Analytics and Tracking

Third-Party Data

Also called 3P data

Data about people collected by an organisation with no direct relationship with them, then sold or licensed to other businesses for targeting.

Quick facts: Third-Party Data

Category
Analytics and Tracking
Also called
3P data
Level
Intermediate
Affects
Audience targeting, list buying, UK GDPR and PECR compliance, campaign efficiency
Where to see it
Ad platform audience libraries, programmatic buying tools, data broker contracts, your CRM
In this article4
  1. How third-party data works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

Third-party data is information about people collected by an organisation that has no direct relationship with them, then sold or licensed to other businesses. A typical example is an audience segment such as “in-market for a new car” or “homeowners aged 35 to 54 in Surrey”, assembled by a data broker from many websites, apps, surveys and public sources.

How third-party data works

Brokers gather signals from places the people concerned rarely think about: partner websites carrying the broker’s tags, software kits inside mobile apps, loyalty schemes, prize draws, public records and other brokers. They attach those signals to an identifier, such as a cookie, a mobile advertising ID, a postal address or an email address, and group people into segments. Businesses then buy access, either as a list they hold themselves or as a targeting option inside an ad platform or programmatic buying tool.

It sits at the far end of a scale. First-party data is what your own customers and visitors give you by using your site and buying from you. Second-party data is another company’s first-party data shared with you under an agreement. Zero-party data is what people tell you on purpose, such as their preferences in a quiz. Third-party data is the furthest removed from the person, which is why both its accuracy and its legal footing are harder to check.

Much of the online trade has relied on third-party cookies, which let one company recognise the same browser across many unrelated sites. Safari and Firefox block those cookies by default. At the time of writing (October 2026), Chrome still allows them after Google dropped its plan to remove them, but the general direction is towards fewer cross-site identifiers, not more.

Why it matters

For a UK business the first question is not whether it works but whether you can use it lawfully. Under UK GDPR, people must be told who will use their data and for what. When data has passed through several hands, the person usually has no idea your business holds it. The ICO has taken action against data brokers over exactly this kind of invisible processing, and it regularly fines companies for marketing calls and texts sent to bought lists.

For email and text marketing, PECR adds a further hurdle. Consent collected by someone else only counts if the person was told specifically that your business would contact them. A tick box agreeing to hear from “selected partners” does not meet that standard, so most bought email lists cannot lawfully be used for marketing at all.

The second question is value. Segments are often built from inferences rather than facts, and they go stale quickly. A segment labelled “small business owners” may include anyone who once read an article about VAT returns. You pay for that guesswork whether or not it fits your customers.

Common mistakes

  • Buying an email or phone list because the seller calls it “GDPR compliant”, without seeing the consent wording or checking that your business was named in it.
  • Assuming targeting options inside an ad platform raise no questions for you. The platform carries much of the responsibility, but you still answer for what you upload and for what your privacy notice says.
  • Judging a bought segment on its size rather than on cost per enquiry or sale compared with a broad audience.
  • Mixing bought records into your CRM, where they later get emailed along with genuine customers.

How to act on it

Treat third-party data as something to test, not something to build on. If you use a bought segment in a campaign, run it alongside a broad or first-party audience with the same budget and creative, and judge both on cost per lead or sale. Ad platforms’ own targeting often holds its own without the extra fee, but that is for your account’s figures to show, not for anyone to assume.

Before buying any list, ask the seller for the exact wording people agreed to, when and where it was collected, and the lawful basis relied on. If they cannot show you, do not buy. Keep a record of those checks, because the ICO expects you to be able to explain why you believed the data was usable.

Put most of your effort into data you collect yourself with clear consent: it is more accurate, cheaper over time and entirely under your control. Working out which audiences and data sources are worth paying for is part of the digital marketing strategy work I do with UK businesses.

Do and do not

Do

  • Ask for the consent wording and source before buying any list
  • Test bought segments against a broad audience on cost per lead
  • Put most effort into data you collect yourself

Do not

  • Email or text a bought list without consent that named your business
  • Mix bought records into your customer CRM
  • Take a seller's "GDPR compliant" label on trust

Questions people ask about this

Is third-party data legal to use in the UK?

It can be, but the burden is on you to show it was collected fairly and that people were told it would be shared for this purpose. Using third-party segments inside a major ad platform is common and generally lower risk, because the platform handles the matching. Buying a list of named people to contact directly is where most UK businesses get into difficulty.

What is the difference between first-party and third-party data?

First-party data comes straight from your own customers and visitors, through your website, purchases, enquiries and sign-ups. Third-party data comes from an organisation that has no relationship with the people concerned and sells what it has gathered. First-party data is usually more accurate and easier to justify under UK GDPR.

Can I send marketing emails to a list I bought?

Usually not. Under PECR, marketing emails to individuals need consent that specifically covered your business, and lists sold to many buyers rarely meet that test. Business email addresses at limited companies are treated differently, but you still have to identify yourself, offer an easy opt-out and respect UK GDPR.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.