Ethical Marketing

Ethical Consumer Data Use: Collection, Profiling, Sharing and Retention

Learn how to collect, use, profile, share and retain consumer data responsibly while respecting purpose, fairness, transparency and customer control.

Ethical Consumer Data Use: Collection, Profiling, Sharing and Retention

Ethical consumer-data use begins before any information is collected, and continues until that information has been deleted, irreversibly anonymised, or transferred under a justified and controlled arrangement.

For marketing teams, the questions that matter are these:

  • Why is the information needed?
  • What did the customer understand when it was collected?
  • What has been observed or inferred since then?
  • Who can access it?
  • What decisions does it influence?
  • Can the customer correct, object or withdraw where applicable?
  • When will the information be deleted?
  • Would the proposed use remain defensible if it were explained clearly to the person affected?

This article provides a lifecycle framework for answering those questions. It does not replace a jurisdiction-specific legal assessment, a technical security design, or a full data-protection implementation programme.

What consumer-data ethics means

Consumer-data ethics is the structured assessment of whether collecting, analysing, sharing and acting on information about people is justified, fair and proportionate.

It considers legal requirements alongside:

  • reasonable customer expectations;
  • power imbalances;
  • the reliability of inferences;
  • the risk of exclusion or manipulation;
  • the availability of less intrusive alternatives;
  • practical customer control;
  • the effects on different groups;
  • accountability for downstream use.

The subject is broader than privacy notices and narrower than general corporate ethics. It concerns specific data, purposes, people, decisions and controls.

Ethics and compliance are not identical

Legal compliance is necessary. It does not automatically make a data use ethical.

A lawful basis answers whether processing can lawfully take place for a defined purpose. It does not prove that:

  • the purpose is commercially or socially worthwhile;
  • every available data field should be used;
  • the resulting inference is accurate;
  • the customer would reasonably expect the use;
  • the same goal could not be achieved less intrusively;
  • an activation decision is proportionate.

Consent has a similarly limited function. Valid consent can provide a lawful basis where its requirements are met, but it does not convert an excessive, misleading or harmful practice into an ethical one.

The current UK position is that the Data (Use and Access) Act 2025 amended the existing regime rather than replacing it. The UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations all remain in force in amended form. Most marketing-relevant provisions were commenced on 5 February 2026, and the remaining data-protection provisions were in force by 19 June 2026 (1)(2). Where this article describes a change introduced by that Act, it says so, because a good deal of guidance published before 2026 is now partially out of date. Several ICO pages cited here carry a notice that they are themselves under review for the same reason.

I would add one observation about how privacy regulation actually lands inside companies, because it is not what the compliance literature describes. When the GDPR arrived, the visible effect was not that anyone stopped marketing. The effect was that clients in government-linked, banking, insurance and health sectors quietly stopped activating anything complicated. The rules did not forbid those scenarios. The teams simply lost their appetite for defending them. Clients who had made a privacy mistake of their own became slower to take any vendor’s word for anything, and everything took longer. That is worth knowing when you build a data programme, because the practical constraint on what you can do is often organisational confidence rather than the text of the law.

For implementation-level compliance work, use the privacy-first compliance framework.

Define the purpose before collecting data

A purpose should identify the intended result, not merely the department or the technology involved.

Weak descriptions include:

  • “for marketing”;
  • “for personalisation”;
  • “for analytics”;
  • “to improve the experience”;
  • “for future business use”.

A useful purpose states:

  • the decision or activity being supported;
  • the people affected;
  • the data required;
  • the expected benefit;
  • the retention period;
  • the recipients;
  • whether the data will be used to infer new characteristics;
  • whether the result affects price, eligibility, ranking, communication or access.

For example:

Use the customer’s last six months of category-level purchase history to rank relevant replenishment reminders for that customer for ninety days.

That is reviewable. “Use first-party data for personalisation” is not.

The UK GDPR principles are lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability (3). A new use should therefore not be accepted merely because the organisation already holds the information.

Collect only what the purpose requires

Data minimisation requires personal information to be adequate, relevant and limited to what is necessary for the purpose (4).

The ethical review should ask:

  • Is each field necessary?
  • Is a less precise value sufficient?
  • Can the purpose be achieved with aggregated information?
  • Is the collection speculative?
  • Will the field be used immediately, or stored in case it becomes useful?
  • Does collection create sensitive inferences even where the source data looks ordinary?
  • Does the marginal benefit justify the additional intrusion and security exposure?

Collecting more information can improve a model’s apparent performance while making the whole system less defensible.

There is also a quality argument for collecting less, which I hold strongly enough that I should declare an interest in it. I now run a company built on purchase data alone, so treat what follows as an interested opinion rather than a neutral one. In ten years of looking at behavioural data, my conclusion was that footprints are so individual that inferring intent from them is mostly guesswork dressed up as insight. Two people with near-identical browsing patterns want different things, and the model cannot tell you which is which. Purchase data is narrower and duller and considerably more honest, because someone actually did the thing. A programme built on fewer, harder signals is usually easier to explain to a customer as well, which is not a coincidence.

First-party and zero-party data

“First-party” describes the organisation’s relationship to the source. It does not mean that any subsequent use is lawful, expected or ethical.

