Certix

Marketing & digital advertising

Data protection for
marketing and advertising agencies

Audience profiling, tracking pixels, transfers to advertising platforms and the data processor role make marketing agencies one of the sectors most exposed to AEPD sanctions. Art. 34 of the LOPDGDD includes advertising and commercial prospecting among the activities that require the appointment of a DPO.

art. 34

LOPDGDD — mandatory DPO

Art. 21

LSSI — email marketing

Art. 28

GDPR — data processing

24 h

personalised proposal

Sector challenges

General obligations for marketing and advertising agencies

Cookies and consent

Tracking pixels, analytics cookies and advertising cookies require prior informed user consent. The cookie banner must be functional and must not use pre-ticked options.

Audience profiling

Creating user profiles for personalised advertising based on behaviour, interests or location is a high-risk processing activity that requires an impact assessment in certain cases.

Role in the client relationship

When the agency accesses the client's data and acts on their instructions, it may operate as a data processor (art. 28 GDPR). The exact legal relationship depends on the contract and the context of each operation; it should be analysed individually and documented.

Transfers to advertising platforms

Sending user data to Meta, Google, TikTok or LinkedIn involves international transfers. For US providers adhering to the Data Privacy Framework (DPF), this is the currently applicable mechanism. For other cases, Standard Contractual Clauses or other mechanisms under art. 46 GDPR are required; their currency should be verified periodically.

Email marketing

Sending commercial communications to contact databases requires prior consent or the existing customer exception. Lists acquired or transferred without adequate guarantees are invalid.

Multiple contractual relationships

The agency manages its own data as a data controller and may act in different roles vis-à-vis its clients depending on the service provided. The exact legal relationship must be analysed in each case; adequate contractual documentation is essential.

Legal obligation

The DPO is mandatory for marketing agencies

Art. 34 of the LOPDGDD establishes the obligation to appoint a Data Protection Officer (DPO) for companies whose main activity is advertising or commercial prospecting. Digital marketing, advertising, email marketing and lead generation agencies are covered by the provisions of that article.

The DPO of a marketing agency has a particularly important role: they must oversee that processing activities carried out on behalf of clients (as data processor) are properly documented and that international transfers to advertising platforms have adequate legal cover.

As a general rule, the final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis.

Certix assumes the role of external DPO under a separate contract, including registration in the AEPD's Register of Data Protection Officers.

Most common legal bases

Art. 6.1.a GDPR

Consent — for advertising cookies, profiling and email marketing.

Art. 6.1.b GDPR

Performance of the marketing services contract with the client.

Art. 6.1.f GDPR

Legitimate interest — aggregate campaign performance analysis.

Art. 28 GDPR

Data processing — access to the advertiser's data.

Art. 45-46 GDPR

DPF or Standard Contractual Clauses — depending on the applicable mechanism for each provider for transfers outside the EEA.

The service

What the service includes for your marketing agency

Record of Processing Activities

Differentiated RoPA: own processing activities and processing on behalf of each advertiser client.

Information clauses

Texts for the client services contract, web forms and lead capture.

Privacy policy and cookies

Legal documentation for the agency's website and its lead capture tools.

Data Processing Agreements (DPA)

Ready-to-sign DPA template for each advertiser client.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Documented procedure for managing requests from email database contacts and users.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited consultations. Updates on regulatory changes.

External DPO

Mandatory appointment for agencies whose main activity is advertising or commercial prospecting (art. 34 LOPDGDD). The final requirement depends on the individual analysis of each entity. Separate contract.

Do you need a proposal for your agency?

Tell us about your agency's size and the services you provide. Proposal within 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection for marketing agencies

Are marketing agencies required to appoint a Data Protection Officer (DPO)?

Art. 34 of the LOPDGDD establishes the obligation to appoint a Data Protection Officer (DPO) for companies whose main activity is advertising or commercial prospecting. Digital marketing agencies that carry out audience profiling, manage databases or run email marketing campaigns are covered by the provisions of that article. As a general rule, the final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis.

Is the marketing agency a data processor or a data controller in relation to its clients?

It depends on the context of each operation and the contractual relationship. As a general rule, when the agency accesses the client's CRM or contact database and acts strictly on their instructions, the relationship tends to be one of data processing (art. 28 GDPR). However, the exact legal relationship may vary: in some cases there may be joint controllership or a controller-to-controller relationship (both parties independently determining purposes and means). Each case must be analysed individually; this information is for guidance only.

What legal basis is required for email marketing?

To send commercial communications by email to natural persons, their prior consent is required, unless they are already customers and the email content is directly related to the product or service they purchased (art. 21 LSSI). Purchased or transferred contact lists without explicit consent for that purpose are not valid for email marketing.

Do tracking pixels and cookies require user consent?

Yes. Facebook/Meta pixels, Google Ads pixels and tracking and advertising cookies require informed user consent before they are activated. The AEPD has sanctioned companies for installing these technologies without prior consent. The cookie banner must obtain genuine, non-pre-ticked consent.

Does transferring user data to Meta or Google constitute an international transfer?

Yes. Sending user data via Meta or Google APIs involves transferring data to entities in the US. These transfers must be covered by a valid mechanism: for providers adhering to the EU-US Data Privacy Framework (DPF), this is the currently applicable mechanism; in other cases, Standard Contractual Clauses or other mechanisms under art. 46 GDPR are required. The agency must verify which mechanism applies to each provider and document it accordingly.

Can the agency access the client's CRM without a data processing agreement?

No. Accessing the client's CRM involves accessing personal data belonging to the advertiser's contacts, clients or leads. Without a formally executed data processing agreement, this access constitutes a breach of art. 28 GDPR. The agency must require this contract as a prerequisite before accessing any system containing the client's data.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Marketing & digital advertising

GDPR compliance
for your agency.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.