Privacy
Second-party data
Also called partner data.
Second-party data is another organization's first-party data that is shared with you under a contract. You did not collect it, and you are not buying it from a broker.
How it is measured
Look for a data-sharing agreement. It names the fields, the permitted purposes, the term, and limits such as no re-identification. The partner collected it under their own notice.
Confirm that the partner's notice allowed the sharing. If it did not, the arrangement has a gap no contract can fix.
Worked example
An airline shares anonymized route-interest counts with a hotel group. The hotel group uses them to plan offers for 20 cities.
The contract bans re-identification and requires deletion after 12 months. The hotel's analyst sets a calendar entry for month 11.
How it differs
Second-party data comes from a partner by agreement. First-party data comes from your own contact with people. The second excludes your own collection; the first excludes outside contracts.
Common errors
Assuming the partner's consent covers your use. Skipping the contract. Merging it into customer profiles. Keeping it past the term. Calling it first-party in your notice.
In practice
Read the agreement and tag every row with its source. Delete on schedule. Ask the partner for their notice text before you start.