GDPR for agencies: a practical client-data checklist
Agencies handle a surprising amount of personal data for their clients. Here is what the EU and UK GDPR expect of you, turned into a list you can actually work through.
On this page
- EU GDPR and UK GDPR: the same idea, two regimes
- Controller or processor? Work it out per activity
- Data processing agreements, both ways
- Sub-processors: your software is on the list
- International transfers
- Retention, security and access
- Breaches: the first 72 hours
- The agency GDPR checklist
- Frequently asked questions
The short answer: if your agency handles personal data about people in the EU or UK, the GDPR applies to that work. For your own staff, leads and suppliers you are usually a controller. For most client work (their customer lists, campaign data, people in their content) you are usually a processor acting on the client’s instructions. In practice, compliance for an agency means: know what data you hold and in which role, sign data processing agreements in both directions, keep a list of the tools that touch client data, set retention periods, secure access, handle international transfers properly and have a plan for breaches.
This is general information, not legal advice. Privacy law changes, and how it applies depends on your agency, your clients and where everyone is. For decisions about your own obligations, speak to a qualified adviser in the relevant country.
EU GDPR and UK GDPR: the same idea, two regimes#
Since Brexit there are two closely related laws. The EU GDPR applies across the EU and EEA. It is enforced by national data protection authorities, such as Ireland’s Data Protection Commission or France’s CNIL, and the European Data Protection Board (EDPB) publishes guidance to keep interpretation consistent. The UK GDPR, alongside the Data Protection Act 2018, applies in the UK and is enforced by the Information Commissioner’s Office (ICO).
The principles are the same: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The UK has started to make its own changes, so if you work on both sides of the Channel, check current ICO guidance as well as EDPB guidance rather than assuming they are identical.
The GDPR can also reach agencies outside Europe. A US, Canadian or Australian agency that offers services to people in the EU or UK, or monitors their behaviour, may be in scope. More often, a non-European agency meets the GDPR through contracts: a European client will require you to process its data to GDPR standards.
Controller or processor? Work it out per activity#
The controller decides why and how personal data is processed. The processor acts on the controller’s behalf. Your role can change from one activity to the next.
| Activity | Usual role | Why |
|---|---|---|
| Staff records, payroll, leave | Controller | You decide what you collect and why |
| Leads from your own website forms | Controller | Your marketing, your purposes |
| Running an email campaign to a client’s customer list | Processor | The client decides the purpose; you follow instructions |
| Managing a client’s ad accounts and audiences | Usually processor, sometimes joint controller | Depends on how much you decide about targeting and data use |
| Filming people for a client’s content | Usually processor | The client decides how the footage is used; releases matter |
| Your software vendors handling client data | Your sub-processors | They process on your behalf, for your client |
Roles follow what actually happens, not what a contract labels them. If you start deciding purposes yourself, for example reusing a client’s data for your own marketing, you may become a controller for that processing, with all the duties that brings.
Data processing agreements, both ways#
Article 28 of the GDPR requires a written contract between a controller and a processor. Agencies usually need two sets:
- With clients, where you are their processor.
- With your vendors, where they process client data for you.
A compliant data processing agreement (DPA) covers, in substance: processing only on documented instructions; confidentiality for people with access; appropriate security; rules for using sub-processors; help with data subject requests and with the controller’s own obligations; deleting or returning data at the end; and making information available for audits. Many clients will send their own DPA. Read it for the sub-processor and breach clauses in particular, because those are the ones that change how you work.
TipKeep a folder of signed DPAs, one per client and one per vendor, with the date and version. When a client asks, you can answer in minutes.
Sub-processors: your software is on the list#
Every tool that touches client personal data (project management, chat, file storage, email, AI, e-signatures) is a sub-processor in your client’s chain. Under the GDPR, a processor needs the controller’s authorisation to use sub-processors, either specific or general written authorisation. With a general authorisation you must tell the client about changes, so they have a chance to object.
- List every tool that stores or processes client personal data.
- For each, note what data goes in, where it is stored, and whether you have a DPA with the vendor.
- Share the list with clients as part of your own DPA, and update them when it changes.
Fewer tools means a shorter list and fewer contracts to manage, which is one quiet benefit of cutting tool sprawl. With Crewqo, files go to storage you choose, and AI requests go to the provider whose key you added, so you decide which of those providers join your list. Crewqo’s own terms describe it as a processor of your workspace data, with you as controller; the Privacy Policy has the details.
International transfers#
Moving personal data from the EU or UK to another country needs a legal basis. The main routes are:
- Adequacy decisions, where the European Commission (or the UK government, for UK transfers) has recognised a country’s protection as adequate.
- The EU–US Data Privacy Framework, for transfers to US companies that have certified under it, with a UK extension for UK transfers.
- Standard contractual clauses for EU transfers, and the UK’s International Data Transfer Agreement or Addendum for UK transfers, usually with a transfer risk assessment.
For an agency, the practical step is to know where each tool on your sub-processor list stores data, and which mechanism it relies on. Vendors normally state this in their DPA.
Retention, security and access#
Retention. Keep personal data no longer than you need it for the purpose. Agree retention with each client (for example, delete campaign data a set period after the campaign ends) and write it into your DPA. Then actually delete it, including from old exports on laptops.
Security. Article 32 asks for security appropriate to the risk. For an agency that usually means: individual logins, not shared ones; access limited to what each person needs; clients seeing only their own work; sign-in protection; encryption in transit; tested backups; and fast offboarding. Crewqo gives access by area rather than page by page, keeps clients in their own portal, and shows owners every signed-in device; see access and devices.
Breaches: the first 72 hours#
Under the GDPR, a controller must report a personal data breach to its supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people. Where the risk is high, the people affected must be told too. A processor must tell the controller without undue delay.
So if you are the processor, your client’s 72-hour clock can start with your email. Agree in your DPA how quickly you will notify them, and prepare now:
- Name who in the agency decides whether something is a breach.
- Keep client privacy contacts in one place.
- Record every incident, even the ones you don’t report, with what happened and what you did.
The agency GDPR checklist#
Work through these in order
Frequently asked questions
Does the GDPR apply to small agencies?
Yes. The GDPR has no general size exemption. Some record-keeping duties are lighter for organisations with fewer than 250 employees, but that exemption is narrow and does not apply to regular processing, so most agencies should keep basic records anyway.
Do agencies need a Data Protection Officer?
Only in specific cases, such as core activities that involve large-scale, regular and systematic monitoring of people, or large-scale processing of special category data. Many agencies don’t need one, but someone should still own data protection.
Does the GDPR apply to a US or Australian agency?
It can. It applies to businesses outside the EU and UK that offer services to, or monitor, people there. More commonly, European clients require non-European agencies to meet GDPR standards through a data processing agreement.
Do I need a DPA with every software tool?
You need one with every vendor that processes personal data on your behalf. Most established vendors publish a standard DPA; check it covers sub-processors, security, breach notice and deletion.
How fast must I tell a client about a breach?
The GDPR requires processors to notify controllers without undue delay. Your DPA with the client often sets a specific window. Because the client may have 72 hours to report, earlier is always better.
Written by the Crewqo team. Spotted something out of date? Tell us at hello@crewqo.com.