“Zero-party data” is a marketing label rather than a legal category. Information deliberately supplied by a customer may still be:

  • excessive for the stated purpose;
  • obtained through an unfair incentive;
  • reused unexpectedly;
  • combined with other data to create intrusive inferences;
  • retained for too long;
  • shared more widely than the customer understood.

Source proximity is relevant. It is not a substitute for purpose, necessity and fairness.

What declared data does offer is confidence, and that turns out to matter at every size of company. I worked with a global consumer-electronics manufacturer, one of the largest companies in the world, that would not commit to a targeted discount on a particular product group using the behavioural data it already held. We ran a short survey, collected the specific attributes the decision needed, and the brand was then willing to act. The lesson was not that surveys outperform models. It was that a company will take a commercial risk on information a customer knowingly gave it, and hesitate over information it merely inferred. That instinct is a reasonable proxy for the ethical question too.

Notice, transparency and comprehension

A privacy notice should make material processing understandable. Its mere availability does not prove comprehension.

The ICO describes the right to be informed as requiring clear and concise information about what an organisation does with personal information, and warns that supplying the minimum information specified in Articles 13 and 14 will not always be enough to satisfy the wider transparency principle (5).

Effective transparency is layered:

  1. At the point of collection: explain the immediate purpose and the material consequences.
  2. Before enrichment or activation: explain unexpected changes or new recipients.
  3. In a full notice: provide the required detail, retention, rights and contact information.
  4. Inside the product: provide accessible controls and explanations when a use is activated.
  5. When practices change: notify affected people before a material new use begins, where required and appropriate.

Comprehension testing should measure what people understand, not whether they clicked a box.

Useful tests include:

  • asking participants to explain the purpose in their own words;
  • checking whether they can identify the recipients;
  • testing whether they understand that profiles or inferences will be created;
  • checking whether the consequences of refusal are understood;
  • comparing the prominence of the acceptance and rejection routes.

That last point has become a regulatory question in its own right where access to a service is conditioned on accepting advertising. The ICO’s position on consent or pay models is not that they are lawful or unlawful as a class, but that they can operate lawfully only where the non-paying user’s consent is genuinely freely given, assessed against factors including power imbalance, whether the fee is appropriate rather than coercive, equivalence of the two services, neutrality of the information given, and whether refusal is as easy as acceptance (6).

Organisations must identify an appropriate lawful basis for each purpose. No single lawful basis is inherently better than the others, and suitability depends on the purpose and the relationship (7).

The bases are consent, contract, legal obligation, vital interests, public task, legitimate interests, and the recognised legitimate interests added by the Data (Use and Access) Act 2025.

That last one needs a warning, because the name invites misuse. Recognised legitimate interest is narrow, covering five pre-approved public-interest situations, and direct marketing is not one of them (8). Marketing may still rely on ordinary legitimate interests under Article 6(1)(f), which requires the purpose, necessity and balancing tests to be done properly and cannot be used where PECR requires consent (9)(10).

Consent must be specific enough to distinguish materially different purposes.

Consent to:

  • create an account is not consent to receive marketing;
  • receive one brand’s offers is not consent to disclosure to unrelated advertisers;
  • use location for fraud prevention is not consent to behavioural advertising;
  • store purchase history is not consent to infer health conditions;
  • receive email offers is not consent to automated marketing calls.

Valid consent requires genuine choice and control. People must be able to refuse without detriment and to withdraw easily (11).

Consent should not be used to transfer ethical responsibility to the customer. The organisation remains responsible for purpose, minimisation, fairness, accuracy, security and downstream effects.

The applicable rule depends on the channel, the recipient, the relationship and the jurisdiction.

Under the UK framework, consent is required for some forms of electronic marketing under PECR. The soft opt-in may apply to certain electronic mail marketing where all five conditions are met: the sender obtained the contact details directly from the recipient; the details were obtained during a sale or genuine negotiations for a sale; the marketing concerns only that sender’s own similar products or services; the recipient was given a simple opportunity to refuse when the details were collected; and every subsequent message gives a simple opportunity to refuse (12).

A separate charitable-purposes soft opt-in applies from 5 February 2026, and only to contact details collected on or after that date, so it does not reach back into an existing supporter database (12).

Postal marketing does not generally require consent, although a lawful basis is still needed where personal information is used. People have an absolute right to object to processing for direct marketing purposes, and once a valid objection is received the organisation must stop (10).

One structural point that has not changed: legitimate interests cannot be used to sidestep a PECR consent requirement (10).

Tracking technologies and the analytics exception

Storage and access technologies now sit under a revised PECR framework with five purpose-specific exceptions, one of which covers statistical or analytics purposes (13).

The ethical point is that the analytics exception is far narrower than the enthusiasm around it suggests. It can apply where the sole purpose is producing aggregate statistical information about how the organisation’s own service is used, and not where the output identifies, tracks, profiles or supports decisions about individuals (13). The exception does not cover behavioural advertising, cross-site profiling, ad measurement or conversion sharing with advertising partners, all of which still require consent (13). Enforcement also changed: the maximum PECR penalty is now £17.5 million or four per cent of worldwide annual turnover, whichever is higher (14).

For implementation requirements across cookies, direct marketing and privacy governance, use the privacy-first compliance framework.

Declared, observed and inferred data

Data governance should distinguish how information came into being. The distinction between data actively provided by a person, data observed from their behaviour, and data inferred or derived from either is also how European regulators analyse targeting, which is useful as a taxonomy even though that guidance is not UK law (15).

