Personalization and Customer Experience

The Future of Consumer Data: What Marketing Leaders Should Prepare For

Explore how first-party data, smart data, privacy-enhancing technologies, platform restrictions and changing customer expectations are reshaping marketing data.

Δ°lkem Erul Δ°lkem Erul β€’ Published β€’ Updated β€’ 31 min read
The Future of Consumer Data: What Marketing Leaders Should Prepare For

The future of consumer data will not be settled by one replacement for the third-party cookie.

Marketing organisations are moving into a more fragmented environment instead. Some browsers block or partition cross-site cookies. Mobile operating systems place controls around advertising identifiers and cross-app tracking. Regulators continue to constrain tracking, profiling and the reuse of personal information, while also consulting on where those constraints might be loosened. At the same time, governments and standards bodies are building new forms of permissioned data portability, controlled collaboration and privacy-preserving analysis.

The movement is away from data that marketers could collect or acquire with limited involvement from the individual. Greater weight now sits on direct customer relationships, clearly stated purposes, authorised access, trustworthy data and controlled forms of analysis.

This does not mean that third-party data will disappear, that every customer will share more information directly, or that privacy-enhancing technology will make unrestricted analysis possible. It means that consumer-data strategies will need to work under greater variation, stronger controls and less complete observability.

What is changing in consumer data

Five changes are happening at once.

  1. Cross-site and cross-app identifiers are becoming less dependable.
  2. Directly collected customer data is becoming more strategically important.
  3. Individuals may gain new ways to authorise data movement between services.
  4. Organisations are testing ways to collaborate without routinely exchanging raw records.
  5. Data quality, provenance and governance are becoming constraints on advanced analytics and AI.

These developments are not at the same stage, and the most common strategic error is treating them as though they were.

Maturity as at 28 July 2026Examples
Established in productionSafari default third-party-cookie blocking; Firefox cookie partitioning; App Tracking Transparency; open-banking services; first-party customer-data systems
Current platform policyChrome continues to offer users third-party-cookie choices rather than enforcing a universal phase-out
Enacted legal foundationThe Data (Use and Access) Act 2025 provides regulation-making powers for smart-data schemes
Published standardsW3C Verifiable Credentials Data Model 2.0; data-clean-room protocols and guidance
Strategy, advice or consultationThe UK Smart Data 2035 Strategy; the July 2026 multi-sector call for evidence; ICO advice to government on online-advertising consent rules
Pilot or experimentationFCA open-finance sprints, proofs of concept and synthetic-data testing
Scenario, not predictionRoutine cross-sector portability or widespread privacy-preserving marketing collaboration

Marketing leaders should therefore ask not only what a technology can do, but whether it is deployed, standardised, legally enabled, being tested or merely proposed.

Why this is not simply the death of cookies

The familiar phrase hides several different changes.

Safari began blocking cookies for cross-site resources by default across the board in March 2020. (1) Firefox subsequently rolled out Total Cookie Protection, which confines cookies to the site where they were created. (2) These are real restrictions already operating in major browsers.

Chrome’s position is different. On 22 April 2025, Google said it would maintain Chrome’s existing approach of offering users a third-party-cookie choice and would not introduce a separate new prompt. (3) In October 2025, Google announced that a large set of Privacy Sandbox advertising technologies, including Topics, Protected Audience and the Attribution Reporting API, would be retired because of low adoption, while work on areas such as CHIPS and FedCM would continue. (4)

On the same day, the Competition and Markets Authority formally released Google from the commitments it had accepted in its Privacy Sandbox investigation. Its reasoning was that the original concerns rested on Google removing third-party cookies from Chrome, or restricting them through a standalone prompt, and Google no longer intended to do either. (5) That release is confined to the Chrome proposals and to Google’s position in browsers. A separate investigation into suspected anti-competitive conduct by Google in ad tech remained open as at July 2026. (6)

Mobile platforms add another set of conditions. Apple requires apps to obtain permission through App Tracking Transparency before tracking a person across other companies’ apps or websites or accessing the advertising identifier. Without that permission, the identifier is unavailable for that purpose. (7) Android documentation describes its advertising ID as user-resettable and gives users an opt-out from advertising personalisation. (8)

UK legal requirements operate separately from browser and operating-system design. The ICO finalised its guidance on storage and access technologies on 29 April 2026, covering cookies, pixels, fingerprinting, scripts, tags, local storage and similar technologies, including their use for advertising and measurement. (9) That guidance reflects amendments made by the Data (Use and Access) Act 2025, which introduced narrow exceptions to the consent requirement for certain statistical and appearance purposes. (10)

The rules themselves are also in motion. On 18 May 2026 the ICO published advice to government on how the consent requirement in regulation 6 of the Privacy and Electronic Communications Regulations might be amended to allow certain lower-risk advertising activities to operate without consent, while continuing to require consent for intrusive tracking and profiling. That advice is a recommendation, not a change in the law, and the existing consent requirements remain in force unless and until they are amended. (11)

The strategic issue is therefore not whether one browser completes one deprecation programme. It is that the availability, legality and comparability of cross-site and cross-app signals vary by browser, device, permission, geography, platform and use. A consumer-data strategy should be resilient to that variation.

