Who owns cookie consent on a client site: the agency liability question
Every agency that ships client websites eventually faces the same uncomfortable question: whose fault is the non-compliant cookie banner? The agency built the site, chose the plugins, and wired the embeds. The client owns the domain, runs the business, and ignored the email about updating the cookie policy. When a complaint arrives, both sides point at each other, and the answer determines who pays. This is worth settling in writing before the complaint, not after.
The short answer: usually the client, but the agency is not safe
Under privacy law, the party that decides the purposes and means of data processing is the data controller, and that is normally the client. The client decides to run analytics, add the ad pixel, and embed the marketing tools, so the client holds the primary liability. But agencies are not bystanders. An agency that configured the tracking, wrote the banner copy, and controls the deployment is close enough to the processing to be named in complaints, and regulators do look at who built what.
In practice, liability follows the paper trail. If the agency scoped consent work, delivered a compliant setup, and documented the handover, the client owns what happens next. If the agency shipped a site with a decorative banner that blocks nothing and never mentioned consent, the agency is exposed the moment someone asks who built it.
What a consent handover should include
Every client handover should include a consent inventory: every tracker found on the site, its purpose, the legal basis, and whether the banner blocks it before consent. This is the document that proves the site was compliant on delivery day. Without it, the agency cannot show that later drift was the client's doing, and the client cannot show the agency ever cared.
Include consent responsibilities in the maintenance contract, not just the build scope. Sites change weekly: clients add plugins, marketers paste in pixels, and every change can break the consent setup. Define who scans, who fixes, and who approves new tools. An agency that keeps consent under its retainer turns a liability risk into recurring revenue; an agency that ignores it after launch keeps the exposure for free.
The conversation agencies avoid, and why to have it
Many agencies skip the consent talk because it slows the sale. Telling a client their marketing stack needs a rebuild is not how you close a project in a week. But the quiet version is worse: a client who learns about the gap from a regulator or a competitor's lawyer will not remember the agency fondly, and will absolutely remember who built the banner.
Frame it as risk, not paperwork. One sentence does the job: your site sets trackers before visitors consent, and that is the kind of thing that draws complaints. Offer the fix as a scoped line item with a price. Most clients say yes once they understand it, and the ones who say no have made a documented decision, which is exactly the paper trail the agency needs.
Documenting the decision protects both sides
Get the client's consent decisions in writing, especially the no. If the client declines a compliant banner, declines regular scans, or insists on a plugin that breaks consent blocking, note it in the project record with their sign-off. This is not about blaming the client later. It is about the agency being able to show it advised correctly and the client chose differently.
The agencies that sleep well at night are not the ones with perfect clients. They are the ones with perfect records. Standardize the consent checklist in your project process, keep the handover inventory, and revisit it at every major site update. Consent ownership should be boring, documented, and settled before anyone needs it.