Industries · Agencies
Website compliance for marketing agencies
Agencies sit on both sides of website compliance risk: the sites you build and the tags you deploy create your clients' exposure, and 'the agency installed it' is the first sentence of the client's explanation when a demand letter arrives. Complidar gives agencies the same 22-check scan plaintiffs' firms run (per client site, in minutes), so portfolio risk is a list you manage instead of a surprise you inherit.
You deployed the pixel. Who owns the violation?
Legally, the demand letter names your client: their site, their public accommodation, their data flows. Commercially, the client's next call is to whoever built the site and installed the tracking. The Sephora pattern (trackers firing before consent, GPC ignored) and the session-replay pattern (recorder loading before the banner) are almost always implementation details an agency controlled. Whether that becomes a contract dispute depends on your statement of work; whether it becomes a fired client usually doesn't.
The defensive posture is diligence you can show: a scan per site at launch and on a schedule, findings triaged, fixes documented. That artifact changes the conversation from 'you exposed us' to 'here's the register we've been working.'
Scanning as a deliverable
Agencies also use compliance scanning as a wedge and a retainer line: a free scan of a prospect's site is a concrete, evidence-backed reason to start a conversation, and monthly monitoring is a recurring deliverable clients understand. Complidar's per-site pricing ($29/month monitoring, $39 one-time audits) is built to be resold as part of a care plan; for portfolio arrangements, talk to us.
What the scan checks for agencies
- Tracker and pixel inventory per client site: what fires, when, and to whom
- Consent-flow behavior including pre-consent firing and GPC honoring (the Sephora pattern)
- Session-replay configuration: which vendor, started before or after consent
- Full WCAG/axe-core accessibility pass on the sites you shipped
- Auto-renewal and checkout mechanics on client stores you operate
- Privacy-policy and ToS completeness against observed site behavior
Common questions
Can we white-label Complidar reports for clients?
Reports are exportable and built to be handed to clients and their counsel: every finding carries evidence and a cited comparable case. Reselling them inside a care plan works today on per-site pricing; for white-label or consolidated portfolio reporting, email info@complidar.com. That's a roadmap conversation we want to have with agencies.
Which findings are usually the agency's to fix?
The implementation layer: tag firing order, consent wiring, replay configuration, alt text and form labels in the theme, and disclosure placement in checkout flows you built. Policy content and legal responses stay with the client and their counsel. The report's per-finding remediation steps split naturally along that line.
How do we scan a site we don't own?
With the owner's authorization. An agency engagement typically provides it, but confirm it covers scanning. The terms require owner permission; agencies usually run scans under the client agreement's site-management scope.
All 22 checks · up to 120 pages · no card
Last updated 2026-06-11 · Informational, not legal advice: how to read this