Declared data

Information supplied directly by the person, such as age range, preferences, stated interests, survey responses, household information or accessibility needs.

Declared data may be inaccurate, outdated, prompted by an incentive, or supplied for a narrow purpose.

Observed data

Information recorded from behaviour, such as purchases, clicks, searches, location events, message opens, device use and customer-service interactions.

Observation can be intrusive even when nobody was asked a question.

Inferred data

Characteristics predicted or assigned from declared or observed information, such as likely income, price sensitivity, health interest, family status, political inclination, vulnerability, likelihood to cancel, or susceptibility to a particular offer.

The published lists understate what this actually looks like in practice. What would surprise an ordinary shopper is not that a brand records what they bought. It is what the brand derives from it: the date their salary lands, how many people they are shopping for, and which circumstances reliably trigger a purchase. None of that is ever declared. All of it comes out of receipts, and none of it requires anything more exotic than a transaction history and a calendar.

So the question I would put before approving an inference is not whether the customer agreed to the collection. It is whether the customer would recognise the conclusion.

An inference is not neutral merely because it was produced statistically. It can be personal data, it can be wrong, and it can reveal or approximate a protected characteristic.

The review should record:

  • the inference definition;
  • the input fields;
  • the validation population;
  • confidence and error rates;
  • known disparities between groups;
  • permitted use cases;
  • prohibited uses;
  • the correction or challenge process;
  • an expiry date.

Data enrichment and brokerage

Enrichment adds information from another source to an existing customer record. Sources may include data brokers, public registers, platforms, partners, identity services and model-generated attributes.

The ethical question is not whether the source will sell the data. It is whether the acquiring organisation can justify receiving and using it.

Organisations using data-broker services must conduct appropriate due diligence, and accepting a broker’s assurances is not enough (16). ICO guidance on collecting information and generating leads addresses buying, renting and licensing marketing lists, buying additive information to append to existing records, and profiling people using third-party or publicly available information. It expects the purchaser to establish its own lawful basis, to investigate where the information originated, how it was collected, what people were told, how old it is, and whether any claimed consent actually covers the purchaser’s intended use, and to check whether the seller screened against suppression lists (17). The statutory data sharing code treats the transfer of a database or list for money or other consideration as data sharing, and expects the recipient to verify the source, the seller’s lawful basis, what people were told, and whether all the transferred fields are necessary (18).

Due diligence should establish:

  • who originally collected the information;
  • the collection context;
  • what people were told;
  • whether the intended recipient or category of recipient was identified;
  • the lawful basis;
  • age and accuracy;
  • consent evidence where consent is claimed;
  • opt-out handling;
  • geographic scope;
  • onward-sharing history;
  • whether sensitive data or proxies are present.

This is not a theoretical risk. The ICO investigated the offline direct-marketing operations of three credit reference agencies and found significant transparency, fairness and lawful-basis concerns across activities including licensing, matching, cleansing, segmentation, profiling, enrichment and screening. Two of the companies withdrew the products identified as non-compliant and were not served with a final enforcement notice. The third did not accept all the required changes and was served with one (19). That notice was appealed, and a tribunal allowed the appeal in part and substituted a narrower notice requiring the company to provide Article 14 privacy information to people whose data came from specified public sources (20). The regulator’s own appeal against that outcome was dismissed, so the narrower notice is the operative result (21). No monetary penalty was imposed at any stage.

Two things follow for a marketing team. The regulator does scrutinise this market. And the boundaries are contested enough that “our supplier says it is fine” is not a position anyone should be comfortable defending.

Opaque provenance is a stop condition, not a documentation inconvenience.

Profiling, segmentation and automated decisions

Profiling uses personal information to evaluate or predict aspects of a person. Marketing segmentation may be technically simple and still affect what a person sees, pays, receives or can access.

A profiling review should consider:

  • purpose and necessity;
  • input relevance;
  • accuracy and update frequency;
  • the consequences of false positives and false negatives;
  • disparity between groups;
  • proxy variables;
  • explainability;
  • customer expectations;
  • objection and correction;
  • human review where decisions are significant;
  • whether the profile is used to exploit rather than assist.

Most published discussion of profiling ethics assumes the data underneath is broadly correct. In my experience that is the assumption most likely to be wrong, and the failures are boring rather than sinister. One of the largest cosmetics groups I worked with had never reconciled identity between its physical estate and its several websites. A purchase through a new channel created a new user record. Category tracking had degraded to the point that the field describing a customer’s most purchased category was arriving with category names that meant nothing to anyone. They eventually paid a CRM provider a great deal of money to sort it out. Nobody in that organisation intended any harm. They were making decisions about real people from a record that was simply wrong, and the personalisation sitting on top of it looked entirely convincing from the outside.

A high predictive score does not prove that activation is fair. A model may accurately identify customers under financial pressure while the proposed campaign uses that insight to intensify urgency.

Automated decisions and human review

The automated decision-making rules changed with the Data (Use and Access) Act 2025. Article 22 was replaced by Articles 22A to 22D, and the previous general restriction on significant solely automated decisions using ordinary personal data was relaxed, subject to lawful basis, transparency and safeguard requirements. Tighter restrictions remain where special category data is involved, and recognised legitimate interest cannot be the lawful basis for significant solely automated decision-making (22).

