Direct answer: A company, agency, and intent-data vendor do not receive one permanent privacy role for an entire relationship. Assign controller, joint-controller, processor, subprocessor, business, service-provider, or contractor status for each processing activity and jurisdiction by asking who determines the purpose and essential means, whose instructions govern the work, and whether any party uses the data for its own purposes. Document the answer in a data-flow map, RACI, contract, and operating controls.
Who this is for: B2B companies, agencies, procurement teams, privacy leads, and operators designing intent-data services. This is general operational information, not legal advice. Obtain qualified counsel for the relevant facts and jurisdictions.
Roles follow facts, not labels
Under the EU GDPR, a controller determines the purposes and means of processing, while a processor handles personal data on the controller’s behalf. The official GDPR text and the EDPB’s final controller-and-processor guidelines emphasize a functional analysis. A contract calling a party a processor does not make it so if that party independently decides why and how personal data will be used.
The same organization can be a processor for one activity and a controller for another. An agency might process a client’s uploaded account list strictly under instructions, while acting as a controller for its own prospecting, billing, security logs, or service improvement. A data provider might have controller responsibilities for collecting and maintaining its own dataset, then act under different restrictions when delivering a client-specific service.
California’s privacy framework uses different statutory concepts, including business, service provider, contractor, third party, sale, and sharing. Do not translate “processor” mechanically into “service provider.” Review the current statute, regulations, contract restrictions, and actual use. Other U.S. states and countries differ again.
Scenario-based role matrix
| Processing activity | Likely client role | Possible agency role | Possible vendor role | Key question |
|---|---|---|---|---|
| Client uploads a target-account list for a defined campaign | Controller/business | Processor/service provider if acting only on instructions | Subprocessor or separate provider role, depending on facts | Who chose the people, purpose, fields, and retention? |
| Agency selects topics and prospects for its own lead generation | Controller/business | Controller/business | Provider role depends on its independent purposes and contract | Is the agency pursuing its own purpose? |
| Vendor builds and maintains a reusable identity or intent dataset | Recipient/user of service | Recipient/user of service | Often has independent controller/business questions | Who decided to collect, combine, retain, and reuse the source data? |
| Agency and client jointly design one shared campaign and essential targeting rules | Controller | Possible joint controller | Processor or other role by activity | Are purposes and essential means jointly determined? |
| Platform processes client-specific exports under documented instructions | Controller/business | Processor or authorized operator | Processor/subprocessor/service provider might be possible | Can the platform use the data outside the instructions? |
| Security, fraud, billing, and legal-retention logs | Controller for its obligations | Controller for its obligations | Controller for its obligations might apply | Does each party have an independent legal or operational purpose? |
“Likely” is deliberate. Counsel must analyze the actual data, purpose, contracts, product design, and jurisdiction.
Build the data-flow and decision record
- Inventory data and events. Include topic research, website visits, IP/domain resolution, device or cookie data, names, work and personal contacts, mobile numbers, CRM fields, ad audiences, outreach outcomes, suppression records, and model scores.
- Map every source and destination. Record collection source, party receiving data, storage, region, integration, export, agent access, and deletion path.
- Define the purpose for each step. “Marketing” is too broad. State whether the step qualifies an account, identifies a visitor, enriches a record, builds an ad audience, routes a call task, measures a campaign, prevents fraud, or bills usage.
- Identify essential decisions. Who decides categories of people, data fields, lawful basis, disclosure, retention, recipients, matching thresholds, and permitted channels?
- Assign candidate roles. Do this per row of the map, not per logo. Record disagreements and escalation.
- Match contracts and notices. Check processing instructions, purpose limits, confidentiality, security, subprocessors, assistance, deletion/return, audits, transfers, and rights handling.
- Operationalize the RACI. Name the person who responds to rights requests, corrects identity errors, approves new topics, investigates incidents, and stops activation.
- Review on change. New data sources, AI agents, pixels, audiences, countries, channels, or reuse purposes can change the analysis.
A practical RACI
The client is usually accountable for the campaign purpose and lawful basis when it decides whom to pursue and why. The agency might be responsible for configuration and delivery under instructions, but can become accountable for independent purposes it introduces. The data/platform provider is responsible for its contractual processing and security duties and might have separate accountability for its own collection or reuse. Privacy and security teams are consulted; sales and marketing operators are informed and trained.
