NakodaX

Situations · Data protection

What happens to your data when an agency contract ends

A stream of customer files accumulating in a former agency’s storage.

When an agency contract ends, disabling logins only stops new access. Every file already sent remains in the agency’s storage and backups indefinitely, available to inform work for their next client. The enforceable alternative is sending files that check for permission on every read, so ending the relationship ends access to everything ever sent.

Four years of files, an hour at a time

The relationship starts with a feed. Customer lists for audience building, purchase history for lookalike modelling, campaign results going back the other way. Hourly, or nightly, or whenever the export job runs.

It is not one file. Over four years it is tens of thousands of them, and they spread the way files spread inside any working company: into the agency’s storage, into their analytics tooling, into working folders on the laptops of the three account managers who have since moved to other jobs, into a backup that runs whether anyone thinks about it or not.

Nobody did anything wrong. This is what it looks like when two companies work closely together.

Offboarding stops the tap. It does not empty the tank.

Then the relationship ends, and offboarding happens. You disable their logins. You remove them from your systems. Somebody sends an email asking them to delete what they hold, and somebody at the other end replies that they will.

Every one of those steps is about future access. None of them touch the four years already sent, which is exactly the part that matters, because that is where your customers are.

That data does not sit still either. It informs the work the agency does next, sometimes deliberately, more often just as accumulated instinct in the heads and the spreadsheets of people who spent four years inside your business. Their next client may well be your competitor. From their side that is not theft. It is experience.

The deletion clause everyone signs and nobody checks

Your contract almost certainly requires deletion on termination. It may require written confirmation. It may even mention audit rights that neither party has ever exercised.

The honest position is that you cannot verify any of it. You cannot see inside their storage. You cannot inspect their backups. You would not know what to ask for if you could, because you do not have a list of every file you sent over four years. The confirmation you receive is a person’s good-faith belief about a system they do not fully control, and you file it because there is nothing else to file.

What changes when the file checks first

The alternative is to stop sending copies that work on their own.

Files sent under data protection are readable only while your permission holds. Their systems read them the same way they always did, on the same schedules, into the same storage. The difference is that each read asks you first, and you can stop answering.

So the end of the relationship becomes a single action rather than a request. You withdraw permission, and the next time anything tries to read anything you ever sent, it fails. The files in their storage, in their backups, in a departed employee’s working folder: all of them, because all of them need the same permission and none of them have it any more.

You are no longer asking a company you have stopped paying to do you a favour they cannot prove they did.

The record is the part compliance cares about

There is a second thing you get, and for regulated businesses it is often the reason to bother at all.

Because every read is checked, every read is logged. When your data protection officer asks what happened to the customer data held by that agency, the answer stops being a forwarded email. It is a date, a time, and a list of every attempt to open anything since.

That is the difference between telling an auditor you asked, and showing them it took effect.

What it asks of the agency

One setup step, once, at the start. After that it runs on its own and nobody at either end thinks about it again.

In practice agencies agree, because the party sending the data is usually the party with the leverage, and because it costs them almost nothing. If a specific partner is likely to resist, say so on the call and we will be straight with you about whether we are a fit.

What changes

Offboarding includes the data. You withdraw permission, and their next attempt to read anything you ever sent fails. Not a request. A switch.

access ended

Related questions

What happens to our data when an agency contract ends?
Disabling logins only stops new access. Everything already sent stays in the agency’s storage, backups and working folders indefinitely, and deletion clauses are almost never verified. Files that check for permission on every read behave differently: ending the relationship ends access to everything you ever sent.
What should be on an agency offboarding data checklist?
Closing accounts, revoking system access, recovering shared credentials, and confirming deletion. The row most checklists are missing is the historical data itself, which is the largest exposure and the only item on the list you cannot verify unless the files were sent under ongoing permission.
How do we get our data back from an ex-agency?
Realistically you cannot retrieve copies from another company’s systems, and a returned drive does not prove other copies were destroyed. The practical goal is not retrieval but revocation: making the copies they hold stop opening, which requires the files to have been permission-checked from the start.

This one, or one very like it

Data protection. Start where the problem actually is.