Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Common Mistakes With Data Processing Agreement Marketing Agencies
- Treating every agency as a processor
- Relying on standard platform terms without mapping the full chain
- Leaving the schedule blank or generic
- Ignoring instructions that arrive informally
- Forgetting retention and access after the relationship ends
- Assuming confidentiality clauses are enough
- Accepting unlimited audit rights without process controls
FAQs
- Does every UK marketing agency need a data processing agreement?
- Can a marketing agency be both a controller and a processor?
- Is a privacy policy the same as a data processing agreement?
- What should agencies do before accepting a client's standard DPA?
- What happens if the DPA does not reflect the real arrangement?
- Key Takeaways
If your agency handles mailing lists, ad audiences, CRM exports or analytics data, a data processing agreement is not just procurement paperwork. It is often the document that decides who is responsible when personal data is misused, transferred overseas or exposed in a breach.
Many agencies make the same mistakes: signing a supplier's standard terms without checking the processing clauses, assuming a privacy policy or privacy notice replaces a DPA, or treating every client relationship as if the agency is always only a processor.
That is where the risk sits. Marketing agencies often touch large volumes of customer data across multiple tools, subcontractors and campaigns, which means the contract needs to match what actually happens in practice. This guide explains what a data processing agreement marketing agencies UK businesses need should cover, when an agency is acting as a controller or processor, which clauses matter before you sign, and the common errors that cause expensive compliance problems later.
Overview
A data processing agreement, often called a DPA, sets the legal rules for how one party processes personal data for another. For UK marketing agencies, the right document helps allocate responsibilities under the UK GDPR, protect client relationships and reduce disputes when campaigns involve platforms, freelancers, software providers and international transfers.
- Whether your agency is acting as a processor, a controller, or both for different activities.
- What personal data is being used, for what purpose, and on whose instructions.
- Whether the DPA includes all mandatory UK GDPR processor clauses.
- How sub-processors, such as email tools, adtech providers and outsourced specialists, are approved and managed.
- Whether data is transferred outside the UK, and what transfer mechanism applies.
- Who handles data subject requests, complaints, security incidents and breach notifications.
- What happens to the data at the end of the contract, including deletion, return and audit rights.
- Whether the contract's liability clauses line up with the real privacy risk.
What Data Processing Agreement Marketing Agencies Means For UK Businesses
For a UK marketing agency, a DPA is the contract that explains how personal data can be used when you process it for a client or when a supplier processes it for you.
That sounds simple, but agency work rarely fits a single label. One agency may manage a client's email campaigns under the client's instructions, analyse audience segments using its own methods, and then use a third party platform to send messages. Each part of that chain can change the legal role and the contract needed.
Why agencies are different
Marketing agencies often work across several systems at once. A campaign can involve customer lists, website tracking, paid social audiences, competition entries, lead forms and reporting dashboards. Personal data may pass through account managers, creative teams, media buyers, developers and freelancers.
That means a DPA for a marketing agency is not a box-ticking annex. It should reflect the actual service model, including:
- campaign planning and targeting;
- use of client databases and CRM data;
- email marketing and SMS activity;
- analytics and performance reporting;
- retargeting and ad platform audience uploads;
- lead generation or event sign-up handling; and
- outsourced support from specialist suppliers.
Processor, controller, or both?
The first legal question is not what the contract is called. The first question is who decides why and how the personal data is used.
If your client decides the campaign purpose, the target audience and the core use of the personal data, and your agency acts only on their documented instructions, your agency is likely acting as a processor for that activity. In that case, the UK GDPR generally requires specific processor terms.
If your agency decides its own purposes for using data, it may be a controller for that processing. This can happen where an agency builds its own prospect database, uses contact data for its own business development, or determines independent methods and purposes beyond the client's instructions.
Sometimes both parties are controllers for different parts of the project. Sometimes the position changes across workstreams. This is where founders often get caught, especially before they accept the provider's standard terms or before they rely on a verbal promise that "we're only processing on your behalf".
What the law expects in plain English
Where an agency acts as a processor, the UK GDPR expects a written contract with mandatory terms. Those terms usually cover:
- processing only on documented instructions;
- confidentiality obligations for anyone handling the data;
- appropriate security measures;
- rules for appointing sub-processors;
- assistance with data subject requests and compliance duties;
- support with personal data breaches;
- deletion or return of data when the work ends; and
- information and audit rights so the client can verify compliance.
A short clause saying "the parties will comply with data protection law" is usually not enough. If the contract misses the required detail, both the legal position and the working relationship can become unclear when there is a complaint, breach or regulator query.