Do not place “privacy” as the owner of every task. Operations owns implementation, engineering owns technical enforcement, procurement owns diligence and commercial documents, and executives own risk acceptance. Privacy counsel advises and validates the legal model.
Tools and documents that support governed roles
Use a data inventory, processing-activity register, data-flow diagram, role matrix, data-protection impact assessment or similar risk assessment, vendor questionnaire, data-processing agreement, subprocessor register, transfer assessment where applicable, retention schedule, rights-request tracker, suppression service, incident plan, and audit evidence repository.
A governance platform can organize these records, but it cannot decide the role from a vendor dropdown. The ICO’s controller and processor guide recommends examining who decides collection, purpose, data types, individuals, disclosures, notices, rights responses, and retention. Use those questions in procurement and design reviews.
Governed controls versus informal practice
An informal model relies on a contract label and assumes the vendor handles compliance. It is cheap at first and expensive during a complaint, audit, breach, or client dispute because no one knows who must act. A governed model costs more to establish but makes instructions, permissions, escalation, and deletion executable.
Vendor assurances are inputs, not controls. Ask for the actual data sources, rights, security commitments, subprocessors, retention, deletion mechanics, role analysis, geographic transfers, and audit evidence. Test exports and deletion rather than accepting a diagram. If a provider reserves broad independent use, the relationship might not behave like pure processing under instructions.
Cost of compliant implementation
Budget for counsel, privacy or governance leadership, security review, procurement, data mapping, engineering controls, contract negotiation, notices, consent or lawful-basis analysis, rights handling, retention automation, incident response, training, monitoring, and periodic reassessment. Cost rises with person-level data, personal emails or mobile numbers, sensitive inferences, cross-border transfers, many subprocessors, ad activation, automated calls, and multiple clients.
BrandWell agency plans are $2,500–$5,000 per month, depending on topic count, contract term, and any contractually scoped topic exclusivity that is available. Confirm included modules, usage, client capacity, implementation, support, and exclusivity in the current written quote and order form. The low end of this approved range is $2,500 per month; the applicable written quote controls. That commercial range does not include or replace the buyer’s legal, privacy, security, integration, or staffing costs.
Audit controls and effectiveness
Audit both design and operation. Design evidence includes the map, RACI, contracts, instructions, lawful-basis record, notices, risk assessment, retention, and incident plan. Operating evidence includes access logs, deletion tests, rights-response time, suppression propagation, subprocessor approvals, transfer controls, training completion, incident exercises, identity corrections, and policy exceptions.
Useful metrics are percentage of processing activities with assigned roles, unresolved role disputes, stale maps, unapproved subprocessors, deletion completion, rights-request SLA, suppression defects, identity correction rate, unauthorized exports, access-review completion, and time to contain an incident. A perfect document score with failed deletion is not effective governance.
Jurisdiction, data type, role, and channel changes
The EU GDPR, UK GDPR, U.S. state privacy laws, sector rules, direct-marketing laws, telecommunications rules, platform terms, and contract duties can overlap. The UK ICO notes its controller/processor guidance is under review following legal changes, which is a reminder to verify current law rather than reuse a static template.
Person-level web identification, personal email, mobile numbers, inferred interests, and cross-context advertising can raise different issues from account-level company data. Calls, texts, emails, and ad audiences have channel-specific rules. Employment status, location, and whether the recipient is a consumer, sole proprietor, or company contact might matter. Get jurisdiction-specific advice.
Intent and identity do not prove consent
An intent score is a model or observed event used for prioritization. It does not prove that a person consented to enrichment, advertising, a call, an email, automated decision-making, or cross-client use. An account-level signal does not prove which employee acted. An identity match does not prove the match is correct or that a purchase is imminent.
Govern these fields with provenance, confidence, minimization, purpose restrictions, retention, correction, suppression, and human review. Do not expose private browsing claims in outreach. Avoid letting an AI agent infer lawful basis or silently expand the purpose.
Highest-risk failure modes
The most serious failures include assigning roles only at company level; using contract labels that contradict behavior; mixing client datasets; reusing data for an agency’s own prospecting without analysis; unapproved subprocessors; indefinite retention; missing notices; weak deletion; unresolved identity errors; exporting personal data into uncontrolled agents; and treating a signal as consent.
