Privacy notice for a marketing agency

A privacy notice for a marketing, advertising or digital agency, drafted for the agency with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.

Share

Privacy notice for a marketing agency

Buy now, £595

A marketing agency's own privacy notice covers the data the agency controls (its prospects, its clients' contacts, its website visitors, its own newsletter), while the campaign data it runs for clients is processed on the clients' behalf under their notices and a data processing agreement; the two are confused on most agency websites. The notice also has to deal with the rules on business-to-business marketing, which apply to the agency's own prospecting, the data sourced from lists and platforms, and the cookies and pixels the agency deploys on clients' sites and its own. The privacy notice and the cookie notice are drafted for the business, with guidance on the consent mechanism, for a fixed £595 and delivery in five working days.

Who this is for

Marketing, advertising, digital, PR, social media and lead generation agencies in England and Wales, and consultancies that run campaigns for clients.

What matters in a marketing agency privacy notice

The agency's own data and the clients' data it processes

Under Article 13 of the UK GDPR the business, being the controller, has to tell the people whose data it controls what it does with it, and for an agency that is its prospects and leads, its clients' staff and contacts, its website visitors, its suppliers and the recipients of its own marketing; the data in the campaigns it runs (the client's customers, the audiences, the leads generated) is the client's, processed by the agency as a processor under Article 28 or as a joint controller under Article 26 where the agency decides the purposes with the client, and the notice should say so in its first section and refer those individuals to the client's notice, because an agency that describes its clients' campaign data as its own has misstated who the controller is.

Controller, processor and the role for each campaign

The agency's role differs by campaign: a processor where it runs the client's email programme or manages the client's advertising accounts on instructions, a controller where it buys media and audiences in its own name or generates leads from its own sources before passing them on, and a joint controller where it and the client decide together what data is collected and how; the notice should explain that the role is set in each client contract and data processing agreement, and the agency's contracts should set it, because the agency's obligations (and its liability under Article 82) follow the role.

Business-to-business marketing and the rules that still apply

Marketing to individuals by electronic means needs consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, or the soft opt-in where it applies, and 'individual' includes sole traders and partnerships, while marketing to corporate subscribers (a named person at a limited company) may rely on legitimate interests under Article 6(1)(f) of the UK GDPR with an opt-out, which is the basis most agency prospecting uses; the notice should state the basis for the agency's own prospecting, the sources of the contacts, the opt-out in every message, and the screening against the Telephone Preference Service for calls, and the agency should not assume that a corporate email address means no rules apply, because the UK GDPR applies to the named individual regardless.

Data sourced from lists, platforms and scraping

Where the agency obtains contacts from purchased lists, data brokers, professional networks or by scraping public sources, Article 14 of the UK GDPR requires it to tell those individuals, within a month or at first contact, what it holds and where it came from, to have checked that the source collected the data lawfully for that purpose, and to honour objections; the notice should name the categories of source and state the basis, and the agency should hold the lists' terms and due diligence, because the Information Commissioner's enforcement against lead generation businesses starts with the question of where the data came from.

Cookies, pixels and the tracking the agency deploys for clients

Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 makes consent a precondition for non-essential cookies and similar technologies, which covers the analytics, advertising pixels, tag managers and conversion tracking the agency deploys on its own website and on clients' sites, with the consent banner doing the work the notice cannot; the agency's notice covers its own site, the pack includes the cookie notice and the guidance on the consent mechanism, and the agency should advise clients that the same rule applies to the tracking it installs for them, because an agency that installs advertising pixels on a client's site without consent has created the client's breach.

The agency's own website, prospects and the newsletter it sends

The notice should cover the agency's website forms and analytics, the CRM and the email platform as processors, the international transfers to US-based tools under the safeguards Article 46 of the UK GDPR requires, the agency's newsletter and its basis, the retention of prospects' data (a stated period after the last contact), the portfolio and case studies (client consent for naming them), the rights of access, rectification, erasure, restriction, portability and objection, the means of exercising them, the one-month response period, and the complaint route to the Information Commissioner's Office; the Data Protection (Charges and Information) Regulations 2018 require registration with the Information Commissioner's Office where the fee applies, and the notice can give the number.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

For named individuals at limited companies, legitimate interests with an opt-out is the usual basis; for sole traders and partnerships, consent or the soft opt-in. The notice states the basis and the sources, and the UK GDPR applies to the named person either way.

Does our privacy notice cover the campaigns we run for clients?

It does not. That data is the client's, processed by the agency as processor or joint controller under the contract and the data processing agreement. The notice says so and refers those individuals to the client's notice.

The client's, as the site owner, but an agency that installs pixels without a consent mechanism has created the client's breach. The pack's guidance on consent applies to both.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.