Zero-party data is information a customer deliberately chooses to tell a business, such as their preferences, what they are shopping for, their budget or how often they want to hear from you. The key word is deliberate: the person knows they are sharing it and usually expects something in return, such as better recommendations.
How zero-party data works
The term sits alongside the older categories. First-party data is what you collect directly from your own customers, much of it observed, such as pages viewed and orders placed. Third-party data is bought or borrowed from others. Zero-party data is a subset of first-party data that is declared rather than observed. Some people simply call it declared data.
It is collected through moments where the customer actively answers:
- a product-finder quiz, such as a skincare brand asking about skin type and concerns;
- a preference centre where subscribers choose topics and frequency;
- a post-purchase survey asking how they heard about you;
- account settings, such as a garden centre asking for postcode and garden size to send relevant planting advice;
- a booking form question about what the customer wants to achieve.
The answers are stored against the customer record in a CRM, email platform or shop system, and used to personalise content, offers and follow-up.
Why it matters
Observed behaviour is a guess. Someone who browses wedding guest dresses might be attending a wedding or buying for a daughter. A person who tells you they are shopping for themselves for an August wedding has removed the guesswork. That makes zero-party data especially useful for email segmentation, product recommendations and deciding what to build next.
It has also become more valuable as tracking has weakened. Visitors declining cookies, browser tracking limits and restrictions on third-party cookies all reduce what businesses can observe. What customers tell you directly does not depend on any of that.
The UK legal position needs stating plainly. The “zero-party” label has no legal standing. Once an answer is linked to a named person, an email address or an account, it is personal data under UK GDPR, with all the usual duties: a lawful basis, a clear explanation of how it will be used, and keeping it no longer than needed. Some answers, such as health conditions in a supplement quiz, can be special category data, which carries stricter rules. And the fact that someone told you their preferences is not consent to send them marketing emails; that still needs its own opt-in under PECR.
Common mistakes
- Treating “they told us” as permission to use the data for anything.
- Asking ten questions when two would do, so people abandon the quiz.
- Collecting preferences and then ignoring them, sending everyone the same emails.
- Asking health or other sensitive questions without considering special category rules.
- Letting answers go stale, so a customer who moved house two years ago still gets offers for the old area.
How to act on it
Pick one decision you would make better if you knew something about each customer, such as which product range to feature in their emails. Ask for that one piece of information at a natural moment, explain why you are asking and what they get, and make it easy to update.
Then prove you used it: the next email should reflect the answer. Review your privacy notice so it describes the data and its purpose, and set a retention period.
Working out which customer data is worth collecting, and how it feeds your channels, is part of the digital marketing strategy work I do with UK businesses.
