Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- Step 1, map every collection point
- Step 2, separate mandatory collection from optional marketing
- Step 3, make the collector identity clear
- Step 4, explain third party tools in plain English
- Step 5, keep consent records
- Step 6, match legal documents to delivery documents
- Common mistakes agencies make
- What founders should sort out before launch
FAQs
- Does every digital marketing agency need a privacy notice?
- Can one checkbox cover both a contact request and future marketing?
- Who should appear in the notice, the agency or the client?
- Do agencies need special wording for overseas software tools?
- What if a client gives the agency all the privacy wording?
- Key Takeaways
Digital marketing agencies in New Zealand often collect more personal information than they realise. A website form that feeds into a CRM, a lead magnet campaign, a remarketing audience, or a newsletter signup can all trigger privacy and marketing consent obligations. The common mistakes are usually practical ones: copying a generic privacy notice from overseas, bundling every type of consent into one checkbox, and collecting client customer data without being clear about who is responsible for what.
That becomes risky fast. Poor privacy wording can undermine consent, confuse website visitors, and expose your agency or your client to complaints under New Zealand privacy law. Sloppy marketing consent practices can also create Fair Trading Act issues if the messaging is misleading, or breach expectations around direct electronic marketing. This guide answers what a privacy notice consent form digital marketing agency should actually cover in New Zealand, when you need one, what founders should sort out before they sign a client contract, and where agencies often get caught.
Overview
A New Zealand digital marketing agency usually needs clear privacy notices wherever it collects personal information, and it needs consent language that matches the actual marketing activity.
The key point is transparency: people should understand what data you collect, why you collect it, who will receive it, and what they are agreeing to.
- Identify each place personal information is collected, including websites, landing pages, forms, pixels, ad campaigns and lead generation tools.
- Separate privacy notice wording from marketing consent wording so users are not misled about what is mandatory and what is optional.
- Confirm whether your agency is acting for itself, for a client, or as a service provider handling the client’s customer data.
- Explain overseas data storage, third party platforms, and analytics or advertising tools in plain language.
- Keep records of what consent was requested, when it was given, and what wording the person saw at the time.
- Align your privacy notice with your client contracts, internal processes, and actual campaign setup.
What Privacy Notice Consent Form Digital Marketing Agency Means For New Zealand Businesses
For a New Zealand agency, a privacy notice consent form is not one document with a fancy title. It is the combined set of disclosures and permissions that sit around your data collection points.
In practice, that usually includes a website privacy policy, short-form collection notices next to forms, cookie or tracking disclosures where relevant, and consent wording for email, SMS, retargeting, or other promotional communications. Each piece has a different job.
Privacy notice versus consent
A privacy notice tells people what happens with their personal information. Consent is a person’s agreement to a particular activity, where consent is appropriate or required for that activity.
Agencies often merge those ideas into one sentence, but they are not the same. A person may need to know that their details are being collected for a quote request, while separately choosing whether they want ongoing marketing emails.
Your notice should usually cover matters such as:
- what personal information you collect
- who is collecting it, whether that is your agency, your client, or both
- why it is being collected
- whether providing it is required or optional
- who it may be shared with, including software providers and ad platforms
- whether it may be stored or accessed overseas
- how the person can access or correct their information
- how they can contact the relevant business about privacy concerns
Your consent wording should then focus on the specific permission being sought. For example, subscribing to a newsletter, receiving promotional emails, joining an SMS campaign, or agreeing to personalised advertising based on behaviour.
Why this matters under New Zealand law
The Privacy Act 2020 is built around transparency, purpose, and fair handling of personal information. If your agency collects information directly from individuals, or sets up systems that do so for clients, you need to be upfront about what is happening.
The main risk is not only a formal privacy complaint. The more common business problem is damage to trust, lower conversion rates, client disputes about who dropped the ball, and campaigns that have to be rebuilt after launch.
Marketing agencies also need to think about the Fair Trading Act 1986. If a signup flow, ad, or landing page gives a misleading impression about why someone is handing over their details, that can create a separate issue. A checkbox that says a person is requesting a quote, when it also signs them up to multiple promotional lists, is where agencies often get caught.
Electronic marketing rules matter too. If you are sending commercial electronic messages, such as promotional emails or texts, you should make sure your process for obtaining consent and handling unsubscribes is sound. The exact setup depends on the campaign channel and facts, but the practical lesson is simple: do not assume one broad statement covers everything.