I saw how unevenly a legal change lands when GDPR arrived. Before it, working across verticals felt broadly similar. Afterwards, clients in government-linked, banking, insurance and health sectors quietly stopped activating the more complicated scenarios, and clients who had made a privacy mistake of their own stopped taking a vendor’s word for anything. Nobody announced a policy. The ideal customer profile of the company I worked for simply drifted, because permission had become slower to obtain and harder to defend internally. That is a commercial observation rather than a legal one, and it is why I read consultations as early signals rather than as paperwork.

From third-party access to direct customer relationships

As ambient cross-site signals become less dependable, the relationship through which data is obtained matters more.

A direct relationship can produce information such as account and purchase records, service interactions, product usage, loyalty activity, customer-support history, communication preferences and information the customer supplies deliberately.

This may be more relevant to the organisation than data acquired indirectly, but first-party is not a guarantee of quality, permission or fairness. Directly collected data can still be inaccurate, excessive, poorly documented or reused for an unexpected purpose.

The advantage is organisational control. The business can design the collection point, state the purpose, record provenance, monitor quality and connect the data to a service the customer recognises.

First-party data as an organisational capability

First-party data is not a replacement identifier or a larger customer database. It is a capability made of several disciplines:

  • designing observable customer interactions;
  • maintaining reliable definitions and identifiers;
  • recording sources, purposes and permissions;
  • monitoring data quality;
  • controlling access and retention;
  • connecting evidence to business decisions;
  • measuring performance despite incomplete signals.

The technical implementation of server-side collection, conversion matching, attribution and marketing-mix modelling belongs in a specialist guide to first-party data measurement systems.

For a future-facing strategy, the point is that first-party data depends on direct relationships and operational discipline. Buying another platform cannot compensate for weak collection purposes, inconsistent identifiers or unowned data-quality problems.

Intentionally declared preferences

Observed behaviour does not always reveal intent. A customer may buy a product as a gift, browse outside their normal category or research without any intention of purchasing. Sometimes it is more useful to ask.

The industry often calls information a customer provides deliberately zero-party data. The term usefully distinguishes declared preferences from observed behaviour, but it is not a separate legal category. Declared preferences might include preferred product types, communication frequency, interests, accessibility needs, intended use, budget range or preferred service channel.

Deliberately supplied information can improve transparency, because the customer can see what they are providing. It can still go stale, arrive incomplete or mislead, and supplying one preference does not authorise every later use of it.

One project changed how I think about who needs this. Working with a global consumer-electronics group, we collected extra information straight from end users through a custom survey, then used it to offer a discount on a specific product group. What struck me was not the campaign. It was that a company of that size would not commit to a decision as ordinary as targeted discounting until users had told it something directly. The commercial lesson is that declared data is not an SME workaround for missing scale. It is often what unlocks a decision an enterprise is otherwise unwilling to make.

I should disclose an interest. I now run a business built on customer-permissioned purchase data, so I have a commercial stake in the direction this section describes.

Collection mechanics, quizzes, surveys and preference-centre design belong in the guide to intentional preference-data collection.

Data portability and smart data

In current UK policy, smart data does not mean collecting more information or applying more advanced analytics.

The Data (Use and Access) Act 2025 provides powers through which government can create schemes for the secure sharing of customer data with the customer or an authorised third party. (10) Those regulation-making powers are in force. That does not mean any particular sector scheme is operational.

The UK Smart Data 2035 Strategy, published on 26 March 2026, sets out a long-term aim of secure and trusted data sharing across the economy, with sector-by-sector next steps and a cross-sector guidebook planned. (12) On 8 July 2026 the Department for Business and Trade opened a multi-sector call for evidence on potential schemes in agri-food, property, retail, trade and transport, which closes on 1 October 2026. It states that use cases identified through it will still require feasibility analysis, design and formal consultation before any regulatory change. (13)

Smart data is therefore best understood as an emerging policy and infrastructure model built around data portability, authorised access, defined purposes, technical standards, governance, security, customer control and interoperability between participating services.

It is not a general marketing exemption, a centralised consumer profile or permission to reuse data without regard to the purpose for which access was granted.

Open banking as one smart-data example

Open banking is strategically relevant because it demonstrates several smart-data principles in a working sector. Access occurs through regulated or authorised participants. The customer chooses whether to use the service, decides what can be accessed and for how long, and can manage or withdraw that access. Standardised interfaces support the exchange.

