First-Party vs. Zero-Party Data: Use the Right Evidence for the Decision

First-party data tells you where the data relationship came from: your organization collected the information through direct interactions with customers, users, or visitors. Zero-party data tells you how the information was provided: a person intentionally and proactively declared it.

That makes zero-party data a narrower description, not a rival data supply. A product event can be first-party without being zero-party. A preference-center answer is zero-party and, in the broader relationship sense, also first-party because it was collected directly.

The distinction matters because the two types of records support different claims. Observed first-party behavior can show what happened in a measured system. Zero-party data can show what someone said they wanted, intended, or preferred at a particular time. Neither automatically proves why someone acted, what they will do next, or what your company is allowed to do with the information.

Classify the record by how it entered the relationship

The UK Information Commissioner’s Office describes first-party data as data relating to direct interactions between an individual and an organization. It contrasts that with second-party data obtained from another organization’s direct relationship and third-party data acquired from sources such as brokers or aggregators. Crucially, the ICO notes that all of these categories can still involve personal data; the commercial label does not determine the applicable data-protection obligations (ICO opinion on online advertising proposals).

The ICO uses first-, second-, and third-party labels to describe data relationships while noting that records in any of those categories can still be personal data. [S1]

Forrester defines zero-party data as information a customer intentionally and proactively shares with a brand. Its examples include preferences, purchase intentions, personal context, and how the person wants the brand to recognize them.

Forrester defines zero-party data as information a customer intentionally and proactively shares and recommends a clear value exchange with limited questioning. [S2]

Use two questions to classify a record:

  1. Did we collect it through our own direct interaction? If yes, it is first-party data.
  2. Did the person intentionally declare this particular information? If yes, it is also zero-party data under Forrester’s definition.

The second question prevents a common error: treating everything in a CRM, CDP, or product database as something the customer told you. System location does not establish evidence type.

RecordUseful classificationStrongest defensible claimWhat it does not establish
A signed-in account used an export featureObserved first-party dataThe instrumented event occurred for the recorded account and timeThe user’s motive, satisfaction, or purchase intent
An admin selected “improve reporting” during onboardingZero-party declaration collected directlyThe admin selected that answer in that contextThat the goal is current, truthful, or shared by every stakeholder
A success score calculated from usage eventsDerived from first-party dataThe account met the score’s defined input conditionsThat the customer declared the score or agrees with its meaning
A buyer changed an email preferenceZero-party declaration collected directlyThe buyer selected that preference at that timePermission for every channel, purpose, or destination

Choose according to the claim you need to make

Use observed first-party data when the decision depends on measured behavior. It can support actions such as suppressing a current customer from an acquisition audience, identifying accounts that have not completed a setup step, or prompting a user after a recorded feature event. Before acting, check that the event was captured reliably and attached to the right person, account, device, and time.

Use zero-party data when the decision depends on stated intent or preference. It is better suited to questions behavior cannot answer cleanly: a buyer’s current priority, an administrator’s onboarding goal, a preferred communication channel, or a requested area of interest. Forrester recommends keeping collection experiences short and simple and offering a clear value exchange; asking for information is easier to justify when the customer can see how the answer improves the experience (Forrester).

Do not treat either record as the whole customer truth. An observed action can be accidental, automated, performed through a shared account, or misread because instrumentation is incomplete. A declared answer can be strategic, misunderstood, or stale. The evidentiary advantage of zero-party data is that the person made the declaration—not that the declaration is permanently accurate.

When observed and declared data conflict, preserve both. Suppose, as an illustration, an administrator says integration reliability is the main priority, but the product record shows that no integration has been configured. The declaration supports a claim about stated importance; the event history supports a claim about recorded setup behavior. Together they justify checking for an implementation barrier. They do not justify silently changing the customer’s stated goal or declaring the account uninterested.

“First-party” is not permission to activate

First-party is a provenance label. It does not, by itself, create consent, a lawful basis, unlimited retention, or permission to send data to another system.

