Data processing agreement for a marketing agency
A data processing agreement for a marketing or advertising agency to use with its clients, drafted for the agency with the privacy notice, for a fixed fee of £795 in five working days.
Data processing agreement for a marketing agency
A data processing agreement between a marketing agency and its clients, drafted for the agency, covering processor, controller or joint controller by campaign, the mandatory terms applied to campaign work, the platforms, the lists and the sub-processors an agency uses, consent, suppression and the compliance the client must deliver, the agency's own analytics and the data it keeps for itself, and liability, fines and the campaign that breaks the rules. £795 with the privacy notice, delivered in five working days.
Buy now, £795A marketing agency runs campaigns on its clients' customer data, which makes it a processor for most of what it does, a joint controller where it decides the targeting with the client, and a controller for the data it collects on its own account; the clients are legally required to have a data processing agreement with it, and the agency is better off supplying one that fits agency work than signing the clients' generic versions. The DPA has to allocate the role by campaign, apply the mandatory terms to the work an agency does, deal with the platforms and lists, place the consent and suppression obligations where they belong, and handle the agency's own analytics and the liability for a campaign that breaks the marketing rules. The data processing agreement and the privacy notice are drafted for the business for a fixed £795 and delivery in five working days, with a note on the operational steps the documents assume.
Who this is for
Marketing, advertising, digital, email, social media and lead generation agencies in England and Wales processing clients' customer and prospect data to run campaigns.
What matters in a marketing agency's data processing agreement
Processor, controller or joint controller by campaign
The agency is a processor where it runs the client's email programme, manages the client's advertising accounts or handles the client's customer data on instructions, a joint controller under Article 26 of the UK GDPR where it and the client together decide the audiences, the data sources and the purposes, and a controller where it generates leads from its own sources or buys media in its own name before passing data to the client; the DPA should set a default role and provide for the role to be stated per campaign in the statement of work, because the obligations and the liability under Article 82 follow the role and an agency that is treated as a processor for a campaign it designed has misdescribed itself.
The mandatory terms applied to campaign work
The written contract Article 28 of the UK GDPR requires between controller and processor must contain the terms the Article sets out, and for an agency the schedule should describe the campaign data (the client's customers, prospects, audiences and leads), the processing (segmentation, sending, tracking, reporting), the duration (the campaign and a stated period after), and the instructions (the brief and the statement of work); the agency must process only on the client's documented instructions, keep the data confidential, apply the security Article 32 requires, engage sub-processors only with authorisation and on the same terms, assist the client with data subject requests and with its own security, breach and impact assessment obligations, delete or return the data at the end, and make available the information needed to demonstrate compliance and allow audits.
The platforms, the lists and the sub-processors an agency uses
Email platforms, advertising platforms, data enrichment services, analytics, landing page tools and the agency's own CRM are sub-processors where they process the client's data on the agency's instructions and controllers where they use it for themselves (advertising platforms always do), and the DPA should list the categories, provide general authorisation with notification of changes, flow down the obligations to each, and name the overseas transfers with the Article 46 safeguards the UK GDPR requires; purchased or rented lists the agency sources for the client need the DPA to say who obtained them, who checked the basis and who is responsible under Article 14 for telling the individuals, because a list with no basis is the client's breach and the agency's negligence.
Consent, suppression and the compliance the client must deliver
Electronic marketing to individuals requires consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 unless the soft opt-in applies, and the DPA should allocate the responsibilities: the client warrants that the data it supplies carries the consent or the soft opt-in for the campaign and provides its suppression list, the agency warrants that it will honour the suppression list, include the unsubscribe, screen against the Telephone Preference Service for calls and not add data from its own sources without the client's agreement, and each tells the other of complaints; an agency that sends a campaign to a list the client said was consented when it was not needs the warranty, and a client whose agency ignored the suppression list needs the other.
The agency's own analytics and the data it keeps for itself
Agencies want to keep campaign performance data, benchmarks and learnings across clients, and the DPA should say what the agency may retain and in what form (aggregated and anonymised results, with no personal data and no client identification without consent), what it may not (the client's lists, the leads, the identifiable results), and the deletion of the client's data at the end of the engagement with certification; the agency's own privacy notice covers the data it controls, and the DPA should refer to it so that the client knows which is which.
Liability, fines and the campaign that breaks the rules
The Information Commissioner fines the sender of unlawful marketing, which may be the client or the agency depending on who instigated the sending, and the DPA should allocate liability for fines and claims between them according to whose breach caused it (the client's for data without a basis, the agency's for a campaign sent against instructions or without the suppression), within the cap in the main services agreement or a stated cap for data protection, and Article 82 of the UK GDPR leaves each party liable for its own failures; the agency should carry insurance that covers it, and the DPA should say that neither party will instruct the other to do something unlawful and that the agency may decline such an instruction.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Are we a processor for our clients' campaigns?
For campaigns run on the client's data and instructions, yes; where the agency designs the targeting and chooses the sources with the client, a joint controller; where it sources leads itself, a controller. The DPA sets a default and states the role per campaign.
Who is responsible if a client's list turns out to have no consent?
The client, under the warranty the DPA contains, where it supplied the list; the agency, where it sourced the list or ignored the suppression. The DPA allocates fines and claims by whose breach caused them.
Can we keep campaign results after the engagement ends?
Aggregated and anonymised, with no personal data and no client identification without consent, yes. The client's lists, leads and identifiable results are deleted with certification.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Privacy notice for a marketing agency
- Data processing agreement for a SaaS vendor
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.