Under GDPR, a marketing agency can be a processor for one activity, an independent controller for another and, less commonly, a joint controller for a third. The answer follows the facts: who determines the purpose and the essential means of each processing operation? It does not follow automatically from managing an ad account, recommending targeting, building an audience or installing a tag. Map the client, agency and platform separately before selecting Article 28 processor terms, an Article 26 joint-controller arrangement or controller-to-controller provisions.

Operator guidance, not legal advice. Data-protection roles, platform statuses and transfer mechanisms change — verify the current position (including DPF/adequacy status and platform sub-processor terms) at the time you rely on this, and take legal advice for your situation.
TL;DR
- Role follows function, not label. A contract calling the agency a "processor" does not make it one if it acts like a controller.
- An agency is a processor only for activity performed on the controller's documented instructions without determining its own purpose or essential means.
- A tracking integration does not automatically make the agency a joint controller. Fashion ID concerned the website operator and Facebook for collection and transmission; classify the agency's separate participation on the facts.
- A DPA must contain specific things under GDPR Article 28 — purpose, duration, security, sub-processors, deletion.
- Platforms are not automatically sub-processors. They may be processors, independent controllers or joint controllers for different operations under their current terms.
- International transfers need a legal basis — the EU-US Data Privacy Framework, SCCs, or the UK extension; this area shifts with court rulings.
- Do not translate regimes one-for-one. UK GDPR is a separate amended regime; California's CCPA concepts overlap but are not a US version of GDPR.
Controller, processor, joint controller — the definitions
Three roles, defined by who decides why and how personal data is processed:
- Controller — determines the purposes and means of processing. It decides what data is collected and why. (Usually: you, the client.)
- Processor — processes personal data on behalf of a controller, on its instructions. It does not decide the purpose. (Usually: the agency, for most tasks.)
- Joint controller — two or more parties jointly determine the purposes and means. (Sometimes: you and the agency, or you and a platform, for specific activities.)
The decisive fact is the function, not the title. A contractual label cannot override conduct, although the contract remains important evidence of intended responsibilities. Controllers decide purposes and essential means; processors may still choose non-essential technical or organisational details within instructions. Professional expertise and recommendations do not, by themselves, turn a processor into a controller.

Usually a processor — so you need a DPA
An agency is a processor where it handles personal data on behalf of a controller and within documented instructions — for example, operating a CRM workflow or sending a defined campaign from the client's list without reusing the data for its own purpose. Campaign management is not enough to decide the role: the data flow, platform terms and decisions still need analysis. Where a controller–processor relationship exists, Article 28 requires binding contractual terms; an NDA is not a substitute.
The Article 28 terms may sit in a separate DPA, an annex or the main services agreement; GDPR does not require a document carrying a particular title. What matters is that the binding terms cover the required content and accurately describe the processing. The marketing agency contract checklist treats a dedicated schedule as a practical way to keep that detail auditable.
When the agency becomes a joint controller
Joint controllership requires joint participation in determining purposes and means. EDPB guidance describes a common decision or converging decisions that complement each other, are necessary for the processing and have a tangible impact on purposes and essential means. Collaboration or mutual benefit alone is not enough.
In Fashion ID, the Court of Justice held that a website operator embedding Facebook's social plugin could be a joint controller with Facebook for the collection and transmission at issue, not for Facebook's later processing. That judgment does not automatically assign the same role to an implementation agency. If the agency installs the Meta pixel or Conversions API solely on the client's documented instructions, it may be the client's processor for that work while the website operator and platform have separate controller arrangements. If the agency determines its own purpose or jointly determines essential means, the result can differ.
Activity → role risk map
| Activity | Typical role | Why |
|---|---|---|
| Managing campaigns on your instructions | Processor | Agency executes; you set the purpose |
| Emailing your customer list | Processor | Agency processes your data on your behalf |
| Building customer or similar audiences | Depends on instructions and platform terms | Audience construction alone does not establish joint control |
| Deploying a pixel / server integration | Map client, agency and platform separately | Fashion ID does not automatically make the implementer a joint controller |
| Recommending targeting | Often compatible with processor expertise | Advice on non-essential means does not itself determine purpose |
| Agency using data for its own purposes | Controller (of that processing) | It decides the purpose itself |
The map is diagnostic, not a legal conclusion. Ask who decided the purpose, data categories, recipients, retention and access rules, then check actual conduct. Where joint control applies, Article 26 requires a transparent arrangement allocating responsibilities, and its essence must be made available to data subjects.

