When your strategist defines a Facebook lookalike audience or your media buyer enables tracking pixels, you become a joint controller - sharing full legal liability with your client. Most agencies discover this after receiving their first data protection authority complaint. The comfortable assumption that you're just following client instructions no longer shields you from £17.5 million fines.
The stakes for marketing agencies jumped dramatically in February 2026. PECR penalties aligned with UK GDPR levels from August 2025. Organisations face potential fines of up to £17.5 million, or 4% of their annual global turnover, for breaches including unlawful cookie use, inadequate consent mechanisms, and electronic marketing violations.
DUAA changes that imbalance by aligning PECR fines with UK GDPR. In short: the things marketers do most often now carry the same penalty ceiling as major data-protection breaches. Setting up a Facebook Custom Audience or installing Google Analytics now carries the same maximum penalty as a major data breach.
In October 2025, the Information Commissioner's Office (ICO) fined Capita £14 million for cybersecurity failures that exposed the data of 6.6 million people. The fine, reduced from £45 million, is the ICO's largest ever. The ICO is showing it will use its full powers.
Here's what triggers joint controller status for UK agencies:
Joint controller status triggers when you make decisions about processing purposes or means. Defining targeting criteria for Facebook Custom Audiences, selecting ad networks, or optimizing algorithms all create joint controller obligations. The EDPB clarifies that agencies setting campaign criteria become joint controllers with both platforms and clients, creating joint and several liability under Article 26.
Real examples from agency work:
When using a social media platform to target political messaging, you are likely to be a joint controller with the platform. Therefore you need to establish who is responsible for each aspect of the processing, and ensure you have an appropriate arrangement in place. The same principle applies to all digital advertising platforms.
The idea that small businesses sit outside UK GDPR remains one of the most persistent myths in UK data protection, and the ICO has consistently rejected it. UK GDPR applies to any controller or processor handling the personal data of people in the UK, regardless of headcount or turnover. The only size-related relief is a narrow exception in Article 30(5) for record-keeping.
Agencies process personal data and must comply with GDPR regardless of size. Even small agencies handling client data fall under GDPR scope. Exemptions are extremely narrow and don't apply to marketing activities.
A recruitment agency fined £130,000 for unlawfully sharing personal data with clients. A small business was fined £10,000 for sending unsolicited marketing emails without proper consent. The ICO doesn't distinguish between large and small agencies when issuing fines.
Here's what typically happens when agencies get it wrong:
1. Inadequate contracts: Many agencies use pre-GDPR contracts with insufficient processor terms. Review all Master Services Agreements to ensure robust Article 28 DPAs.
2. Missing joint controller agreements: Joint Controller Agreements are required when agencies make targeting decisions, clearly allocating GDPR responsibilities under Article 26.
3. Poor vendor chain documentation: Ad tech creates sprawling data supply chains. Data passes through exchanges, supply-side platforms, verification services, and attribution tools. Agencies must document this chain and ensure contractual coverage.
4. Consent implementation failures: With penalty ceilings aligned and powers strengthened, expect the ICO to prioritise high-impact conduct such as mass unsolicited communications, ignoring opt-outs, and manipulative consent flows. Cookies remain hot: The ICO has repeatedly signalled focus on cookies and online tracking.
Generally, it is not uncommon for the Information Commissioner to take several instances of enforcement action in respect of illegal direct marketing activities per month, and in many cases it only takes only a very small number of complaints (and sometimes just a single complaint) to trigger an ICO investigation in respect of this type of breach.
Your legal status under GDPR changes based on function, not contract labels. The same agency can be a processor for one activity and a joint controller for another.
Document each processing activity:
A key point to be aware of is that in order to safeguard data security there must always be a written contract in place between the data controller and the data processor. This means that, as a marketing agency, you must put in place a written contract for your services between you and the clients that you work with.
Required contract elements:
Platform contracts often contain processor terms buried in terms of service that may not meet GDPR requirements. Supplementary DPAs with major platforms should explicitly address Article 28 requirements. Subprocessor lists must be actively maintained and publicly accessible. Publishing a list once during contract signature is insufficient - clients need real-time visibility into who processes their data.
Maintain current documentation for:
Implement consent management platforms that block all tracking until users provide explicit consent. Use granular consent options allowing users to accept analytics while rejecting advertising. Ensure Consent Mode v2 integration for Google platforms. Never load tracking scripts before receiving consent.
On April 29, 2026, the UK Information Commissioner's Office ("ICO") published the final updated version of its guidance on storage and access technologies such as cookies, pixels and similar technologies. The guidance takes into consideration the requirements of the Privacy and Electronic Communications Regulations, the UK General Data Protection Regulation ("UK GDPR") and the latest changes introduced by the Data (Use and Access) Act 2025. The guidance sets out the key obligations for organizations when using Technologies, such as when and how to procure consent.
The DUAA's clearest change to data subject rights was the introduction of a brand-new right to complain, with its own bespoke response deadline requiring controllers to acknowledge a complaint within 30 days, with a full response 'without undue delay'. This will come into force instead on 19 June 2026.
Set up:
The larger fines change the risk calculus. Direct-marketing and tracking practices now carry strategic (not just operational) risk. Budgeting for compliance work - data quality, consent UX, CMP upgrades, suppression automation - is a cost-avoidance play against seven- or eight-figure exposure.
Conduct an immediate audit of:
If you're not sure whether your business is covered, Rowpa generates your full ROPA in 15 minutes. Start free at rowpa.app
1. CMS Law GDPR Enforcement Tracker - United Kingdom - UK GDPR enforcement statistics and marketing-related fines 2. ICO Guidance on UK GDPR - Official UK data protection guidance 3. Data (Use and Access) Act 2025 Changes - 2026 legislative changes affecting agencies 4. GDPR Compliance Guide for Marketing Agencies (2026) - Detailed agency compliance framework 5. UK ICO Storage and Access Technologies Guidance - 2026 cookie consent requirements 6. Legal Guidance on Controllers and Processors - Marketing agency role definitions 7. PECR Fines UK Analysis - Marketing-specific penalty increases 8. 2025 UK Data Protection Cases Overview - Recent enforcement actions
Disclaimer: This post is for information only and does not constitute legal advice.