Open Banking Limited states that consumers are not automatically opted in and that they choose the firms, the information and the duration involved. (14)

This does not create unrestricted permission to use financial information for marketing. The purpose presented to the customer, the participant’s regulatory role and applicable data-protection requirements all continue to apply. Open-banking standards also distinguish the explicit consent required under payment-services rules from consent as a lawful basis under UK data-protection law. (15)

Open banking should be read as evidence that permissioned, standardised portability can work. It is not proof that every sector will adopt identical rules, nor that transaction data becomes freely available for targeting.

The regulatory structure and sector opportunities are covered in the open-banking pillar guide. Dated sector developments belong in the separate open-banking trends report.

Interoperability and permissioned access

Portability becomes useful only when participating systems can interpret and govern what is exchanged.

Technical connectivity is one part of interoperability. Organisations also need agreement about what each field means, how identity and authorisation are checked, which party is responsible for errors, how access is revoked, how corrections propagate, how purpose and permitted use are represented, how origin and transformations are recorded, and how disputes and security incidents are handled.

The FCA’s open-finance roadmap illustrates the timescale. Published on 14 April 2026, it sets out a path to move open finance from vision to delivery between then and 2030, prioritising high-impact use cases such as SME lending and mortgages, with a discussion paper on a first open-finance scheme expected later in 2026. (16) Open finance beyond current open-banking services should therefore be described as a developing programme, not a complete operational system.

Interoperability may reduce the cost of customer-directed data movement. It does not remove the need for governance, and it does not create a single universal customer record.

Privacy-enhancing technologies

Privacy-enhancing technologies, or PETs, can help organisations analyse, share or verify information while reducing particular privacy and security risks. They do not all solve the same problem.

ProblemPossible approach
Publishing useful statistics while limiting exposure of individualsDifferential privacy
Analysing distributed data without routinely moving raw records to one locationFederated analysis
Computing over protected informationSecure multiparty computation or homomorphic encryption
Collaborating across organisations under controlled conditionsData clean rooms
Developing or testing systems without directly using production recordsSynthetic data
Proving an attribute without disclosing every underlying recordPrivacy-preserving credentials

The ICO warns that PETs are not a universal solution. Many PET uses still involve personal information, implementation mistakes can undermine the protection claimed, and lawful, fair and transparent processing remains necessary. (17) That guidance is under review following the Data (Use and Access) Act, so its status should be checked before it is relied on for detailed compliance interpretation.

For implementation choices and deeper technical analysis, see privacy-enhancing technologies for personalisation.

Differential privacy

Differential privacy addresses the risk that a statistical output reveals too much about a particular individual. It introduces controlled randomness so that the presence or absence of one person’s information has a limited effect on the result.

It is mainly an output-privacy approach. It can protect published statistics or model outputs, but it does not secure the original records while they are collected or processed. The trade-off is between privacy and utility. Stronger protection may reduce precision; weak configuration may provide an inadequate guarantee. It requires a defined threat model, appropriate parameters, technical expertise and control over repeated queries.

Federated analysis

Federated analysis keeps data distributed and sends an analysis, query or model process to participating environments rather than assembling all raw records centrally.

This can reduce data movement and the number of parties receiving underlying records. It does not mean nothing sensitive can leak. Model updates, query results or trained models may reveal information unless further protections are used. NIST documented attacks capable of extracting information from federated model updates and concluded that federated learning alone is not a complete privacy solution. (18) Depending on the use, federated methods may need to be combined with secure aggregation, cryptography, access controls or differential privacy.

Secure computation

Secure multiparty computation enables parties to compute a result using their respective inputs without each disclosing all of its input data to the others. Homomorphic encryption supports computation over encrypted information in some circumstances, with the result decrypted later by an authorised party.

These methods can reduce exposure during computation. They do not determine whether the result should be produced, whether the inputs were lawfully obtained, or whether the output reveals sensitive information. They can also carry significant computational, operational and key-management demands.

Data clean rooms

A data clean room is a controlled environment in which two or more parties can match, analyse or measure data subject to technical and organisational restrictions. It may include access controls, approved queries, aggregation thresholds, restricted outputs, secure matching, audit logs, contractual controls and PETs such as private set intersection or trusted execution environments.

The name does not prove that the environment is private, lawful or secure. The guarantees depend on its design, administrators, identity-matching process, permitted outputs and auditability.

Industry specifications are still moving. IAB Tech Lab released data-clean-room guidance and an initial interoperability standard in July 2024, finalised ADMaP 1.0 in February 2025 and PAIR version 1.1 in July 2025, and deprecated an earlier protocol in July 2025. (19) That is evidence of active standardisation, not proof that clean rooms have resolved every privacy or interoperability question.

