All posts

GDPR Agency UK: Why Digital Marketing Agencies Face Joint Controller Risk in 2026

29 June 20266 min read

When your strategist defines a Facebook lookalike audience or your media buyer enables tracking pixels, you become a joint controller - sharing full legal liability with your client. Most agencies discover this after receiving their first data protection authority complaint. The comfortable assumption that you're just following client instructions no longer shields you from £17.5 million fines.

What changed for UK agencies in 2026

The stakes for marketing agencies jumped dramatically in February 2026. PECR penalties aligned with UK GDPR levels from August 2025. Organisations face potential fines of up to £17.5 million, or 4% of their annual global turnover, for breaches including unlawful cookie use, inadequate consent mechanisms, and electronic marketing violations.

DUAA changes that imbalance by aligning PECR fines with UK GDPR. In short: the things marketers do most often now carry the same penalty ceiling as major data-protection breaches. Setting up a Facebook Custom Audience or installing Google Analytics now carries the same maximum penalty as a major data breach.

In October 2025, the Information Commissioner's Office (ICO) fined Capita £14 million for cybersecurity failures that exposed the data of 6.6 million people. The fine, reduced from £45 million, is the ICO's largest ever. The ICO is showing it will use its full powers.

The joint controller trap most agencies fall into

Here's what triggers joint controller status for UK agencies:

Joint controller status triggers when you make decisions about processing purposes or means. Defining targeting criteria for Facebook Custom Audiences, selecting ad networks, or optimizing algorithms all create joint controller obligations. The EDPB clarifies that agencies setting campaign criteria become joint controllers with both platforms and clients, creating joint and several liability under Article 26.

Real examples from agency work:

  • Creating lookalike audiences based on client data
  • Setting up Google Analytics tracking parameters
  • Choosing which ad networks to use
  • Defining retargeting pixel criteria
  • Installing third-party tracking tools
Processor role applies when executing strictly defined tasks with client-provided instructions. Sending email campaigns to client-supplied lists using client-approved copy qualifies as processing. Most agencies do both processor and controller activities within the same client relationship.

When using a social media platform to target political messaging, you are likely to be a joint controller with the platform. Therefore you need to establish who is responsible for each aspect of the processing, and ensure you have an appropriate arrangement in place. The same principle applies to all digital advertising platforms.

Why small agencies aren't exempt

The idea that small businesses sit outside UK GDPR remains one of the most persistent myths in UK data protection, and the ICO has consistently rejected it. UK GDPR applies to any controller or processor handling the personal data of people in the UK, regardless of headcount or turnover. The only size-related relief is a narrow exception in Article 30(5) for record-keeping.

Agencies process personal data and must comply with GDPR regardless of size. Even small agencies handling client data fall under GDPR scope. Exemptions are extremely narrow and don't apply to marketing activities.

A recruitment agency fined £130,000 for unlawfully sharing personal data with clients. A small business was fined £10,000 for sending unsolicited marketing emails without proper consent. The ICO doesn't distinguish between large and small agencies when issuing fines.

The common compliance failure pattern

Here's what typically happens when agencies get it wrong:

1. Inadequate contracts: Many agencies use pre-GDPR contracts with insufficient processor terms. Review all Master Services Agreements to ensure robust Article 28 DPAs.

2. Missing joint controller agreements: Joint Controller Agreements are required when agencies make targeting decisions, clearly allocating GDPR responsibilities under Article 26.

3. Poor vendor chain documentation: Ad tech creates sprawling data supply chains. Data passes through exchanges, supply-side platforms, verification services, and attribution tools. Agencies must document this chain and ensure contractual coverage.

4. Consent implementation failures: With penalty ceilings aligned and powers strengthened, expect the ICO to prioritise high-impact conduct such as mass unsolicited communications, ignoring opt-outs, and manipulative consent flows. Cookies remain hot: The ICO has repeatedly signalled focus on cookies and online tracking.

Generally, it is not uncommon for the Information Commissioner to take several instances of enforcement action in respect of illegal direct marketing activities per month, and in many cases it only takes only a very small number of complaints (and sometimes just a single complaint) to trigger an ICO investigation in respect of this type of breach.

