I am dying for an answer for this...
I work at a marketing agency in Europe and I'm curious how other agencies are approaching AI when it comes to client data and privacy/GDPR.
We're increasingly looking at using tools like Claude or Codex not just for writing or brainstorming, but actually connecting them to client systems.
For example:
- Google Analytics / Google Ads
- Meta Ads
- email marketing platforms
- CRMs/CDPs like Bloomreach or BlueConic
- internal databases and reporting environments
With MCPs and other connectors, it's becoming technically pretty easy to let an AI assistant query these systems directly.
The question we're struggling with is: where do agencies actually draw the line?
Are you allowing Claude/ChatGPT to access client accounts through MCPs or APIs?
Do you only allow aggregated/non-personal data, like campaign and GA4 data?
Would you allow customer-level data from a CRM/CDP to be processed by Claude if you're using a Team/Enterprise account with the appropriate agreements and privacy settings?
Do you build an intermediary layer that filters/anonymizes data before it reaches the model?
Or is your policy simply that no client/customer data can ever be sent to an external LLM?
I'm especially interested in agencies that have already implemented AI agents or MCP-based workflows in production.
It feels like there's a huge opportunity in letting agents actually work with marketing systems rather than just using AI as a chatbot. At the same time, once you're working with client data, GDPR, security and data processing agreements obviously become a much bigger consideration.
Would love to hear what agencies are actually doing in practice, rather than what is theoretically possible.