The boundary becomes clear in advertising. Google permits advertisers to use qualifying first-party data to create audiences on certain services, but its policies separately restrict personalized advertising, sensitive-interest targeting, data collection, and sharing (Google Ads first-party data policy, personalized advertising restrictions). Technical availability on a platform is therefore not blanket approval for a particular activation.

Google allows qualifying advertiser-provided first-party data for specified audience uses while separately imposing collection, sharing, and sensitive-interest restrictions. [S3], [S4]

Legal requirements also depend on the technology, purpose, and jurisdiction—not just who collected the data. For example, the ICO states that using storage or access technologies for online advertising requires consent under the UK rules it administers, including associated tracking and profiling (ICO guidance on online advertising). A record does not escape that review merely because it has been moved into a first-party database.

ICO guidance makes technology and purpose relevant to UK online-advertising consent requirements; a first-party database label does not remove that review. [S5]

Apply a five-check activation contract

Before a team uses either observed or declared data, document one specific activation. The review should answer five questions:

  1. What decision will this record influence? Name the action, such as changing an onboarding prompt or excluding an existing customer from an acquisition campaign.
  2. What does the record actually prove? Preserve its source, timestamp, collection interface, identity key, and evidence type: declared, observed, derived, or inferred.
  3. Does the proposed use fit the collection promise? Check the notice, applicable consent or other basis, opt-out state, sensitive-data rules, retention requirements, and the value offered when a declaration was requested.
  4. Is it current enough, and what overrides it? Define an expiry or review point, a contradiction rule, and a way for people to revise declared preferences.
  5. Where may it go? Specify approved systems, fields, users, and decisions. Record prohibited uses and the condition that stops the activation.

A compact contract can be copied into a ticket, data catalog, or campaign review:

Decision influenced:
Record and evidence type:
Strongest claim supported:
Source, identity key, and collection context:
Permission or collection-promise check:
Freshness rule:
Contradiction and override rule:
Approved destination and users:
Prohibited use:
Stop condition and owner:

If the team cannot complete those fields, it is not ready to activate the record. The practical rule is simple: use observed first-party data for claims about measured actions, and zero-party data for claims about what a person intentionally stated. Use either only within the identity, permission, freshness, and destination boundaries attached to the actual record.

Sources

  1. Information Commissioner’s Office, “Opinion on data protection and privacy expectations for online advertising proposalsSupports: First-party data relates to direct interactions between an individual and an organization; Second-party and third-party labels describe other relationship paths, while any category can still contain personal data. Checked 2026-09-09.Limitation: This UK regulatory opinion focuses on online advertising proposals; it is not a universal data taxonomy or legal opinion for a specific activation.
  2. Forrester, “Ask, Don’t Interrogate: Best Practices For Collecting Zero-Party DataSupports: Zero-party data is information a customer intentionally and proactively shares; Examples include preferences, purchase intentions, personal context, and recognition preferences, with a clear value exchange recommended. Checked 2026-09-09.Limitation: This is analyst guidance, not a statutory category or proof that a declaration is current, accurate, or sufficient for a proposed use.
  3. Google Ads Policy Help, “Customer Match policiesSupports: Google permits qualifying advertiser-provided first-party data for specified audience uses; Use remains subject to platform data-collection, sharing, and audience requirements. Checked 2026-09-09.Limitation: This is one platform’s policy; eligibility does not establish consent, lawful basis, or permission outside Google’s services.
  4. Google Ads Policy Help, “Personalized advertisingSupports: Google restricts personalized advertising involving sensitive interests and specified audience practices. Checked 2026-09-09.Limitation: These are Google-specific advertising restrictions, not a complete privacy or advertising-law analysis for a particular use.
  5. Information Commissioner’s Office, “How do the rules apply to online advertising?Supports: Under the UK rules described, storage and access technologies used for online advertising can require consent; The applicable analysis depends on technology and purpose rather than the first-party label alone. Checked 2026-09-09.Limitation: This guidance concerns UK PECR and data-protection rules; teams need qualified review for their own jurisdiction, technology, purpose, and facts.

Continue the evidence path

Run your growth team from one screen.

Invite only