In short: Start with the work the partner must perform, identify the customer data it needs, and grant each named person the smallest useful access for a defined period. Record how data may be viewed, exported, shared, retained, and removed.
A marketing partner may need to work with analytics, advertising, CRM, or email systems. Each system can expose a different set of customer information. An access request becomes easier to assess when it names the task, the data, the people, and the actions the partner needs to perform.
This guide focuses on customer-data access during active work. The separate agency transition guide covers account and work transfer when a provider changes.
Start with the task and the data
Write down the work the partner will perform. A campaign build, lead-quality analysis, audience upload, or CRM review can require different records and permissions. For each task, identify:
- The systems and datasets involved
- The fields the work needs, including whether direct identifiers are required
- The people who will use the data and their roles
- The permitted purpose and the expected period of access
- Whether a smaller or less identifiable dataset can support the task
The question is whether the proposed access matches the work. If the agency asks for broad access to a full CRM, analytics account, or customer export, ask which specific activity requires it and what information the team will use.
Grant access to named people at the right level
Use individual accounts so permissions are assigned to a person. Give each person only the role and system level needed for the assigned task. Keep administrative access with the client-side owner when the partner can complete its work without it. Review access when responsibilities change.
Platform hierarchies can make a broad role wider than expected. Google Analytics, for example, gives users added at the account level access across the account’s properties, while property-level access can be limited to one property. Check the platform’s inheritance rules before granting a role.
NIST’s least-privilege control calls for access needed to perform assigned tasks and periodic review of granted privileges. The publication addresses controlled unclassified information in specific federal contractor contexts; it provides a security reference for thinking about the access each task requires.
Set rules for exports and connected tools
Viewing data inside a platform and copying it elsewhere create different handling needs. Decide whether the partner may download customer lists, export CRM records, connect third-party applications, or upload audiences to an ad platform. Require a clear purpose, an approved destination, and an owner for any such movement.
Ask the partner to identify any subcontractor or tool that will handle the data. Confirm who will authorize that use, what information it receives, and how the same handling rules will apply. Keep a record of approved connections and exports so the client can review them later.
Agree on retention and removal
Name the approved storage location and how long working copies may be kept. Set a review point for access when the scope, team, or data requirement changes. At the end of the task or engagement, confirm which access will be removed and whether any copies must be returned or deleted under the agreement and applicable rules.
If a partner processes personal data on your behalf, the legal roles and requirements depend on the activity and jurisdiction. The UK Information Commissioner’s Office guidance, for example, describes written controller-processor terms covering the purpose and duration of processing, data types, security, authorised subprocessors, and end-of-contract handling under UK GDPR. The ICO notes that its detailed contracts guidance is under review following changes made by the Data (Use and Access) Act. Check current requirements and obtain professional advice for the applicable jurisdiction.
Review access while work is active
Assign one internal owner to approve access and review the record. Recheck permissions at agreed milestones and when someone joins or leaves the delivery team. Remove access that no longer supports the work, then confirm that connected apps and shared files have been reviewed as well.
If the platform provides access or activity logs, decide who will check them and when. For example, Google Analytics documents account- and property-level user management; some Analytics 360 properties also offer data-access history. Use the controls available in the systems your team relies on, and document any important gaps.
A quick access record
- Task and business purpose: ______
- Systems, datasets, and required fields: ______
- Named people and permission level: ______
- Exports, integrations, and approved destinations: ______
- Subcontractors or other recipients: ______
- Start date, review point, and access end date: ______
- Storage, retention, return, or deletion terms: ______
- Internal access owner: ______
Clear access rules make it easier for a partner to start work and for your team to understand where customer information can go. Connect the access plan to the responsibilities in the statement of work and the delivery roles in the agency team guide.
If the requested access is broader than the task or the data-handling terms remain unclear, map the systems, owners, and decisions involved.
Related reading
Read the agency transition guide for handing off accounts and work, and the delivery-team guide for identifying the people who will access those systems.
Sources and scope
- UK Information Commissioner’s Office: Contracts — UK GDPR guidance on controller-processor contract terms, including processing purpose, data, security, sub-processors, and end-of-contract handling. The ICO notes the detailed guidance is under review after the Data (Use and Access) Act.
- Google Analytics Help: Add, edit, and delete Analytics users and user groups — explains account-level and property-level access.
- NIST SP 800-171 Revision 3 — a federal information-security standard with least-privilege and access-review controls for its defined scope.
Privacy obligations and security controls depend on the data, processing roles, contracts, and jurisdiction. These references are examples for evaluating access; use current local guidance for legal requirements. Accessed October 8, 2026.
How did this article land?
Choose one reaction. You can change it anytime.
