Under GDPR, whether your marketing agency is a data controller, a processor or a joint controller depends on the function it performs with personal data — not the label written in the contract. In most of what an agency does on your behalf (managing campaigns, sending emails to your list) it is a processor, and you need a Data Processing Agreement (DPA). But some activities — building audiences, deploying the Meta pixel, choosing targeting — can make it a joint controller with you or with the platform, which changes the paperwork required. Getting the role right is not pedantry; it decides which agreements you actually need to be compliant.

Operator guidance, not legal advice. Data-protection roles, platform statuses and transfer mechanisms change — verify the current position (including DPF/adequacy status and platform sub-processor terms) at the time you rely on this, and take legal advice for your situation.
TL;DR
- Role follows function, not label. A contract calling the agency a "processor" does not make it one if it acts like a controller.
- Usually the agency is a processor — it processes your data on your instructions — and you need a DPA.
- Some activities make it a joint controller — notably deploying tracking like the Meta pixel, where you and the platform jointly determine collection.
- A DPA must contain specific things under GDPR Article 28 — purpose, duration, security, sub-processors, deletion.
- Platforms (Google, Meta, TikTok) have their own roles — processor, sub-processor or controller depending on the data; verify current terms.
- International transfers need a legal basis — the EU-US Data Privacy Framework, SCCs, or the UK extension; this area shifts with court rulings.
- The bridge: UK GDPR (ICO) mirrors the EU; the US equivalent is CCPA/CPRA's "business" vs "service provider."
Controller, processor, joint controller — the definitions
Three roles, defined by who decides why and how personal data is processed:
- Controller — determines the purposes and means of processing. It decides what data is collected and why. (Usually: you, the client.)
- Processor — processes personal data on behalf of a controller, on its instructions. It does not decide the purpose. (Usually: the agency, for most tasks.)
- Joint controller — two or more parties jointly determine the purposes and means. (Sometimes: you and the agency, or you and a platform, for specific activities.)
The decisive fact is the function, not the title. GDPR and the EDPB are explicit that the role is determined by what a party actually does with the data, so a contract that labels the agency a "processor" is worthless if the agency is really deciding purposes and means — the regulator will treat it as a controller regardless. This is why you cannot fix a role problem with wording alone; you fix it by matching the paperwork to what actually happens.

Usually a processor — so you need a DPA
For the bulk of agency work, the agency is a processor: you decide the purpose (promote your products, generate leads), and the agency executes on your instructions using your data. Running your ad accounts, emailing your customer list, managing your CRM data — these are processing on your behalf. GDPR requires a Data Processing Agreement governing that relationship, and an NDA is not a substitute.
A DPA is a legal requirement wherever a processor handles personal data for a controller, and its absence is itself a compliance gap. It should be a distinct agreement or annex to the main contract — not a stray clause — because it has specific mandatory contents (below). The marketing agency contract checklist treats the DPA as a required annex for exactly this reason.
When the agency becomes a joint controller
The nuance that trips up most contracts: some common marketing activities make the agency (or you, or both) a joint controller rather than a simple processor. The role flips when a party helps determine the purposes and means of processing, rather than just executing instructions.
The clearest example is tracking pixels and the Conversions API. European case law and EDPB guidance established that a website operator embedding a platform's tracking (the Fashion ID line of reasoning) is a joint controller with the platform for the collection and transmission of the data, because both benefit from and shape that processing. So when an agency deploys the Meta pixel and Conversions API or builds audiences, the arrangement can be joint control — between you and Meta, and the agency's role has to be mapped to what it actually decides.
Activity → role risk map
| Activity | Typical role | Why |
|---|---|---|
| Managing campaigns on your instructions | Processor | Agency executes; you set the purpose |
| Emailing your customer list | Processor | Agency processes your data on your behalf |
| Building custom/lookalike audiences | Leans towards joint control | Shapes purposes/means of the profiling |
| Deploying the Meta pixel / CAPI | Joint control (with the platform) | Both determine collection; established in case law |
| Choosing targeting and data used | Can tip towards controller/joint | Deciding "how" and "why," not just executing |
| Agency using data for its own purposes | Controller (of that processing) | It decides the purpose itself |
The map is directional, not absolute — the exact role turns on the specifics of each arrangement — but the pattern is clear: pure execution is processing; helping decide the purpose or means moves towards (joint) control. Where joint control applies, GDPR Article 26 requires a transparent arrangement setting out each party's responsibilities.