A right to human intervention arises where all three elements are present: a system makes a decision about the person, the decision produces a legal or similarly significant effect, and it is based solely on automated processing with no meaningful human involvement before the outcome was applied. The safeguards also include information about the decision, an opportunity to make representations, and a right to contest it. Human intervention has to be meaningful reconsideration by somebody with authority to change the outcome (22).

Two cautions. This does not mean every personalised advertisement or recommendation triggers a right to human review, because the significant-effects threshold has to be met. Nor does a token sign-off remove a decision from the regime. And the detailed ICO guidance on all of this remains in draft: it was updated on 31 March 2026, consultation closed on 29 May 2026, and final guidance had not been issued at the time of writing (22).

For the offer, price, channel and message consequences of a profile, apply an ethical review across Product, Price, Place and Promotion.

Sensitive and special-category data

Special category data includes information revealing or concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetics, biometrics used for identification, health, sex life and sexual orientation.

Processing requires an Article 6 lawful basis and, separately, an Article 9 condition, with an additional Data Protection Act 2018 Schedule 1 condition where required. The two do not have to correspond, and an Article 9 condition is not a substitute for a lawful basis (23). An ordinary legitimate-interests assessment is not sufficient on its own.

Marketing teams must also consider inferred special category data. An inference becomes special category data where the processing is intended to infer a characteristic falling within Article 9, or where the organisation intentionally treats a person differently because of such an inference. Confidence that the inference is correct is not the deciding factor (24). Profiling designed to infer ethnicity, religion, political views, health status or sexual orientation therefore involves special category data, whatever the segment is called internally.

The converse also holds. Merely holding a name, a photograph or a product preference from which somebody might conceivably guess a characteristic does not turn every use of that field into special category processing (24).

Sensitivity also extends beyond the statutory categories. Precise location, financial distress, indicators of domestic abuse, immigration circumstances and children’s behaviour can all create serious harm even where the legal classification differs. Location data is the clearest example of a category whose sensitivity comes from what it reveals rather than what it is called, and it has attracted enforcement attention on that basis in other jurisdictions (25).

The default question should be whether the marketing purpose is important enough to justify using the information at all.

Vulnerability and power imbalance

A customer may be vulnerable permanently, temporarily, or only in relation to a particular decision.

Relevant circumstances may include financial distress, illness, disability, bereavement, addiction, low literacy, limited digital access, urgency created by personal circumstances, dependence on an essential service, or an inability to understand a complex inference or automated process.

Data can help identify support needs. The same data can be used to increase pressure, reduce choice or charge a higher price.

A defensible activation should distinguish:

  • using vulnerability information to provide assistance;
  • excluding a person from a harmful or unsuitable offer;
  • using vulnerability to predict willingness to pay;
  • targeting a person when their capacity to evaluate the offer may be reduced.

The first two may be protective. The last two require strong challenge and may warrant prohibition.

Sharing, processors and third parties

The organisation must identify whether each party is a controller, joint controller or processor. Controllers determine the purposes and means of processing. Processors act on a controller’s documented instructions, although processors also carry direct legal responsibilities of their own (26). A vendor does not become a processor because a contract uses that word.

Before sharing, document:

  • the purpose;
  • the legal role of each party;
  • the data fields;
  • the lawful basis;
  • any special-category condition;
  • security controls;
  • permitted use;
  • sub-processors;
  • international transfers;
  • retention;
  • return or deletion;
  • audit and incident obligations;
  • handling of rights and objections.

Article 28 contracts must, among other requirements, limit a processor to documented instructions and deal with deletion or return at the end of the service (27).

International transfers were reworded rather than removed by the Data (Use and Access) Act. The standard is now whether protection in the destination is not materially lower than under UK law (28), and the approved standard clauses remain the UK International Data Transfer Agreement and the UK Addendum, since the EU clauses are not sufficient alone for a UK transfer (29). The mechanics belong in a compliance programme. The ethical question is narrower: whether the customer would recognise where their information ends up, and whether anyone checked before it went.

Where independent controllers receive data for their own purposes, each party needs its own justification. A data-sharing agreement helps define roles. It does not make the sharing lawful or ethical.

Direct marketing and customer expectations

Marketing teams should distinguish service communications from direct marketing.

A service communication is necessary to administer or deliver a requested service: a transaction receipt, a security alert, notice of a material service interruption, a required contractual notice.

A message does not become a service communication because it was sent to an existing customer. Cross-selling, promotional content and encouragement to buy remain marketing even when wrapped in an operational template.

Customer expectations should be assessed using:

  • the original collection context;
  • the relationship;
  • time elapsed;
  • the channel;
  • product sensitivity;
  • frequency;
  • profiling depth;
  • the source of the data;
  • whether the message introduces another organisation;
  • whether the person can object easily.

People have the right to object at any time to processing for direct marketing, including related profiling, and once a valid objection is received the organisation must stop that processing (30).

Access, correction, objection and withdrawal

Customer control has to work operationally, not merely appear in a notice.

Access

People may have the right to receive their personal information and related processing information, and the organisation should carry out a reasonable and proportionate search rather than forcing the requester to narrow a valid request (31). The ethical test is comprehension: a response that discloses a profile as a list of internal codes has complied and explained nothing.

Correction

Inaccurate data should be corrected without undue delay. This includes deciding whether a disputed inference should be corrected, marked as contested, suspended or deleted.

Objection

Direct-marketing objections are absolute. Other objections may require a context-specific assessment.

