Clarifying responsibilities between company, agency and tool provider
Companies, agencies, and tool providers need clear responsibilities for selection, configuration, and testing. Contracts do not replace operational tasks.
"Clarifying Data Protection Responsibilities in the Setup" is considered here from the perspective of "Data Protection Inventory and Responsibility." For website operators and data protection officers, "Decision versus Execution" and "Agency as Owner" are particularly important.
Published: 3 min read · Author: Sebastian Geier
How do you distribute responsibilities for consent and tracking among three parties?
The company remains responsible for business decisions and authorized processing, while the agency and provider take on defined implementation or operational tasks. For each data flow, decision-making authority, executing role, documentation, and escalation are documented both in writing and technically.
Change and Incident Pathway
Control signal
Signal 1
Proportion of critical data protection and tracking tasks with clearly defined decision-makers, executors, and lines of authority.
Control signal
Signal 2
Number of unclear ownership, access, or escalation cases in changes and exercises.
Access Model
Data flows and operational tasks are broken down into decision-making, implementation, control, documentation, and escalation.
A RACI matrix is aligned with accounts, roles, contracts, runbooks, and technical approvals.
A change or incident scenario is jointly simulated, revealing unmanaged handoffs.
Diagnostic case: "Agency as owner"
The agency manages the Tag Manager, the company approves purposes and recipients, and the tool provider operates the platform. A new tag requires both internal approvals; accounts remain with the company, and the incident path identifies all three roles.
Decision versus execution
Test criterion
Decision versus execution
The role that defines purpose and means is separated from the role that configures tags or provides platform operation.
Test criterion
Access Model
Accounts, roles, secrets, audit logs, and revocation are subject to the agreed-upon responsibility and delegation model.
Change and Incident Pathway – New vendors, releases, data breaches, and deletion requests have predefined contacts, deadlines, and documentation.
Agency as owner
Agency as owner – Accounts, containers, and documentation reside exclusively with one service provider, hindering control or switching providers.
Vendor defaults unchecked – Default settings are treated as the tool provider's decision, even though the specific configuration must be approved.
Shared gap – All parties assume another party is testing consent, deleting data, or monitoring new subcontractors.
What questions arise next?
A relevant follow-up question answered Configuring Tag Manager to prevent consent rules from being bypassed“How do you prevent a tag manager from circumventing established consent rules?”
A second link for "Clarifying Data Protection Responsibility in Setup" leads to Clearly define roles and rights in content management systems.This article remains focused on the question "How are roles and rights in a content management system transparently limited?"
If you want to practically implement "Clarifying Data Protection Responsibility in Setup," you can refer to Robust Website Systems This article focuses on "Data Protection Inventory and Responsibility" and "Decision-Making vs. Execution."
Conclusion: Clarifying Data Protection Responsibility in the Setup
Clear responsibility links organizational decision-making with technical access and accountability. Outsourcing work does not replace the allocation of ownership.
Sources and Further Information
The following sources document the technical and methodological guidelines used for "Clarifying Data Protection Responsibility in the Setup."
Guidelines 05/2020 on Consent – European Data Protection BoardOfficial European interpretation of the organizational and evidence-based requirements for consent.
General Data Protection Regulation – EUR-LexPrimary source on accountability, information obligations, records of processing activities, and the roles of controllers and processors.
Key Thesis
A RACI-like matrix assigns each processing activity, configuration change, control, and disruption to a responsible party. Approvals and documentation remain traceable with the designated owner.
What This Is Not About
A contract with an agency or tool provider does not automatically transfer all professional, technical, and data protection-related decisions from the company.
What it's about
A RACI and operational model clearly assigns purpose, configuration, access, modification, audit, incident, data subject process, and deletion.
More insights
Consent, data protection & tracking quality
Conduct a technical data privacy inventory for websites
"Clarifying data privacy responsibility in the setup" includes, as a separate audit step, the question: What technical traces must a data privacy inventory of a website capture?
Consent, data protection & tracking quality
Defining Cookie Categories Based on Actual Function
Supplements "Clarifying data privacy responsibility in the setup" with a separate decision: How are cookies and similar technologies appropriately categorized?
Insights Overview
All VELUNO Insights at a Glance
Further analyses on Website Systems, digital visibility, and robust working models.
Change and incident pathway: Starting point of implementation
A critical data flow is first broken down into decision-making, implementation, and control. The roles are then checked against actual accounts and incident pathways.