Running a ten-person digital agency in the UK is a genuinely complex legal undertaking. You are simultaneously a data controller under UK GDPR, a potential data processor on behalf of your clients, a VAT-registered business (probably), an employer navigating IR35 if you use freelancers, and a party to contracts governed by English or Scottish law. Most of this complexity is invisible until something goes wrong — and when it does go wrong, it tends to go wrong expensively.
The compliance landscape for UK agencies shifted substantially in 2021 when UK GDPR diverged from EU GDPR post-Brexit, and again in 2023 when IR35 reforms bedded in. Yet the majority of agency operators we speak to have not revisited their compliance posture since they started up — their privacy policy is a template from 2018, their client contracts were drafted by a non-specialist, and their freelancer arrangements have never been properly assessed for IR35 risk.
This checklist covers the six areas where UK digital agencies most commonly have gaps: data protection, client contracts, freelancer compliance, financial obligations, website and digital marketing legality, and operational record-keeping. Work through it honestly. It is not designed to alarm you — the vast majority of issues are fixable — but it will show you where the genuine risks are.
Disclaimer: this article provides general guidance for UK digital agencies and is not legal advice. For specific legal and regulatory questions, engage a solicitor qualified in UK commercial and employment law. Fines and penalties described are based on publicly available regulatory information as of mid-2024.
UK GDPR and Data Protection: Your Obligations as a Data Controller
Since 1 January 2021, UK businesses have operated under UK GDPR — a domesticated version of the EU regulation, implemented through the Data Protection Act 2018 and maintained by the Information Commissioner’s Office (ICO). The core obligations are broadly similar to EU GDPR, but there are meaningful differences in international data transfer rules and several areas where UK-specific guidance has since emerged.
As a digital agency, you are almost certainly a data controller — you determine the purposes and means of processing personal data about your contacts, leads, clients, and employees. You may also be a data processor for clients when you manage their customer data, run their email marketing, or maintain their website databases. Each role carries different obligations, and many agencies have never clearly mapped which hat they are wearing in each context.
The ICO requires most organisations that process personal data to register and pay a data protection fee. For a small agency this is typically Tier 1 — currently £40 per year. Failure to register is a criminal offence with fines of up to £4,350. It takes about five minutes to check and remedy at ico.org.uk/registration, yet a surprising number of agencies have simply never done it.
Your UK GDPR checklist:
- Register with the ICO (if you process personal data, you almost certainly need to). Renew annually.
- Publish a compliant privacy policy on your website. This must identify the data controller, list the categories of data you collect, explain your lawful bases for processing, describe how long you retain data, and explain individual rights. A template from 2019 is not sufficient — check it against current ICO guidance.
- Maintain a Record of Processing Activities (ROPA). This is a formal document listing what personal data you hold, why you hold it, who you share it with, and how long you keep it. Required for organisations with 250+ employees, but recommended for all.
- Have a lawful basis for every category of processing. For most client-side data this will be “legitimate interests” or “contract performance.” For marketing to prospects it is typically “consent” or “legitimate interests” — but the bar for legitimate interests has specific conditions attached.
- Review your data retention schedule. Do you delete prospect records that went cold two years ago? Do you still hold data for clients you parted ways with in 2020? Holding data without a current purpose is a compliance breach.
- Ensure any third-party tools you use (your CRM, email platform, analytics) are covered by a valid Data Processing Agreement (DPA). The major SaaS providers offer standard DPAs — you need to have actually signed or accepted them, not just assumed they exist.
- For international data transfers (e.g., using US-headquartered software), understand the transfer mechanism in use. Post-Brexit, the UK has its own adequacy decisions and International Data Transfer Agreements (IDTAs) that differ from EU Standard Contractual Clauses. Most major US providers have updated their terms — check yours.
Practical note: if you use a CRM or agency management platform to store client and contact data, that tool’s DPA is one of your most important compliance documents. Marque CRM stores all data on UK/EU infrastructure and provides a standard DPA for customers. If your current tools can’t tell you where your data is physically stored, that is a red flag worth investigating.
