Agencies managing client email marketing under GDPR act as data processors while the client is the data controller. Compliance requires a signed Data Processing Agreement (DPA), a lawful basis for sending (usually consent or legitimate interest), documented opt-in records, secure data handling, and clear sub-processor disclosure. Both parties share liability, so contracts must define responsibilities precisely.

Who is the controller and who is the processor?

Under GDPR Article 4, the controller decides why and how personal data is processed. The processor acts on the controller's instructions. When an agency runs email campaigns on behalf of a client, the client owns the relationship with the contacts and sets the purpose, so the client is the controller. The agency processes that data and is the processor.

This distinction matters because Article 28 requires a binding contract between controller and processor. Most teams get this wrong by assuming the agency carries no liability. It does. Article 82 lets data subjects claim damages from either party, and regulators can fine processors directly.

What if the agency builds its own lists?

If the agency collects contacts, sets sending logic, and decides targeting without client instruction, it may become a joint controller under Article 26. Joint controllers need an arrangement document defining who handles consent, access requests, and breach notifications. Get legal review here before assuming you're just a processor.

Diagram showing data flow between a marketing agency acting as processor and a client acting as controller under GDPR

Sign a Data Processing Agreement (DPA)

The DPA is non-negotiable. Article 28(3) lists exactly what it must cover:

  • Subject matter, duration, and purpose of processing
  • Types of personal data and categories of data subjects
  • The processor acts only on documented instructions
  • Confidentiality obligations for staff
  • Security measures (Article 32)
  • Sub-processor rules and authorization
  • Assistance with data subject requests and breach reporting
  • Deletion or return of data at contract end
  • Audit rights for the controller

Most email platforms publish their own DPAs. Mailchimp's data processing addendum and similar documents from SendGrid or HubSpot cover the platform as a sub-processor. The agency still needs its own DPA with the client on top of these.

Establish a lawful basis for every send

No email goes out without a lawful basis under Article 6. For B2C marketing in the EU, that almost always means consent that meets the GDPR standard: freely given, specific, informed, and unambiguous. Pre-ticked boxes don't count.

Consent vs. legitimate interest

B2B email sometimes relies on legitimate interest (Article 6(1)(f)), but you must run and document a Legitimate Interest Assessment (LIA). The ePrivacy Directive and national laws like Germany's UWG often still require consent for marketing emails regardless of GDPR's lawful basis, so check the destination country.

Keep records that prove consent: timestamp, source form, IP address, and the exact wording the contact agreed to. If the client hands over a list, ask for that proof before the first campaign. No proof, no send.

Handle data subject rights

Contacts can request access, erasure, or objection at any time. The agency must build workflows to act fast since GDPR gives controllers one month to respond. Practical steps:

  1. Honor every unsubscribe immediately and suppress permanently
  2. Forward access and erasure requests to the client controller
  3. Maintain a suppression list that syncs across all campaigns
  4. Document each request and the action taken
Checklist screenshot of GDPR email marketing tasks including consent records, DPA, suppression lists and breach response

Secure the data and manage sub-processors

Article 32 requires "appropriate technical and organizational measures." For an email agency that means encryption in transit and at rest, access controls limiting who sees contact lists, MFA on platform logins, and a documented breach response plan. Article 33 gives processors a duty to notify the controller "without undue delay" after discovering a breach.

Every tool you plug in is a sub-processor: your ESP, CRM, analytics, and any enrichment service. List them all, get controller authorization, and confirm each has GDPR-compliant terms. The same vendor diligence applies whether you run campaigns in-house or weigh outsourcing parts of the workflow to a third party.

International data transfers

If data leaves the EEA, for example to a US-based platform, you need a transfer mechanism. Standard Contractual Clauses (SCCs) are the common route after Schrems II. Many large ESPs now offer EU data residency options that keep contact data inside the region and simplify this.

Common mistakes agencies make

  • Treating the platform DPA as a substitute for an agency-client DPA
  • Reusing one client's list for another client (a clear purpose-limitation breach)
  • Failing to document consent received with imported lists
  • Ignoring the ePrivacy/consent rules and relying on legitimate interest alone
  • No process for breach notification within the contractual window

Clear documentation protects you the way a structured discovery process protects a sales conversation: it removes guesswork and creates an audit trail.

Key takeaways

  • The client is the controller; the agency is the processor (sometimes a joint controller).
  • Sign an Article 28-compliant DPA with every client.
  • Confirm a lawful basis and keep consent records for every contact.
  • Build fast workflows for data subject rights and suppression.
  • Secure data, disclose sub-processors, and handle EU-to-non-EU transfers with SCCs.
  • Both parties carry liability, so define responsibilities in writing.

GDPR isn't a one-time checkbox. Audit your campaigns, contracts, and tooling regularly, and document everything you do.