Reduce risk through tenant separation, least privilege, field-level access, versioned instructions, approved subprocessors, deletion verification, centralized suppression, incident drills, role-based agent permissions, and a change gate for new data or activation. Stop processing when instructions are unlawful, ambiguous, or outside the approved purpose, and escalate.
What an agency must document before selling the service
Document the service purpose, data categories, sources, client instructions, candidate roles per activity, permitted and prohibited uses, client billing boundary, tenant separation, subprocessors, transfers, retention, deletion, rights handling, incident roles, security measures, identity-confidence rules, suppression, channels, agent access, approval gates, audit evidence, and exit process. The agency bills its clients and owns its promises; wholesale platform access does not transfer that accountability.
BrandWell is the separate complete white-label agency sales-and-delivery engine for intent-data services; LeadFuze is underlying data infrastructure. The legacy BrandWell SEO writer is out of scope. A $70 seven-day reseller pilot with branded topic reports can test operations and documentation, but it is not a legal safe harbor.
Agent-ready instructions
Claude or ChatGPT can compare the data-flow map to approved contract clauses and flag missing fields; they should not make the final legal classification. Moxby is a separate browser product that might execute approved browser steps. Require source citations, tenant boundaries, no data reuse, no silent exports, no channel activation, and mandatory human privacy/legal approval.
Controller-processor contract checklist
Where a controller appoints a processor under GDPR-style rules, the contract commonly needs documented subject matter and duration, nature and purpose, data types, categories of people, controller rights and obligations, processing only on documented instructions, confidentiality, security, subprocessor authorization and flow-down terms, assistance with individual rights, assistance with security and impact assessments, deletion or return, and information and audits needed to demonstrate compliance. The exact requirements depend on the applicable law and relationship.
Contract language should also match operations. Identify who configures topics, decides identity thresholds, exports data, chooses channels, approves agents, handles corrections, and sets retention. Add a change process for new sources, models, countries, or subprocessors. State prohibited uses, cross-client restrictions, and whether aggregated or deidentified data might be created and under what standard. Avoid broad clauses that defeat the claimed “instructions only” model.
Maintain an instruction register
Keep one versioned register for operational instructions rather than scattering them across tickets and chat. Record the approving controller, affected dataset, permitted purpose, fields, recipients, locations, retention, activation channels, agent permissions, effective date, and superseded version. Link each instruction to the implemented configuration and an evidence owner. When an operator receives an ambiguous or conflicting request, pause that activity, preserve the conflict, and escalate it; do not quietly choose the broader use. Sample the register against logs and exports during every control review.
Subprocessor and onward-transfer controls
Maintain a current subprocessor list with service, location, data categories, purpose, security review, transfer mechanism where applicable, authorization status, and deletion path. A logo list without processing detail is insufficient. Define how customers receive notice of changes, how objections are handled, and what happens if no acceptable alternative exists.
Map onward transfers and remote access, not just hosting. Support staff, analytics, monitoring, model providers, and browser agents might receive data. Confirm whether data is used to train general models. Apply tenant isolation, least privilege, key management, logging, and contractual restrictions.
Rights requests, corrections, and suppression
The RACI must make an individual’s request executable. The receiving party authenticates and routes it; the controller decides the response; processors search, export, correct, restrict, or delete within the instructed scope; every party updates suppression and downstream recipients as required. Test the path with sample identities, including misspelled names, changed employers, hashed audiences, and data already exported to CRM.
Identity systems require correction controls because a wrong match can propagate into outreach and reporting. Record the original value, corrected value, source, reason, time, and every downstream system notified. Suppression should survive normal re-enrichment so a deleted contact does not silently reappear from the next feed.
Incident response by role
Define who detects, contains, investigates, preserves evidence, assesses impact, notifies counterparties, communicates with individuals or authorities, and approves resumption. Contracts should provide fast notice without waiting for a final root cause. The controller needs enough facts to meet its own deadlines; the processor should not make unauthorized public statements.
Run tabletop exercises involving the client, agency, data provider, CRM, ad platform, and any AI or browser execution layer. Scenarios should include a cross-client export, compromised API key, wrong-person audience, unapproved subprocessor, failed deletion, and agent-generated outreach outside instructions. Record remediation owners and retest.
