But the emphasis on first-party data is the wrong way to think about data privacy. Instead of focusing on the differences among first-, second-, and third-party data, marketers should be asking themselves whether the consumer data they are using was collected with clear and affirmative consent. That includes when consent was obtained, whether it is still valid, and precisely what the consumer has consented for businesses to do with their information.
Let’s consider an example. If Juan consents for the New York Times to collect data on his reading habits or for a data purveyor to collect information on his age and share it with Adidas, it is perfectly fine for the sneaker brand to use his data, even though Adidas does not have a direct relationship with Juan. If Adidas knows when the data was sourced and that Juan has consented for the businesses collecting his information to share it with others, Adidas knows it is using consensual, timely, quality consumer data.
The fact that, in Adidas’ hands, Juan’s information is second- or third-party data is irrelevant to the data’s quality, security, and respect for privacy. The data meets industry-leading privacy standards as long as Juan has explicitly consented for Adidas to use it to market to him.
By contrast, let’s say Juan purchased sneakers from Adidas in 2016 and filled out a digital form providing his email address. This is first-party data, stemming from the direct relationship between Adidas and its customer. But let’s say Adidas then turns around and sells or shares Juan’s email address with other parties or that Adidas is still using the email address five years later, despite all the messages to that address bouncing. In either event, the use of Juan’s data is non-consensual and ineffective. Juan has not necessarily consented for his data to be shared, nor used in perpetuity. Like milk, his data has spoiled, and through Adidas’ use of that data, it is engaging in both inefficient and unethical business.
Juan’s case demonstrates that what matters for companies aiming to respect consumer data privacy is not first-party data; it is consent, no matter where data originates.
It is understandable why the consumer data industry has developed an obsession with first-party data as a stand-in for consent: an unmediated relationship between a company and a consumer offers the company control over how its data is sourced and the opportunity to ask the consumer how much data they will hand over and how it can be used. But it is counter-productive and risky to center a data strategy on first-party relationships, as opposed to clear and affirmative consent, for a few reasons.
For one, the first-party obsession risks lulling marketers into a false sense of security about the ethical and legal standing of their data collection practices. The fact that your data comes directly from one of your customers and that you ask for it once is not enough. You need to be specific and clear about how much data you’re asking for, what you’ll do with it, and how long the consumer’s consent lasts. Assuming that any amount of data and any of use of it is fair game is unethical, even though this remains the standard practice. Increasingly, treating data in that manner could even land companies in legal trouble as codified privacy standards in the US and abroad.