What a DPA must contain
A DPA is not free-form; GDPR Article 28 sets out mandatory contents. A compliant DPA specifies:
- Subject matter, duration, nature and purpose of the processing.
- The types of personal data and categories of data subjects.
- The controller's instructions — the processor acts only on documented instructions.
- Confidentiality — persons processing the data are bound to confidentiality.
- Security measures — appropriate technical and organisational measures.
- Sub-processors — conditions for engaging them (authorisation, flow-down terms).
- Assistance — helping the controller with data-subject rights and breach obligations.
- Deletion or return of the data at the end of the engagement.
- Audits — allowing the controller to verify compliance.
If a DPA is missing any of these, it is incomplete. This is a "liftable" checklist you can hold any agency's DPA against.
Sub-processors: the platforms in the chain
An agency may engage sub-processors for processing it performs on the client's behalf, such as a hosting or workflow provider. Google, Meta, TikTok, email tools and CRMs are not sub-processors merely because the agency uses them. First determine who contracts with the provider, on whose behalf it processes and whether its terms assign processor, independent-controller or joint-controller roles.
For actual sub-processors, Article 28 requires prior specific or general written authorisation, notice of intended changes under general authorisation and equivalent data-protection obligations. For platforms acting as controllers, a sub-processor list is the wrong governance tool; review the relevant controller terms, transparency, lawful basis and allocation of responsibilities instead.

