Privacy

Third-party data

Also called bought data.

Third-party data is information assembled by a broker that never had a relationship with the person. It is sold as lists or audiences.

How it is measured

Ask the seller for the source, the collection date, and the legal basis. Treat missing answers as a finding.

Check accuracy by sampling. Mail or validate 200 records and count the bad ones.

Worked example

A furniture retailer buys 50,000 "recent mover" addresses. A sample of 200 finds 31 invalid and 12 that opted out of marketing elsewhere.

Under CCPA the retailer must be able to say where the list came from. The broker's data-broker registration helps, but does not prove each person's permission.

How it differs

Third-party data comes through a broker. First-party data comes from you. The first excludes your relationship with the person; the second excludes purchase.

Common errors

Assuming legality because it was sold. Skipping provenance checks. Merging into customer records. Ignoring age. Paying for stale lists.

In practice

Ask for provenance before you pay. Test a sample. Prefer what you collect yourself.

See also

First-party data, Personal data, CCPA

Sources

Count this on a real site.

Watch my website