided consent.
- Another lawful basis permits the communication.
- The communication is otherwise allowed under applicable electronic-marketing rules.
You may unsubscribe at any time by:
- Selecting the unsubscribe link in an email.
- Changing available communication preferences.
- Contacting legal@megri.com.
We may retain limited suppression information after an unsubscribe request to ensure that the preference continues to be respected.
Necessary administrative, account, security or request-related communications may still be sent.
12. Advertising and Analytics
Megri.com may use analytics and advertising technologies to understand readership, improve content and support the operation of the Website.
Depending on consent and applicable law, these technologies may process:
- Online identifiers.
- Cookie identifiers.
- IP addresses.
- Browser and device information.
- Approximate location.
- Pages viewed.
- Advertising impressions.
- Link and advertisement interactions.
Non-essential analytics and advertising technologies may require consent in the UK and EEA.
Commercial relationships and advertising practices are described in our Advertising, Sponsored Content and Affiliate Disclosure.
13. Recipients of Personal Data
We may disclose personal data to:
- Website-hosting providers.
- Content-delivery networks.
- Cloud-storage and backup providers.
- Email and newsletter providers.
- Analytics providers.
- Security and anti-spam providers.
- Advertising and affiliate partners.
- Account-authentication providers.
- Technical-support providers.
- Lawyers, accountants, insurers and other professional advisers.
- Regulators, courts and public authorities where legally required.
- Parties involved in a merger, acquisition, reorganization or sale of assets.
- Other parties acting under your direction or consent.
Where a service provider processes personal data on our behalf, we seek to use appropriate contractual and organizational protections.
14. International Data Transfers
Megri.com serves an international audience. Personal data may be processed or stored in the United States, the United Kingdom, India or other countries where our technology and service providers operate.
Some receiving countries may not provide data-protection laws considered equivalent to those in the UK or EEA.
Where required, we may rely on safeguards such as:
- An adequacy decision.
- European Commission Standard Contractual Clauses.
- The UK International Data Transfer Agreement.
- The UK Addendum to Standard Contractual Clauses.
- Another legally recognized transfer mechanism.
- A permitted exception for a specific transfer.
Where appropriate, supplementary technical, contractual or organizational measures may also be considered.
15. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal, editorial, security and operational needs.
Retention periods depend on:
- The type of information.
- The purpose of processing.
- Whether an account remains active.
- Legal and regulatory requirements.
- Security and fraud-prevention needs.
- Editorial and journalistic recordkeeping.
- Existing or anticipated disputes.
- The need to establish, exercise or defend legal claims.
For example:
- Account information may be retained while an account is active and for a reasonable period afterward.
- Newsletter information may be retained until you unsubscribe, after which limited suppression information may remain.
- Enquiries may be retained while the matter is active and for a reasonable recordkeeping period.
- Security logs may be retained for a limited period unless needed for an investigation.
- Editorial records may be retained for corrections, source protection, publication history, public-interest archiving or legal claims.
- Cookie durations are described in the Cookie Policy.
Personal data may remain temporarily within protected backups until those backups are overwritten under normal procedures.
16. Data Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, misuse, loss or destruction.
These measures may include:
- Access controls.
- Encryption in transit.
- Secure hosting.
- Software updates.
- Data backups.
- Security monitoring.
- Anti-spam and fraud controls.
- Restrictions on access to personal data.
- Appropriate service-provider arrangements.
No Internet transmission or storage system can be guaranteed completely secure.
17. Personal Data Breaches
We evaluate suspected personal-data breaches to determine:
- What happened.
- What personal data was affected.
- The likely risk to individuals.
- What containment and remedial measures are appropriate.
- Whether notification is legally required.
Where a breach is reportable under applicable GDPR requirements, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it.
Where a reportable breach is likely to create a high risk to affected individuals, we will notify those individuals where required by law.
Not every security incident or personal-data breach requires regulatory or individual notification.
18. Your GDPR Rights
Subject to applicable law and any lawful exception, you may have the following rights:
Right to Be Informed
You have the right to receive information about how your personal data is processed.
