When choosing an ads agency, price and references get discussed; access and data security usually come up later, when something has already gone wrong. The ten questions below can be asked in 15 minutes during the first meeting. Next to each we describe what a "good answer" looks like.
1. How will you access my account?
Good answer: a manager account (MCC) link in Google Ads, partner permission in Meta Business Manager, or an app connection via OAuth. Bad answer: "Share your username and password."
2. Do you ask for my password at any step?
Good answer: No, at no step. If a process asks for a password, that process is set up wrong.
3. Which permissions do you need, and why?
Good answer: the permissions are listed one by one (campaign management, page insights and so on) and each has a reason. Payment method, adding users and account ownership are not requested.
4. Who will own the account?
Good answer: you. The ad account, page and pixel are created in your business account; the agency connects to them. Assets created under the agency's own account cause trouble when you part ways.
5. Where and how do you store access keys?
Good answer: country/region, encryption method and who can read them are stated clearly (for example "in the EU, encrypted with AES-256-GCM, readable only by the server"). "Somewhere safe" is a vague answer.
6. Can I see who did what, and when?
Good answer: yes; every change is visible in the portal or in the platform's change history with user name, date and reason. If AI is used, the human who approved the change is recorded too.
7. Do you make automatic changes?
Good answer: automation and AI produce recommendations; an expert approves budget and targeting changes. There are no unapproved automatic changes, or their limits are written down and they are reversible.
8. Who else sees my data; is it sold or used to train models?
Good answer: only the assigned team; sub-processors (hosting, database, AI provider) are listed in the privacy policy; data is never sold; identifiable client data is not used for model training.
9. How long do you keep data, and what happens if I leave?
Good answer: retention periods are written down (for example personal data at most 24 months, invoices for the legal period). On leaving, access keys are deleted immediately, accounts and historical data stay with you, and data is deleted on request.
10. Can you put this in writing?
Good answer: yes: a privacy policy, a security summary and a data processing agreement (DPA) on request. An agency that will not put it in writing offers verbal assurance that is useless when a problem occurs.
Scoring
One point for each "good answer". 8–10 points: you can start with confidence. 5–7: tie the gaps to written commitments. Below 5: look for another agency; no campaign result is worth the risk of losing your account.
YUEN's answers to these ten questions are public: Trust & access, Privacy Policy and the downloadable security summary PDF.

