GDPR Policy Generator for agencies
Written for the agency’s own policy, the client sites it builds, and the processor role in between.
Agency GDPR work has an unusual audience: your clients’ compliance teams. The documents that get requested are the processor agreement, the sub-processor list and the security summary, and having them ready is a commercial advantage as much as a legal one.
An agency has three privacy problems and usually documents only the first. There is the agency’s own site and CRM, where you are a controller. There is client data you hold to do the work - ad account access, analytics logins, CRM exports, customer lists for a campaign - where you are a processor. And there are the sites you build and hand over, where the tracking you installed becomes someone else’s legal exposure.
The middle one is where the contractual risk sits. If you touch client customer data, GDPR Article 28 requires a written processor agreement, and most agency master service agreements do not contain one. Without it, both sides are non-compliant, and the client finds out during their own audit rather than yours.
The third is where the reputational risk sits. An agency that installs GTM, a Meta pixel, a heatmap and a chat widget during a build, and hands over without documenting them, has left a client publishing a privacy policy that is inaccurate from day one. Increasingly, clients notice.
What a GDPR policy for an agency has to cover
Article 30 records for both roles - your own processing and processing on client instructions
A reusable Article 28 schedule covering all the mandated terms
A sub-processor list including tooling, contractors and offshore teams
Transfer mechanisms where contractors or tooling sit outside the UK or EEA
Deletion and return procedures at the end of each engagement
How an agency actually moves personal data
Client customer lists for campaigns
Uploading a customer list to an ad platform for matching is processing on the client’s behalf, and it needs their basis, not yours.
Ad account and analytics access
Delegated access to a client’s Google Ads, Meta Business Manager or GA4 property gives you access to personal data under their control.
Creative assets containing personal data
Testimonials, case study material, customer photographs and user-generated content used in campaigns.
Your own project tooling
Notion, Slack, Figma, Asana and Drive all end up holding client personal data, which makes them sub-processors even though nobody thinks of them that way.
Freelance and offshore contractors
A common sub-processing relationship that most agency contracts do not disclose, and that transfer rules may also cover.
Tracking installed on client sites
Whatever you add during a build becomes a permanent part of the client’s processing, and it needs handing over in writing.
Third parties the draft will ask you about
Google Ads and GA4 · Meta Business Manager · HubSpot · Notion or Asana · Slack · Figma · Dropbox or Google Drive · freelance contractors
The rules that apply
Article 28 processor agreements
Required in writing wherever you process client personal data. It is the document clients now ask for at onboarding, not at renewal.
Sub-processor disclosure to clients
Your own tooling - project management, analytics, reporting, freelancers - are sub-processors from the client’s point of view.
Freelancers and contractors
Anyone outside your legal entity handling client data is a sub-processor needing a contract and, usually, client authorisation.
Marketing consent on behalf of clients
Running a client’s email or ads programme means operating on their consent records. If the records are weak, the exposure is theirs and the professional embarrassment is yours.
Hand-over documentation
Not a legal requirement, but the practical difference between a clean hand-over and a client publishing a policy that misdescribes their own site.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
The agency compliance stack
Publish your own privacy policy as a controller
Covering your site, your CRM, your recruitment and your client contacts.
Add an Article 28 schedule to your MSA
One schedule, reusable across clients, covering instructions, confidentiality, security, sub-processors, assistance, deletion and audit.
Maintain a sub-processor list
Including your tooling and any contractors, ready to send when a client asks.
Standardise a hand-over pack
Every tag installed, what it collects, which policy sections it affects, and who now owns each one.
Set a client-data retention rule
Delete or return exports at project end, and actually run it.
Give each client site its own documents
Generated from that site’s actual stack rather than copied from the last build.
Where this usually goes wrong
No processor agreement with clients
The single most common agency gap. It surfaces when the client’s own compliance review asks for one and there is nothing to send.
Undisclosed sub-processors
Freelancers, offshore teams and the project tooling holding client data all count, and clients increasingly ask for the list.
Installing tracking without documenting it
Hand-over should include the exact list of tags, what each collects, and what the client now needs to disclose.
Reusing one privacy policy across every client site
Different sites, different tools, different processors, different markets. A shared template is inaccurate on most of them by definition.
Holding client data indefinitely after a project ends
Article 28 requires deletion or return at the end. Agency drives are full of exports from clients who left years ago.
Running email campaigns on consent nobody can evidence
If the client cannot produce the consent record, the campaign should not go out.
Frequently asked questions
Is my agency a controller or a processor?
A controller for your own business data - your site, your CRM, your staff - and a processor for client data you handle on their instructions. Most agencies need both a privacy policy and a processor agreement.
Do I need a DPA with my clients?
If you process personal data on their behalf, yes, and Article 28 requires it in writing. Adding it as a schedule to your standard contract is far easier than negotiating one per client.
Am I responsible for tracking I installed on a client site?
The client is the controller once they operate the site, but you carry professional responsibility for what you installed and for documenting it. Undocumented tracking is the source of most post-hand-over disputes.
Can I use one privacy policy across all my client sites?
Not accurately. Each site has a different toolset, different processors and often different markets, and an inaccurate transparency notice is itself a breach for the client.
Are my freelancers sub-processors?
If they handle client personal data, yes. That means a contract, and usually disclosure to and authorisation from the client.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator for agencies
Answer a short questionnaire and get a draft written for an agency. Free to start, no card required.
Generate your GDPR policyOther documents an agency needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.