Typical agency examples
A paid media agency receives a client list and uploads hashed data to an advertising platform for a matched audience campaign. The client decides the campaign goal and provides the source list. In many cases, the agency is likely processing on the client's instructions, but the platform terms, audience creation rules and transfer arrangements still need checking.
An email marketing agency manages sends from the client's CRM using the client's customer database. Again, the agency may be a processor, but the DPA should spell out who handles unsubscribe requests, retention periods, segmentation rules and any use of sub-processors.
A lead generation agency collects leads through landing pages it controls and then sells or shares those leads with multiple clients. That may point to controller activity rather than pure processor activity. A processor-style DPA alone may not accurately cover that model.
Legal Issues To Check Before You Sign
Before you sign a DPA, make sure it reflects what the agency actually does with the data, not just what the template assumes.
Scope of processing
The contract should identify the subject matter, duration, nature and purpose of the processing, plus the types of personal data and categories of data subjects. If those details are vague, arguments start later about whether a use was authorised.
For a marketing agency, this should be specific enough to cover the real work, such as:
- campaign management;
- audience segmentation;
- email deployment;
- analytics and reporting;
- lead capture and form hosting;
- customer support messaging; and
- platform integrations.
Overly broad wording can create unnecessary risk. Overly narrow wording can stop the agency carrying out routine tasks without repeated approvals.
Documented instructions
A processor should only act on the client's documented instructions, unless the law requires otherwise. That sounds straightforward, but marketing projects often evolve quickly.
The contract should deal with practical questions, including:
- how instructions are given, for example through the statement of work, ticketing system or email approval;
- who on the client side can authorise new processing activities;
- what happens if an instruction appears to breach data protection law; and
- whether the agency can suspend work until a risky instruction is clarified.
Without this, account teams may follow informal requests that fall outside the agreed data use.
Sub-processors
Most agencies use third party tools and specialist suppliers. If your agency uses email platforms, cloud storage, CRM tools, analytics products, developers, designers, call centres or freelancers who can access personal data, the DPA should address sub-processing properly.
Check:
- whether the client gives specific approval or general written authorisation for sub-processors;
- how the client will be notified of changes;
- whether sub-processors are bound by equivalent data protection obligations; and
- which party carries the risk if a sub-processor causes a breach or service failure.
A common problem is accepting a client contract that bans sub-processors in practice, even though the agency's service model depends on them.
International transfers
If personal data leaves the UK, the DPA should say how that transfer is legitimised. This issue comes up often because many martech tools, hosting providers and ad platforms store or access data overseas.
Before you sign, identify:
- which suppliers receive or can access the data outside the UK;
- whether a recognised transfer mechanism is in place;
- what transfer risk assessment steps are needed in the circumstances; and
- whether the privacy information given to individuals matches the transfer reality.
Do not assume the platform's headline compliance statement solves the issue on its own.
Security and breach response
The DPA should say what level of security is required and what happens if something goes wrong. Agencies often focus on the client's security questionnaire and miss the actual legal wording.
Look for clauses covering:
- access controls and least-privilege access;
- password standards and multi-factor authentication;
- encryption where appropriate;
- staff confidentiality commitments and training;
- incident logging and internal escalation;
- how quickly the agency must notify the client of a personal data breach; and
- what information must be supplied for the client's own reporting and response obligations.
Very short notification deadlines can be difficult in practice. The agency still needs enough time to investigate and avoid inaccurate reporting.
Data subject rights and compliance support
The contract should explain who handles access requests, erasure requests, objections and complaints. In many client relationships, the client remains the main point of contact for individuals, but the agency may need to help locate or remove data quickly.
The DPA should also allocate responsibility for assistance with:
- data protection impact assessments;
- regulator enquiries;
- security reviews;
- records of processing; and
- consultation where high-risk processing is involved.
If this is left unclear, agencies can end up doing urgent unpaid compliance work under unrealistic deadlines.
Deletion, return and retention
When the contract ends, the personal data should not simply remain in forgotten folders, archived mailboxes and old ad accounts. The DPA should state whether data is returned, deleted, anonymised or retained for a limited lawful purpose.
This needs to work operationally. Agencies may need time to extract reporting, close campaigns, deal with backups or preserve information for legal claims. Those exceptions should be drafted carefully.
Liability and indemnities
Privacy liability clauses often receive less attention than service levels and fees, but they matter just as much. Some DPAs make the agency responsible for losses that are far wider than the agency can control.