Withdrawal

Where processing depends on consent, withdrawal must be as easy as giving consent. Withdrawal does not retrospectively invalidate lawful processing already completed, but it should stop the consent-dependent use going forward.

Complaints

Since 19 June 2026 organisations have had an express duty to provide a route for data-protection complaints, acknowledge within thirty days, investigate without undue delay and communicate the outcome (32). Thirty days is the acknowledgment deadline rather than the deadline for an answer. There are no departmental exemptions, so a complaint reaching a marketing inbox carries the same duty as one reaching a privacy team, which is worth telling the people who staff that inbox.

Retention and deletion

There is no universal statutory retention period. Organisations cannot keep personal data for longer than they need it for their specified purposes (33).

A retention schedule should cover all categories of personal information, reflect both business need and applicable legal requirements, state a period for each category, document the reason for that period, state the action at the end of it, identify who is responsible for implementation, and be reviewed and version-controlled (34).

“In case it becomes useful” is not a retention purpose.

Deletion design must reach:

  • production systems;
  • campaign platforms;
  • analytics environments;
  • customer-service tools;
  • exports;
  • vendor systems;
  • model-training datasets where applicable;
  • derived profiles;
  • backups, with documented restoration controls.

The right to erasure is not absolute. It applies in specified circumstances, including where the data is no longer necessary, where consent has been withdrawn and no other basis applies, or where the person objects to direct marketing (35).

That last case creates an apparent contradiction worth handling deliberately. Deleting every trace of somebody who objected to marketing is how they get added to the next campaign. The expected approach is to keep the minimum information necessary on a suppression list so the person is not reintroduced through a later campaign or a purchased list, processed for the purpose of honouring the objection and nothing else (36). A suppression record should not carry the person’s marketing profile, behavioural history or enrichment attributes, and should not be used for analytics, targeting or reactivation.

Retention schedules also need review triggers rather than only end dates, particularly for anything derived. A segment that described a customer accurately eighteen months ago may describe nobody now. I learned this from conversion testing rather than from privacy work: everyone in personalisation assumes that something which performed better once will keep performing better, and it is not true, because the audience keeps changing underneath the result. The practical fix was to keep a small control group running, or to re-run the test roughly every six months. Inferences deserve the same treatment. Give each one an expiry date and a revalidation trigger, and treat a stale profile as a data-quality defect rather than an asset.

Anonymised and pseudonymised data

Pseudonymisation replaces or separates direct identifiers. It does not necessarily take data outside data-protection law, because the additional information may permit re-identification.

Effective anonymisation requires the risk of identification to be sufficiently remote in the relevant context, and identifiability extends well beyond names, arising from combinations of information (37).

Therefore:

  • pseudonymised data remains controlled as personal data;
  • anonymisation requires a documented identifiability-risk assessment;
  • contractual restrictions can support anonymisation but do not correct weak technical protection;
  • re-identification risk must be reassessed as datasets and external information change.

Security and internal access

Security is part of ethical data stewardship, and this article does not attempt to cover it in depth.

The relevant obligations sit in the integrity and confidentiality principle and in Article 32, and they apply to controllers and processors alike. The measures required depend on the nature, scope, context and purpose of processing and on the likelihood and severity of the risk, which is why no universal technical checklist exists (38). The ICO’s outcomes framework, developed with the National Cyber Security Centre, frames this around four aims: managing security risk, protecting personal data against attack, detecting security events, and minimising their impact (39).

At minimum, marketing teams should establish role-based access, least privilege, authentication controls, logging and monitoring, segregation of high-risk data, secure transfer, incident processes, vendor assurance, deletion controls, staff training and periodic access review.

A lawful and ethically justified purpose can still become unacceptable if the organisation cannot protect the information adequately.

For implementation detail, use the guides to data security in marketing and secure personalisation under GDPR.

Children and vulnerable consumers

Children merit particular protection, because they may not understand commercial profiling, long-term consequences or complex consent choices.

The Children’s Code is a statutory code of practice prepared under section 123 and issued under section 125 of the Data Protection Act 2018. It came into force on 2 September 2020 and has applied fully since 2 September 2021, and the ICO and the courts must take relevant provisions into account (40). It expects privacy information to be concise, prominent and expressed in language suited to the child’s age, with contextual explanations at the point a use is activated (41).

The Code remains current. The ICO has said that from 2026 it will update its guidance and consider the implications of the Data (Use and Access) Act for the Code, which is a review rather than a suspension (42).

An ethical review should consider:

  • whether collection is necessary at all;
  • age-appropriate language;
  • parental involvement where applicable;
  • profiling defaults;
  • behavioural advertising;
  • persuasive design;
  • location;
  • sharing;
  • retention into adulthood;
  • the child’s ability to access, correct and delete information.

Meeting an age threshold does not remove the need to think about developmental capacity and likely understanding.

Ethical-review process

A proportionate review can follow ten steps:

  1. Define the purpose.
  2. List the required data.
  3. Classify data as declared, observed, inferred, sensitive or special category.
  4. Identify the lawful basis and any additional condition.
  5. Assess customer expectations and likely understanding.
  6. Map enrichment, sharing and processors.
  7. Evaluate profiling accuracy and group effects.
  8. Specify controls, rights, retention and deletion.
  9. Consider a less intrusive alternative.
  10. Approve, revise, escalate or stop.

