
Rules and ethics
Part of UK rules and ethics for a social media agency
Check social media agencies UK regulations before you sign: a pre-signature checklist
A pre-signature checklist for social media agencies and UK regulations: PECR, UK GDPR, ICO rules, consent tools, processor clauses and B2B marketing checks.
What to take away
- Use this checklist before you sign with a social media agency in the UK.
- Confirm controller and processor roles, cookie consent, B2B marketing, sub-processors and breach terms.
- Check the tools that will touch data, such as Meta Pixel, LinkedIn Insight Tag and Google Analytics 4.
- Log consent, objections and data sources for every campaign.
- PECR and the UK GDPR apply across the UK, with the ICO as the lead regulator in England.
Pre-signature checklist
1. Data roles and contracts
Check the contract names the client as controller and the agency as processor for each campaign. The agency is usually controller for its own prospecting, staff records and audience research. Ask for a UK GDPR Article 28 data processing agreement. Check sub-processors.
Scheduling, analytics and CRM vendors need authorising in that contract. The ICO's guide to data protection for organisations covers lawful bases, individual rights and breach reporting. The wider framework is in the social media agencies UK rules and compliance guide. Read it before you brief a supplier.
If the agency uses HubSpot or Salesforce, list them as sub-processors where they handle client data. HubSpot offers a free CRM tier; Salesforce editions are paid.
2. Cookie consent and tags
Check which tags will fire on client sites. Meta Pixel, LinkedIn Insight Tag and Google Analytics 4 sit inside PECR cookie rules when used for reporting or retargeting. Consent must be specific, informed and freely given. Pre-ticked boxes and bundled terms fall short.
Where consent is the basis, tags must not fire before opt-in. A consent management platform can record choices. Cookiebot and OneTrust are common options. OneTrust is enterprise and quote-based. Cookiebot offers paid annual plans. Check consent logs are exportable. Check Google Consent Mode settings if using Google tags.
3. B2B marketing
B2B is not exempt from PECR. The ICO's business-to-business marketing guidance explains that some corporate subscribers keep individual protection. Check whether a sole trader or partnership is the subscriber. Keep suppression lists and log consent and objection dates. Give a clear opt-out in every message.
For calls, check the Corporate Telephone Preference Service. For email, Mailchimp and Klaviyo include unsubscribe and consent tracking. Mailchimp has a free tier up to 500 contacts. Klaviyo has a free tier up to 250 contacts. Check those limits if you manage a small list.
4. Breach, transfers and liability
Check the contract covers breach notification. The ICO expects reportable breaches within 72 hours. Check who reports and who notifies affected people. If data leaves the UK, check the ICO's International Data Transfer Agreement or the UK Addendum. Check indemnities and audit rights.
The social media agencies commercial contracts article sets out clauses to settle before work starts. Liability can fall on the sender and, depending on the contract, the agency. Agree indemnities in writing before launch.
5. PECR and lawful basis
PECR sets the rules on electronic marketing, cookies and consent. The Privacy and Electronic Communications (EC Directive) Regulations 2003 are the primary instrument for agency work. Check who holds the lawful basis and how it is recorded. A soft opt-in covers only narrow cases involving existing customers.
If an agency buys a list or scrapes profile data, the risk usually sits with the client. Record the source of every contact. Check the agency does not scrape LinkedIn or other platforms in breach of terms.
Common questions
Does an agency need consent for B2B email?
Often yes, unless a narrow exception applies. Some corporate subscribers keep individual protection, so check the subscriber type and record your reasoning.
Who is liable if a campaign breaches PECR?
Liability can fall on the sender and, depending on the contract, the agency. Agree indemnities in writing before launch.
Do we need a cookie banner for social pixels?
In most cases yes. PECR covers storing and accessing information on a user's device, which includes pixels and tags.
Is this the same across the UK?
PECR and the UK GDPR apply across the United Kingdom, and the ICO is the lead regulator in England. Campaigns in Scotland, Wales or Northern Ireland should check devolved guidance.



