Subscribe
Learn Library

Marketing Agencies, Listen Up: In the Eyes of GDPR, You May Not Be the "Outsider" — You May Be an "Accomplice"

A while back, a friend of mine who runs an agency came to me venting.

ads
2026-08-21SupaMarketers7 min read

A while back, a friend of mine who runs an agency came to me venting.

He owns a marketing shop of about twenty-plus people with a dozen or so clients. One day, a client's legal counsel sent an email asking: did your ad strategists define the Facebook Lookalike Audiences themselves? Was it your people who configured the tracking pixels?

He said, sure, that's just how we do the work.

The lawyer replied with a sentence that kept him up at night: "Then you're not a 'processor' — you're a 'joint controller.' If something goes wrong, you share the liability."

He came to me asking: what does that mean? How did my small agency end up in the same boat as its clients?

I said, don't panic. This deserves a proper walkthrough.

What Is a "Controller"?

GDPR defines two roles, and many agencies have never sorted out the difference.

One is the "processor." Simply put, you're the vendor following instructions: the client hands you the list and the copy, and you send the emails accordingly. In that scenario your responsibility is light — keep security tight and follow the documented instructions.

The other is the "controller." The moment you make decisions about "why the data is processed and how it is processed," you are a controller. It has nothing whatsoever to do with what the contract says.

Think about what agencies do every single day.

Ad strategists define targeting conditions, media buyers deploy tracking pixels, optimizers tweak the algorithms. Every one of those is a "decision."

The European Data Protection Board (EDPB) has said it plainly: the moment an agency sets ad-targeting parameters, it becomes a joint controller together with the client and the platform. The legal basis is Article 26 GDPR, and the liability is joint and several.

You think you're the hands that execute. In the regulator's eyes, you're the brain that decides.

My friend only learned about this after receiving his first regulatory complaint. That's how it goes for most agencies.

One Pixel, Times Fifty

The agency business has another deadly trait: leverage.

What do I mean? If your own tracking pixel gets misconfigured and deployed across 50 client websites, that's 50 potential violations. If a consent management platform (CMP) fails to block cookies before the user says yes, then every client gets hit at once.

More leverage means more ways for things to go wrong.

Let me count a few traps unique to agencies:

Departed employees still hold access to client platforms. Those "orphaned accounts" sit scattered across CRMs, ad accounts, and analytics tools, with nobody watching them.

The tools the agency itself uses — reporting dashboards, data warehouses, optimization platforms — are all "sub-processors" the client never approved. The contract lists the client's systems and somehow omits the agency's own kit.

Employees download client lists into local spreadsheets. The campaign ends; the spreadsheet lives on. The pixel stays on the website, quietly collecting data.

Individually, each of these looks small. But when a regulator comes knocking, they don't look at one incident — they look at your entire client portfolio. The same compliance failure recurring across several clients isn't bad luck; it's a systemic problem in your organization. Fines and enforcement orders will land together.

Okay, so what do you do? Start with the most basic thing: consent.

Cookies are actually governed by two layers. One is the ePrivacy Directive (as implemented in national law, such as the UK's PECR), and the other is GDPR. Here's the interesting part: even where GDPR might allow "legitimate interests," ePrivacy still requires that non-essential cookies obtain consent first, before they load.

Valid consent has four requirements: freely given, specific, informed, and unambiguous. Pre-ticked boxes, "cookie walls" that block entry until you click, and vague wording are all invalid. And the burden of proof is on you.

What's the most common way this goes wrong? The banner is still asking while the pixels are already firing. Before the user clicks "agree," analytics and advertising scripts have already loaded. Automated scanners catch this every time.

Consent must also be granular. Analytics is analytics, advertising is advertising, social media is social media. Bundle everything into one master switch? Not allowed — that in itself is a violation.

Now, about Google. As of 2026, if you run Google Ads or Analytics with traffic from the EEA or the UK, Consent Mode v2 is no longer optional. A certified CMP must be able to send those signals: ad_storage, ad_personalization, analytics_storage. Misconfigure it and your conversion data goes dark and your remarketing audiences stop working. And the integration between the CMP and Google tags has to be explicitly configured — it does not work automatically. This is the platform enforcing compliance on the regulator's behalf: fail the standard, lose functionality first, fines later.

You Can't Do This by Hand

At this point you might be thinking: fine, I get it, but I manage dozens of client websites — surely I can't check each one manually every day?

Right. You can't.

And that's the point I want to make: manual compliance doesn't scale.

Consent logs in Excel can't keep up with the real-time consent status of 50 websites. Manual cookie audits won't catch the consent script a client deleted during a site redesign. A hand-maintained sub-processor list is outdated the day you finish writing it. Someone who can still log into client systems six months after leaving can't be caught by a quarterly review.

So when my friend came back last month, my advice came down to three lines:

First, consolidate identities. Stop sharing logins and passwords. Use Meta Business Manager's partner access, use Google Ads manager accounts, and give the agency a dedicated role in the CRM with clearly documented permissions. When the project ends, access expires and is automatically revoked. When an employee leaves, one SSO switch cuts them off across every platform at once.

Second, get the paperwork in order. Sign an Article 28 DPA with every client; declare your own tools where required (Supermetrics, data warehouses — they all count as sub-processors, and any addition triggers a 30-day client objection window); maintain two sets of records of processing activities (RoPA) — one for your company's internal processing and one for the work you do for clients; for international data transfers, US tools go through SCCs where required, and do a TIA where needed. The Irish DPC demands RoPA production within 10 days — if your documents live scattered across inboxes, spreadsheets, and chat logs, you'll never make it in time.

Third, keep the evidence. Timestamped consent logs: who consented, when, to which version of the privacy policy, and through which mechanism. If any of this is ever challenged, this is your lifeline. One focus of EU regulators in recent years is the "right to be forgotten" — when a user asks for deletion, you must be able to actually delete their data from every sub-processor, report, backup, and test environment. Exported CSVs and shadow IT are the easiest blind spots to miss.

Finally

How big are the fines? €20 million, or 4% of global annual turnover, whichever is higher. A joint-controller arrangement also means the client can come after you for indemnification.

But my friend later told me something that stuck with me. He said he turned his compliance reporting into a monthly dashboard sent to clients — consent rates, cookie compliance scores, sub-processor changes, DSR response times — and during a pitch, a new client brought it up specifically, saying that dashboard was exactly why they chose his agency.

You see, compliance isn't a cost. It's a selling point.

Clients have been nervous all along; they want an agency that genuinely takes data seriously. Whoever gets there first earns the trust first.

Starting today, pull out your pixels, your accounts, and your contracts, and run them against those three lines.

Don't wait for the complaint letter to do it for you.