Privacy
First-party data
Also called 1P data.
First-party data is information you collect yourself from your own sites, apps, stores, and customers. You hold the relationship and the notice that went with it.
How it is measured
Inventory it by source: checkout records, form submissions, support tickets, and on-site events. For each source, write down the fields, the date range, and the notice the person saw when it was collected.
Check quality by sampling 100 rows. Count how many have a source tag, a collection date, and a consent flag where one is needed. Rows that fail all three are risk, not an asset.
Worked example
A cheese shop has 6,200 customer records from checkout, 1,900 newsletter signups, and 40,000 site sessions. Only 2,500 of the checkout records carry a marketing consent flag.
The owner wants to email the full 6,200. Doing so would mean 3,700 sends with no recorded permission, so the first campaign goes to the 2,500 plus the newsletter list.
How it differs
First-party data comes from your own contact with people. Second-party data is a partner's first-party data shared under contract. The first excludes anything bought or borrowed; the second excludes anything you collected yourself.
Common errors
Assuming it needs no lawful basis. Mixing it with purchased lists until origin is unclear. Losing consent flags during an export. Keeping everything indefinitely. Treating a large table as clean without sampling it.
In practice
Map your sources and the notice shown at each. Add source and consent columns where missing. Delete the rows you cannot explain.