Founding offer: save 20% for life, only 50 places·14-day free trialClaim yours →

US agencies and client data: state privacy laws, contracts and what clients now ask for

There is no single US privacy law, but there is a clear pattern. Clients pass state-law duties to their agencies through contracts, and the questionnaires keep getting longer.

The Crewqo team Published Updated 6 min read
On this page
  1. The landscape in plain terms
  2. Is your agency a “business” or a “service provider”?
  3. What client contracts now include
  4. Security questionnaires: how to answer without panic
  5. Working with Canadian clients
  6. A practical setup for a US agency
  7. Checklist for US agencies
  8. Frequently asked questions

The short answer: the US has no single, comprehensive federal privacy law. Instead, a growing number of states have their own, led by California’s CCPA as amended by the CPRA, alongside sector laws and the Federal Trade Commission’s power over unfair or deceptive practices. Most agencies meet these laws not as the main regulated business but as a service provider or processor for their clients. That shows up as contract clauses, data processing addenda and security questionnaires. Preparing for those three things covers most of what a US agency needs.

This is general information, not legal advice. Privacy law changes, and how it applies depends on your agency, your clients and where everyone is. For decisions about your own obligations, speak to a qualified adviser in the relevant country.

The landscape in plain terms#

  • California. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights to know, delete, correct and opt out of the sale or sharing of their personal information. It is enforced by the California Privacy Protection Agency, which also writes regulations, and by the California Attorney General.
  • Other states. Virginia, Colorado, Connecticut, Utah, Texas, Oregon and a number of other states have passed comprehensive privacy laws. Most use GDPR-style terms, controller and processor, and require a contract between them.
  • Sector laws. HIPAA for health information, GLBA for financial institutions and COPPA for children’s data online can all apply to specific clients.
  • The FTC. The Federal Trade Commission can act against unfair or deceptive practices, including privacy promises a company doesn’t keep.
  • Breach laws. Every state has a data breach notification law, with its own definitions and timelines.

The list of state laws keeps growing and their details differ, so treat any summary, including this one, as a starting point and check the current position for the states your clients operate in.

Is your agency a “business” or a “service provider”?#

Under the CCPA, a “business” is a for-profit company doing business in California that meets at least one threshold: annual revenue above a set amount (adjusted periodically), handling personal information of a large number of California consumers or households, or earning a significant share of revenue from selling or sharing personal information. Other states use their own thresholds, often based on the number of residents whose data is processed.

Many small and mid-sized agencies don’t meet these thresholds for their own data. But their clients often do, and when a client shares personal information with its agency, the law expects a contract that makes the agency a service provider or contractor (California) or a processor (most other states). That contract is how the law reaches you.

Ad agenciesAdvertising work needs extra care. Under the CPRA, “sharing” includes making personal information available for cross-context behavioural advertising, and consumers can opt out of it. Know which side of that line each campaign sits on.

What client contracts now include#

Common privacy clauses in US agency contracts
ClauseWhat it meansHow to prepare
Purpose limitationYou may use their data only to deliver the servicesDon’t reuse client data for your own marketing, case studies or tests
No selling or sharingYou may not sell the data or share it for cross-context advertisingCheck any tool that might use the data for its own purposes
Sub-processorsYou must flow the same terms down to your vendorsKeep a list of tools that touch client data, with their terms
Consumer requestsYou must help the client answer access, deletion and correction requestsBe able to find and delete one person’s data across your tools
SecurityReasonable security appropriate to the dataIndividual logins, least-privilege access, encryption, tested backups
Breach noticeYou must tell the client promptly, often within a set windowA written plan with names and client contacts
Deletion or returnData must be deleted or returned when the work endsA real offboarding step for every client, including exports on laptops
Assessments and auditsThe client may check how you complyKeep your answers and evidence in one place

Security questionnaires: how to answer without panic#

Larger clients now send security questionnaires before signing, and again at renewal. Some are a short form, others run to hundreds of questions based on standard frameworks. The trick is to answer once, well, and reuse.

  1. Build an answer library. A single document with your standard answers on access control, devices, backups, encryption, incident response, vendors and staff training.
  2. Be specific and honest. “Access is given by role, reviewed quarterly, removed on the day someone leaves” beats “industry-standard security”. If you don’t do something, say so and say what you do instead.
  3. Know your vendors’ answers. Many questions are really about your tools: where files are stored, how backups are protected, who can sign in. Collect those answers once.
  4. Keep evidence. Screenshots of settings, policies, and vendor documentation, dated.

Our vendor security question template is a good starting point for the vendor half of your library.

Working with Canadian clients#

Canada’s federal private-sector law is PIPEDA, overseen by the Office of the Privacy Commissioner of Canada. It is built on accountability: an organisation that transfers personal information to a third party for processing stays responsible for it, and is expected to use contracts and other means to protect it. Organisations must report breaches of security safeguards that create a real risk of significant harm to the Commissioner and notify affected people, and keep records of all such breaches. Quebec has its own, stricter private-sector law, updated by what is often called Law 25, and Alberta and British Columbia have their own private-sector laws for activity within those provinces.

In practice, Canadian clients ask the same things US clients do: where is our data, who can see it, how fast will you tell us if something goes wrong.

A practical setup for a US agency#

  • Data map. One page listing what personal information you hold for each client and where it lives.
  • Fewer places. Every extra tool is another row on the map and another questionnaire answer. See how to cut tool sprawl.
  • Access by role. Clients see only their own work; staff see what their job needs. Crewqo gives access by area and shows owners every signed-in device.
  • Files you control. Keep client files in storage the agency owns, so you can answer where they are. Crewqo saves files straight into your own storage.
  • Encrypted, tested backups with clear key custody. See encrypted backups explained.
  • Contract templates. Your own standard data terms, so you are not always negotiating on the client’s paper.

Checklist for US agencies#

Before the next client questionnaire arrives

Frequently asked questions

Does the CCPA apply to a small agency?

Only if your agency meets one of the CCPA thresholds for a “business”. Many small agencies don’t, but they still take on CCPA duties by contract when they act as a service provider or contractor for clients that do.

Do I need a data processing addendum with US clients?

If a client is covered by a state privacy law and shares personal information with you, the law generally expects a contract with specific terms. Many clients will send their own addendum; read the use, sub-processor and breach clauses carefully.

What counts as “sharing” under the CPRA?

Making personal information available to a third party for cross-context behavioural advertising, whether or not money changes hands. It matters for ad and performance agencies because consumers can opt out of it.

How fast must I tell a client about a breach?

Whatever your contract says, and contracts increasingly set a short, specific window. State breach laws set separate timelines for notifying individuals, which usually fall on your client.

Written by the Crewqo team. Spotted something out of date? Tell us at hello@crewqo.com.

Founding offer · first 50 agencies

Claim one of 50 founding spots

Save 20% for as long as you stay, start with a 14-day free trial, and cancel any time.

14-day free trialNo card neededCancel any time