Client Contracts: What UK Law Actually Requires
The UK has several pieces of legislation that interact with your client contracts in ways that many agency owners do not fully appreciate. Two of the most practically significant are the Late Payment of Commercial Debts (Interest) Act 1998 and the Consumer Rights Act 2015 — and the latter applies even in B2B contexts when you deal with sole traders.
Under the Late Payment Act, you are legally entitled to charge statutory interest on overdue commercial invoices at 8% above the Bank of England base rate. You can also claim fixed debt recovery costs: £40 for debts under £1,000, £70 for £1,000–£9,999, and £100 for debts of £10,000 or more. You do not need to include these in your contract for them to apply — they are statutory rights. However, you should reference them in your payment terms so clients know they exist. A standard payment term clause might read: “Payment is due within 30 days of invoice date. Late payments will attract interest at 8% above the Bank of England base rate under the Late Payment of Commercial Debts (Interest) Act 1998.”
Your client contracts should also clearly address the following areas, where UK agencies most commonly face disputes:
- Intellectual property ownership. Under UK copyright law, the creator of a work owns the copyright unless there is a written agreement to the contrary. If you want to license (rather than assign) your work — keeping ownership while granting the client usage rights — that needs to be explicit. Conversely, if a client expects to fully own the designs, code, or copy you produce, that assignment must be in writing and specifically worded. Vague contracts on IP are a source of genuine disputes.
- Limitation of liability. UK courts will enforce reasonable limitation clauses between commercial parties. A clause limiting your liability to the fees paid under the contract is standard and sensible. Without one, you are theoretically exposed to a client’s consequential losses — which, for a business whose website you built, could be substantial.
- Termination and notice periods. UK law implies reasonable notice periods into contracts that are silent on termination. “Reasonable” is unhelpfully vague. Specify exactly how either party can exit, what notice they must give, and what happens to work in progress and deposits on termination.
- Change of scope process. This is operational as much as legal, but disputes about scope are the most common cause of agency client conflict. A clear change request process — in writing, agreed by both parties before work proceeds — protects you both contractually and reputationally.
- Governing law and jurisdiction. Specify that the contract is governed by the laws of England and Wales (or Scotland if relevant). In a UK-only context this seems obvious, but if you work with international clients, an express governing law clause prevents arguments about which country’s courts have jurisdiction.
If your current contracts were drafted based on a free template or an American agency’s boilerplate, have them reviewed by a UK commercial solicitor. A one-off review costs a few hundred pounds and is worth every penny against the cost of a single disputed invoice or IP argument. For getting contracts signed efficiently, an e-signature workflow built into your agency management system is the most practical approach — it removes friction and creates an auditable record of acceptance.
IR35 and Freelancer Compliance
If your agency uses freelancers or contractors — and almost all do — IR35 is your most significant ongoing compliance exposure. The off-payroll working rules (IR35) require that if a contractor would effectively be an employee if engaged directly, the hiring business must deduct income tax and National Insurance contributions at source. Since April 2021, this responsibility was extended to medium and large private-sector businesses. Most growing agencies will cross the threshold for “medium-sized” sooner than they expect: the test is whether you meet two of three criteria — annual turnover over £10.2m, balance sheet over £5.1m, or more than 50 employees.
If you are currently small enough to be exempt from the reformed rules, contractors are responsible for their own IR35 assessment. But this is worth monitoring actively as you grow, and getting your assessments and working practices right now is better than scrambling when you cross the threshold.
Regardless of size, you should:
- Have a proper written contract with every freelancer that accurately reflects the actual working relationship. A contract that says “no mutuality of obligation” or “substitution is permitted” is meaningless if the reality is that you always use the same person, at your premises, under your direction. HMRC looks at substance, not paperwork.
- Use HMRC’s Check Employment Status for Tax (CEST) tool for any contractor engagement that is material in value or duration. Document the result. If CEST returns an indeterminate result, get a professional opinion rather than assuming the most favourable answer.
- Avoid paying contractors through their personal service companies for work that is clearly employed in nature — in-office, full-time, under your direct supervision, with no real ability to substitute.
- Review your arrangements annually, not just when you first engage someone. A contractor who started as a genuinely independent specialist can drift into de facto employment over time as the relationship deepens.