Who is responsible, the agency or the client?
Usually, both parties have work to do, but their roles differ. If your agency runs its own website and captures leads for itself, it is directly responsible for its own privacy notice and marketing consent language.
If you build campaigns for clients, the position can be more nuanced. Your client may be the main business collecting customer information, but your agency may still handle that information, host landing pages, configure tracking, or choose software tools. That means responsibility should be allocated clearly in your client contract and matched in your campaign documents.
Before you sign a contract, pin down:
- who owns the collected data
- who decides the purposes of collection and use
- who drafts or approves the privacy wording
- who responds to privacy access or correction requests
- who handles complaints or data incidents
- what happens to data at the end of the engagement
When This Issue Comes Up
This issue comes up any time your agency collects, receives, tracks, or uses information about identifiable people. It is not limited to long website privacy policies.
Many agencies first notice the problem when a client asks for a landing page and says, “Just add a checkbox.” That is usually the moment to pause and work out what data is being collected and what the person is actually agreeing to.
Website and landing page forms
If you use contact forms, booking forms, quote requests, downloadable guides, webinar registrations, or newsletter signups, you need a clear privacy collection notice and suitable consent wording. The shorter the form, the more important the wording around it becomes.
A lead generation form might collect:
- name and contact details
- job title and employer
- budget and project information
- behavioural or campaign source data
- preferences for future communications
That information may seem ordinary, but it is still personal information if it relates to an identifiable person.
Email marketing and nurture sequences
If someone downloads a resource, can you automatically place them into a promotional nurture sequence? Sometimes yes, sometimes no, but only if your notice and consent process make that clear and lawful for the context.
This is where founders often get caught. They assume that because a person engaged once, the agency or client has a blank cheque for future promotional messaging. A better approach is to state the purpose clearly at collection and offer a genuine choice where needed.
Client campaigns using pixels, cookies and audience matching
Tracking technologies often sit in the background of digital campaigns, but they still raise privacy questions. If your agency installs pixels, builds retargeting audiences, or uploads contact lists for ad matching, your privacy notice and campaign setup should explain that activity in understandable terms.
People do not need a technical essay. They do need enough information to understand that their interactions may be used for analytics, ad measurement, personalisation, or remarketing.
Agency CRM and sales pipeline management
Your own agency may collect prospect and client information through proposal requests, discovery calls, mailing lists, and event signups. That means privacy compliance is not only a client-delivery issue, it is also an internal business issue.
Before you spend money on setup, check whether your CRM, email tools, and project systems store data outside New Zealand. Overseas storage is common, but it should be covered transparently in your privacy policy and handled carefully.
White-label or subcontracted service delivery
If contractors, media buyers, developers, or virtual assistants can access personal information, your privacy position should match your operational reality. A privacy notice that says information is only used internally may be inaccurate if multiple external providers can see the data.
This is also a contract issue. Agencies should use service agreements, contractor terms, and client agreements that reflect who can access information and for what purpose.
Practical Steps And Common Mistakes
The best approach is to map your actual data flow first, then draft notices and consent wording that match it. Most privacy problems start with businesses documenting the version of their operations they wish existed, not the version they actually run.
Step 1, map every collection point
List every place where your agency or your client collects personal information through campaigns. Include online and offline touchpoints.
- website forms
- landing pages
- chat widgets
- newsletter signups
- competition entries
- lead ads on social platforms
- event registrations
- call booking tools
- manual imports into a CRM
For each one, identify what data is collected, why it is collected, who receives it, and what happens next.
Step 2, separate mandatory collection from optional marketing
A common mistake is forcing people to agree to all future marketing just to submit a basic enquiry form. That can create poor consent and an unpleasant customer experience.
If someone needs to provide their contact details so you can answer a question or prepare a proposal, say that clearly. If you also want permission to send future promotional material, ask for that separately where appropriate.
Good form design often includes:
- a short notice explaining the immediate purpose of collection
- a separate optional checkbox for marketing communications, if needed
- clear wording about the type of messages the person may receive
- an easy unsubscribe process for future electronic marketing
Step 3, make the collector identity clear
Agency campaigns often blur who is asking for the data. If a landing page is branded for the client but hosted and operated through the agency’s systems, be clear about whether the information is collected by the client, the agency on the client’s behalf, or both.