A data-protection impact assessment may be legally required. The test is whether the processing is likely to result in high risk to people’s rights and freedoms, and the screening question is whether features indicating potential high risk are present, not whether harm has already been demonstrated (43). Several entries on the ICO’s high-risk list sit squarely inside ordinary marketing work: large-scale profiling, data matching that combines personal data from multiple sources with direct marketing given as an express example, invisible processing including list brokering and online advertising, tracking including cross-device and behavioural tracking and loyalty schemes, and using the data of children or other vulnerable people for marketing, profiling or automated decision-making (44).

That does not mean every marketing profile needs a DPIA. It does mean that large-scale profiling, enrichment from broker-sourced data, and anything touching children or vulnerable people should be assumed to need one until somebody has checked properly.

An ethical review can be incorporated into the DPIA, provided that doing so does not quietly reduce the exercise to legal compliance alone.

AI-specific systems should also be reviewed through the AI ethics framework. Privacy-preserving personalisation implementation belongs in the guide to privacy-safe personalisation.

Consumer-data lifecycle table

StageEthical questionRequired evidenceCustomer controlWarning sign
CollectionIs the information necessary?Purpose and minimisation reviewChoice where appropriateSpeculative collection
EnrichmentDoes added data change customer expectations?Source, notice, accuracy and due-diligence reviewNotice and objectionOpaque broker data
ProfilingIs the inference fair and reliable?Validation, error and disparity testingExplanation, correction and challengeSensitive proxy
ActivationIs the decision proportionate?Use-case and customer-outcome assessmentOpt-out or reasonable alternativeExploitative pressure
SharingCan each recipient justify its role and purpose?Role map, contract and transfer assessmentNotice and relevant rightsUncontrolled onward use
RetentionIs continued storage necessary?Retention schedule and system inventoryErasure where applicableIndefinite storage
DeletionHas information been removed from relevant systems?Deletion logs and vendor confirmationRequest trackingProfiles survive source deletion

Consumer-data decision register

For every material use, record:

FieldRequired entry
Use-case IDStable reference
Business ownerPerson accountable for the outcome
PurposeSpecific decision or activity
People affectedCustomers, prospects, children or other groups
Data inputsDeclared, observed, inferred and enriched data
Data sourceDirect, partner, broker, public or generated
Lawful basisBasis for each purpose
Additional conditionSpecial-category or other statutory condition
Expected customer understandingWhat people are likely to expect
Profiling or automationLogic, significance and consequences
RecipientsControllers, processors and sub-processors
RisksPrivacy, exclusion, manipulation, accuracy and security
ControlsMinimisation, testing, access, objection and alternatives
RetentionTrigger and deletion method
DecisionApprove, revise, escalate or stop
Review triggerDate, complaint level, model change or new recipient

Data-use checklist

Do not approve the use until the team can answer yes to the relevant questions:

  • Is the purpose specific and current?
  • Is every data field necessary?
  • Is the source known?
  • Is the lawful basis appropriate, and is it the right one rather than the convenient one?
  • Are consent and non-consent purposes separated?
  • Would the use be understandable at the point of collection?
  • Are inferred attributes identified and dated?
  • Have sensitive proxies been tested?
  • Has broker or partner provenance been verified independently?
  • Are controller and processor roles accurate?
  • Can customers access and correct the relevant information?
  • Can direct-marketing objections be applied across every system?
  • Is withdrawal as easy as consent where consent is used?
  • Is the retention period tied to the purpose?
  • Can derived profiles be deleted or refreshed?
  • Are children and vulnerable people protected?
  • Has a DPIA been considered against the high-risk criteria?
  • Is a less intrusive method reasonably available?
  • Is an accountable owner able to stop the use?

Frequently Asked Questions

Does all marketing require consent?

No. The requirement depends on the channel, recipient, relationship and jurisdiction. Some electronic marketing requires consent under PECR, while other activity may rely on another lawful basis where its conditions are satisfied. Note that direct marketing is not one of the recognised legitimate interests introduced by the Data (Use and Access) Act 2025, so ordinary legitimate interests still require the full purpose, necessity and balancing assessment.

Is first-party data automatically ethical?

No. First-party data may still be excessive for the purpose, unexpected in its use, inaccurate, insecurely held, or applied to a purpose incompatible with the one it was collected for. Where the data came from tells you about provenance, not about justification.

Is zero-party data more ethical than inferred data?

Not automatically, although it usually starts from a better position. Deliberately supplied information improves transparency, but the request, the incentive offered, later reuse, combination with other sources, retention and downstream consequences all still require review.

Does consent make later processing ethical?

No. Consent applies to specified purposes and can be invalid where the choice is not genuine. It does not remove the requirements of fairness, minimisation, accuracy, security and accountability, and it should not be used to move ethical responsibility onto the customer.

Is pseudonymised data anonymous?

No. Pseudonymised data remains personal data where it can be attributed to a person using separately held information. Effective anonymisation is a higher bar and requires the risk of identification to be sufficiently remote in context.

Can marketers use inferred sensitive information?

Only after determining whether the inference amounts to special category data or otherwise creates high sensitivity, identifying both an Article 6 lawful basis and a separate Article 9 condition, and assessing necessity and fairness. An inference intended to identify a characteristic such as health, ethnicity or political opinion is special category data regardless of what the segment is called internally. Many ordinary marketing purposes will not justify the risk.