Practical note: HMRC IR35 investigations are most commonly triggered by contractors who later dispute their status when they want to claim employment rights. The best protection is having your working practices genuinely reflect the contractor relationship — not just having a contract that says they do.
VAT, Making Tax Digital, and Financial Obligations
Any agency with taxable turnover above £90,000 (the 2024/25 threshold) must register for VAT. If you are already registered, Making Tax Digital for VAT (MTDfV) has been mandatory since April 2022 — you must keep digital VAT records and file returns via MTD-compatible software. HMRC no longer accepts manual spreadsheet submissions. If you are not yet compliant with this, it is a penalty risk that will only grow over time.
MTD for Income Tax Self Assessment (MTDfITSA) is being phased in from April 2026 for sole traders and landlords with income over £50,000, extending to those over £30,000 from April 2027. If your agency is structured as a sole trader, start preparing now — moving to compliant bookkeeping software is a process that benefits from time, not a last-minute scramble.
On financial record-keeping more broadly:
- Limited companies must file annual accounts and a confirmation statement with Companies House. These are public documents. Missing filing deadlines triggers automatic penalties starting at £150 and escalating to £1,500 for accounts more than six months late, plus the risk of compulsory strike-off.
- PAYE obligations must be reported in real time via RTI (Real Time Information) submissions to HMRC. If you have employees or pay yourself a salary through the company, these submissions must be made on or before each payment date.
- Keep business records for at least six years. For VAT records, the requirement is also six years from the date of the return. Documents relating to assets held for more than six years (e.g., office equipment or domain names) must be kept for the life of the asset plus six years.
If you use Xero, QuickBooks, or FreeAgent and connect them to your agency management platform, this creates a single source of truth for invoices, payments, and time tracking that dramatically simplifies your end-of-year accounting. Marque CRM’s accounting integrations push invoices and expense records directly to both Xero and QuickBooks, eliminating the manual export cycle that most agencies still rely on.
Website and Digital Marketing Legal Requirements
As a digital agency, you almost certainly advise clients on their websites and marketing. But is your own house in order? The legal requirements for UK websites are more extensive than many agency operators realise.
Cookie consent. The Privacy and Electronic Communications Regulations (PECR), alongside UK GDPR, require that non-essential cookies (analytics, advertising, personalisation) can only be set after obtaining valid consent. Valid consent under PECR must be freely given, specific, informed, and unambiguous — a pre-ticked box or a notice that says “by continuing to browse you consent” is not compliant. The ICO has been increasingly active in enforcement in this area, particularly for analytics cookies. If your website uses Google Analytics, Hotjar, or Meta Pixel without a proper consent management platform (CMP), you are not compliant.
Email marketing. PECR also governs direct marketing emails. For B2C contexts, prior consent is required for marketing emails. For B2B prospects (limited companies, LLPs), the “soft opt-in” rule can apply — but only if you obtained their contact details during a commercial transaction and are marketing similar products or services. Cold B2B email to a bought list is not compliant without soft opt-in qualification. The ICO issues fines of up to £500,000 for serious PECR breaches.
Mandatory website information. Under the Companies Act 2006 and the E-Commerce Regulations 2002, limited company websites must display the full registered company name, registered number, and registered office address. This applies even if the address is a registered office service rather than your actual premises. Many agency websites bury this in the footer or omit it entirely.
Advertising standards. Digital ads must comply with the CAP Code, administered by the Advertising Standards Authority (ASA). For agencies running client campaigns, this is typically the client’s responsibility — but make sure your client contracts specify that the client is responsible for approving ad content for compliance. If you are also running paid ads promoting your own services, the same rules apply to you.
Your Responsibilities When Processing Client Data
When your agency handles personal data on behalf of a client — managing their email list, maintaining their CRM, running their analytics, building and hosting their website — you are acting as a data processor. This distinction matters because it creates specific legal obligations between you and the client, and between you and the data subjects whose information you are handling.
