Marketing & Advertising
Your Biggest Liability Is on Your Client's Website, Not Your Network
An agency's exposure is not the office. It is the client property you touch - the content management system you have admin on, the ad accounts you manage, and the tracking scripts you placed on a checkout page.
You are a data processor whether or not your contracts use the word, and enterprise procurement will treat you as one.
The operational reality
What Makes Marketing & Advertising Different
Your access is broader than your headcount. A ten-person agency can hold administrative credentials to dozens of client websites, ad platforms, analytics properties, and email systems. That concentration is the asset an attacker wants.
Contractor churn is your offboarding problem, and nobody owns it. Freelancers finish a project and keep live access to client ad accounts, shared drives, and CMS logins for months. This is the most common finding in any agency review.
The scripts you add are in scope for someone. PCI DSS 4.0.1 addresses management and inventory of scripts on payment pages and change detection on those pages - which lands squarely on the tag managers, pixels, and chat widgets an agency deploys, even though the client is merchant of record. Pull the requirement text from the PCI SSC document library before you tell a client what it says.
Enterprise procurement audits agencies now. SIG Lite questionnaires and MSA security addenda arrive before signature and ask about multi-factor, retention, subprocessors, and breach notification SLAs. Agencies are unprepared because they think of themselves as creative rather than as a processor of other people's data.
Your client's regulator can become your problem by contract. Healthcare marketing touching patient data, financial services clients' customer data, EU visitors - none of that changes what you do, and all of it changes what you owe.
Frameworks
Your Compliance Landscape
Almost all of this reaches you through contracts and through your clients' obligations rather than directly. That does not make it optional - it makes it negotiated.
Almost always applies
- Applies if you build, host, or maintain pages that take payment. Version 4.0.1 brought requirements around script management and change or tamper detection on payment pages. Read the official standard rather than a blog summary before advising a client.
- If your client is subject to it and you handle California residents' personal information on their behalf, you are a service provider with contractual obligations, and the contract terms are specified (California AG; California Privacy Protection Agency).
- The structure most client security questionnaires are derived from (NIST CSF).
Applies in some cases
- Targeting or tracking individuals in the EU brings processor obligations, including Article 28 contract terms (Regulation 2016/679).
- Contractual, arriving through enterprise RFPs and master service agreements rather than through any regulator.
- Financial institution clients are required to oversee their service providers, which is how the Safeguards Rule reaches your contract terms (16 CFR Part 314).
- Campaigns directed to children under thirteen, or services with actual knowledge of collecting their data (16 CFR Part 312).
- Healthcare marketing that touches protected health information makes the agency a business associate, with a required contract and direct liability (HHS).
- Facial or likeness recognition in creative tooling raises biometric statute questions (740 ILCS 14). Verify current scope with counsel before deploying an AI likeness tool on a campaign.
The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.
Failure patterns
What Usually Goes Wrong
- A client WordPress site is compromised through a plugin the agency installed and never updated. The client experiences it as your failure regardless of the contract.
- A former freelancer still has access to the ad account, the CMS, and the shared drive.
- A phished agency credential leads to an ad account takeover and a drained client budget over a weekend.
- Shared drives are set to "anyone with the link" because it was the fastest way to send a video file.
- Credentials are handed off in Slack messages and spreadsheets with no vault and no rotation.
- A payment page collects a new script from a tag manager nobody inventoried.
- The master service agreement has no data clause, so allocation of a breach cost is decided after the breach.
- Client data is retained indefinitely across drives, project tools, and personal machines - including the accounts of people who left.
Our services
How We Work With Marketing & Advertising
Cyber Risk Management
Identity and email protection for a business whose credentials are the crown jewels, plus multi-factor and privileged access management across client platforms.
Third-Party Assessments
The answers to client security questionnaires and MSA security addenda, built from documentation - and diligence on your own subprocessors.
Governance, Risk & Compliance (GRC)
Access inventory, an offboarding process that survives contractor churn, retention rules, and the written program enterprise procurement asks to see.
Helpdesk Support
Onboarding and offboarding actually executed, across a workforce that changes shape every quarter.
Digital Forensics & Incident Response
Response when a client site or an ad account is compromised, including what you can defensibly tell the client and when.
Fractional CIO, CTO & CISO
A named security owner, which is itself an answer on most enterprise questionnaires.
Questions people ask
Frequently Asked Questions
- Do agencies need PCI compliance if we build client e-commerce sites?
- The client is the merchant, but PCI DSS 4.0.1 addresses management of scripts loaded on payment pages and detection of unauthorized changes to those pages - and those scripts are frequently the agency's deliverable. Read the standard at pcisecuritystandards.org and settle responsibility in the contract rather than after an incident.
- Are we liable if a client site gets hacked through our CMS access?
- Liability depends on your contract, your standard of care, and counsel. What is predictable is the commercial outcome: the client that lost a site will hold the agency that maintained it responsible, whatever the agreement says.
- Are we a controller or a processor under CCPA and CPRA?
- An agency handling personal information on a client's behalf and under the client's instructions is typically a service provider, which requires specific contract terms to establish. If you use client data for your own purposes, that characterization changes. The California AG and the CPPA publish the definitions.
- Do I need a DPA with every client under CCPA?
- Where you act as a service provider, the statute contemplates a written contract containing specific terms. In practice a security and data addendum to the master service agreement is how agencies handle it.
- Does GDPR apply if only one client has EU customers?
- If you process personal data of individuals in the EU on that client's behalf, you have processor obligations for that engagement, including Article 28 contract terms. It applies to the engagement, not to your whole agency.
- What happens when an employee leaves with the client's Meta or Google Ads access?
- Usually nothing, until it matters. The fix is structural: client accounts held in business manager structures the agency controls, individually assigned seats, and offboarding that revokes platform access at the same time as email. Personal-account access to client platforms is the pattern to eliminate.
- Do we need SOC 2 to work with enterprise clients?
- Some programs require it; many accept a completed questionnaire plus evidence. Ask procurement what they will accept before commissioning an audit, because the answer is often less expensive than the assumption.
- Do we need COPPA compliance for a client with content aimed at kids?
- COPPA obligations attach to the operator of the online service collecting the data, and analysis of who that is in an agency-client relationship depends on the arrangement. Given the penalties, this is a question for the client's counsel before launch, not after.
- Are client ad pixels and tracking scripts a compliance risk?
- They are a risk in three directions: PCI script requirements on payment pages, privacy law disclosure and consent obligations, and the plain security risk of executing third-party code on a page that collects data. An inventory of what loads where is the starting point.
- How should agencies securely share large creative files?
- Through systems with per-recipient access, expiring links, and an audit trail - not open link sharing. The requirement is not the tool; it is being able to state who accessed a client asset and when.
Florida & the Treasure Coast
Marketing & Advertising on the Treasure Coast
Florida has not enacted a comprehensive consumer privacy law of the CCPA type, so a Palm Beach County agency's privacy obligations generally arrive through its clients' jurisdictions and through federal rules rather than through a Florida statute. Confirm current Florida law at flsenate.gov before making that representation to a client, and route the specific question to their counsel. Breach notification for Florida residents runs under §501.171 on a 30-day clock.
The regional agency market across West Palm Beach, Jupiter, and Stuart skews toward healthcare, hospitality, real estate, and financial services clients - three of which carry regulated data. An agency serving a medical group and a title company from the same shared drive has a scoping problem that its client contracts have probably not addressed.
[NEEDS: client proof for this vertical]
