What Is First Party Data and Why Does It Matter in Digital Marketing?
The advertising industry spent two decades borrowing information about people from companies that had never met them. That has become steadily less reliable, though not for the reason most articles give. Meanwhile almost every business already holds more of its own than it uses.
The Four Kinds Of Data
The distinction is about where information came from and who holds the relationship. That decides how accurate it is, how durable it is and what you are allowed to do with it.
First party. Collected from your own customers, on your own properties.
A plumber's booking records: who called, what the job was, what it cost, whether they came back. Accurate, because it happened.
Second party. Somebody else's first party data, shared with you by arrangement.
A wedding venue sharing enquiry details with a photographer it recommends, with the couple's agreement. Reliable, though dependent on a relationship you do not control.
Third party. Bought from a broker who never met the customer.
A list of people supposedly in the market for a new kitchen, assembled from behaviour across many sites. Inferred rather than observed, the least accurate of the four.
Zero party. What somebody deliberately tells you.
A customer choosing which emails they want, else stating their budget in an enquiry form. The most accurate of all, because they chose to say it.
Why Borrowed Data Is Running Out
Most writing on this subject says third party cookies are being phased out of Chrome. That was announced, repeatedly delayed, then abandoned. Anybody still telling you a deadline is coming has not checked.
What actually happened. The phase out was cancelled.
In April 2025 Google confirmed it would not deprecate third party cookies in Chrome and would not introduce the planned choice prompt, keeping its existing settings instead. The UK Competition and Markets Authority subsequently moved to release the commitments it had put in place.
Why the direction is still real. Four things, none of them that one.
Other major browsers already restrict these identifiers by default, so a share of your audience was never trackable that way. Mobile platforms ask people whether they want to be followed between apps. Many decline. Regulation tightened. And people themselves block, delete and refuse more than they used to.
What that means practically. Gradual erosion rather than a cliff.
Borrowed data did not stop working on a date. It became progressively less complete and less reliable, which is harder to notice and produces the same outcome.
Why this matters to how you plan. No deadline to wait for.
Businesses postponed collecting their own data because an event was coming that would force it. The event was cancelled. The reason for doing it never depended on the event.
Where Your Own Data Already Exists
Nine places, most of which exist in any established business. The problem is almost never collection. It is that these sit in separate systems that do not speak to each other.
Website behaviour. What people looked at before enquiring.
Purchase history. Who bought what, when, for how much.
Enquiry forms. Including the free text, which is the richest part.
The email list. However neglected.
Customer records or the CRM. Frequently a spreadsheet.
Telephone records. Who called and what about.
Bookings and appointments. Timing and frequency patterns.
Loyalty or account schemes. Where they exist.
Surveys and reviews. Volunteered opinions, already public.
The actual problem. Three systems, no connection.
Bookings in one place, email in another, accounts in a third. Nobody can answer a simple question like which customers have not returned in two years, so nobody asks it.
Data People Give You Deliberately
Information somebody chose to tell you is more accurate than anything inferred about them. It also does not decay in the same way. It also requires them to see a reason for telling you.
Preference centres. Letting people choose what they hear about.
Somebody selecting two topics out of five has told you something no analysis could have worked out, while making your future messages more welcome.
Onboarding questions. Asked at the point of signing up or buying.
One or two questions, where the answer changes what you send them.
Stated interests and circumstances. Volunteered in a form.
Property type, timescale, budget range, what prompted the enquiry.
Why it is the least fragile. Nobody can restrict it.
It does not depend on a browser, a platform or a tracking method. Somebody told you directly. The record is yours.
The exchange that makes it work. Something in return.
People answer questions when the answer visibly benefits them: a better quotation, a more relevant reply, fewer irrelevant emails. Asking without offering a reason produces blanks and mild irritation.
Consent And Lawful Basis
This section is general information rather than legal advice. It reflects Information Commissioner's Office guidance checked in August 2026. The ICO has said some of its guidance is under review following the Data (Use and Access) Act 2025. Check the current position before relying on it.
What consent has to look like. Four qualities.
Freely given, specific, informed and unambiguous. No pre-ticked boxes, nothing bundled into terms and conditions, plus it must name you.
The soft opt-in. The exception most small businesses rely on.
Per the ICO, you may email your own previous customers about similar products or services where you collected their details in the course of a sale or negotiations for a sale, provided you gave them a clear chance to opt out both at that point and in every message since.
What the soft opt-in does not cover. Two things people assume it does.
Prospects who only enquired without buying. And anybody on a bought list, which it never covers.
Business contacts. Different rules.
The ICO position is that marketing email may be sent to companies without consent, while still identifying yourself and offering a way to opt out.
The right to object. Absolute.
If somebody objects you must stop, with no grounds to refuse. The soft opt-in does not override this. Keep a record of what was agreed and when, because the record is what you would rely on.