The key requirement is a Data Processing Agreement (DPA) with every client for whom you process personal data. This is not optional — UK GDPR Article 28 requires it. The DPA should specify what data you process, for what purposes, under what instructions from the client (who is the controller), what security measures you apply, and what happens to the data at the end of the engagement. If a client’s data is ever involved in a breach while you hold it, the absence of a DPA makes your position considerably worse — both legally and reputationally.
Practically, this means:
- Audit which clients have you handling personal data on their behalf. This includes: running their email platform, accessing their WordPress back-end with user data, managing their Google Analytics account, building systems that collect user information.
- Ensure your client contracts include Article 28-compliant data processing clauses, or have a separate DPA addendum. A standard DPA template from a UK legal provider is a reasonable starting point.
- Understand your data breach notification obligations. If you experience a breach affecting client personal data, you may need to notify the ICO within 72 hours and the affected clients promptly. Your incident response plan should cover who is responsible for this, not leave it as an open question under pressure.
- When an engagement ends, have a clear process for returning or securely destroying client data. Retaining data after the engagement has no legal basis under UK GDPR.
Tracking which clients have signed DPAs, when they were last reviewed, and whether your processing activities have changed is exactly the kind of ongoing compliance task that benefits from being stored in your agency management platform as a contract record with a review reminder, rather than in someone’s inbox or a shared document that gets forgotten.
Operational Compliance: What to Keep and for How Long
Beyond the regulatory-specific requirements above, there is a broader set of operational records that UK agencies should be maintaining systematically. Poor record-keeping is both a direct compliance risk and a practical problem when disputes arise — with clients, contractors, employees, or HMRC.
Client file documentation. For each client, you should maintain: signed contracts and any amendments, change request records with written approval, invoices and payment records, significant communications (particularly anything relating to scope, deliverables, or disputes), and a data processing register entry if you process personal data on their behalf. The question to ask is: if this client disputes something in two years, do we have a clear paper trail? If not, fix the gaps now.
Project audit trails. Many disputes and scope creep arguments come down to “we agreed X” versus “we never agreed that.” An audit log in your project management system — showing who approved what and when — is your first line of defence. This is one reason the audit log feature in an agency management platform is worth taking seriously, not just as a nice-to-have.
Time records. If you bill by the hour or on retainer with time-based reviews, your time tracking records are both a financial and a legal asset. Under the Working Time Regulations 1998, UK employers must also maintain adequate records to demonstrate compliance with the 48-hour working week limit — though in practice, for most agency setups, this amounts to having your time tracking system in reasonable order.
Employee records. For employees, you must retain: signed employment contracts, payroll records for six years, records of working hours, holiday records, and any disciplinary or grievance documentation. For leavers, retain records for at least six years from the date of leaving. Under GDPR, you cannot retain these indefinitely — have a retention and deletion policy.
Most agencies only discover their compliance gaps when something goes wrong. The cost of a structured annual review is a few hours of focused attention. The cost of discovering a gap in the middle of a client dispute, HMRC investigation, or ICO inquiry is considerably higher.
Making This an Annual Process, Not a One-Time Fix
Compliance is not a destination — UK law evolves, your agency grows, your services change, and what was adequate two years ago may no longer be. The most pragmatic approach is to treat compliance as an annual review cycle rather than a one-off project.
Set a reminder each April — aligned with the start of the UK tax year — to work through the following:
- ICO registration: renewed and fees paid
- Privacy policy: reviewed against any new ICO guidance or changes to your data practices
- Client contracts: still fit for purpose, particularly if you have launched new services or changed your pricing model
- Freelancer arrangements: reassessed for IR35 risk, particularly any long-running relationships
- VAT and MTD compliance: confirmed with your accountant
- Data processor relationships: any new tools handling personal data, and whether DPAs are in place
- Cookie consent: any changes to your website’s tracking practices
- Companies House filings: confirmation statement and accounts on track
If this review reveals gaps, prioritise them by risk. ICO registration failure is a criminal offence and costs £40 to fix — do it today. A contract template that needs updating is lower urgency but worth addressing before you sign the next significant client. An IR35 assessment question is worth a conversation with your accountant this quarter.
For more on the operational side of running a well-organised agency, see our guides to getting client contracts signed efficiently, building agency operations that scale, and the full breakdown of Marque CRM’s features for agency management.