Second-party data: what it is and when it helps
Second-party data is a partner's first-party data passed to you under an agreement. It helps a DTC brand's attribution when the partner holds exposure or sales data you lack and you can join it, with restricted output and GDPR duties on both sides.
By Joris van Huët, Founder & CEOPublished 5 min read
Second-party data is another company's first-party data, passed to you or joined with yours under an agreement, and it helps a DTC brand's attribution when a partner holds exposure or sales data you lack and you can join it, for example in a clean room. The catch is the output. Clean rooms are built to help stop either side reading raw rows, and in Google's Ads Data Hub each result row typically needs 50 or more users. The GDPR adds its own duties, because two parties who decide the purpose together are joint controllers (Article 26).
What is second-party data, and who shares what with whom?
These are industry terms, not legal ones: Article 4 of the GDPR defines controller, processor, recipient and third party, and has no term for second-party data. First-party data is what you collect from your own customers and visitors. Second-party data is another company's first-party data, passed to you directly: a retailer's buyer list, a publisher's audience, a partner brand's customer file. Third-party data is gathered by a company with no direct relationship to the people in it, and sold on.
It moves in one of two ways. A file changes hands and you hold the records. Or a clean room joins both sides' data without either side seeing the other's rows: Google's BigQuery documentation describes an environment where multiple parties share, join and analyse their data assets without moving or revealing the underlying data (Google Cloud, updated 24 September 2026). IAB's guideline on clean rooms in commerce, dated 29 September 2026, lists audience overlap, data enrichment, targeting and suppression among the common use cases and says clean rooms aren't the right solution for every data or measurement need. Its full text sits behind a free login, so this post cites only the summary.
What does the GDPR require when you share or receive it?
Three duties to check:
- Roles. Two controllers who jointly determine the purposes and means of processing are joint controllers, and must set out their responsibilities in an arrangement between them (GDPR, Article 26). Shoppers can still exercise their rights against each of you. The UK regulator's guidance uses a co-branded prize draw run by two brands as its example, and says each joint controller is liable for the entire damage unless it can prove it is not in any way responsible (ICO, UK GDPR guidance).
- Transparency. If you receive data about people from a partner, Article 14 requires you, unless an exception applies, to tell them who you are, why you hold the data and where it came from, within a reasonable period and at the latest within one month, or at your first contact with them if that comes sooner.
- Consent. Where processing rests on consent, the controller must be able to demonstrate it (Article 7). Ask the partner for the wording shown and the record. Without them you won't be able to demonstrate consent yourself.
That is a reading of the regulation's text, not legal advice. Have your data protection officer or counsel check the arrangement.
Does second-party data help a DTC brand's attribution?
Attribution asks what your spend caused. Your own orders and sessions already cover your own store, and a holdout answers the causal part without anyone else's data. Second-party data adds what you can't see, such as exposure or sales on a partner's side, and a clean room hands it back in a restricted form. Ads Data Hub's aggregation checks need typically 50 or more users per row, or 10 or more for queries on clicks and conversions only, and rows below the threshold are filtered out (Google, Ads Data Hub documentation). Google's clean-room documentation cautions that analysis rules can miss an unauthorised query designed to extract raw data.
Nothing read for this post reports how much a clean-room join improves measurement accuracy. Treat any such number from a vendor as vendor-published until you see the test behind it.
Five questions before you sign:
- What decision will the joined data change? If the answer is nothing, stop.
- Could a holdout answer it instead? If yes, run that first.
- What comes back, rows or aggregates? Small segments can fall under the minimum count and disappear.
- Can the partner show the consent wording and records behind each record?
- Is there a written arrangement naming each side's role and who answers shoppers' requests?
What the answers mean:
- Pass: a named decision, no cheaper test, aggregates large enough for your segments, consent records in hand and a signed arrangement.
- Fail: any missing piece. Fix it first or skip the deal.
Sources, 30 September 2026: Share sensitive data with data clean rooms (Google Cloud documentation, updated 24 September 2026); Privacy checks in Ads Data Hub (Google for Developers, updated 25 September 2026); Data Clean Rooms in Commerce: Common Use Cases (IAB, 29 September 2026; summary page only); GDPR Articles 4, 7, 14 and 26 (Regulation (EU) 2016/679, text as reproduced by gdpr-info.eu; the official text is in the Official Journal); What does it mean if you are joint controllers? (Information Commissioner's Office, UK GDPR guidance). Vendor documentation describes how the tools work, not how much they improve measurement.
Related answers
Frequently asked questions
What is second-party data?
Another company's first-party data, passed to you directly under an agreement, such as a retailer's buyer list or a publisher's audience. It is an industry term. The GDPR has no category for it and looks at each party's role, such as controller, joint controller or processor.Is second-party data GDPR compliant?
It can be, if roles, transparency and consent are in order: an arrangement between joint controllers (Article 26), information to the people concerned within one month of receiving their data (Article 14), and consent the controller can demonstrate (Article 7). Check the arrangement with counsel.Does second-party data improve attribution?
Where a partner holds exposure or sales data you lack and you can join it, for example in a clean room that returns restricted results. For what your own spend caused, your orders plus a holdout answer it without a partner's data.
Go deeper: Causal attribution, explained.
Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.
Keep reading
Terms in this article
- AttributionAttribution identifies user actions that contribute to a desired outcome and assigns value to each. It reveals which marketing touchpoints drive conversions.
- ClickClick is the action a user takes to interact with a digital advertisement, redirecting them to a website or landing page. Clicks are a fundamental metric for measuring ad engagement and a primary input for click-based attribution models.
- ConversionConversion is a specific, desired action a user takes in response to a marketing message, such as a purchase or a sign-up.
- CookieCookie is a small piece of data stored on a user's computer by a web browser, used for tracking behavior, personalizing content, and remembering preferences.
- GDPRGDPR is a European Union regulation governing data protection and privacy, impacting how businesses collect and process customer data.
- IncrementalityIncrementality measures the true causal impact of a marketing campaign. It quantifies the additional conversions or revenue directly from that activity.
- Incrementality TestingIncrementality Testing measures the additional impact of a marketing campaign. It compares exposed and control groups to determine causal effect.
- SessionA Session is a group of user interactions with your website within a given timeframe. It can include multiple page views, events, and transactions.