Synthetic data

Synthetic data is artificially generated information designed to reproduce selected statistical properties of another dataset. It may be useful for software testing, prototyping, analyst training, policy experimentation, some model development and reducing routine access to production records.

The FCA’s Smart Data Accelerator describes a secure environment in which organisations can use synthetic data to develop proofs of concept. (20) That is an experimental and developmental use. It is not evidence that synthetic data can replace real data in operational decisions.

Synthetic data is not automatically anonymous. Generating it may still require protected source information, rare patterns can be reproduced, and a dataset may preserve statistical relationships that enable inference. Its quality has to be tested against the purpose it will serve.

Privacy-preserving credentials

A digital credential allows an issuer to make a verifiable claim that a holder presents to a verifier. The W3C published the Verifiable Credentials Data Model 2.0 as a Recommendation on 15 May 2025, defining an issuer, holder and verifier model and a standard way to express and secure claims. (21)

Combined with selective-disclosure or zero-knowledge methods, credentials may eventually let a person prove an attribute, such as meeting an eligibility threshold, without disclosing every underlying record.

The standard is established. Widespread use for consumer marketing attributes is not. Adoption, governance, issuer trust, revocation, wallet design and the risk of unwanted correlation remain open questions.

Data provenance and lineage

Future data environments will combine information from owned services, customer declarations, authorised third parties, platforms, statistical models and synthetic sources. Without provenance, those sources get mistaken for one another.

A useful provenance record identifies where the data originated, when it was collected or generated, the purpose attached to it, whether it records fact, inference, model output or preference, the permission involved, the transformations applied, the quality checks performed, the responsible owner, retention and review dates, and known limitations.

The UK Government Data Quality Framework defines data quality as fitness for purpose and warns that poor or unknown quality weakens evidence and trust. (22) ICO accuracy guidance says organisations should record the source of personal information and keep its source and status clear. (23)

The worst data problem I ever saw was not sinister. It was arithmetic. One of the largest cosmetics groups I worked with had never reconciled its offline database with its several online ones, so a customer buying through a new channel was stored as a new person. Product-category tracking had drifted so far that the most-purchased-category field they sent us contained category names that meant nothing. They were counting everything wrongly and had no way to know. In the end they paid a CRM vendor heavily to clean it up. Nobody in that organisation had set out to mislead anyone.

This matters for marketing because a declared preference, a predicted interest and a completed purchase are not equivalent evidence. Combining them into one score without preserving their meaning produces confident, unreliable decisions.

Browser and platform restrictions

Browser and platform restrictions should be treated as ongoing operating conditions rather than as a transition with an end date.

A resilient data strategy should assume that some cross-site cookies are blocked, some are partitioned, some mobile identifiers require permission, users can reset or restrict identifiers, browser APIs may be introduced, changed or retired, platform reporting may use different attribution logic, technical access does not override legal requirements, and signals available in one environment may be unavailable in another.

The consequence is not the end of digital advertising or analytics. It is the end of the expectation that one user-level path can be observed consistently across every environment.

Measurement under reduced observability

Reduced observability changes what marketing measurement can claim.

A platform report describes activity visible to that platform. First-party analytics describe interactions the organisation can observe. Attribution models allocate credit across observed paths. Experiments estimate effects for defined interventions and populations. Marketing-mix models examine aggregate relationships under modelling assumptions. None of them reconstructs every customer journey without assumptions.

I learned how much that matters from a hold-out test. A French beauty retail chain ran an email automation giving its loyal segment a discount 30 days after purchase. For five months the dashboard looked excellent: strong opens, strong clicks, strong conversions. We then split out a group that received no discount. Opens were similar, clicks were lower, and conversions differed by only 2 per cent. The campaign had mostly been paying people who were going to buy anyway. That is a commercial finding about margin, not a compliance one, and no amount of dashboard detail would have surfaced it without a control group.

Marketing organisations will increasingly need to define which decision each measure supports, document missing populations and signals, distinguish attribution from causation, run experiments where feasible, compare platform and first-party reporting carefully, use aggregate methods for questions individual paths cannot answer, and express uncertainty rather than manufacture false precision.

The detailed choice between attribution, experiments and marketing-mix modelling belongs in the guide to measuring marketing performance.

AI and the demand for reliable data

AI does not remove the need for a data strategy. It raises the cost of weak foundations.

Models can process more records and detect more relationships. They can also reproduce stale classifications, amplify sampling problems, rely on undocumented proxies and make outputs hard to trace to their source. UK rules on automated decision-making were themselves reformed by the Data (Use and Access) Act 2025, which replaced the previous general prohibition with a permission-plus-safeguards structure for many uses. (10)

Before using customer information for training, scoring, generation or automated decisions, an organisation should be able to answer what the original purpose of the data was, whether the source is reliable and current, whether the training population represents the intended use, which fields are observed, declared, inferred or synthetic, whether outputs can be tested for material errors, whether it can explain which data and transformations affected a result, whether the model or its outputs could reveal information about individuals, and who can stop or correct the use.

