
Rules and ethics
Part of Why local SEO rules and ethics now decide which agencies win trust
Nine local SEO data protection duties for agency client work
Local SEO data protection duties for agencies: lawful bases, notices, retention, security and subject requests, with the UK GDPR and 2018 Act behind them.
What to take away
- Most teams buy a contact list or scrape directory results first. Wrong order: lawful basis, notice and retention rule come before the data.
- The UK GDPR and the Data Protection Act 2018 govern client and customer data in England, and the same rules apply across the UK.
- An agency is usually a processor for client campaign data and a controller for its own prospecting lists.
- Consent is one of six lawful bases. Legitimate interests can fit prospecting, but only with a recorded balancing test.
Why the mistake happens before any data arrives
A local SEO retainer often begins with a list. Someone exports directory entries, scrapes map results or buys a file of nearby businesses. Nobody asks who agreed to that use.
The Information Commissioner's Office regulates this in England, Scotland, Wales and Northern Ireland. Its guidance sits under the UK GDPR and the Data Protection Act 2018.
Sole traders and small limited companies are still people. Treat business contact data as personal data unless you can show otherwise.
Individual cases need a qualified adviser. This is general guidance, not legal advice.
The nine duties that apply to local SEO data protection
- Name your lawful basis for each processing activity before collection starts.
- Write the privacy notice in plain English and link it wherever you collect data.
- Keep a record of processing activities, including purpose and retention period.
- Sign a data processing agreement with every client whose data you touch.
- Collect the minimum needed for the campaign and nothing extra.
- Check your lawful basis before any list purchase, scrape or enrichment step.
- Apply retention periods, then delete or anonymise when they expire.
- Put technical and organisational security measures in place and record them.
- Answer subject access, erasure and objection requests within one month.
Retention is rarely written down, security is assumed and requests sit in a shared inbox. If a client asks how the wider rules fit together, the UK rules and compliance guide covers licensing and claims alongside these duties.
Consent, legitimate interests and retention
Consent must be freely given, specific, informed and unambiguous. A pre-ticked box or bundled opt-in does not meet that standard.
Legitimate interests can cover business-to-business prospecting, but only with a documented balancing test covering purpose, necessity and effect on the individual.
Marketing emails to individuals also fall under the Privacy and Electronic Communications Regulations, adding a separate consent or soft opt-in test.
Advertising claims sit under a different regulator. ASA rulings show how the Advertising Codes have been applied to misleading marketing. Read them before you publish case study numbers.
Retention schedules that survive an audit
A schedule should state the data category, the purpose, the period and the disposal method, and be reviewed annually.
For example, a team might set 12 months from last contact for unconverted leads and six years for converted customer records. Those are illustrative figures, not a legal minimum.
Security measures worth documenting
Access control, encryption, backups and a breach log are the basics. Document who holds admin access to your client's analytics, search console and advertising accounts.
A breach that risks people's rights must be reported to the ICO within 72 hours of you becoming aware.
Building a data map for a local SEO campaign
Start with the sources, not the tools: client CRM exports, website forms, call tracking, review platforms and directory listings.
For each source, note the lawful basis, the retention period and who can access it. That table answers most client due diligence questions.
Retail media and local commerce data are moving quickly. The ISBA and mediasense capability baseline is a useful reference for how that side of the market is measured.
If you also run paid local campaigns, the local SEO advertising rules guide covers the claim and disclosure side.
Training is part of the duty. The CIM marketing training courses list includes digital marketing modules covering data handling.
Common questions
Do I need a data processing agreement with every client?
Yes, where you handle personal data on their behalf. Article 28 of the UK GDPR requires a written contract setting out the subject matter, duration, purpose and your obligations.
Can I scrape business contact details for local SEO outreach?
Only with a lawful basis and a notice that covers it. Scraping does not create a lawful basis, and platform terms may separately prohibit it.
How long can I keep prospect data?
There is no single statutory period. Set a period justified by your purpose, document it, and delete or anonymise the data when it expires.



