Card on social media agency data protection roles, consent and breach reporting
Image: Social Partner

Rules and ethics

Part of UK rules and ethics for a social media agency

Data protection roles, consent and breach reporting for social media agencies

Data protection roles, consent and breach reporting for England social media agencies, covering UK GDPR, PECR, ICO duties, ASA sanctions and a cost example.

What to take away

  • A client in Leeds asks you to export 4,000 Instagram commenter names for an email campaign. You need a lawful basis under data protection law, and the client's audience consent is rarely yours to use.
  • Agencies act as processors for client customer data and controllers for their own staff and prospect records. The contract must say which.
  • Cookies, pixels and remarketing tags fall under PECR, which needs consent before non-essential storage.
  • As a processor, tell the client about a personal data breach without undue delay; the client, as controller, reports it to the ICO within 72 hours where it risks people's rights.

What does data protection law require of a social media agency?

The UK GDPR and the Data Protection Act 2018 apply across England, Scotland, Wales and Northern Ireland. A Salford agency and a Swansea agency carry the same duties. What differs is the contract behind the client relationship.

When you shortlist agencies from a directory, ask each one to confirm in writing which role it takes for your customer data, who handles subject access requests and what its breach route is. A provider that cannot answer plainly in writing is a compliance risk to your business, however good its creative work looks.

Controller vs processor roles

Processor

Typical work
Running client's page
Legal basis
Documented instructions
Contract cover
Article 28 clause
Example duty
Security of client data

Controller

Typical work
Managing own pitch list
Legal basis
Own lawful basis
Contract cover
Not required
Example duty
Consent for marketing

Two roles matter. Running a client's page and touching their customers' details makes you a processor acting on documented instructions, while managing your own pitch list makes you the controller. Under Article 28 of UK GDPR, whenever a controller instructs a processor to process data on its behalf, the processing must be governed by a contract, also referred to as a data processing agreement (DPA), or other legal agreement. That DPA should set out the subject matter, duration, purpose and security of the processing.

A lawful basis is not optional, and you must be able to name it. UK GDPR Article 6 sets out six: consent, contract, legal obligation, vital interests, public task and legitimate interests. Legitimate interests can support analytics or fraud prevention. Direct marketing by email or text to individuals usually needs consent under the Privacy and Electronic Communications Regulations 2003, although the soft opt-in lets you email existing customers about similar products if they could refuse when their details were collected and in every message since. Keep a consent record showing who consented, when, what they were told and how they can withdraw.

Client work carries duties beyond data handling, including contract terms and advertising disclosure. Our guide to UK rules and compliance for agencies brings them together before you sign a retainer.

Where do agencies most often get consent wrong?

Cookie banners on a landing page you host, pixel placement, and lookalike audiences built from a client's customer list are the recurring failures. Consent must be freely given, specific, and easy to withdraw.

Client lists are the biggest trap. A retailer may hold consent for its own emails, but that consent does not travel to your agency and does not cover paid social targeting. Ask for the consent record, not reassurance.

The ICO's guidance on online safety and data protection explains how data protection duties interact with online safety rules, including the Online Safety Act 2023, for services and platforms. Read it before uploading an audience list and assuming the platform will sort permissions.

How are breaches and complaints handled?

A personal data breach can be as simple as a campaign sent to the wrong segment. Where you process on a client's behalf, tell that client without undue delay; the client, as controller, assesses the risk and, if it is likely to result in a risk to people's rights, reports it to the ICO within 72 hours using the ICO's personal data breach reporting form, and tells affected people where the risk is high. Those controller duties sit in UK GDPR Articles 33 and 34.

The ICO can issue reprimands, enforcement notices and monetary penalties. Advertising content sits with the ASA, whose sanctions page explains outcomes such as adverse publicity and referral to Trading Standards.

Subject access requests must be answered within one month, and can arrive as a direct message to a client's page. Brief whoever runs the inbox on routing them and on logging when each request arrives.

What does compliance cost a small agency?

Take an illustrative example. A six-person agency in Reading runs three client accounts on retainers of £1,500 a month each, so £54,000 a year. It sets aside £60 a year for the ICO data protection fee, an illustrative lowest-tier figure.

One-off work includes a contract and processor-clause review at £900, records-of-processing templates at £250, and staff training at £75 a head for six people, so £450. Year one costs £1,600 before recurring spend.

Ongoing costs include about £120 a month to maintain consent and cookie audit logs across three client sites, which comes to £1,440 a year. First-year spend lands near £3,100, roughly 5.7% of the £54,000 retainer income.

Common questions

Do we need to register with the ICO?

Usually yes if you process personal data as a controller, and the exemptions are narrow. Use the ICO's registration self-assessment to check, and the register of fee payers to confirm an agency is listed. Registration is separate from reporting a breach.

Does the UK GDPR still apply after Brexit?

Yes. It applies in England, Scotland, Wales and Northern Ireland alongside the Data Protection Act 2018. The EU version can also reach you if you market to people in the EU.

Who owns the follower data on a client account?

The client controls its page and audience. You hold that data on the client's instructions and should not reuse it for your own campaigns.

More in Rules and ethics