Stale classifications are easy to underestimate. A French luxury house told me its main digital target was women over 40. That was the profile in every deck. When we looked at who actually bought on the website, the buyers were women between 27 and 40 and men between 25 and 35. The profile had been built on the boutique clientele and quietly inherited by the digital team. Nothing about it was dishonest, and it had been true somewhere. Feed a definition like that into a model and it will faithfully optimise towards a customer who is not buying.

AI readiness is therefore inseparable from provenance, quality, evaluation, access control and accountable ownership.

The risk of collecting more than the organisation can govern

A future-ready data strategy is not a programme to accumulate every available signal.

ICO data-minimisation guidance says organisations should identify and hold the minimum personal information needed for their purpose. (24) Purpose-limitation guidance requires purposes to be defined from the outset and warns against function creep. (25)

Collecting data without a defined use creates liabilities: more systems and copies to secure, more uncertain permissions, more stale or contradictory attributes, more complex deletion and correction processes, more opportunities for incompatible reuse, more model inputs whose meaning is unclear, and more difficulty answering a customer’s questions.

Something I noticed after a decade of this work is that shoppers are rarely surprised that brands record what they buy. Most people assume it. What tends to land differently is what gets derived from it: roughly when someone’s salary arrives, how many people they appear to be shopping for, which moments reliably trigger a decision. None of that is collected. All of it is inferred. I raise it because inference is where the gap between what an organisation holds and what a customer thinks it holds usually opens up, and that gap is a governance problem long before it is a legal one.

The objective is sufficient, trustworthy and governable information, not maximum information.

The wider fairness and trust questions belong in the guide to ethical consumer-data use.

Three plausible consumer-data scenarios

These are planning tools, not forecasts. More than one may emerge at once, in different sectors or markets.

Scenario 1: Stronger direct relationships

Customer-permissioned and first-party data become more important, while access remains fragmented by organisation, browser, platform and sector.

This is the best-supported scenario today. Safari and Firefox already restrict cross-site cookie use, mobile platforms impose identifier and tracking controls, Chrome retained user choice rather than creating a single market-wide endpoint, and UK rules continue to govern storage and access technologies. It assumes cross-site observability stays inconsistent, customers keep using accounts and direct channels, cross-sector smart-data schemes develop slowly, and platforms retain control of their own measurement environments.

If it holds, logged-in and service-based relationships become more valuable, preference management and customer value exchange attract investment, and measurement leans on first-party events, experimentation and aggregate evidence. The risks are that large incumbents with more direct interactions gain an advantage, that businesses over-collect first-party data in response to signal loss, that identity resolution creates new exposure, and that customers face repeated account prompts with no benefit attached.

It would be undermined by a widely adopted interoperable identifier restoring dependable cross-site observability, by cross-sector portability becoming easy and ubiquitous, or by a material decline in direct customer channels.

Scenario 2: Wider interoperable smart-data schemes

Regulated or standardised portability expands beyond banking into further sectors.

The supporting evidence is real but early: the Data (Use and Access) Act 2025 created the powers, the Smart Data 2035 Strategy sets a cross-economy direction, the July 2026 call for evidence is examining five further sectors, and the FCA has published a staged open-finance roadmap to 2030. It assumes government proceeds from consultation to sector regulation, that governance and funding models are established, that data holders and authorised recipients adopt common standards, that customers see enough value to authorise access, and that security and liability arrangements are trusted.

If it holds, customer-authorised data becomes available from new sectors, comparisons can draw on more portable records, and marketers must distinguish data held directly from data accessed for a defined authorised service. Permission, revocation and provenance become core architecture. The risks are schemes that never progress past consultation, incompatible sector standards, portability that exists but goes unused, complex or manipulative permission journeys, and reuse beyond the customer’s expected purpose.

Watch for published secondary legislation, formal sector consultations followed by final rules, accreditation frameworks, operational APIs with conformance tests, and measurable customer adoption. Repeated strategy work without scheme rules would suggest it is not arriving.

Scenario 3: Privacy-preserving collaboration

Organisations derive aggregate insight through PETs and controlled environments without routinely exchanging raw personal records.

The ICO has published detailed PET guidance, NIST and UK government researchers have investigated privacy-preserving federated learning, IAB Tech Lab has published clean-room guidance and interoperability protocols, the FCA is using synthetic data for proofs of concept, and W3C has published a verifiable-credentials standard. It assumes PET performance and usability keep improving, that organisations build cryptographic and privacy-engineering expertise, that standards support interoperability and audit, that participants accept limits on query detail and output precision, and that regulators and customers trust independently verifiable guarantees.

