Verified as of August 2026: EU and UK rules are actively changing, and some widely-shared claims are out of date. This is operational orientation, not legal advice; confirm with official sources or your data protection adviser.
Hiring a marketing agency outside the EU or UK is entirely lawful and routine. What makes it go wrong is that the compliance work is usually discovered at contract stage, by a procurement or privacy team, after the commercial decision is made: at which point it becomes an obstacle instead of a checklist. The four things that actually need to exist are: an Article 28 processor agreement with real terms, a Chapter V transfer mechanism (for India, which has no EU adequacy decision, that means Standard Contractual Clauses plus a transfer impact assessment), a disclosed sub-processor list, and clarity about where the tooling stores data. I work from India with European clients, so what follows is how I'm set up, written from the supplier side, because almost nobody writes it from here.
Key Takeaways
- The client is the controller and carries the accountability. The agency is usually a processor. That allocation determines everything else.
- India has no EU adequacy decision. Transfers require appropriate safeguards, in practice the 2021 Standard Contractual Clauses plus a documented transfer impact assessment.
- Article 28 processor terms are mandatory, not optional boilerplate, and must cover a specific list of items.
- Sub-processor transparency is the item that most often fails an audit, every tool in the stack is a sub-processor.
- Article 27 representative obligations sit with whoever offers goods or services to, or monitors, people in the EU without an EU establishment.
- EU-region tooling and data minimisation reduce the surface area more effectively than any contractual clause.
- The UK requires its own paperwork, the IDTA or the UK Addendum to the EU SCCs.
Who Is What: Controller, Processor, and Why It Matters
The default allocation
In a typical marketing engagement the client determines the purposes and means of processing, they decide who to market to and why, so the client is the controller. The agency processes personal data on the client's documented instructions, so the agency is a processor.
This matters because controllers carry the accountability obligations: lawful basis, transparency, data subject rights, records of processing under Article 30. The processor's obligations are narrower but real: process only on instruction, maintain security, assist the controller, and not engage sub-processors without authorisation.
Where it gets blurry
An agency that decides audience targeting independently, builds and owns lookalike audiences, or uses client data to improve its own services is exercising controller-like discretion for those activities. That can create joint controllership under Article 26 with its own transparency requirements.
The honest supplier position: be explicit about which activities are on instruction and which involve agency discretion, and get the allocation written down. Ambiguity here is what makes privacy reviews slow.
Article 28: What a Real Processor Agreement Contains
Article 28(3) specifies what the contract must set out. It is not a formality and a one-page "we comply with GDPR" clause does not satisfy it.
The required elements:
- Subject matter, duration, nature and purpose of the processing.
- Types of personal data and categories of data subjects: actual lists, not "as required."
- Processing only on documented instructions, including for transfers, with an obligation to flag instructions the processor believes are unlawful.
- Confidentiality commitments from everyone authorised to process.
- Article 32 security measures: described, not asserted.
- Sub-processor conditions: prior authorisation (specific or general with notice), and flow-down of equivalent obligations.
- Assistance with data subject rights requests.
- Assistance with Articles 32–36: security, breach notification, DPIAs, prior consultation.
- Deletion or return of all personal data at the end of the engagement, at the controller's choice.
- Audit and information rights, making available the information needed to demonstrate compliance and allowing audits or inspections.
The supplier-side version
I keep a standing DPA that covers all of this and I send it before the contract discussion rather than after. It shortens the privacy review substantially, and it signals that the compliance conversation isn't going to be adversarial.
The annexes are where the value is: an accurate description of processing, an actual data inventory, a named sub-processor list, and a security measures schedule that describes what is in place rather than what would be nice.
Chapter V: Transfers to India
There is no adequacy decision
The European Commission has adopted adequacy decisions for a number of jurisdictions. India is not among them. Any content suggesting otherwise is wrong, and it's worth checking the Commission's adequacy decisions page directly rather than trusting a summary.
The mechanism: SCCs plus a TIA
The standard route is the 2021 Standard Contractual Clauses, adopted by Commission Implementing Decision (EU) 2021/914, with the correct module selected, Module Two (controller to processor) for a typical agency arrangement.
