The operational reality

What Makes Marketing & Advertising Different

Your access is broader than your headcount. A ten-person agency can hold administrative credentials to dozens of client websites, ad platforms, analytics properties, and email systems. That concentration is the asset an attacker wants.

Contractor churn is your offboarding problem, and nobody owns it. Freelancers finish a project and keep live access to client ad accounts, shared drives, and CMS logins for months. This is the most common finding in any agency review.

The scripts you add are in scope for someone. PCI DSS 4.0.1 addresses management and inventory of scripts on payment pages and change detection on those pages - which lands squarely on the tag managers, pixels, and chat widgets an agency deploys, even though the client is merchant of record. Pull the requirement text from the PCI SSC document library before you tell a client what it says.

Enterprise procurement audits agencies now. SIG Lite questionnaires and MSA security addenda arrive before signature and ask about multi-factor, retention, subprocessors, and breach notification SLAs. Agencies are unprepared because they think of themselves as creative rather than as a processor of other people's data.

Your client's regulator can become your problem by contract. Healthcare marketing touching patient data, financial services clients' customer data, EU visitors - none of that changes what you do, and all of it changes what you owe.

Failure patterns

What Usually Goes Wrong

  • A client WordPress site is compromised through a plugin the agency installed and never updated. The client experiences it as your failure regardless of the contract.
  • A former freelancer still has access to the ad account, the CMS, and the shared drive.
  • A phished agency credential leads to an ad account takeover and a drained client budget over a weekend.
  • Shared drives are set to "anyone with the link" because it was the fastest way to send a video file.
  • Credentials are handed off in Slack messages and spreadsheets with no vault and no rotation.
  • A payment page collects a new script from a tag manager nobody inventoried.
  • The master service agreement has no data clause, so allocation of a breach cost is decided after the breach.
  • Client data is retained indefinitely across drives, project tools, and personal machines - including the accounts of people who left.

Questions people ask

Frequently Asked Questions

Do agencies need PCI compliance if we build client e-commerce sites?
The client is the merchant, but PCI DSS 4.0.1 addresses management of scripts loaded on payment pages and detection of unauthorized changes to those pages - and those scripts are frequently the agency's deliverable. Read the standard at pcisecuritystandards.org and settle responsibility in the contract rather than after an incident.
Are we liable if a client site gets hacked through our CMS access?
Liability depends on your contract, your standard of care, and counsel. What is predictable is the commercial outcome: the client that lost a site will hold the agency that maintained it responsible, whatever the agreement says.
Are we a controller or a processor under CCPA and CPRA?
An agency handling personal information on a client's behalf and under the client's instructions is typically a service provider, which requires specific contract terms to establish. If you use client data for your own purposes, that characterization changes. The California AG and the CPPA publish the definitions.
Do I need a DPA with every client under CCPA?
Where you act as a service provider, the statute contemplates a written contract containing specific terms. In practice a security and data addendum to the master service agreement is how agencies handle it.
Does GDPR apply if only one client has EU customers?
If you process personal data of individuals in the EU on that client's behalf, you have processor obligations for that engagement, including Article 28 contract terms. It applies to the engagement, not to your whole agency.
What happens when an employee leaves with the client's Meta or Google Ads access?
Usually nothing, until it matters. The fix is structural: client accounts held in business manager structures the agency controls, individually assigned seats, and offboarding that revokes platform access at the same time as email. Personal-account access to client platforms is the pattern to eliminate.
Do we need SOC 2 to work with enterprise clients?
Some programs require it; many accept a completed questionnaire plus evidence. Ask procurement what they will accept before commissioning an audit, because the answer is often less expensive than the assumption.
Do we need COPPA compliance for a client with content aimed at kids?
COPPA obligations attach to the operator of the online service collecting the data, and analysis of who that is in an agency-client relationship depends on the arrangement. Given the penalties, this is a question for the client's counsel before launch, not after.
Are client ad pixels and tracking scripts a compliance risk?
They are a risk in three directions: PCI script requirements on payment pages, privacy law disclosure and consent obligations, and the plain security risk of executing third-party code on a page that collects data. An inventory of what loads where is the starting point.
How should agencies securely share large creative files?
Through systems with per-recipient access, expiring links, and an audit trail - not open link sharing. The requirement is not the tool; it is being able to state who accessed a client asset and when.