Who owns consumer-data ethics?

The business owner of the use case should be accountable for its outcome. Privacy, legal, information-security, analytics and customer-experience specialists provide review and challenge. Responsibility should not be handed wholesale to a data-protection officer or to a vendor.

Conclusion

Ethical consumer-data use depends on discipline across the whole lifecycle rather than judgement at a single moment.

Define a purpose before collection. Minimise the inputs. Distinguish what the customer told you from what you inferred. Verify where enriched data came from, independently. Test the profiles and date them. Control the sharing. Honour objections across every system. Tie retention to the purpose, and design deletion in from the start.

Lawful processing is the floor, and the floor moved recently. A defensible decision also needs reasonable customer expectations, proportionate effects, evidence you would be willing to show the person it describes, and an accountable owner with the authority to stop a use that should not proceed.

References

  1. Information Commissioner’s Office, The Data Use and Access Act 2025 (DUAA): what does it mean for organisations?, regulatory guidance, published 19 June 2025, materially updated 19 June 2026. https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/
  2. Secretary of State, The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, statutory instrument, SI 2026/82 (C.10), made 29 January 2026. Commenced the majority of the marketing-relevant provisions on 5 February 2026. https://www.legislation.gov.uk/uksi/2026/82/made
  3. Information Commissioner’s Office, A guide to the data protection principles, regulatory guidance, updated 23 March 2026. The page states that the guidance is under review following the Data (Use and Access) Act 2025 and may change. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/
  4. Information Commissioner’s Office, Principle (c): Data minimisation, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/data-minimisation/
  5. Information Commissioner’s Office, Right to be informed, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-be-informed/
  6. Information Commissioner’s Office, Consent or pay, regulatory guidance, published 23 January 2025. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/online-tracking/consent-or-pay/
  7. Information Commissioner’s Office, A guide to lawful basis, regulatory guidance, updated 2 April 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/
  8. Information Commissioner’s Office, Recognised legitimate interest, regulatory guidance, published 23 March 2026. Direct marketing is not a recognised legitimate interest. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/recognised-legitimate-interest/
  9. Information Commissioner’s Office, Legitimate interests, regulatory guidance, updated 23 March 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/legitimate-interests/
  10. Information Commissioner’s Office, When can we rely on legitimate interests?, regulatory guidance, no page-specific update date displayed. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/legitimate-interests/when-can-we-rely-on-legitimate-interests/
  11. Information Commissioner’s Office, What is valid consent?, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/consent/what-is-valid-consent/
  12. Information Commissioner’s Office, Guidance on direct marketing using electronic mail, regulatory guidance, updated 28 April 2026 to incorporate the charitable-purposes soft opt-in. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-direct-marketing-using-electronic-mail/
  13. Information Commissioner’s Office, Guidance on the use of storage and access technologies, regulatory guidance, first published 20 December 2024, finalised 29 April 2026. Replaces the previous detailed cookies guidance. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/
  14. Information Commissioner’s Office, Statement on the commencement of the Data (Use and Access) Act (DUAA), official regulator statement, published 5 February 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/statement-on-the-commencement-of-the-data-use-and-access-act-duaa/
  15. European Data Protection Board, Guidelines 8/2020 on the targeting of social media users, version 2.0 adopted 13 April 2021. See paragraphs 40, 67, 79 to 80 and 83 on provided, observed and inferred data. EEA guidance under the EU GDPR framework; not UK law and not binding on the ICO or UK courts. https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en
  16. Information Commissioner’s Office, Organisations using marketing services of data brokers: what you need to know, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/organisations-using-marketing-services-of-data-brokers/
  17. Information Commissioner’s Office, Direct marketing guidance: Collect information and generate leads, regulatory guidance, published 5 December 2022, updated 28 April 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/collect-information-and-generate-leads/
  18. Information Commissioner’s Office, Data sharing: a code of practice, statutory code of practice under section 121 of the Data Protection Act 2018, laid before Parliament 18 May 2021, in force 5 October 2021. See the section on sharing personal data in databases and lists. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/sharing-personal-data-in-databases-and-lists/
  19. Information Commissioner’s Office, Investigation into data protection compliance in the direct marketing data broking sector, regulatory investigation report, published October 2020. Predates the Data (Use and Access) Act 2025. https://ico.org.uk/media2/migrated/2618470/investigation-into-data-protection-compliance-in-the-direct-marketing-data-broking-sector.pdf
  20. First-tier Tribunal (General Regulatory Chamber, Information Rights), appeal against an Information Commissioner enforcement notice concerning direct marketing data broking, decision of 20 February 2023, refs. EA/2020/0317 and [2023] UKFTT 00132 (GRC). The appeal was allowed in part and a narrower enforcement notice substituted. https://informationrights.decisions.tribunals.gov.uk/DBFiles/Decision/i3176/Experian%20Limited%20EA-2020-0317%20FP%20%2817.02.23%29.pdf
  21. Upper Tribunal (Administrative Appeals Chamber), appeal by the Information Commissioner in the same proceedings, decision of 22 April 2024, refs. UA-2023-000512-GIA and [2024] UKUT 105 (AAC). The Commissioner’s appeal was dismissed and the substituted notice stood. https://assets.publishing.service.gov.uk/media/662fa61624347c67e8e3cba0/UA_2023_000512_GIA.pdf
  22. Information Commissioner’s Office, Automated decision-making, including profiling, draft regulatory guidance, updated 31 March 2026. Consultation closed 29 May 2026 and final post-consultation guidance had not been issued at the time of writing. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/
  23. Information Commissioner’s Office, Special category data, regulatory guidance, last updated 28 October 2024. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/special-category-data/
  24. Information Commissioner’s Office, What is special category data?, detailed regulatory guidance, last updated 9 April 2024. Under review following the Data (Use and Access) Act 2025. The older Article 22 discussion on this page should not be read as the current post-DUAA position. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/
  25. Federal Trade Commission, FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data, enforcement announcement, published 9 January 2024, final order 11 April 2024, matter no. 2123038. United States enforcement material; not UK law. https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
  26. Information Commissioner’s Office, Controllers and processors, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/controllers-and-processors/controllers-and-processors/
  27. Information Commissioner’s Office, What needs to be included in the contract?, regulatory guidance on Article 28 controller and processor contracts, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/
  28. Information Commissioner’s Office, A brief guide to international transfers, regulatory guidance, published 15 January 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-brief-guide-to-international-transfers/
  29. Information Commissioner’s Office, What are standard data protection clauses (the UK IDTA and the Addendum)?, regulatory guidance, no page-specific update date displayed. IDTA A.1.0 and Addendum B.1.0 were laid before Parliament on 2 February 2022. The ICO plans to update both during 2026 and says organisations should continue using the current versions meanwhile. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/
  30. Information Commissioner’s Office, Plan direct marketing, regulatory guidance, no page-specific update date displayed. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/plan-direct-marketing/
  31. Information Commissioner’s Office, A guide to subject access, regulatory guidance, updated 16 July 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/
  32. Information Commissioner’s Office, How to deal with data protection complaints, regulatory guidance, published 12 February 2026, updated 8 May 2026. The complaints duty was commenced on 19 June 2026. https://ico.org.uk/for-organisations/how-to-deal-with-data-protection-complaints/
  33. Information Commissioner’s Office, Principle (e): Storage limitation, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/
  34. Information Commissioner’s Office, Retention, Data Protection Audit Framework records management toolkit, no publication or update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/records-management/retention/
  35. Information Commissioner’s Office, Right to erasure, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-erasure/
  36. Information Commissioner’s Office, Direct marketing guidance: Respect people’s preferences, regulatory guidance, published 5 December 2022, updated 28 April 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/respect-peoples-preferences/
  37. Information Commissioner’s Office, How do we ensure anonymisation is effective?, regulatory guidance, no page-specific update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/anonymisation/how-do-we-ensure-anonymisation-is-effective/
  38. Information Commissioner’s Office, A guide to data security, regulatory guidance, latest recorded update 19 May 2023. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/
  39. Information Commissioner’s Office, developed with the National Cyber Security Centre, Security outcomes, regulatory security guidance, no publication or update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/security-outcomes/
  40. Information Commissioner’s Office, Age appropriate design: a code of practice for online services, statutory code of practice prepared under section 123 and issued under section 125 of the Data Protection Act 2018, laid before Parliament 11 June 2020, in force 2 September 2020, full application from 2 September 2021. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/
  41. Information Commissioner’s Office, 4. Transparency, Children’s Code standard, no page-specific update date displayed. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/4-transparency/
  42. Information Commissioner’s Office, Children’s Code Strategy progress update, December 2025, regulator progress update, published 1 December 2025. States that from 2026 the ICO will update its guidance and consider the implications of the Data (Use and Access) Act for the Code. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/protecting-childrens-privacy-online-our-childrens-code-strategy/children-s-code-strategy-progress-update-december-2025/
  43. Information Commissioner’s Office, When do we need to do a DPIA?, regulatory guidance, no publication or update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/
  44. Information Commissioner’s Office, Examples of processing ‘likely to result in high risk’, Article 35(4) list and accompanying guidance, no publication or update date displayed. Under review following the Data (Use and Access) Act 2025. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/examples-of-processing-likely-to-result-in-high-risk/

