First-party data is information that an organisation collects directly from the people it serves, through channels it owns. A retailer's purchase history, a publisher's subscriber logins, an app's event logs and a bank's CRM (customer relationship management) records all fit. The "first party" is the company holding the direct relationship, which separates such records from data bought from, or passed on by, other companies. The category matters in advertising because targeting and measurement need audiences and proof of results, while browsers, mobile operating systems and regulators have narrowed the supply of data that travels between companies. Records about a firm's own customers face fewer of those limits, since a legal basis for processing, usually consent, can be secured at the moment of collection.

From collection to activation

The first step is collection. A tag on a website or an SDK (software development kit) inside an app logs page views, searches, basket additions and purchases. Sign-in and checkout forms add email addresses, phone numbers or customer numbers, while shops, call centres and loyalty schemes supply offline records. Server-side collection, in which the advertiser's own server forwards events to ad platforms instead of the browser doing so, has spread as browsers restrict scripts.

Governance comes next. The GDPR (General Data Protection Regulation), adopted on April 27, 2016 and applicable since May 25, 2018, requires consent to be freely given, specific, informed and unambiguous, as PPC Land's explainer on consented data sets out. The choice then travels as a signal: a TC String under the Transparency and Consent Framework of the IAB (Interactive Advertising Bureau) Europe, a Global Privacy Platform string, or a Google Consent Mode state. Consent Mode V2, added in December 2023, introduced the ad_user_data and ad_personalization parameters, and Google began disabling personalisation, remarketing and conversion tracking for UK and EEA advertisers without a working setup on July 21, 2025.

Unification follows. Records are merged in a CRM or a CDP (customer data platform), software that stitches data from separate systems into one profile per person. Joining on an exact key such as a verified email is deterministic matching, as opposed to inferring links from weaker signals such as IP address. Before leaving a company's systems, identifiers are normalised (trimmed, lowercased, phone numbers set to international format) and hashed with SHA-256, producing a 64-character string, according to Google's Customer Match documentation. A formatting error is not rejected; the record simply fails to match.

Activation is the last step: uploading audiences, sending conversion events, attaching signals to bid requests, or joint analysis in a clean room, a governed environment where two parties combine datasets and only aggregate results leave.

Buy-side and sell-side use

On the buy side, an advertiser or its agency loads customer lists into platform audience tools. Google announced Customer Match in September 2015, according to MarTech, letting advertisers target uploaded email lists across Search, Gmail and YouTube. Meta's custom audiences follow the same principle. Google's developer documentation recommends uploading at least 5,000 members per list and caps membership at 540 days.

The plumbing has since been consolidated. Google launched the Data Manager API on December 9, 2025, one interface for sending audiences and conversions to Google Ads, Google Analytics and Display & Video 360. Each cloud project is limited to 100,000 requests a day and 300 a minute, with up to 10,000 audience members per request. Conversion uploads, such as enhanced conversions, attach hashed customer details to an event so that sales can be attributed.

On the sell side, publishers work from logged-in audiences. Google's PPID (Publisher Provided Identifier), announced in March 2021, is a string of 22 to 150 characters that a publisher generates, hashes or encrypts, and passes to Google Ad Manager for frequency capping, segmentation and targeting across sessions. According to Google's help page, PPID needs Ad Manager 360, must be re-sent after 180 days of inactivity, and applies in programmatic only where third-party cookies or device IDs are absent. Passing PPIDs to non-Google bidders is unavailable in the EEA, Switzerland, the UK and listed US states.

Outside Google's stack, Prebid.org documentation places publisher segments in the OpenRTB (Open Real-Time Bidding) user.data and site.content.data objects, with a segtax value naming the taxonomy. Seller-defined audiences, finalised by IAB Tech Lab on February 24, 2022 and renamed Curated Audiences on December 16, 2024, use that route to send numeric audience codes in place of identifiers.

Origin and evolution

The vocabulary comes from browser cookies, where a first-party cookie is set by the domain a person visits and a third-party cookie by another domain embedded in the page. Digital use of customer lists grew from the mid-2010s, with Customer Match in 2015 as a marker.

Browser and platform changes then raised the value of owned records. WebKit's ITP (Intelligent Tracking Prevention) 2.1, published on February 21, 2019, capped JavaScript-written cookies at seven days. Version 2.2, announced on April 24, 2019, cut that to one day when a visitor arrived through a link carrying a query string or fragment from a domain classified as a cross-site tracker. Mozilla's Marissa Wood announced on September 3, 2019 that Firefox would block third-party tracking cookies for all users. Apple's App Tracking Transparency framework, requiring permission to track, took effect with iOS 14.5 on April 26, 2021.

Chrome followed a different path. Google announced in January 2020 that it would phase out third-party cookies, then reversed: on April 22, 2025, Anthony Chavez said Chrome would keep its current approach to cookie choice, and on October 17, 2025 Google retired most Privacy Sandbox technologies citing low adoption.

Industry standards addressed provenance. IAB Tech Lab's Data Transparency Standard 1.0 arrived in July 2019, asking data providers to disclose segment recency, provenance and criteria, in the manner of a nutrition label.

Why it matters to marketers

Owned records determine how much budget reaches known customers, how well automated bidding is fed and how sales are credited. An IAB Tech Lab article by Andreea Mandeal of iubenda, covered by PPC Land on May 12, 2026, argued that consent must mature before activation tooling. The piece cites a July 2023 Deloitte Digital report commissioned by Meta, which found 18 percent lower acquisition costs and 27 percent higher conversion rates for businesses using such data for tailored experiences. A platform with a commercial interest paid for that research.

Google packages the argument as data strength, a four-step framework of connection, signal enrichment, activation and proof, explained by PPC Land on September 5, 2026. Google reports an 11 percent average rise in Search conversions for enhanced conversions over standard imports; the figure is self-reported.