If it holds, some collaboration shifts from raw-data exchange to approved computations and aggregate outputs, data-sharing negotiations start specifying threat models and output controls, marketers receive fewer user-level records but safer aggregate evidence, and technical assurance becomes part of supplier evaluation. The risks are that privacy-enhancing becomes an unverified vendor label, that matching keys still expose identity, that outputs permit inference or repeated-query attacks, that organisational controls undercut technical protections, and that cost exceeds the value of the analysis.

Independently tested implementations, stable standards and repeatable deployments beyond pilots would confirm it. Projects that stay in proof of concept, and raw exports that remain the default, would not.

Capabilities to build now

No scenario has to be selected before acting. These capabilities are useful under all three.

Data inventory and provenance

Record the source, purpose, owner, status, transformations, retention rules and known limitations of important data.

Direct customer value exchange

Be explicit about what service, convenience, insight or control the customer receives when providing information or creating an account.

Permission and preference management

Separate legal bases, service permissions, channel preferences and platform choices. Design for withdrawal and change rather than treating permission as permanent.

Data quality and observability

Monitor freshness, completeness, validity, duplication and pipeline failures. Record whether an attribute is observed, declared, inferred or synthetic.

Measurement pluralism

Build the ability to use first-party analytics, experiments, aggregate models and qualitative evidence together, without pretending they answer identical questions.

PET evaluation

Develop a method for assessing the problem, threat model, guarantee, maturity, implementation risk, utility loss, cost and auditability of each proposed PET.

Interoperability readiness

Use stable definitions, APIs, metadata and identity controls that can accommodate authorised exchange without assuming every sector will use the same model.

Scenario governance

Review browser policies, regulatory programmes, standards and pilots on a dated schedule. Record which strategic assumptions would change an investment decision.

Consumer-data readiness checklist

A marketing organisation is better prepared when it can answer yes to the following:

  • Do we know which decisions depend on third-party, platform or mobile identifiers?
  • Can we quantify where those signals are missing or inconsistent?
  • Are important customer attributes linked to a documented source and purpose?
  • Do we distinguish observed, declared, inferred and synthetic information?
  • Can customers understand and change relevant permissions and preferences?
  • Do we have a deletion, correction and revocation path across downstream systems?
  • Are data-quality failures visible to the teams using the data?
  • Can we measure outcomes without relying exclusively on user-level attribution?
  • Do our PET evaluations identify the precise privacy problem being addressed?
  • Can suppliers state what their privacy-enhancing claims technically guarantee?
  • Have we separated operational schemes from consultations, pilots and forecasts?
  • Do we review our consumer-data scenarios at least annually, and after any major platform or regulatory change?

Frequently Asked Questions

The most defensible direction is a mixture of directly collected data, intentionally declared preferences, customer-authorised portability, platform-controlled signals and privacy-preserving aggregate analysis. The balance will vary considerably by sector and by organisation, and no single model is likely to replace all the others.

There is no single replacement. Organisations are likely to use combinations of first-party relationships, contextual information, platform measurement, experiments, aggregate modelling, permissioned data access and collaboration through privacy-enhancing technologies.

Chrome has not implemented a universal phase-out. In April 2025 Google said it would retain its existing user-choice approach rather than introduce a separate prompt, and in October 2025 it retired a large set of Privacy Sandbox advertising technologies. Other browsers and mobile environments already impose substantial restrictions, so a strategy should not depend on Chrome alone.

No. It offers greater control over collection and governance, but it can still be inaccurate, excessive, incomplete, reused beyond its stated purpose or poorly connected to business decisions. Control is an opportunity rather than a guarantee.

In UK policy, smart data concerns the secure sharing of customer data with the customer or with authorised third parties, usually at the customer's request and under a defined scheme. It is about portability and authorised access rather than collecting more data.

Open banking is one working example of smart-data principles. Smart-data policy may extend into other sectors, but proposed schemes should not be described as operational before the relevant rules, standards and services actually exist.

Not necessarily. Different technologies protect different data, different parties and different stages of processing, and many uses still involve personal information. See the privacy-enhancing technologies guide for the threat models, guarantees and limitations of clean rooms, federated learning, differential privacy and synthetic data.

No. They should collect information that is necessary, useful, explainable and governable for defined purposes. Excess collection increases security, quality, compliance and trust risks without necessarily improving decisions.

Conclusion

The future of consumer data is not a transition from one universal tracking technology to another.

It is a shift towards a more conditional environment, in which access depends on the relationship, the browser, the platform, the permission, the purpose, the sector and the technical controls involved.

