Third-party data is information about people collected by an organisation that has no direct relationship with them, then sold or licensed to other businesses. A typical example is an audience segment such as “in-market for a new car” or “homeowners aged 35 to 54 in Surrey”, assembled by a data broker from many websites, apps, surveys and public sources.
How third-party data works
Brokers gather signals from places the people concerned rarely think about: partner websites carrying the broker’s tags, software kits inside mobile apps, loyalty schemes, prize draws, public records and other brokers. They attach those signals to an identifier, such as a cookie, a mobile advertising ID, a postal address or an email address, and group people into segments. Businesses then buy access, either as a list they hold themselves or as a targeting option inside an ad platform or programmatic buying tool.
It sits at the far end of a scale. First-party data is what your own customers and visitors give you by using your site and buying from you. Second-party data is another company’s first-party data shared with you under an agreement. Zero-party data is what people tell you on purpose, such as their preferences in a quiz. Third-party data is the furthest removed from the person, which is why both its accuracy and its legal footing are harder to check.
Much of the online trade has relied on third-party cookies, which let one company recognise the same browser across many unrelated sites. Safari and Firefox block those cookies by default. At the time of writing (October 2026), Chrome still allows them after Google dropped its plan to remove them, but the general direction is towards fewer cross-site identifiers, not more.
Why it matters
For a UK business the first question is not whether it works but whether you can use it lawfully. Under UK GDPR, people must be told who will use their data and for what. When data has passed through several hands, the person usually has no idea your business holds it. The ICO has taken action against data brokers over exactly this kind of invisible processing, and it regularly fines companies for marketing calls and texts sent to bought lists.
For email and text marketing, PECR adds a further hurdle. Consent collected by someone else only counts if the person was told specifically that your business would contact them. A tick box agreeing to hear from “selected partners” does not meet that standard, so most bought email lists cannot lawfully be used for marketing at all.
The second question is value. Segments are often built from inferences rather than facts, and they go stale quickly. A segment labelled “small business owners” may include anyone who once read an article about VAT returns. You pay for that guesswork whether or not it fits your customers.
Common mistakes
- Buying an email or phone list because the seller calls it “GDPR compliant”, without seeing the consent wording or checking that your business was named in it.
- Assuming targeting options inside an ad platform raise no questions for you. The platform carries much of the responsibility, but you still answer for what you upload and for what your privacy notice says.
- Judging a bought segment on its size rather than on cost per enquiry or sale compared with a broad audience.
- Mixing bought records into your CRM, where they later get emailed along with genuine customers.
How to act on it
Treat third-party data as something to test, not something to build on. If you use a bought segment in a campaign, run it alongside a broad or first-party audience with the same budget and creative, and judge both on cost per lead or sale. Ad platforms’ own targeting often holds its own without the extra fee, but that is for your account’s figures to show, not for anyone to assume.
Before buying any list, ask the seller for the exact wording people agreed to, when and where it was collected, and the lawful basis relied on. If they cannot show you, do not buy. Keep a record of those checks, because the ICO expects you to be able to explain why you believed the data was usable.
Put most of your effort into data you collect yourself with clear consent: it is more accurate, cheaper over time and entirely under your control. Working out which audiences and data sources are worth paying for is part of the digital marketing strategy work I do with UK businesses.