Right of Access
You may request confirmation that we process your personal data and obtain a copy of certain personal data and related information.
Right to Rectification
You may request correction of inaccurate personal data or completion of incomplete personal data.
Right to Erasure
You may request deletion of personal data in certain circumstances.
This right is not absolute and may not apply where processing is necessary for legal compliance, journalism, freedom of expression, public-interest archiving or legal claims.
Right to Restrict Processing
You may request that processing be restricted in certain circumstances, including while the accuracy or lawfulness of processing is being reviewed.
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you may request certain personal data in a structured, commonly used and machine-readable format.
Right to Object
You may object to processing based on legitimate interests or a task in the public interest.
We may continue processing where compelling legitimate grounds override your interests, rights and freedoms or where processing is required for legal claims.
You may object to direct marketing at any time.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Rights Concerning Automated Decision-Making
You may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.
Megri.com does not currently use personal data to make solely automated decisions producing legal or similarly significant effects concerning ordinary readers.
Right to Complain
You may complain to a competent data-protection supervisory authority.
19. How to Exercise Your Rights
To submit a GDPR request, contact:
Megri Legal Team
Email: legal@megri.com
Use the subject line:
GDPR Data Request
Please provide:
- Your name.
- The right you wish to exercise.
- The email address or account associated with your interaction.
- Information reasonably necessary to identify the relevant data.
- Your country of residence where relevant.
We may request information reasonably necessary to verify your identity and protect personal data against unauthorized access or deletion.
Verification information will be used only to verify, process and document the request.
20. Response Times
We will respond to a valid request without undue delay and normally within one month of receipt, subject to identity verification and applicable law.
Where a request is complex or multiple requests have been made, the response period may be extended where legally permitted. If an extension is required, we will provide notice and an explanation.
We may refuse or charge a reasonable fee for a request where permitted by law, including when a request is manifestly unfounded or excessive.
If we decline or limit a request, we will explain the reason and available complaint rights where required.
21. Limits and Exemptions
GDPR rights are subject to limitations and exceptions.
We may be unable to fulfil all or part of a request where personal data is required for:
- Freedom of expression and information.
- Journalism.
- Public-interest reporting.
- Source confidentiality.
- Legal obligations.
- Public-interest archiving.
- Security and fraud prevention.
- The rights and freedoms of other individuals.
- Establishment, exercise or defence of legal claims.
Each request will be considered according to its circumstances and applicable law.
22. Children’s Privacy
Megri.com is a general-audience publication and is not directed to children.
We do not knowingly seek personal data from children under 13. Where European law requires parental authorization for a child’s consent to an online service, the applicable age may differ by country.
A parent or guardian who believes a child has submitted personal data may contact legal@megri.com.
23. Complaints to a Supervisory Authority
If you are in the United Kingdom, you may have the right to complain to the Information Commissioner’s Office:
https://ico.org.uk/make-a-complaint/
If you are in the EEA, you may complain to the supervisory authority in the country where you live, work or believe a data-protection infringement occurred.
A list of European data-protection authorities is available through the European Data Protection Board:
https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
We encourage you to contact the Megri Legal Team first so that we have an opportunity to review and address your concern.
24. Changes to This Statement
We may update this GDPR Compliance Statement to reflect changes in:
- Our Website and Services.
- Our processing practices.
- Privacy and advertising technologies.
- Applicable law or regulatory guidance.
- Security and operational requirements.
The revised Statement will be posted on this page with an updated “Last updated” date.
Where required, we will provide additional notice before personal data is used for a materially different purpose.
25. Related Policies
You may also review:
- Privacy Policy
- California Privacy Notice and CalOPPA Policy
- Cookie Policy
- Terms of Use
- General Disclaimer
- Copyright Statement
- Accessibility Statement
- Editorial Policy
- Corrections Policy
- AI Use Policy
- Advertising, Sponsored Content and Affiliate Disclosure
26. Contact Us
For questions, requests or concerns about this GDPR Compliance Statement, contact:
Megri Legal Team
Email: legal@megri.com
Contact page: https://www.megri.com/contact
Home page: https://www.megri.com/

