Glossary
First-party data
Information you collected directly from your own customers through your own properties. Distinct from data bought or obtained through an intermediary.
Also called: 1P data
First-party data is what your customers gave you, on your own site or app, in the course of dealing with you: purchases, sign-ups, support conversations, email addresses, what they browsed while logged in.
The distinction that matters is the relationship, not the storage location. Data does not become first-party because it sits in your warehouse. If you bought it, or an intermediary collected it on someone else’s property and passed it to you, it is not first-party however you store it.
Why it became the whole conversation. As third-party cookies and cross-site tracking got restricted, the data you collected yourself became the only reliable input left. It is also the only data you can explain the provenance of, which matters when a regulator or a customer asks.
The two things people get wrong.
First, “first-party” is not a synonym for “compliant”. You still need a lawful basis to collect it, and a customer who gave you an email address to receive an order confirmation has not necessarily agreed to anything else. Collecting it yourself does not grant you unlimited use of it.
Second, first-party data is not automatically better data. It is narrower by definition — you only see your own customers on your own properties — and it is frequently messier, because nobody normalises an email address at the point of capture. Its value comes from being defensible and durable, not from being comprehensive.
Do not confuse with
Close enough to get mixed up, different enough that the mix-up costs something.
- Identity resolution Deciding that separate records — a click, a session, an order, an email — belong to the same person. Everything downstream inherits whatever this gets wrong.
- PII Personally identifiable information — data that identifies a specific person. The category is narrower than most regulation, which is why "we removed the PII" is rarely the whole answer.
- Server-side tagging Sending marketing and analytics events from your own server instead of from the visitor's browser, so a request the browser might block is made somewhere it cannot be.
- Zero-party data Information a customer deliberately gave you about themselves — preferences, intent, stated needs — rather than something you observed. A marketing coinage, not a legal category.