Four practical scenarios
Client-defined campaign: A client supplies accounts, topics, permitted channels, and retention. The agency operates under those instructions. Processor/service-provider analysis might be plausible for that activity, but the agency’s independent billing, security, and business-development uses remain separate.
Agency-developed managed service: The agency chooses the market, topics, people, and purposes, then sells the resulting intelligence. That autonomy creates controller/business questions even if a platform contract calls the agency a processor. Document the split rather than forcing one label.
Reusable vendor dataset: A provider independently collects, combines, scores, and retains data for many customers. Its role in creating that dataset might differ from its role when hosting a client-specific workspace or executing a narrow instruction. Diligence must cover both layers.
Jointly designed program: Client and agency jointly decide the target population and essential means for a shared purpose. Joint-controller analysis might arise under GDPR-style law. If so, a transparent allocation is needed, while individuals might still exercise rights against relevant parties. Counsel should decide.
BrandWell operating boundary
For a BrandWell reseller deployment, document BrandWell’s platform and delivery scope separately from LeadFuze’s underlying data infrastructure, the agency’s service decisions, and the agency client’s campaign purposes. Identify which party chooses topics, identities, routing, reports, channels, retention, and agent instructions. The agency owns client billing and must not imply that BrandWell’s wholesale service determines the agency’s legal role.
Topic count, term, usage, modules, and any available topic exclusivity belong in the proposal and order form. The order should not be used to claim exclusivity beyond the written scope or to conceal data-governance responsibilities. The seven-day pilot should use a narrow, approved dataset, named reviewers, controlled exports, and a written deletion or continuation decision.
Procurement questions before signature
Ask the vendor to describe, by processing activity, which data it collects directly, receives from partners, infers, licenses, or obtains from the customer; the role it claims; its independent purposes; the instructions it accepts; and the uses it prohibits. Request the relevant privacy notice, DPA or service-provider terms, subprocessor list, security documentation, retention schedule, deletion process, transfer mechanism, incident commitments, and audit support.
Then ask operational questions. Can the customer configure retention? Can one client’s data improve another client’s outputs? Are personal emails or mobile numbers included, and under what rights? How are identity disputes corrected? How are suppressions enforced after re-enrichment? What agents or model providers receive prompts or records? Can data leave the platform through browser automation, CSV, API, ad sync, or CRM? Who disables those paths at termination?
Record answers as verified, partially verified, unavailable, or conflicting. Sales assurances should not override product behavior or contract language. High-risk unknowns belong in an approval register with an owner, mitigation, deadline, and stop condition.
Change management and annual review
Reassess the role map when the agency adds a client, data source, pixel, identity method, topic, country, ad platform, call/text channel, AI model, browser agent, analytics purpose, or retention period. A minor product feature can create a new purpose or recipient. Require privacy, security, legal, and operational sign-off proportional to risk.
At least annually, compare the documented map with logs, integrations, exports, subprocessors, contracts, notices, and actual staff practices. Interview operators; shadow a rights request and deletion; sample suppressions; and check that offboarded clients no longer have active keys or audiences. Report exceptions to leadership and track closure. Governance is credible when the evidence survives a real workflow, not when every box in a questionnaire is green.
When an answer remains uncertain, document the uncertainty, narrow the processing, and block new activation until the accountable owner and qualified counsel approve a defensible path.
The practical takeaway
Role allocation is a living operating model. Map the processing, identify who makes essential decisions, contract to the facts, test the controls, and reassess when the purpose or technology changes. This guide is informational and is not legal advice.
Before operationalizing the role map, request BrandWell’s $70 seven-day reseller pilot with privacy, legal, and security review gates written into the test scope.
Validate the agency offer before a full plan
For $70, an agency receives seven days of reseller-pilot access. BrandWell generates topic reports carrying the agency’s branding and provides the full sales playbook for taking the offer to prospective clients and seeking commitments before full-plan enrollment.
The pilot is designed to help the agency validate demand and check whether expected commitments would cover its costs before it builds a profit-center model. Results vary, and BrandWell does not guarantee commitments, cost recovery, or profit. Review the $70 seven-day reseller pilot.