Three directions deserve sustained attention: stronger direct customer relationships, wider permissioned portability and privacy-preserving collaboration. None is certain to dominate, and each carries its own risks.

Marketing leaders should avoid betting an entire strategy on one identifier, one browser proposal, one smart-data scheme or one PET. The more durable investment is in first-party capability, provenance, quality, permission management, measurement under uncertainty, interoperability and accountable governance.

Those capabilities remain useful whichever scenario emerges.

References

  1. WebKit (Apple). Full Third-Party Cookie Blocking and More. Browser engine announcement. No reference number. Published 24 March 2020; no later update stated. Not UK law; describes a global browser implementation by its own developer. https://webkit.org/blog/10218/full-third-party-cookie-blocking-and-more/

  2. Mozilla. Firefox rolls out Total Cookie Protection by default to more users worldwide. Product announcement. No reference number. Published 14 June 2022; page updated 28 August 2024. Not UK law; describes a global browser implementation by its own developer. https://blog.mozilla.org/en/mozilla/firefox-rolls-out-total-cookie-protection-by-default-to-all-users-worldwide/

  3. Google (Anthony Chavez), Privacy Sandbox. Next steps for Privacy Sandbox and tracking protections in Chrome. Product policy announcement. No reference number. Published 22 April 2025; no later update stated. Not UK law; Google owns Chrome and is describing its own product policy. https://privacysandbox.google.com/blog/privacy-sandbox-next-steps

  4. Google (Anthony Chavez), Privacy Sandbox. Update on Plans for Privacy Sandbox Technologies. Product roadmap announcement. No reference number. Published 17 October 2025; no later update stated. Not UK law; Google is reporting decisions about technologies it developed. https://privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies

  5. Competition and Markets Authority. Decision to release commitments previously accepted by the CMA in respect of Google’s Privacy Sandbox Proposals. Decision under section 31A(4) of the Competition Act 1998. Case 50972. Dated 17 October 2025; no later update shown. The case page, published 8 January 2021 and last updated 17 October 2025, records the case as closed with a commitments outcome. Confined to Google’s Privacy Sandbox proposals in Chrome and its position in browsers; expressly not a clearance of Privacy Sandbox on Android, of Google Ads, or of conduct in other markets. United Kingdom. https://www.gov.uk/cma-cases/investigation-into-googles-privacy-sandbox-browser-changes

  6. Competition and Markets Authority. Investigation into suspected anti-competitive conduct by Google in ad tech. Competition Act 1998 investigation case page. Published 26 May 2022; last updated 19 May 2026; status shown as open as at 28 July 2026. A statement of objections is not a finding of infringement, and the page cautions that no conclusion should be drawn that competition law has been broken. United Kingdom. https://www.gov.uk/cma-cases/investigation-into-suspected-anti-competitive-conduct-by-google-in-ad-tech

  7. Apple. User privacy and data use. Developer and App Store policy documentation. No reference number. Undated page, accessed 28 July 2026; App Tracking Transparency applies from iOS and iPadOS 14.5. Not UK law; Apple defines and enforces the policy described. https://developer.apple.com/app-store/user-privacy-and-data-use/

  8. Android Developers (Google). Get a user-resettable advertising ID. Technical documentation. No reference number. Last updated 26 February 2026. Not UK law; Google develops Android and this documentation. https://developer.android.com/identity/ad-id

  9. Information Commissioner’s Office. Guidance on the use of storage and access technologies. Regulatory guidance. No reference number. Published in draft 20 December 2024; finalised 29 April 2026. Final, not draft; the ICO’s separate review of regulation 6 of PECR for online advertising continues alongside it. United Kingdom. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/

  10. UK Parliament. Data (Use and Access) Act 2025. Primary legislation. 2025 c. 18. Royal Assent 19 June 2025. Part 1 smart-data powers commenced on 20 August 2025. The specific Part 5 amendments discussed here took effect on 5 February 2026, and all DUAA data-protection provisions were in force by 19 June 2026. United Kingdom. https://www.legislation.gov.uk/ukpga/2025/18/contents

  11. Information Commissioner’s Office. Our advice to government on potential changes to online advertising rules. Regulator statement accompanying formal advice to government. No reference number. Published 18 May 2026. Advice only; no change to the law has been made and existing consent requirements remain in force. United Kingdom. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/our-advice-to-government-on-potential-changes-to-online-advertising-rules/

  12. Department for Business and Trade. Smart Data 2035: The UK’s Smart Data Strategy. Policy paper. CP 1551; ISBN 978-1-5286-6348-9; E03572600. Published 26 March 2026; no later update stated. A strategy, not secondary legislation or an operational scheme. United Kingdom. https://www.gov.uk/government/publications/smart-data-strategy

