BLOG · GDPR

GDPR:
What is a web agency responsible for?

Agencies touch personal data every day — contact forms, analytics, newsletters, client site backups. Yet there is constant confusion over who carries the responsibility: the agency or the client? The answer depends on your role. Here are the roles explained, the five classic mistakes, and a 5-step checklist.

Updated August 2026 · Reading time: 7 minutes

Two roles: controller and processor

The GDPR (Regulation 2016/679) defines two main roles, and understanding them decides who answers to the supervisory authority:

🎯 Controller

The party that determines why and in broad terms how data is processed. Your client is typically the controller for their website's data: they decide the purposes (marketing, sales) and the means (CMS, newsletter tools).

🔧 Processor

The party that processes data on the controller's instructions. An agency maintaining a client site with access to user data via admin logins, backups or staging environments is typically a processor.

⚖️ Both at once

Many agencies are both: processor for client website data — but an independent controller for their own data (employees, own leads, analytics on their own domain).

Why it matters: as a processor you cannot simply "follow the client's instructions" if those instructions breach the GDPR — you are jointly exposed. And without a written data processing agreement (DPA), the processing is unlawful from day one (Art. 28).

The five classic agency mistakes

1. No data processing agreement. Art. 28 requires a written DPA BEFORE processing starts — not "we'll get to it later". This also applies to your sub-processors (hosting, e-mail).

2. Cookies before consent. Non-essential cookies (analytics, marketing, social plugins) may only be set after active, informed consent — and refusing must be as easy as accepting. A banner with "Accept all" and a buried reject button does not comply.

3. Analytics without a legal basis. A default Google Analytics setup transfers data to the US. European data protection authorities have ruled this requires extra safeguards (IP truncation, DPA, possibly proxy solutions) — otherwise traffic data is effectively personal data without a lawful basis.

4. Form data in email chains. Contact forms forwarded as email scatter personal data across mailboxes with no retention limit or access control. Better: deliver form submissions directly to the CMS/database with logged access.

5. Forgotten staging and backup environments. Copies of production sites with real user data often sit unprotected on staging domains. Either anonymise the data or lock the environments behind login — and set a deletion deadline.

The 72-hour rule — it applies to agencies too

In case of a personal data breach, the controller must notify the supervisory authority within 72 hours where the risk is real (Art. 33). As a processor your duty is tighter: you must notify the client without undue delay after becoming aware of the breach (Art. 33(2)).

In practice: if you discover a client site has been compromised, the client's 72-hour clock starts immediately — and your notification duty makes your reaction time a contractual matter. Have a written incident process ready: who detects, who assesses, who notifies, within how many hours.

📝 What must a DPA contain?

Art. 28(3) lists the minimum: subject matter and duration, nature and purpose, data categories, the controller's rights and obligations, confidentiality, security measures, sub-processors, assistance with notifications, deletion/return of data and audit rights. Our e-book includes a ready-to-use template.

🌍 Hosting and third countries

Clients increasingly ask where their site is hosted. EU/EEA hosting removes a whole chapter of transfer questions. If you use sub-processors in third countries, they must be listed in the DPA and covered by Standard Contractual Clauses.

A 5-step checklist for your agency

How to get the basics in place — without turning it into a months-long project:

1. Map your data processes. Which client sites do you have access to? Where do form submissions land? Which tools do you set up yourself (analytics, newsletters)? One overview goes a long way.
2. Get DPAs on every client relationship. One standard template + a short process: send at contract start, archive the signed version.
3. Clean up cookies and tracking. Consent banner with equal terms for yes/no, strictly necessary cookies only before consent, documented cookie policy.
4. Write the incident process. One page: detection → assessment → client notification (hours, not days) → help with the authority report.
5. Review annually. New clients, new tools, new sub-processors? Update the list and the agreements. A documented review counts at audits.

Scan your site free →    See the GDPR e-book →    NIS2 readiness guide →

Frequently asked questions

Is the agency responsible for the client's website cookies?

As a rule, no — the client determines the purpose of tracking. BUT: if you set up the cookie, you chose the technical solution and delivered the configuration. Make sure the client actively approved the setup and that the consent solution actually works. Responsibility can be shared (Art. 26, joint controllership).

Do we need a DPA with the hosting provider too?

Yes — hosting a website containing personal data is processing on behalf of the controller. Either the client is the direct party (typical when the client owns the hosting account), or you are the intermediary and must have your own agreement with the host, passing on the same requirements.

How big are the fines?

Up to €20 million or 4% of global turnover for serious violations of principles; €10 million / 2% for e.g. missing DPAs or inadequate security. For small businesses, the realistic risk is usually orders, supervisory proceedings and lost trust.

Does GDPR even apply to small sites?

Yes. GDPR has no size threshold — only exemptions for purely personal/household use. A business contact page with names and emails is personal data, whether the company has three employees or three hundred.

How does this relate to NIS2 and the EAA?

Three tracks: GDPR protects personal data, NIS2 requires operational cybersecurity, the EAA demands accessibility. A single incident can hit several tracks at once. See our NIS2 and EAA guides for the other pillars.

Related guides