Limitations and disputes

Scale is the first constraint. A company knows only people who have bought, signed in or subscribed, so prospecting still depends on other sources.

Quality is the second. Firmable surveyed 222 B2B sales professionals in research released on September 9, 2026; respondents estimated that 32 percent of their CRM contact and account records were inaccurate, incomplete or outdated. The sample is small, self-reported and confined to B2B.

Law is the third. On June 1, 2026 Norway's Datatilsynet fined two Elkjop companies NOK 20 million, about EUR 1.85 million. The retailer's loyalty club required members to accept all processing at once, and club data had been reused for Customer Match without a compatibility assessment. A misconfigured consent banner can also hurt delivery: one agency account reported conversions falling 90 percent overnight when consent signals never reached Google's tags, as PPC Land reported on April 10, 2026. The case is a single anecdote.

Hashing is no shield. The FTC wrote on July 24, 2024 that hashed data is not anonymous, because a hash works as a persistent identifier, and that misdescribing it can be a deceptive practice.

Gatekeepers face a further rule. Article 5(2) of the Digital Markets Act bars designated gatekeepers from combining personal data across their own services without GDPR-standard consent. The Commission found in April 2025 that Meta's consent-or-pay model breached it and imposed a EUR 200 million fine, while Meta's 2026 compliance report disputes that reading, as the PPC Land explainer on the Digital Markets Act records.

Finally, concentration is contested. Critics of the data strength approach note that each step moves decisions into one vendor's stack, measured by that vendor's tools.

Not the same as

Zero-party data is what customers volunteer on purpose, such as stated preferences or quiz answers; Forrester Research is credited with the term, according to Zuora. Second-party data is another company's first-party data, passed on under a direct agreement without exclusive rights. Third-party data comes from firms with no relationship to the people described; the data broker explainer covers that trade. A first-party cookie is a storage mechanism, not a category of data: a browser may expire it in seven days or less, yet the information it points to remains owned data.

Recent developments

Platform rules continue to shift. Customer Match uploads through older Google Ads API routes closed on April 1, 2026 to developers without recent activity, after Google told developers to move to the Data Manager API. On May 28, 2026 Google added IP addresses to Customer Match uploads, excluding users in the EEA, the UK and Switzerland, and promised higher match rates from the third quarter. On September 10, 2026 Google introduced a Data Strength Uplift Metric for Google Ads; its calculation method is not described in PPC Land's coverage.

Browsers remain a risk. Safari in iOS 27 blocks requests to a list of ad tech domains, including those of ID5, PPC Land reported on October 3, 2026. ID5's chief executive, Mathieu Roche, called the change "an attack against the business model of the web". Permutive's chief executive, Joe Root, estimated that about 30 percent of web traffic is addressable.

Timeline

  • September 2015: Google announces Customer Match for Search, Gmail and YouTube.
  • April 27, 2016: GDPR adopted.
  • May 25, 2018: GDPR becomes applicable.
  • February 21, 2019: WebKit publishes ITP 2.1, capping JavaScript-written cookies at seven days.
  • April 24, 2019: WebKit announces ITP 2.2, with a one-day cap for cookies on pages reached through decorated links.
  • July 2019: IAB Tech Lab announces Data Transparency Standard 1.0.
  • September 3, 2019: Mozilla blocks third-party tracking cookies by default for all Firefox users.
  • January 2020: Google announces plans to phase out third-party cookies in Chrome.
  • March 2021: Google announces Publisher Provided Identifiers for publishers.
  • April 26, 2021: Apple's App Tracking Transparency requirements take effect with iOS 14.5.
  • February 24, 2022: IAB Tech Lab finalises seller-defined audiences 1.0 and Data Transparency Standard 1.1.
  • December 2023: Google adds ad_user_data and ad_personalization parameters in Consent Mode V2.
  • December 16, 2024: IAB Tech Lab renames seller-defined audiences as Curated Audiences.
  • April 22, 2025: Google says Chrome will keep its current approach to third-party cookie choice.
  • July 21, 2025: Google begins enforcing Consent Mode V2 for UK and EEA advertisers.
  • October 17, 2025: Google announces retirement of most Privacy Sandbox technologies.
  • December 9, 2025: Google launches the Data Manager API.
  • April 1, 2026: Customer Match uploads through older Google Ads API routes close to developers without recent activity.
  • May 28, 2026: Data Manager API adds IP address support for Customer Match.
  • June 1, 2026: Norway's Datatilsynet decides the Elkjop case, fining two companies NOK 20 million.
  • September 10, 2026: Google introduces the Data Strength Uplift Metric.
  • October 3, 2026: ID5's chief executive criticises Safari's iOS 27 domain blocking.

Summary

Who: Organisations that hold direct relationships with customers, subscribers or users, among them advertisers, retailers and publishers. Platforms such as Google, Meta and Amazon receive the data for activation, while regulators including data protection authorities, the FTC and the European Commission set the rules.

What: Information collected directly through owned channels, such as purchases, logins, app events and CRM records, then consented, unified, hashed and used for audiences, bidding signals and measurement.

When: Customer-list targeting reached major platforms around 2015. Browser restrictions in 2019, Apple's tracking prompt in 2021 and Chrome's cookie reversal in 2025 shaped its value, and platform tooling consolidated around December 2025 and April 2026.

Where: In advertiser CRM and CDP systems, publisher ad servers, platform audience tools, bid requests under OpenRTB and clean rooms, with the strictest consent rules in the EEA, the UK and Switzerland.

Why: Such records are the most direct basis for consent, feed automated bidding and attribution, and hold up better against browser and platform restrictions than purchased data. Open questions remain over scale, record quality, consent proof, hashing and dependence on a single vendor's tools.