Marketing & digital advertising
Data protection for
marketing and advertising agencies
Audience profiling, tracking pixels, transfers to advertising platforms and the data processor role make marketing agencies one of the sectors most exposed to AEPD sanctions. Art. 34 of the LOPDGDD includes advertising and commercial prospecting among the activities that require the appointment of a DPO.
art. 34
LOPDGDD — mandatory DPO
Art. 21
LSSI — email marketing
Art. 28
GDPR — data processing
24 h
personalised proposal
Sector challenges
General obligations for marketing and advertising agencies
Cookies and consent
Tracking pixels, analytics cookies and advertising cookies require prior informed user consent. The cookie banner must be functional and must not use pre-ticked options.
Audience profiling
Creating user profiles for personalised advertising based on behaviour, interests or location is a high-risk processing activity that requires an impact assessment in certain cases.
Role in the client relationship
When the agency accesses the client's data and acts on their instructions, it may operate as a data processor (art. 28 GDPR). The exact legal relationship depends on the contract and the context of each operation; it should be analysed individually and documented.
Transfers to advertising platforms
Sending user data to Meta, Google, TikTok or LinkedIn involves international transfers. For US providers adhering to the Data Privacy Framework (DPF), this is the currently applicable mechanism. For other cases, Standard Contractual Clauses or other mechanisms under art. 46 GDPR are required; their currency should be verified periodically.
Email marketing
Sending commercial communications to contact databases requires prior consent or the existing customer exception. Lists acquired or transferred without adequate guarantees are invalid.
Multiple contractual relationships
The agency manages its own data as a data controller and may act in different roles vis-à-vis its clients depending on the service provided. The exact legal relationship must be analysed in each case; adequate contractual documentation is essential.
Legal obligation
The DPO is mandatory for marketing agencies
Art. 34 of the LOPDGDD establishes the obligation to appoint a Data Protection Officer (DPO) for companies whose main activity is advertising or commercial prospecting. Digital marketing, advertising, email marketing and lead generation agencies are covered by the provisions of that article.
The DPO of a marketing agency has a particularly important role: they must oversee that processing activities carried out on behalf of clients (as data processor) are properly documented and that international transfers to advertising platforms have adequate legal cover.
As a general rule, the final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis.
Certix assumes the role of external DPO under a separate contract, including registration in the AEPD's Register of Data Protection Officers.
Most common legal bases
Art. 6.1.a GDPR
Consent — for advertising cookies, profiling and email marketing.
Art. 6.1.b GDPR
Performance of the marketing services contract with the client.
Art. 6.1.f GDPR
Legitimate interest — aggregate campaign performance analysis.
Art. 28 GDPR
Data processing — access to the advertiser's data.
Art. 45-46 GDPR
DPF or Standard Contractual Clauses — depending on the applicable mechanism for each provider for transfers outside the EEA.
The service
What the service includes for your marketing agency
Record of Processing Activities
Differentiated RoPA: own processing activities and processing on behalf of each advertiser client.
Information clauses
Texts for the client services contract, web forms and lead capture.
Privacy policy and cookies
Legal documentation for the agency's website and its lead capture tools.
Data Processing Agreements (DPA)
Ready-to-sign DPA template for each advertiser client.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Documented procedure for managing requests from email database contacts and users.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited consultations. Updates on regulatory changes.
External DPO
Mandatory appointment for agencies whose main activity is advertising or commercial prospecting (art. 34 LOPDGDD). The final requirement depends on the individual analysis of each entity. Separate contract.
Do you need a proposal for your agency?
Tell us about your agency's size and the services you provide. Proposal within 24 hours.
FAQ
Frequently asked questions about data protection for marketing agencies
Are marketing agencies required to appoint a Data Protection Officer (DPO)?
Art. 34 of the LOPDGDD establishes the obligation to appoint a Data Protection Officer (DPO) for companies whose main activity is advertising or commercial prospecting. Digital marketing agencies that carry out audience profiling, manage databases or run email marketing campaigns are covered by the provisions of that article. As a general rule, the final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis.
Is the marketing agency a data processor or a data controller in relation to its clients?
It depends on the context of each operation and the contractual relationship. As a general rule, when the agency accesses the client's CRM or contact database and acts strictly on their instructions, the relationship tends to be one of data processing (art. 28 GDPR). However, the exact legal relationship may vary: in some cases there may be joint controllership or a controller-to-controller relationship (both parties independently determining purposes and means). Each case must be analysed individually; this information is for guidance only.
What legal basis is required for email marketing?
To send commercial communications by email to natural persons, their prior consent is required, unless they are already customers and the email content is directly related to the product or service they purchased (art. 21 LSSI). Purchased or transferred contact lists without explicit consent for that purpose are not valid for email marketing.
Do tracking pixels and cookies require user consent?
Yes. Facebook/Meta pixels, Google Ads pixels and tracking and advertising cookies require informed user consent before they are activated. The AEPD has sanctioned companies for installing these technologies without prior consent. The cookie banner must obtain genuine, non-pre-ticked consent.
Does transferring user data to Meta or Google constitute an international transfer?
Yes. Sending user data via Meta or Google APIs involves transferring data to entities in the US. These transfers must be covered by a valid mechanism: for providers adhering to the EU-US Data Privacy Framework (DPF), this is the currently applicable mechanism; in other cases, Standard Contractual Clauses or other mechanisms under art. 46 GDPR are required. The agency must verify which mechanism applies to each provider and document it accordingly.
Can the agency access the client's CRM without a data processing agreement?
No. Accessing the client's CRM involves accessing personal data belonging to the advertiser's contacts, clients or leads. Without a formally executed data processing agreement, this access constitutes a breach of art. 28 GDPR. The agency must require this contract as a prerequisite before accessing any system containing the client's data.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Marketing & digital advertising
GDPR compliance
for your agency.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.