What You Can Actually Do With It
Owning data is worth nothing on its own. These are the six things a small business can do with it that produce money.
Segmentation. Treating different customers differently. A garage separating people whose service is due from people who bought a car last month.
Personalised email. Messages relevant to what somebody actually bought. A nursery emailing planting advice for the specific plants somebody purchased.
Suppression lists. The most immediately profitable. Excluding existing customers from advertising aimed at winning new ones, so you stop paying to reach people who already bought.
Audiences built from your own list. Uploading customer details to an advertising platform to reach similar people, else to exclude the ones you have.
Better measurement. Connecting an enquiry to the sale it became, which is what makes the arithmetic in return on marketing investment possible at all.
Reactivation. Contacting people who bought once and disappeared. A dentist writing to patients who have not attended in two years is the cheapest campaign available to them.
Quality And Hygiene
Data ages from the moment it is recorded. People move, change jobs, abandon email addresses and change names. A list left alone for three years is substantially fiction.
What decay looks like. Silent.
Nothing tells you an address has been abandoned. Messages appear to send. Nobody reads them.
Duplicates. The commonest fault by far.
The same customer appearing three times because they used two email addresses and their partner booked once. Each version holds part of the picture and none holds it all.
Deduplication. Merging those into one record.
Tedious, unglamorous and it improves everything downstream immediately.
A single customer view. The goal rather than a product.
One record per person, covering every interaction. Large organisations buy systems for this. A small business can achieve most of the benefit with one properly maintained list.
What a dirty list costs. More than wasted sends.
Poor delivery rates affect whether your messages reach anybody at all, so the neglected portion of a list actively damages the reachable portion.
Storage, Security And Retention
Customer data is personal data, which makes this a business responsibility rather than a technical detail. None of it requires a large budget.
Where it lives. Business accounts, not personal ones.
Customer information held in somebody's personal email or private spreadsheet leaves when they do.
Who can reach it. Only people who need it.
Shared logins make this impossible to answer, which is reason enough to stop using them.
How long you keep it. Decided, rather than forever.
Retention should be a choice with a reason attached. Keeping everything indefinitely because deleting feels wasteful is the default. It also increases what you would have to explain after a breach.
When somebody asks to be removed. Have a process.
Know who handles it, how it is done across every system and how it is recorded. Discovering this during a request is the wrong moment.
When a staff member leaves. The one nobody plans for.
Access revoked, plus any customer data on personal devices returned or deleted. Handled in advance, this is administration. Handled afterwards, it is a problem.
Building The Collection Habit
Businesses that hold useful data are rarely the ones that ran a project. They are the ones that collect a little at every interaction, consistently, over years.
Where the opportunities are. Points you already have.
The enquiry, the quotation, the sale, the completion, the follow up. Each is a moment where one additional question is natural rather than intrusive.
What makes people answer. A visible reason.
Asking how somebody heard about you works because it is obviously useful to you and costs them nothing. Asking their date of birth for no stated reason does not.
The rule that keeps it useful. Collect nothing you will not use.
Data collected without a use is not an asset. It is risk sitting on a server, waiting to be part of a breach nobody benefited from.
The test before adding a field. One question.
What decision will this change. If nothing, remove it. Shorter forms also produce more completions, so the discipline pays twice. What belongs in a customer profile is covered in defining your target audience.
What To Do First
Nothing here requires software or budget. The order matters, because each step makes the next possible.
One. Find out what you already hold. A list of lists.
Every system containing customer information, who controls it and roughly how many records. Most businesses are surprised, usually by how much and by where.
Two. Get the consent position straight. Before using anything.
For each list, how those people came to be on it and what they were told. Anything you cannot account for should not be marketed to until you can.
Three. Get it into one place. Or connect what exists.
One list that is complete beats three that are each partly right.
Four. Clean it. Duplicates merged, dead addresses removed.
Unglamorous, quick and it improves everything measurably.
Five. Then use it. Starting with suppression.
Excluding existing customers from acquisition advertising saves money in the first month, which funds the rest, per what is display advertising. What you hold is also part of an audit.
Common Mistakes
Each of these is either wasted effort or accumulated risk. Several are both.
Collecting fields nobody uses. Long forms gathering information no decision depends on. Fewer completions, more to protect, nothing gained.
No consent record. Holding a list nobody can account for. The list becomes unusable at the moment you most want to use it.
Buying lists. Poor accuracy, no relationship and no valid basis for marketing to them. It looks like a shortcut and produces complaints.
Letting the list decay unused. Keeping data carefully and never contacting anybody, so it quietly becomes worthless. Common in businesses that are cautious rather than careless.
Storing customer data in personal accounts. Records in an individual's inbox or private drive, which leave with them.
Treating it as an IT matter. The one that causes the rest. Customer data is a marketing asset and a business responsibility. Handing it entirely to whoever manages the computers means nobody is thinking about what it is for. The full series is on the digital marketing guide.