US agencies and client data: state privacy laws, contracts and what clients now ask for
There is no single US privacy law, but there is a clear pattern. Clients pass state-law duties to their agencies through contracts, and the questionnaires keep getting longer.
On this page
The short answer: the US has no single, comprehensive federal privacy law. Instead, a growing number of states have their own, led by California’s CCPA as amended by the CPRA, alongside sector laws and the Federal Trade Commission’s power over unfair or deceptive practices. Most agencies meet these laws not as the main regulated business but as a service provider or processor for their clients. That shows up as contract clauses, data processing addenda and security questionnaires. Preparing for those three things covers most of what a US agency needs.
This is general information, not legal advice. Privacy law changes, and how it applies depends on your agency, your clients and where everyone is. For decisions about your own obligations, speak to a qualified adviser in the relevant country.
The landscape in plain terms#
- California. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights to know, delete, correct and opt out of the sale or sharing of their personal information. It is enforced by the California Privacy Protection Agency, which also writes regulations, and by the California Attorney General.
- Other states. Virginia, Colorado, Connecticut, Utah, Texas, Oregon and a number of other states have passed comprehensive privacy laws. Most use GDPR-style terms, controller and processor, and require a contract between them.
- Sector laws. HIPAA for health information, GLBA for financial institutions and COPPA for children’s data online can all apply to specific clients.
- The FTC. The Federal Trade Commission can act against unfair or deceptive practices, including privacy promises a company doesn’t keep.
- Breach laws. Every state has a data breach notification law, with its own definitions and timelines.
The list of state laws keeps growing and their details differ, so treat any summary, including this one, as a starting point and check the current position for the states your clients operate in.
Is your agency a “business” or a “service provider”?#
Under the CCPA, a “business” is a for-profit company doing business in California that meets at least one threshold: annual revenue above a set amount (adjusted periodically), handling personal information of a large number of California consumers or households, or earning a significant share of revenue from selling or sharing personal information. Other states use their own thresholds, often based on the number of residents whose data is processed.
Many small and mid-sized agencies don’t meet these thresholds for their own data. But their clients often do, and when a client shares personal information with its agency, the law expects a contract that makes the agency a service provider or contractor (California) or a processor (most other states). That contract is how the law reaches you.
Ad agenciesAdvertising work needs extra care. Under the CPRA, “sharing” includes making personal information available for cross-context behavioural advertising, and consumers can opt out of it. Know which side of that line each campaign sits on.
What client contracts now include#
| Clause | What it means | How to prepare |
|---|---|---|
| Purpose limitation | You may use their data only to deliver the services | Don’t reuse client data for your own marketing, case studies or tests |
| No selling or sharing | You may not sell the data or share it for cross-context advertising | Check any tool that might use the data for its own purposes |
| Sub-processors | You must flow the same terms down to your vendors | Keep a list of tools that touch client data, with their terms |
| Consumer requests | You must help the client answer access, deletion and correction requests | Be able to find and delete one person’s data across your tools |
| Security | Reasonable security appropriate to the data | Individual logins, least-privilege access, encryption, tested backups |
| Breach notice | You must tell the client promptly, often within a set window | A written plan with names and client contacts |
| Deletion or return | Data must be deleted or returned when the work ends | A real offboarding step for every client, including exports on laptops |
| Assessments and audits | The client may check how you comply | Keep your answers and evidence in one place |
Security questionnaires: how to answer without panic#
Larger clients now send security questionnaires before signing, and again at renewal. Some are a short form, others run to hundreds of questions based on standard frameworks. The trick is to answer once, well, and reuse.
- Build an answer library. A single document with your standard answers on access control, devices, backups, encryption, incident response, vendors and staff training.
- Be specific and honest. “Access is given by role, reviewed quarterly, removed on the day someone leaves” beats “industry-standard security”. If you don’t do something, say so and say what you do instead.
- Know your vendors’ answers. Many questions are really about your tools: where files are stored, how backups are protected, who can sign in. Collect those answers once.
- Keep evidence. Screenshots of settings, policies, and vendor documentation, dated.
Our vendor security question template is a good starting point for the vendor half of your library.
Working with Canadian clients#
Canada’s federal private-sector law is PIPEDA, overseen by the Office of the Privacy Commissioner of Canada. It is built on accountability: an organisation that transfers personal information to a third party for processing stays responsible for it, and is expected to use contracts and other means to protect it. Organisations must report breaches of security safeguards that create a real risk of significant harm to the Commissioner and notify affected people, and keep records of all such breaches. Quebec has its own, stricter private-sector law, updated by what is often called Law 25, and Alberta and British Columbia have their own private-sector laws for activity within those provinces.
In practice, Canadian clients ask the same things US clients do: where is our data, who can see it, how fast will you tell us if something goes wrong.
A practical setup for a US agency#
- Data map. One page listing what personal information you hold for each client and where it lives.
- Fewer places. Every extra tool is another row on the map and another questionnaire answer. See how to cut tool sprawl.
- Access by role. Clients see only their own work; staff see what their job needs. Crewqo gives access by area and shows owners every signed-in device.
- Files you control. Keep client files in storage the agency owns, so you can answer where they are. Crewqo saves files straight into your own storage.
- Encrypted, tested backups with clear key custody. See encrypted backups explained.
- Contract templates. Your own standard data terms, so you are not always negotiating on the client’s paper.
Checklist for US agencies#
Before the next client questionnaire arrives
Frequently asked questions
Does the CCPA apply to a small agency?
Only if your agency meets one of the CCPA thresholds for a “business”. Many small agencies don’t, but they still take on CCPA duties by contract when they act as a service provider or contractor for clients that do.
Do I need a data processing addendum with US clients?
If a client is covered by a state privacy law and shares personal information with you, the law generally expects a contract with specific terms. Many clients will send their own addendum; read the use, sub-processor and breach clauses carefully.
What counts as “sharing” under the CPRA?
Making personal information available to a third party for cross-context behavioural advertising, whether or not money changes hands. It matters for ad and performance agencies because consumers can opt out of it.
How fast must I tell a client about a breach?
Whatever your contract says, and contracts increasingly set a short, specific window. State breach laws set separate timelines for notifying individuals, which usually fall on your client.
Written by the Crewqo team. Spotted something out of date? Tell us at hello@crewqo.com.