Free scan
Agency-installed tags · troubleshooting

My agency installed the pixel — am I still responsible?

In practice, yes — the letters arrive at the business that operates the website, because that is whose domain served the script and whose visitors were affected. Who you can recover from afterwards is a contract question. Who gets the letter is not.

The short answer

That is an uncomfortable answer, so here is the useful part: the same fact that makes you the recipient also makes you the person who can fix it, and most owners in this position discover they have less visibility into their own site than they assumed. The agency has publish rights in Tag Manager. The agency knows which pixels are live. Nobody on your side has looked at the container in a year.

Whether your agency agreement shifts any cost — through an indemnity, a data-processing addendum, or service-provider contract terms — is a real question for a lawyer reading your actual contract. It is worth asking. It is not a substitute for knowing what is running on your own domain.

Last reviewed: September 1, 2026Diagnostic + fix checklistGeneral information, not legal advice

How this usually surfaces

The pattern is consistent. A campaign launches; the agency adds a pixel or three through the Tag Manager container you gave them access to; nobody tells the website owner because nobody considers it a change to the website. Months later a scan, an audit, or a letter surfaces a tracker the owner has never heard of — and the first internal question is "who added this?", which nobody can answer because the container has no change log anyone reads.

The second discovery is worse: the owner does not have admin rights on their own container, or the analytics property is on the agency's account, or the pixel belongs to an ad account the agency owns.

Audit your own access in five minutes

Before the contract conversation, establish the facts. All of this is read-only and takes minutes.

  1. Confirm you own the container. In Tag Manager: Admin → User Management. Are you listed with Administrator rights on both the account and the container? If the only admin is an agency address, that is finding one.
  2. Read the version history. Admin → Container Versions (or the Versions tab). Every publish is listed with who did it and when. Open the last few and read what changed — this is the change log you did not know you had.
  3. List the live tags. Workspace → Tags, sorted by last edited. Anything you cannot name a business reason for is a candidate for removal, not gating.
  4. Check ownership of the accounts behind the tags. Whose ad account is the pixel ID from? Whose analytics property? If a vendor account is not yours, you are dependent on them for both the data and the ability to turn it off.
  5. Scan the rendered page. Load your site in a fresh incognito window with DevTools → Network open and list every third-party domain contacted before you answer the banner. Compare that list against the container: anything in the network log but not in the container was installed some other way — a plugin, a theme edit, or a platform integration.
  6. Write the two lists down. "Tags I can account for" and "tags nobody can account for." The second list is the agenda for the next agency call.

What a healthy result looks like: You should end up owning admin rights, with a readable publish history, and a list of live tags each of which has a named owner and a business reason.

Why this keeps happening

1. Tag Manager publishes bypass every other control

A container edit ships instantly. No code review, no deploy, no QA. Your engineering change-control process, however good, does not cover the surface that adds most trackers.

2. Access was granted once and never revisited

Agency onboarding hands over admin rights on the container, the ad accounts, and sometimes the CMS. Offboarding rarely reverses all of it. Old vendors frequently still have publish rights.

3. Nobody asked "does this add a third-party script?"

New tools get evaluated on price and features. The question of what they inject into the page — and whether it needs to be consent-gated — is not on the approval checklist at most small businesses.

4. The consent setup was done once, for the tags that existed then

Whoever configured the banner categorized the trackers present that week. Nothing forces a tag added later to pass through the same process, so each addition ships ungated by default.

The risk context

California's Invasion of Privacy Act (CIPA), Penal Code § 631, prohibits reading or learning the contents of a communication in transit without the consent of all parties, and separately reaches anyone who "aids, agrees with, employs, or conspires with" a person who does. Demand letters built on that theory are addressed to the operator of the website whose visitors were affected. Statutory damages under § 637.2 run up to $5,000 per violation, argued per session.

Separately, California's consumer-privacy framework does contemplate the relationship you have with vendors: Civil Code § 1798.140 defines service providers and contractors, and the CCPA regulations set out required contract terms for them. Those provisions are about how a business and its vendors allocate obligations — a genuinely useful conversation to have with counsel and with your agency. They are not a reason to assume the exposure sits somewhere else.

To be precise: a tracker firing before consent is a technical finding — it establishes when a script transmitted data, not who is legally answerable for it. Who ends up bearing the cost depends on facts and contracts a network log knows nothing about.

The accountability checklist

What this is called

Terminology bridge

The person the law looks to is usually the website operator or, in privacy-law language, the business — as opposed to a service provider or contractor, terms California defines with specific contract requirements attached. The document that sets out those terms is typically a data processing addendum (DPA). The operational discipline you are missing has a name too: tag governance — controlling who can publish tags, with review and a change log. And a tracker nobody can account for is, in audit language, an unattributed third party.

What a scan can and can't tell you

This page is general information, not legal advice, and the allocation of responsibility between a business and its agency depends entirely on documents we cannot see. What a scan settles is narrower and still valuable: exactly which third parties your site loads, in what order, relative to consent — so the conversation with your agency and your attorney starts from evidence instead of recollection.

Sources

  1. California Penal Code § 631 (leginfo.legislature.ca.gov)leginfo.legislature.ca.gov
  2. California Civil Code § 1798.140 — service provider and contractor definitionsleginfo.legislature.ca.gov
  3. CPPA: final CCPA regulations text (contract requirements, § 7051)cppa.ca.gov
  4. Google: Managing users and permissions in Tag Managersupport.google.com

Check your own site

RegSentry loads your site in a real browser, records when each third-party tracker first contacts its server, and flags everything that fires before consent — with the fix for each one. Continuous monitoring re-runs it and emails you when something new appears.

Free real-browser scan

See every pre-consent tracker on your site — free, 30 seconds, no signup.

Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.

Common questions

If my agency added the tracking pixel, are they responsible?
Demand letters are addressed to the business that operates the website, because that is whose domain served the script to the visitor. Whether your agreement with the agency shifts any of the cost — through indemnity or data-processing terms — depends on the contract and is a question for your attorney. It does not change who receives the letter.
How do I find out which tags my agency added?
Google Tag Manager keeps a version history: Admin → Container Versions shows every publish, who made it, and what changed. Combine that with a scan of the rendered page, because anything installed outside the container — via a plugin, theme edit, or platform integration — will not appear in the version history at all.
What access should I keep from an agency?
You should hold Administrator rights on the Tag Manager account and container, and own the analytics property and ad accounts behind the tags. Agencies get edit or publish rights that you can revoke. Also restrict who can publish, so container changes go through a review rather than shipping instantly.

Keep reading

Guide: why tracking compliance driftsYour tracking changed after the auditGTM fires tags before consentReport: the state of website trackingMonitoring plans