What agencies must do to stay compliant

1. Map your actual roles

Your legal status under GDPR changes based on function, not contract labels. The same agency can be a processor for one activity and a joint controller for another.

Document each processing activity:

  • Email campaigns from client lists (processor)
  • Setting up Facebook pixel tracking (joint controller)
  • Creating Custom Audiences (joint controller)
  • Installing Google Analytics (joint controller)

2. Fix your contracts immediately

A key point to be aware of is that in order to safeguard data security there must always be a written contract in place between the data controller and the data processor. This means that, as a marketing agency, you must put in place a written contract for your services between you and the clients that you work with.

Required contract elements:

  • Article 28 Data Processing Agreement for processor activities
  • Article 26 Joint Controller Agreement for shared decision-making
  • Clear allocation of GDPR responsibilities
  • Subprocessor lists and notification procedures

3. Document your vendor chain

Platform contracts often contain processor terms buried in terms of service that may not meet GDPR requirements. Supplementary DPAs with major platforms should explicitly address Article 28 requirements. Subprocessor lists must be actively maintained and publicly accessible. Publishing a list once during contract signature is insufficient - clients need real-time visibility into who processes their data.

Maintain current documentation for:

  • Google Ads and Analytics
  • Facebook/Meta Business Manager
  • Email service providers
  • CRM platforms
  • Analytics tools
  • Attribution services

4. Implement proper consent management

Implement consent management platforms that block all tracking until users provide explicit consent. Use granular consent options allowing users to accept analytics while rejecting advertising. Ensure Consent Mode v2 integration for Google platforms. Never load tracking scripts before receiving consent.

On April 29, 2026, the UK Information Commissioner's Office ("ICO") published the final updated version of its guidance on storage and access technologies such as cookies, pixels and similar technologies. The guidance takes into consideration the requirements of the Privacy and Electronic Communications Regulations, the UK General Data Protection Regulation ("UK GDPR") and the latest changes introduced by the Data (Use and Access) Act 2025. The guidance sets out the key obligations for organizations when using Technologies, such as when and how to procure consent.

5. Prepare for the June 2026 complaints deadline

The DUAA's clearest change to data subject rights was the introduction of a brand-new right to complain, with its own bespoke response deadline requiring controllers to acknowledge a complaint within 30 days, with a full response 'without undue delay'. This will come into force instead on 19 June 2026.

Set up:

  • Complaints handling procedures
  • Response templates and workflows
  • Staff training on the new complaint right
  • Documentation systems for complaint tracking

6. Assess your current risk exposure

The larger fines change the risk calculus. Direct-marketing and tracking practices now carry strategic (not just operational) risk. Budgeting for compliance work - data quality, consent UX, CMP upgrades, suppression automation - is a cost-avoidance play against seven- or eight-figure exposure.

Conduct an immediate audit of:

  • All client data processing activities
  • Current contract terms with clients and vendors
  • Consent mechanisms across all client properties
  • Data retention and deletion procedures
  • Staff access controls and training records
The cost of getting this wrong isn't just the fine. Reputational harm often exceeds the fine itself. Clients will abandon agencies that expose them to regulatory risk.

If you're not sure whether your business is covered, Rowpa generates your full ROPA in 15 minutes. Start free at rowpa.app

Sources

1. CMS Law GDPR Enforcement Tracker - United Kingdom - UK GDPR enforcement statistics and marketing-related fines 2. ICO Guidance on UK GDPR - Official UK data protection guidance 3. Data (Use and Access) Act 2025 Changes - 2026 legislative changes affecting agencies 4. GDPR Compliance Guide for Marketing Agencies (2026) - Detailed agency compliance framework 5. UK ICO Storage and Access Technologies Guidance - 2026 cookie consent requirements 6. Legal Guidance on Controllers and Processors - Marketing agency role definitions 7. PECR Fines UK Analysis - Marketing-specific penalty increases 8. 2025 UK Data Protection Cases Overview - Recent enforcement actions

Disclaimer: This post is for information only and does not constitute legal advice.

Further reading