  13. Department for Business and Trade. Smart Data: multi-sector call for evidence. Call for evidence. CP 1608; ISBN 978-1-5286-6684-8; E03637357. Opened 8 July 2026; closes 11:59pm on 1 October 2026. Open consultation; identified use cases remain subject to feasibility work and formal consultation. United Kingdom. https://www.gov.uk/government/calls-for-evidence/smart-data-multi-sector-call-for-evidence

  14. Open Banking Limited. FAQs. Ecosystem information page. No reference number. Undated page, accessed 28 July 2026. United Kingdom. https://www.openbanking.org.uk/faqs/

  15. Open Banking Limited. Consent - AIS (PSD2) (the live page renders the separator as a dash). Customer experience guidelines and standards guidance. No reference number. Latest version dated 18 March 2026. Industry standards guidance rather than law. United Kingdom. https://standards.openbanking.org.uk/customer-experience-guidelines/introduction/customer-journey-consent/latest/

  16. Financial Conduct Authority. Open finance roadmap: our vision for a smart data future. Corporate document. No reference number. Published 14 April 2026. A roadmap and vision rather than a consultation or final rules; a discussion paper on a first open-finance scheme is expected later in 2026. United Kingdom. https://www.fca.org.uk/publications/corporate-documents/open-finance-roadmap

  17. Information Commissioner’s Office. How can PETs help with data protection compliance? Regulatory guidance. No reference number. Published 19 June 2023. Under review following the Data (Use and Access) Act as at 28 July 2026. United Kingdom. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/privacy-enhancing-technologies/how-can-pets-help-with-data-protection-compliance/

  18. Joseph Near, David Darais, Dave Buckley and Mark Durkee, National Institute of Standards and Technology. Privacy Attacks in Federated Learning. Government technical research blog. No reference number. Published 24 January 2024; no later update stated. Not UK law; a United States federal agency publication produced with UK contributors. https://www.nist.gov/blogs/cybersecurity-insights/privacy-attacks-federated-learning

  19. IAB Technology Laboratory. Data Clean Rooms Guidance. Industry guidance and standards status page. No reference number. No publication date shown; page last updated 22 July 2025. Statuses shown on the page: Data Clean Rooms Guidance v1.0 dated July 2024, although the linked PDF states it was released on 5 July 2023 and its title carries a post public comment draft label; ADMaP v1.0 finalised February 2025; PAIR v1.1 finalised July 2025; an earlier join-and-activation protocol deprecated as of July 2025. IAB Tech Lab’s separate standards index has not been reconciled with these statuses. Not UK law; industry standards documentation produced by a member-backed advertising body, not regulatory approval. https://iabtechlab.com/datacleanrooms/

  20. Financial Conduct Authority. Smart Data Accelerator. Innovation programme page. No reference number. First published 22 September 2025; last updated 29 May 2026. Describes an experimental programme, not a production requirement. United Kingdom. https://www.fca.org.uk/firms/innovation/smart-data-accelerator

  21. World Wide Web Consortium. Verifiable Credentials Data Model v2.0. W3C Recommendation. REC-vc-data-model-2.0-20250515. Published 15 May 2025. Not UK law; an international open web standard. https://www.w3.org/TR/2025/REC-vc-data-model-2.0-20250515/

  22. Government Data Quality Hub, UK Government. The Government Data Quality Framework. Government framework. No reference number. Published 3 December 2020; no later update stated. Written for public-sector use and applied here by analogy to marketing data; not a legal requirement for private organisations. United Kingdom. https://www.gov.uk/government/publications/the-government-data-quality-framework/the-government-data-quality-framework

  23. Information Commissioner’s Office. Principle (d): Accuracy. Regulatory guidance. No reference number. Undated page, accessed 28 July 2026. Marked under review following the Data (Use and Access) Act. United Kingdom. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/accuracy/

  24. Information Commissioner’s Office. Principle (c): Data minimisation. Regulatory guidance. No reference number. Undated page, accessed 28 July 2026. United Kingdom. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/data-minimisation/

  25. Information Commissioner’s Office. Principle (b): Purpose limitation. Regulatory guidance. No reference number. Undated page, accessed 28 July 2026. United Kingdom. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/purpose-limitation/

Position as at 28 July 2026. Guidance, standards and platform policies in this area change frequently. Several sources above are marked as under review, in draft, at consultation stage or as advice to government rather than settled law, and at least one substantive change to UK online-advertising consent rules is currently under consideration. Verify the current status of any source before relying on it for a compliance decision.

Δ°lkem Erul

Written by

Δ°lkem Erul

Contributor

I have over nine years of experience in digital marketing, account management, and B2C loyalty. I've helped global brands grow, and now, as a co-founder of Herm.io, I work on smarter, safer shopping experiences for consumers.

More from Δ°lkem

Related Articles