Confusion here can lead to complaints, especially when someone later asks to access or correct their information and nobody knows who is supposed to respond.
Step 4, explain third party tools in plain English
You do not need to list every line of software code, but you should accurately describe key categories of third party recipients and services. That may include email platforms, CRM systems, analytics tools, hosting providers, and advertising platforms.
Where overseas disclosure or storage is relevant, mention it plainly. New Zealand businesses commonly use global tools, and the legal issue is usually transparency and proper handling rather than avoiding those tools altogether.
Step 5, keep consent records
If a person later says they never agreed to marketing, your agency should be able to show what wording they saw and when they opted in. This is especially important when campaigns are changed frequently.
Useful records include:
- screenshots or archived versions of forms and landing pages
- date and time stamps of opt-ins
- source information showing where the signup occurred
- the exact checkbox or signup wording used at that time
- unsubscribe logs and preference changes
Step 6, match legal documents to delivery documents
Your privacy notice should not say one thing while your proposal, onboarding form, and client contract say another. If your agency contract says the client controls all customer data, but your privacy wording implies your agency determines the marketing use, that mismatch creates risk.
Consistency matters across:
- website privacy policies
- collection notices
- terms of use
- client service agreements
- data processing or subcontracting clauses
- internal privacy procedures
Common mistakes agencies make
The most common mistakes are operational, not academic. They usually happen when a campaign is rushed live before anyone checks the wording.
- Copying a privacy policy from an overseas template that does not fit New Zealand law or the actual campaign setup.
- Using one pre-ticked or vague checkbox to cover all communications, tracking, and data sharing.
- Failing to say when data will be shared with a client, a white-label provider, or a software platform.
- Collecting more information than is needed for the campaign objective.
- Leaving old forms active after the purpose of collection has changed.
- Ignoring unsubscribe requests or making them hard to action.
- Assuming the client has sorted privacy wording when the agency built the funnel and controls the tools.
What founders should sort out before launch
Before you launch online, make sure privacy and consent are part of your setup list, not an afterthought. That is particularly true if you are starting a digital marketing agency in New Zealand and setting up your business structure, company setup, client contracts, internal workflows, and trade mark position at the same time.
Your wider legal setup may include company registration through the Companies Office, terms with clients, contractor agreements, and brand protection. Privacy should sit alongside those basics because it affects your website, lead generation, service delivery, and reputation from day one.
If your agency sells recurring marketing services, also check that your terms and statements about campaign performance are accurate. Privacy compliance and fair marketing practices often overlap, especially when you are collecting lead data and making promises about how it will be used.
FAQs
Does every digital marketing agency need a privacy notice?
Almost always, yes. If your agency collects personal information through its website, CRM, mailing list, or client campaigns, you should have privacy wording that explains what happens to that information.
Can one checkbox cover both a contact request and future marketing?
Usually that is not the best approach. A person asking for a quote or callback should not be misled into broader promotional consent. Separate wording is often clearer and safer.
Who should appear in the notice, the agency or the client?
It depends on who is collecting and controlling the information. In many campaign setups, the client should be identified, but the agency’s role may also need to be explained if it operates the systems or handles the data.
Do agencies need special wording for overseas software tools?
You should be transparent if information is stored with or accessible through overseas providers. The notice should reflect the real tools you use and the flow of data, in plain language.
What if a client gives the agency all the privacy wording?
Do not assume it is correct for your campaign build. If your agency changes the form logic, adds tracking, or routes data through different tools, the wording may need updating before launch.
Key Takeaways
- A privacy notice consent form digital marketing agency setup is usually a mix of collection notices, privacy policy wording, and clear marketing permissions.
- New Zealand agencies should be transparent about what personal information is collected, why it is collected, who receives it, and whether it may go overseas.
- Privacy notice wording and marketing consent wording should not be treated as the same thing.
- Agency and client responsibilities should be allocated clearly in contracts, especially where the agency hosts landing pages, manages tools, or handles customer data.
- Good records matter. Keep copies of the wording used, the opt-in history, and your unsubscribe process.
- The biggest mistakes are vague checkboxes, copied templates, unclear ownership of data, and campaign setups that do not match the legal wording.
If your business is dealing with privacy notice consent form digital marketing agency and wants help with privacy notices, marketing consent wording, client contracts, data handling clauses, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