Signing the SCCs is not sufficient on its own. Following Schrems II and the EDPB's recommendations on supplementary measures, the exporter must assess whether the law and practice of the destination country undermines the protection the clauses promise, and apply supplementary measures where it does. That assessment is the transfer impact assessment.
What a TIA for India covers
- The specific transfer: what data, what volume, what sensitivity, what frequency, and who can access it.
- The relevant Indian legal framework, including the Digital Personal Data Protection Act 2023 and its implementation, and the government access powers that exist under Indian law.
- Whether those powers, in practice and given the actual data involved, undermine the SCC protections for this transfer.
- Supplementary measures applied: encryption in transit and at rest, access controls, data minimisation, pseudonymisation, EU-region storage where feasible, and a documented policy on government access requests.
The TIA is the controller's obligation as exporter, but a processor who arrives with a completed draft, honest about the legal framework rather than dismissive of it, removes weeks from the process. That's the version I maintain.
The most effective supplementary measure
Not encryption. Not transferring the data. If the personal data stays in EU-region infrastructure that the agency accesses under controlled conditions, the transfer surface shrinks dramatically. Remote access from a third country is still a transfer, but a much narrower one than replicating datasets.
The UK route
UK transfers use the ICO's International Data Transfer Agreement, or the UK Addendum bolted onto the EU SCCs: usually the addendum, since it avoids maintaining two documents. A transfer risk assessment is expected; the ICO publishes a TRA tool that is more workable than most EU equivalents.
Sub-Processors: The Audit Failure Point
Every tool is a sub-processor
Your email platform, CRM, analytics, scheduling tool, design tool, project management system, cloud storage, transcription service and AI assistant are all sub-processors if they touch client personal data. Most agency sub-processor lists name three of them.
What good looks like
- A published, versioned list with each sub-processor's name, purpose, and processing location.
- Advance notice of changes with a defined objection window, thirty days is standard.
- Flow-down: each sub-processor bound to obligations equivalent to those the agency owes the client.
- A change process that actually runs. A list that hasn't been updated in a year is worse than no list, because it's a documented inaccuracy.
The AI tooling question
Generative AI tools in an agency workflow deserve explicit treatment. Which tools are approved, what data may be entered, whether the vendor's terms permit training on inputs, and where processing occurs. "We don't put client data into AI tools" is a policy that needs enforcement, not just a sentence in a proposal.
Note also that from 2 August 2026 the EU AI Act's Article 50 transparency obligations apply, relevant if agency-built assets include synthetic media or AI-driven conversational interfaces. Covered in the Article 50 piece.
Article 27 Representatives
Article 27 requires controllers and processors not established in the EU to designate a written representative in the Union where they offer goods or services to individuals in the EU, or monitor their behaviour. The UK GDPR contains an equivalent requirement for a UK representative.
Exemptions exist for processing that is occasional, does not include special-category or criminal-offence data on a large scale, and is unlikely to result in a risk to individuals.
The practical position for an agency: whether you need a representative depends on your own processing, not your client's. If you're a processor acting on a European controller's instruction and not independently targeting EU individuals, the analysis often points away from a requirement: but it's a specific assessment, and it should be documented rather than assumed. Don't let a vendor sell you a representative service without one.
EU-Region Tooling and Data Minimisation
Configure residency deliberately
Most major platforms now offer EU data residency, and most are not configured for it by default. Check and set it at the outset, migrating later is painful and sometimes impossible without recreating the account.
Minimise before you transfer
Ask what the agency actually needs. Running an organic content and SEO programme requires very little personal data: aggregate analytics, keyword data, content performance. It does not require a customer list.
The engagements that create real transfer exposure are the ones involving CRM access, email list management, or paid audience building. Those need the full apparatus. A content and organic growth engagement often needs far less than the DPA template assumes: and saying so, as a supplier, is more useful than pretending the paperwork is the only thing standing between you and a signature.
The stack questions worth asking any non-EU agency
- Which of your tools will hold or access our personal data?
- Where does each one store it, and is EU residency configured?
- What is your sub-processor notification process?
- What is your breach notification timeline and escalation path? (Controllers face a 72-hour clock under Article 33; a processor must notify "without undue delay.")
- Who on your team has access, and how is that access controlled and revoked?
- What happens to our data at the end of the engagement, and can you evidence deletion?
- What AI tools are in your workflow and what data goes into them?
