A compliance checklist for social media managers who download client content

The riskiest download an agency makes is rarely the one it worries about. It is the routine pull of a client's own feed — the asset everybody assumes is cleared because "it's their account." That assumption is where the trouble usually starts, and most of it is avoidable with a few written steps taken before anyone touches a download button.

Get the right to download in writing

A verbal "sure, grab whatever you need" is not a permission you can rely on. People forget they said it, the person who said it leaves, and a nod in a kickoff call is worth nothing if a rights dispute ever lands. Put the authorisation in the contract or the statement of work, in text, signed.

Do not stop at "the agency may download content." Specify the scope, because scope is what a dispute turns on:

  • Which accounts. Name them. A brand with five handles has not authorised all five just because one is in the SOW.
  • Which channels the assets may be used on. Downloading for internal archiving is a narrower grant than downloading to re-cut into paid advertising.
  • For how long. Rights that end with the contract need to say so, and so do rights that are meant to survive it.
  • Whether onward licensing is included. If you will hand assets to a media buyer or another vendor, the client has to have agreed to that sub-licence explicitly.

Vague scope is not a convenience that gives you room to move. It is an argument you will lose later.

Owning content and having posted it are different things

This is the trap worth spelling out slowly, because it is the one that catches careful teams.

A client can post something to their own account without owning the rights to it. User-generated content is the obvious case: a brand reshares a customer's photo, a creator's Reel, an influencer's clip. It sits on the brand's feed and looks like brand content. It is not. The rights still belong to whoever made it, unless a licence was actually signed — and a repost is not a licence.

So when a client authorises you to download "their" content, check what is genuinely theirs to grant. If a post is reshared UGC, the client's permission may not be theirs to give, and downloading it on their say-so puts you in the chain of a rights problem you did not create.

The rule of thumb: before you download a post, know who made it, not just whose feed it is on. If the answer is "someone else, and we reshared it," the client's blessing is not enough on its own.

Music is almost always a separate problem

Treat the soundtrack as a distinct rights question from the video, because it is. A track that a creator added inside Instagram was cleared for playback inside Instagram, through the licensing deals the platform holds with rights holders. That clearance does not travel with the file.

The moment the same clip is downloaded and re-used in a client's advertisement, a paid campaign, a website embed or anything outside the app, the in-app music licence no longer covers it. "But it was on their Instagram" is not a defence — it describes exactly the use that was licensed and none of the ones you are now making. Sync licensing for commercial use is its own negotiation with its own rights holders.

The safe operating position is that any track destined for a client's own paid or public output must be cleared or replaced with properly licensed music, regardless of where the clip originally lived.

Keep an audit trail

If you cannot show who authorised a download, when, and on what basis, you effectively have no authorisation at all. Build the record as you go rather than reconstructing it under pressure.

For each asset, keep:

  • Who authorised it — the named person, not just "the client."
  • When the authorisation was given, and which version of the contract or SOW it rests on.
  • The evidence itself — the signed clause, the email, the licence — stored with the asset, not in a separate inbox that gets archived and lost.

Storing the paperwork alongside the file means the next person who touches the asset, possibly years later, can see its provenance without asking you. The trail has to outlast the individual who created it.

Hand assets over at the end of the contract

Decide before the relationship ends what happens to everything you downloaded. Two questions need answers in writing: what gets handed back or transferred, and what — if anything — you are allowed to retain, for how long, and for what purpose.

A clean handover of source files, edits and rights paperwork protects both sides, and it forces the retention question into the open. An agency quietly keeping a client's full media library after the contract ends is a data-governance liability, not a convenience. If you retain anything, retain it because the contract says you may, for a stated reason, and delete the rest.

Recognisable people carry their own rights

When a real, identifiable person appears in content — a customer, an employee, a member of the public — their image is personal data in many jurisdictions, and their likeness can carry publicity or personality rights on top of the copyright in the footage.

Copyright in the video and consent from the person in it are two separate permissions. You can hold the first and still lack the second. Before reusing content featuring a recognisable individual, especially in advertising, confirm that the appropriate consent or model release exists. The client owning the footage does not by itself mean the person in it agreed to appear in a campaign.

Platform terms still apply to you

The client relationship does not put you outside Instagram's terms. Those terms govern your access to the platform directly, regardless of who is paying you. A client cannot authorise you to do something the platform prohibits, because the client is not a party to your agreement with the platform.

In practice this means the content that is out of reach stays out of reach: private accounts you do not follow, posts behind access controls, anything a login gate protects. A client instruction does not unlock any of that, and no legitimate tool will pretend to. This site does not — it works only with content that is already public, and the rights to reuse that content are a separate matter you still have to hold. When you are pulling a client's own public posts with the paperwork in place, the posts downloader saves the original file, but the file is only the easy part.

A pre-download checklist

Run through this before you download anything for a client:

  1. Is there a written grant covering this account and this use, signed and current?
  2. Did the client actually create or licence this specific post — or is it reshared UGC that belongs to someone else?
  3. Does anything in it need separate music clearance before it can be used commercially?
  4. Is there a recognisable person whose consent or model release you need?
  5. Have you recorded who authorised it and when, and stored that evidence with the asset?
  6. Does the download stay inside the scope and duration the contract allows?

If any answer is no or unknown, stop and resolve it before the download, not after.

This is practical guidance for organising your process, not legal advice, and the rules differ by country and by the type of content involved. Have your own counsel review your template contract and your standard permission language before you rely on them across a roster of clients. If you want the site's own position on rights and takedowns, the DMCA and terms of service pages set it out, and the post on who owns a Reel covers the underlying rights question in more depth.

PotatoPlayer for Android

Batch downloads, a built-in video and music player and MP3 conversion — free on Google Play.

Download the app

Related reading

How to archive your own Instagram account properly before you delete it

Instagram's own Download Your Information export is the authoritative way to save your account. Here is how to run it, where it falls short, and how to top up the gaps at full quality before you delete anything.

Instagram Stories and the 24-hour clock: what can and can't be recovered

A Story is public for 24 hours, then it moves to a private archive only its owner can reach. Here is what that actually means for recovering one, and the routes that genuinely work for your own.

"The 640-pixel trap: why most Instagram photo downloads are far smaller than they should be"

The photo field a downloader reaches for first is a 640-pixel feed thumbnail, not the real image. Getting the full-size file means understanding how Instagram lists its candidates.

← Back to the blog