Before you sign, compare the data protection liability wording with the main services agreement or contract review notes. Check:
- whether liability caps apply to privacy breaches;
- whether certain losses are carved out of the cap;
- whether indemnities are one-way or mutual;
- whether the agency is liable for the client's unlawful instructions; and
- whether the allocation of risk reflects the parties' actual roles.
This is especially important where the client decides the campaign strategy and lawful basis but expects the agency to absorb most of the downstream risk.
Common Mistakes With Data Processing Agreement Marketing Agencies
The biggest mistake is assuming the label on the document matches the real legal role.
Treating every agency as a processor
Some agencies sign processor clauses as a default, even where they independently determine purposes or re-use data for their own aims. That mismatch can create problems with privacy notices, lawful basis analysis and accountability.
If your agency is partly acting as a controller, the contract set should reflect that. One size rarely fits all campaign models.
Relying on standard platform terms without mapping the full chain
Agencies often assume that if a software provider offers a DPA, the agency's work is covered. It is not. You still need to map the flow of personal data from client to agency to every supplier and specialist involved.
The main risk is hidden access. A freelance developer, reporting consultant or overseas support team may have access to data even if they are not part of the original proposal.
Leaving the schedule blank or generic
Many disputes come from poorly completed annexes and schedules. A blank field for categories of data or a generic line saying "marketing services" does not help when the parties later disagree about retargeting, profiling or event lead capture.
Before you sign, complete the operational detail properly. It takes less time than dealing with a complaint after the fact.
Ignoring instructions that arrive informally
Agency teams often receive requests through chat messages, calls and last-minute emails. If an account manager acts on an informal request to upload a list, combine data sets or extend retention, the agency may process data outside the agreed scope.
The contract should support a practical approval process. Internal playbooks should do the same.
Forgetting retention and access after the relationship ends
Old campaign folders, inactive platform seats and historic exports are common problem areas. A client may believe all data has been deleted, while the agency still retains copies across backups, inboxes or archived project systems.
This is where founders often get caught, especially after a client termination or agency handover. Exit steps should be specific and assigned to actual people.
Assuming confidentiality clauses are enough
A general confidentiality clause does not replace a proper DPA. Confidentiality matters, but UK data protection rules also require detail on instructions, sub-processors, security support, breach response and end-of-term handling.
Accepting unlimited audit rights without process controls
Clients may ask for broad audit rights, but unlimited access can create confidentiality, security and disruption issues. The better approach is a sensible audit mechanism with notice periods, scope limits and protection for other clients' confidential information.
That still gives the client assurance, without turning the clause into an operational burden.
FAQs
Does every UK marketing agency need a data processing agreement?
No, not for every activity. A DPA is generally needed where the agency processes personal data on behalf of a client as processor. If the agency is acting as a controller for some activities, different contractual and privacy arrangements may be needed instead or as well.
Can a marketing agency be both a controller and a processor?
Yes. An agency may be a processor for managing a client's email list, but a controller for its own prospecting, internal analytics or other independent uses. The answer depends on who decides the purposes and means of each processing activity.
Is a privacy policy the same as a data processing agreement?
No. A privacy policy explains to individuals how their personal data is used. A DPA is a contract between business parties that sets the rules for processing personal data on behalf of another party.
What should agencies do before accepting a client's standard DPA?
Check the role allocation, the processing description, sub-processor permissions, international transfer wording, breach deadlines, deletion obligations and liability clauses. Make sure the terms match how your team and suppliers actually work before you sign.
What happens if the DPA does not reflect the real arrangement?
The parties may struggle to show compliance, allocate responsibility or respond properly to complaints and incidents. A poor DPA does not automatically decide every legal outcome, but it can create avoidable risk, cost and client disputes.
Key Takeaways
- A data processing agreement marketing agencies UK businesses use should match the real data flow, not just a generic template.
- The first issue is role allocation, including whether the agency is acting as a processor, a controller, or both across different services.
- A valid processor arrangement should cover documented instructions, confidentiality, security, sub-processors, assistance with rights and breaches, and deletion or return of data.
- Marketing agencies need to pay close attention to martech suppliers, freelancers, overseas access and platform-based transfers.
- Blank schedules, vague processing descriptions and unrealistic liability wording are common contract traps before you sign.
- Good DPAs work alongside actual internal processes for approvals, retention, breach response and supplier management.
If you want help with role allocation, DPA drafting, supplier terms, international transfer clauses, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