Position stated as at 28 July 2026. Regulatory guidance changes, and several of the sources above are marked by their publishers as under review. Check the linked sources before relying on any statement of the current legal position.

◍ herm · cite this

Use this guide as a source

If it settled an argument in your reporting, cite it — and add Herm as a preferred source so the next answer you get from search or a model comes from work with its definitions attached.

└ Erul, İ. (2026) Ethical Consumer Data Use: Collection, Profiling, Sharing and Retention. Herm. www.herm.io/blog/respecting-privacy-ethical-use-of-consumer-data-in-marketing/
İlkem Erul
Written by

İlkem Erul

Contributor

I have over nine years of experience in digital marketing, account management, and B2C loyalty. I've helped global brands grow, and now, as a co-founder of Herm.io, I work on smarter, safer shopping experiences for consumers.

More from İlkem →

Related reading

All in this category →

More in Ethical Marketing Practices

01 AI Ethics in Marketing: Governance, Bias and Human Oversight 02 Ethical Rules for Digital Marketing: A Campaign Checklist 03 The 4Ps of Ethics in Marketing: Product, Price, Place and Promotion 04 Ethical Marketing: Principles, Trade-Offs and Governance

Get the next guide

Readiness

Attribution you can't defend is one symptom. See how five AI models currently describe, price and recommend your brand.

Get your score