Data Privacy & Consent
Two forces changed what marketing measurement can see. The first is legislation: the GDPR, in effect since May 2018, requires a lawful basis such as consent before tracking EU users, and a growing set of US state laws followed. California's CCPA took effect in 2020 and was amended by the CPRA; Utah's Consumer Privacy Act took effect at the end of 2023; Virginia, Colorado, Connecticut, and Texas have passed comparable laws, and more states introduce them each legislative session. The second force is platform policy: Apple's Intelligent Tracking Prevention has restricted cookie lifetimes in Safari since 2017, and App Tracking Transparency, introduced in iOS 14.5 in 2021, made cross-app tracking opt-in. The combined effect is that a portion of visitors never enters the tracking record, and another portion appears as new on every visit. The enforcement exposure belongs on the risk committee's agenda rather than in a marketing review: GDPR fines reach 4% of global annual turnover or 20 million euros, whichever is higher, which prices a tag deployed without a lawful basis as a balance-sheet risk rather than a compliance formality.
How it actually works
The legislation works through consent, and the consent model differs by regime. The GDPR requires express consent: an affirmative opt-in before tracking that is not strictly necessary begins, so a visitor who declines the banner produces no analytics record at all. Most US state laws, including the CCPA, use an implied-consent model: tracking runs by default and stops for residents who opt out. The state laws differ in thresholds and enforcement, and the measurement gap they create grows as each new one takes effect. Plans built on individual tracking should assume the covered share of the audience keeps rising.
The platform policies work through the browser and the operating system. Intelligent Tracking Prevention caps how long cookies persist in Safari, so a returning visitor can be counted as a new one. App Tracking Transparency requires an opt-in prompt before an app can track users across other companies' apps, and most users decline. These effects compound with ordinary behavior: people research on one device and buy on another, and no consented, persistent identifier connects the two.
Measurement designed for these constraints stops depending on individual-level tracking. Controlled experiments and holdouts compare groups, so they need no identifier at all. First-party purchase records measure revenue directly. Where customer-level analysis is needed, it can run on pseudonymous records inside the company's own systems, with consent governing what was collected in the first place.
In practice
The reporting cost of these constraints is specific. Apple's Intelligent Tracking Prevention not only removed advertiser access to user data; it often strips UTMs and metadata, which makes direct or organic channels look like they are pulling in traffic you actually paid for ([bot and AI traffic](/insights/marketing-measurement#bot-and-ai-traffic)). A paid channel then reads as underperforming while an owned channel absorbs its credit. The measurement design that survives this needs no identifier at all: controlled experiments and holdouts compare groups, so a visitor who declines every banner still counts in the result. Our own engagements are built for these constraints. Analysis runs inside the client's own cloud accounts, on pseudonymous records: a customer ID and a zip code, never names, emails, or other directly identifying fields. Those records can be linked back to customers only inside the client's own systems, which is where the retained copies live. Working copies on our side are released two weeks after a project ends, held in that window in case a dataset needs updating.
Where we come in
We design measurement that holds under privacy constraints rather than around them: controlled experiments and holdouts that need no individual tracking, first-party revenue records as the source of truth, and customer-level analysis run inside your own cloud on pseudonymous records.
Start a Revenue Health Pre-Assessment →See it in action
Related terms
- Express vs. implied consent
- Express consent is an affirmative opt-in collected before tracking begins, the GDPR standard. Implied consent lets tracking run until the person opts out, the model in most US state laws. The same visitor produces a full record under one regime and none under the other.
- PII
- Personally identifiable information: names, emails, phone numbers, and other fields that identify a person directly. Privacy law regulates its collection, storage, and transfer.
- Pseudonymization
- Replacing identifying fields with an internal identifier, so records can be analyzed without exposing who they describe. Linking back requires the key, which stays with the data owner.
- Intelligent Tracking Prevention (ITP)
- Apple's Safari feature, introduced in 2017, that restricts cookie lifetimes. Returning visitors can appear new, which understates retention and misattributes conversions.
- App Tracking Transparency (ATT)
- Apple's iOS 14.5 policy requiring an opt-in prompt before cross-app tracking. Most users decline, which removed much of the identifier coverage mobile attribution relied on.
- First-party data
- Data a company collects directly from its own customers with their knowledge: purchases, subscriptions, service history. The measurement substrate least affected by tracking restrictions.