What a DPA must contain
A DPA is not free-form; GDPR Article 28 sets out mandatory contents. A compliant DPA specifies:
- Subject matter, duration, nature and purpose of the processing.
- The types of personal data and categories of data subjects.
- The controller's instructions — the processor acts only on documented instructions.
- Confidentiality — persons processing the data are bound to confidentiality.
- Security measures — appropriate technical and organisational measures.
- Sub-processors — conditions for engaging them (authorisation, flow-down terms).
- Assistance — helping the controller with data-subject rights and breach obligations.
- Deletion or return of the data at the end of the engagement.
- Audits — allowing the controller to verify compliance.
If a DPA is missing any of these, it is incomplete. This is a "liftable" checklist you can hold any agency's DPA against.
Sub-processors: the platforms in the chain
Your agency does not process your data alone — it uses platforms (Google, Meta, TikTok, email tools, CRMs), and those are sub-processors in the chain. A DPA should require the agency to disclose its sub-processors, flow down equivalent obligations, and notify you of changes so you can object.
The platforms' own roles vary and must be checked rather than assumed: a platform can be a processor for some data, a sub-processor in your chain, or an independent/joint controller for other processing (advertising platforms often act as controllers or joint controllers for parts of ad delivery and measurement). These classifications shift as platforms update their data terms, so verify each platform's current role and terms at the time you set up the DPA rather than relying on a fixed statement.