- Have you completed a transfer impact assessment for your jurisdiction, and can we see it?
If an agency can't answer these quickly, the problem isn't their paperwork. It's that nobody has thought about it.
How I'm Set Up
Plainly, so you can compare rather than take my word for it:
- A standing Article 28 DPA with completed annexes, sent before contracting.
- 2021 SCCs, Module Two, with the UK Addendum where the client is UK-based.
- A maintained transfer impact assessment for India, honest about the DPDP Act and government access powers, with the supplementary measures I actually apply.
- A published, versioned sub-processor list with thirty days' notice on changes.
- EU-region residency configured on tooling where it's available.
- Data minimisation by default: for organic and content engagements I ask for analytics and content access, not customer data.
- A written AI tooling policy specifying approved tools and what may not be entered into them.
- Documented access control, offboarding, and end-of-engagement deletion with evidence.
None of that is exotic. It's a weekend of work that saves a month of procurement, and I'd rather it be a reason to hire me than a hurdle to clear afterwards.
Frequently Asked Questions
Does India have an EU adequacy decision?
No. Transfers of personal data from the EEA to India require appropriate safeguards under Chapter V, in practice the 2021 Standard Contractual Clauses plus a documented transfer impact assessment.
Is it legal to hire an Indian marketing agency under GDPR?
Yes. It requires an Article 28 processor agreement, a Chapter V transfer mechanism, and appropriate supplementary measures. It is routine and well-established.
What is a transfer impact assessment?
An assessment of whether the laws and practices of the destination country undermine the protection the SCCs are meant to provide for a specific transfer, and what supplementary measures address any gap. It follows from Schrems II and EDPB recommendations.
Who signs the SCCs?
The data exporter (typically the European client, as controller) and the data importer (the non-EU agency, as processor). Module Two applies for controller-to-processor transfers.
Do I need an Article 27 representative as a non-EU agency?
It depends on your own processing. The requirement attaches to offering goods or services to, or monitoring, individuals in the EU without an EU establishment, with exemptions for occasional low-risk processing. Assess and document it rather than assuming either way.
What happens if my agency uses a tool I haven't approved?
That's an unauthorised sub-processor and a breach of the Article 28 terms. It's why the sub-processor list and the notification process need to actually operate rather than exist.
Does using EU-region cloud infrastructure remove the transfer?
It substantially reduces the surface but doesn't eliminate it, remote access from a third country is still a transfer. It is nonetheless the single most effective supplementary measure available.
What about UK clients specifically?
Use the ICO's IDTA or the UK Addendum to the EU SCCs, with a transfer risk assessment. The ICO publishes a TRA tool. Note that the Data (Use and Access) Act 2025 revised the UK's approach to assessing transfers, all data protection provisions were active as of 19 June 2026.
How long should an agency keep our data after the engagement ends?
Only as long as needed for wind-down, then deleted or returned at your choice per Article 28(3)(g). Ask for evidence of deletion; a defensible retention period for wind-down is measured in weeks, not years.
Does the EU AI Act affect an agency using AI tools?
Potentially. Article 50 transparency obligations apply from 2 August 2026: relevant to synthetic media in campaigns and to AI-driven conversational interfaces. High-risk obligations were postponed to December 2027 and August 2028, but transparency was not delayed.
Further Reading
- European Commission, adequacy decisions
- European Commission, Standard Contractual Clauses
- GDPR Article 28, processor
- ICO, international data transfers
A Note at Post 210
This is the two hundred and tenth post on this site. That number isn't a milestone I planned toward, it's just what accumulates when you write down what you actually learned each time you did the work.
The through-line across all of it has been the same argument, whether the subject was Instagram growth for an edtech brand, Indian regional-language SEO, or European transfer mechanisms: organic, original, genuinely useful work compounds. It compounds slowly enough to be unglamorous and reliably enough to be worth building a career on. The channels change constantly. The regulations change constantly: this batch alone documents an AI Act timeline that moved, a UK statute that commenced, and an EU package still being argued over. What hasn't changed is that the people who do specific, honest, useful work end up with an audience that trusts them, and the people who chase whatever is working this quarter end up starting again every quarter.
Thanks for reading: whether this is your first post here or your hundredth. If you're building something in Europe and want a hand with the organic side of it, come and say hello at younusfardeen.com.