International transfers
If personal data leaves the UK/EEA — and it often does, because major platforms are US-based — you need a lawful transfer mechanism. The main routes:
- EU-US Data Privacy Framework (DPF) — provides an adequacy route for transfers to DPF-certified US organisations. It currently underpins many US platform transfers, but it is subject to legal challenge, so its status must be verified.
- UK Extension to the DPF (the "UK-US data bridge") — the UK equivalent for transfers to certified US organisations.
- Standard Contractual Clauses (SCCs) — a contractual safeguard where adequacy does not apply, accompanied by the assessment and supplementary measures required for the transfer context.
As of July 2026, the European Commission continues to list the EU–US DPF adequacy decision. It covers only participating US organisations and the data categories within their certification; verify the recipient in the official DPF list. A US address or a vendor's general claim of compliance is not enough. Transfer routes can change, so record the source and date checked.
The jurisdiction bridge: UK and US
These regimes should be mapped separately:
- United Kingdom — UK GDPR and the Data Protection Act 2018 have been amended by the Data (Use and Access) Act 2025. The ICO states that all its data-protection provisions were in force by June 19, 2026. Controller and processor analysis remains relevant, but do not assume every EU rule or transfer test is identical.
- United States — there is no single comprehensive federal equivalent to GDPR. California's "business," "service provider," "contractor" and third-party concepts have their own statutory definitions and contractual conditions.
For a company operating across markets, build a jurisdiction and data-flow map rather than translating labels approximately. Territorial scope, consumer rights, sensitive-data rules, contracts and advertising-technology requirements can differ.
Data at the end of the engagement
A frequently missed clause: what happens to personal data when the relationship ends. The DPA should require the processor to delete or return all personal data at the end of the engagement (at the controller's choice), and delete existing copies unless law requires retention. This connects to offboarding — your audiences and data should come back to you, and the agency's copies should be deleted — which is part of the account and data ownership picture.
Classify each processing activity, not the whole agency
One supplier can occupy several roles. Campaign execution against the client's CRM list may be processing on instructions. The agency's own lead generation is separate controllership. A jointly designed research panel may involve joint decisions over purpose and essential means. The record should therefore classify each activity, dataset, purpose, system, recipient, retention period, and transfer.
The contract cannot override the facts. A controller remains responsible for choosing processors that provide sufficient guarantees. A processor needs written authorization before adding sub-processors and must flow equivalent Article 28 protections down the chain. At exit, deletion should include production systems, exports, support tools, and sub-processors, with any legally required retention identified separately.
For US vendors, an EU-US Data Privacy Framework certification can support a transfer only while the recipient and data category are covered. Otherwise, another transfer mechanism and transfer-risk assessment may be needed. UK transfers use the UK framework, and current ICO guidance should be checked after the Data (Use and Access) Act 2025 changes.
Glossary
- Controller — determines the purposes and means of processing personal data.
- Processor — processes personal data on behalf of a controller, on its instructions.
- Joint controller — jointly determines purposes and means with another party (GDPR Art. 26).
- DPA (data processing agreement) — the Article 28 contract governing controller-processor processing.
- Sub-processor — a third party a processor engages to help process the data.
- DPF (Data Privacy Framework) — an EU-US adequacy route for transfers to certified US organisations.
- SCCs — Standard Contractual Clauses, a contractual transfer mechanism.
- CCPA/CPRA — California's privacy regime; "business" ≈ controller, "service provider" ≈ processor.
How Space Ads approaches data roles
Space Ads maps processing by activity, system and data flow rather than assigning one role to the entire relationship. Where we act on a client's documented instructions, Article 28 terms may apply. A platform integration is reviewed separately: the client's and platform's terms do not automatically make Space Ads a joint controller, and our role depends on the decisions we actually make.
The operating record should identify controller instructions, actual sub-processors, platform-controller terms, transfer route, retention, access and deletion evidence. That governance sits alongside performance marketing run in client-owned accounts and the agency contract checklist. Space Ads can implement agreed controls, but the controller and its legal advisers should approve the legal analysis for their markets and risk profile.
FAQ
Is a marketing agency a data controller or a data processor?
It depends on each processing activity. An agency is a processor when it handles personal data on behalf of a controller within documented instructions. It is a controller for its own purposes and a joint controller only when it jointly participates in determining purposes and essential means. Campaign management, audience building or tag installation does not decide the role by itself.
When does a marketing agency become a joint controller?
When it jointly participates in determining purposes and essential means through a common or converging decision with tangible impact. Fashion ID treated the website operator and Facebook as joint controllers for specific collection and transmission, not every supplier that implements a tag. Analyse the agency separately from the client–platform arrangement.
Do I need a DPA with my marketing agency?
Yes, wherever the agency acts as your processor. Article 28 requires binding terms, but they can be in the services agreement, a schedule or a separate DPA. An NDA is insufficient because it does not normally cover the mandatory processor obligations.
What must a DPA contain under GDPR?
Under Article 28: the subject matter, duration, nature and purpose of processing; the data types and data subjects; that the processor acts only on documented instructions; confidentiality; security measures; sub-processor conditions; assistance with data-subject rights and breaches; deletion or return of data at the end; and audit rights. Missing any of these makes the DPA incomplete.
Are Google, Meta and TikTok processors or controllers?
It varies by the data and the processing, and it changes as platforms update their terms. A platform can be a processor for some data, a sub-processor in your chain, or an independent or joint controller for parts of ad delivery and measurement. Because these classifications shift, verify each platform's current role and data-processing terms rather than assuming a fixed answer.
Does GDPR apply to my US business, and what is the equivalent?
EU GDPR can apply to a US business offering goods or services to people in the EU or monitoring their behaviour there; UK GDPR has separate territorial scope. The United States has no single GDPR equivalent. California and other state laws use different definitions and contracts, so assess each applicable regime rather than substituting labels.
How is personal data handled when the agency relationship ends?
The DPA should require the processor to delete or return all personal data at the end of the engagement, at the controller's choice, and delete existing copies unless retention is legally required. This ties into offboarding — your audiences and data return to you, and the agency's copies are deleted — and should be an explicit clause, not left to good faith.
Key takeaways
- Under GDPR the agency's role follows its function, not the contract label.
- Processor status requires processing on behalf of a controller within instructions; do not assume it from the supplier relationship.
- Tracking can create a client–platform joint-controller arrangement for defined operations, but does not automatically make the implementing agency joint controller.
- Article 28 terms must contain the mandatory elements; platforms must be classified rather than automatically listed as sub-processors.
- International transfers need a current legal basis (DPF, SCCs, UK extension) — a fast-moving area to verify.
Sources and further reading
- EUR-Lex — GDPR Articles 26 and 28
- European Commission — Controller–processor standard clauses 2021/915
- EDPB — Guidelines on controller and processor concepts
- Court of Justice of the European Union — Fashion ID judgment summary
- European Commission — EU-US Data Privacy Framework
- ICO (UK) — Controllers, processors, and factual role assessment
- ICO (UK) — Data (Use and Access) Act 2025 changes in force
Continue learning
Continue reading

Lead Generation for Online Courses and Education Providers
Education lead generation must connect an honest promise with learner fit, enrolment and course starts—not just form volume. Learn how to design the journey, evidence claims and measure each intake.

How to Choose a Performance Marketing Agency
Choose a performance marketing agency with a defined brief, evidence-based scorecard and clear commercial safeguards. This guide covers team evaluation, measurement, account access, fees, contracts and handover.

Website Marketing: How to Actually Drive Revenue From Your Site
A website creates commercial value when it helps the right people complete the right task and gives the business reliable feedback. This guide connects audience journeys, acquisition, experience, measurement and experimentation.


