International transfers
If personal data leaves the UK/EEA — and it often does, because major platforms are US-based — you need a lawful transfer mechanism. The main routes:
- EU-US Data Privacy Framework (DPF) — provides an adequacy route for transfers to DPF-certified US organisations. It currently underpins many US platform transfers, but it is subject to legal challenge, so its status must be verified.
- UK Extension to the DPF (the "UK-US data bridge") — the UK equivalent for transfers to certified US organisations.
- Standard Contractual Clauses (SCCs) — the fallback contractual mechanism where adequacy does not apply, usually with a transfer risk assessment.
This is the most time-sensitive area in the whole topic. Adequacy decisions and frameworks have been struck down before (Safe Harbor, then Privacy Shield, via the Schrems rulings), and the current DPF faces its own challenges. Do not treat any transfer mechanism's validity as permanent — confirm the current position when you rely on it.
The jurisdiction bridge: UK and US
The GDPR framework extends and mirrors across jurisdictions:
- UK GDPR — post-Brexit, the UK has its own GDPR mirroring the EU version, overseen by the ICO; the controller/processor concepts and DPA requirements are equivalent.
- US — CCPA/CPRA — California's regime uses different language for the same idea: a "business" is broadly analogous to a controller, and a "service provider" to a processor, with contractual requirements that echo a DPA.
For a company operating across these markets, the practical point is that the same functional analysis applies — who decides purposes and means — even though the labels and specific rules differ. Map the role first; then apply the right jurisdiction's paperwork.
Data at the end of the engagement
A frequently missed clause: what happens to personal data when the relationship ends. The DPA should require the processor to delete or return all personal data at the end of the engagement (at the controller's choice), and delete existing copies unless law requires retention. This connects to offboarding — your audiences and data should come back to you, and the agency's copies should be deleted — which is part of the account and data ownership picture.
Classify each processing activity, not the whole agency
One supplier can occupy several roles. Campaign execution against the client's CRM list may be processing on instructions. The agency's own lead generation is separate controllership. A jointly designed research panel may involve joint decisions over purpose and essential means. The record should therefore classify each activity, dataset, purpose, system, recipient, retention period, and transfer.
The contract cannot override the facts. A controller remains responsible for choosing processors that provide sufficient guarantees. A processor needs written authorization before adding sub-processors and must flow equivalent Article 28 protections down the chain. At exit, deletion should include production systems, exports, support tools, and sub-processors, with any legally required retention identified separately.
For US vendors, an EU-US Data Privacy Framework certification can support a transfer only while the recipient and data category are covered. Otherwise, another transfer mechanism and transfer-risk assessment may be needed. UK transfers use the UK framework, and current ICO guidance should be checked after the Data (Use and Access) Act 2025 changes.
Glossary
- Controller — determines the purposes and means of processing personal data.
- Processor — processes personal data on behalf of a controller, on its instructions.
- Joint controller — jointly determines purposes and means with another party (GDPR Art. 26).
- DPA (data processing agreement) — the Article 28 contract governing controller-processor processing.
- Sub-processor — a third party a processor engages to help process the data.
- DPF (Data Privacy Framework) — an EU-US adequacy route for transfers to certified US organisations.
- SCCs — Standard Contractual Clauses, a contractual transfer mechanism.
- CCPA/CPRA — California's privacy regime; "business" ≈ controller, "service provider" ≈ processor.
How Space Ads approaches data roles
We handle this from the agency side, and our operating position is to map the role honestly to the function rather than papering over it with a label. In practice that means a DPA where we act as processor, and transparent joint-controller handling where the function requires it — most concretely for the Meta pixel and Conversions API, where the collection is genuinely joint with the platform, so the disclosure reflects that rather than pretending it is simple processing.
Our approach is to keep the DPA as a proper Article 28 annex to the contract, disclose sub-processors and flow down obligations, verify each platform's current role and the transfer mechanism at setup (because DPF and platform terms move), and require deletion or return of data at the end. That data-protection layer sits inside performance marketing run on your own accounts, and it is spelled out alongside the agency contract checklist. When compliance needs senior ownership across the whole stack, a fractional CMO engagement holds the same line — always with the caveat that the specifics are for your lawyer to confirm.
FAQ
Is a marketing agency a data controller or a data processor?
It depends on the function, not the contract label. For most work — running campaigns and processing your data on your instructions — the agency is a processor, and you need a DPA. For activities where it helps determine the purposes and means, such as deploying tracking pixels or building audiences, it can become a joint controller. GDPR determines the role by what a party actually does.
When does a marketing agency become a joint controller?
When it helps determine the purposes and means of processing, rather than only executing your instructions. The clearest example is deploying a platform's tracking (like the Meta pixel and Conversions API), where European case law treats the arrangement as joint control with the platform. Building audiences and choosing the data and targeting can also tip the role towards joint control.
Do I need a DPA with my marketing agency?
Yes, wherever the agency processes personal data on your behalf. GDPR requires a Data Processing Agreement governing the controller-processor relationship, and an NDA is not a substitute. The DPA should be a distinct agreement or annex with the mandatory Article 28 contents — purpose, security, sub-processors, deletion and more.
What must a DPA contain under GDPR?
Under Article 28: the subject matter, duration, nature and purpose of processing; the data types and data subjects; that the processor acts only on documented instructions; confidentiality; security measures; sub-processor conditions; assistance with data-subject rights and breaches; deletion or return of data at the end; and audit rights. Missing any of these makes the DPA incomplete.
Are Google, Meta and TikTok processors or controllers?
It varies by the data and the processing, and it changes as platforms update their terms. A platform can be a processor for some data, a sub-processor in your chain, or an independent or joint controller for parts of ad delivery and measurement. Because these classifications shift, verify each platform's current role and data-processing terms rather than assuming a fixed answer.
Does GDPR apply to my US business, and what is the equivalent?
GDPR can apply to a US business that targets or monitors people in the EU/UK. The US equivalent concepts are in California's CCPA/CPRA, where a "business" is broadly analogous to a controller and a "service provider" to a processor, with contractual requirements that echo a DPA. The same functional analysis — who decides purposes and means — applies across jurisdictions.
How is personal data handled when the agency relationship ends?
The DPA should require the processor to delete or return all personal data at the end of the engagement, at the controller's choice, and delete existing copies unless retention is legally required. This ties into offboarding — your audiences and data return to you, and the agency's copies are deleted — and should be an explicit clause, not left to good faith.
Key takeaways
- Under GDPR the agency's role follows its function, not the contract label.
- Usually it is a processor and you need a DPA; some activities make it a joint controller.
- Deploying the Meta pixel/CAPI and building audiences can create joint control with the platform.
- A DPA must meet Article 28's mandatory contents; platforms are sub-processors whose roles must be verified.
- International transfers need a current legal basis (DPF, SCCs, UK extension) — a fast-moving area to verify.
Sources and further reading
- EUR-Lex — GDPR Articles 26 and 28
- European Commission — Controller–processor standard clauses 2021/915
- EDPB — Guidelines on controller and processor concepts
- European Commission — EU-US Data Privacy Framework
- ICO (UK) — Controllers, processors, and factual role assessment
Continue learning
Continue reading

Your First Senior Marketing Hire: CMO, VP, or Fractional?
When founder-led marketing hits its ceiling, the instinct is to hire a CMO. Often that is too senior, too early, and too expensive — a VP who still executes, or a fractional lead for direction plus specialist hands, fits better until the company is large enough for a full CMO to have leverage.

Who Owns Your Google Ads, Meta, and GA4 When You Leave an Agency?
You should own your ad accounts and data; the agency is a revocable manager, not the owner. But access is not ownership — the billing profile and account structure decide. This is the platform-by-platform mechanics of what you keep, what you can lose, and how to check before it's too late.

SMS & RCS Marketing: Revenue From a List You Already Own
SMS and RCS are owned channels: revenue from a list you already have, not paid media you rent. They deliver immediacy and high engagement, but only work with clean consent, disciplined frequency and RCS's branded, richer messaging replacing plain texts.




















