zero-party data 9 min read

Zero-party data: consent-based collection beyond third-party cookies

Published on EBM Solution

A customer preference interface collecting declared data with consent

Zero-party data is the concrete answer to the end of third-party cookies. Their definitive sunset, repeatedly announced and postponed by Google Chrome, is less a technological threat and more an opportunity to rethink the relationship between companies and users in data collection. While large international players have already invested millions in enterprise solutions, small companies face a fork: keep depending on opaque advertising infrastructure, or build direct relationships based on data users share voluntarily. The progressive phase-out of third-party cookies is not only a regulatory matter. It reflects growing awareness among European users: according to Salesforce's State of the Connected Customer report, 63% of consumers believe most companies are not transparent about how they use shared personal data. The same expectation now extends to accessibility and sustainability, which weigh on the same purchase decision. The alternative is zero-party data: information the user intentionally and proactively shares with a company, in exchange for a value perceived as real. An explicit declaration of preferences, needs and expectations, rather than hidden tracking. The challenge for small companies is understanding how to implement consent-based data collection without spending tens of thousands of euros on enterprise platforms.

What zero-party data are and why they matter now

Zero-party data are a distinct category in the business data ecosystem. Unlike first-party data, collected passively through cookies and behavioural tracking, zero-party data come from a deliberate user action: filling in a product profiling quiz, expressing preferences in a personalised preference centre, answering incentivised surveys. The key distinction is intentionality: the user actively chooses to communicate relevant information, rather than being observed.

Second-party data are essentially a commercial partner's first-party data shared under specific agreements, while third-party data come from external aggregators with no direct relationship with the user. That last category, built on cross-site tracking cookies, is the one being progressively phased out, for both regulatory reasons and the technology choices of the main browsers.

Under the GDPR, zero-party data rest mainly on Article 6(1)(a): the data subject's explicit consent for specific purposes. This makes them intrinsically more solid than constructions based on legitimate interest or other weaker legal bases. Collection happens through transparent notices that clearly explain what will be collected, why and how it will be used.

The European regulatory context is evolving further. The Digital Omnibus package, presented by the European Commission in November 2025 and expected to enter into force no earlier than 2027, promises a simplification of privacy rules without introducing new obligations. It is a reorganisation that could reduce the adjustment burden for SMEs, particularly on managing consent for cookies and online tracking. In Italy, transposition will require at least two legislative decrees with the involvement of the Data Protection Authority.

Collection frameworks for SMEs: beyond the quiz

Zero-party data collection requires strategic design, not improvisation. The most widespread method is the product profiling quiz, particularly effective in e-commerce: the user answers questions on preferences, style and budget and receives personalised recommendations in return. The classic example is beauty, where configurators guide the user towards products compatible with skin type, scent preferences or specific needs.

Preference centres are a more sophisticated solution: interfaces where the user actively manages which communications to receive, at what frequency and on which channels. This is an ecosystem where the user declares granular interests, beyond a simple newsletter opt-out. A furniture company could let customers choose between new modern kitchens, space-saving solutions and sustainable products, with weekly or monthly cadence.

Incentivised surveys work on a give-and-take logic: a percentage discount, premium content or early access to new products in exchange for detailed information. The key lies in balancing the perceived value of the incentive against the effort required. Surveys that are too long or invasive generate abandonment even with substantial incentives.

All these methods share one critical point: user experience design. A badly designed quiz with ambiguous or too many questions produces abandonment rates above 70%. The issue is strategic rather than technical: it takes UX design skill, deep knowledge of the target and the ability to build paths the user perceives as useful to them, not only to the company. This is why many do-it-yourself implementations fail despite accessible tools.

Accessible tools: possible democratisation with caveats

The market for zero-party data tools has expanded considerably, making solutions once reserved for big players accessible to small companies too. Typeform is probably the best-known option, with plans starting at 29 dollars a month for Basic, up to 99 dollars for Business with priority support and advanced filters. Its conversational one-question-per-page interface favours completion on mobile, but costs grow quickly with response volume.

Jotform sits in a similar range, with Bronze at 34 dollars a month for a thousand submissions and Gold at 99 dollars with higher limits. Its architecture is more traditional than Typeform's, favouring complete forms over conversational flows, but it offers a wider ecosystem of integrations and workflow automation.

Tally emerges as a radical alternative: unlimited forms with unlimited submissions in a fully free tier, monetising through optional premium features. For a micro-enterprise taking its first steps in zero-party data, it can be the ideal starting point to validate the approach without financial commitment.

The comparison with enterprise Customer Data Platforms highlights the gap. Solutions such as Segment or mParticle, designed to unify complex data flows across hundreds of integrations, start at five thousand dollars a month for mid-market configurations and can exceed twenty thousand for enterprise deployments. The difference is architecture as much as price: enterprise CDPs handle real-time synchronisation across dozens of systems, data validation through predefined schemas and unified customer profiles through advanced identity resolution.

For a small company with revenue under one million euros, these investments are simply out of reach. The democratisation promised by tools under a hundred euros a month is real, but it comes with a trade-off: you gain the ability to collect declared data, not an integrated ecosystem that processes it automatically across the whole technology stack. Strategy is therefore needed: define clearly which data you need, how it will be used and which integrations are genuinely necessary before investing even a few hundred euros a month.

Concrete ROI metrics: beyond vanity metrics

Consent-based data collection is economically justified when it generates measurable results. The form completion rate is the entry metric: the percentage of users who start and finish the profiling path. A realistic benchmark ranges between 40% and 60% for well-designed quizzes with a clear incentive. Values below 30% signal problems in the user experience or the value proposition.

The quality of the leads generated through consent-based collection is measured by comparing sales qualified leads and marketing qualified leads. A lead that has explicitly declared budget, timing and preferences has a significantly higher conversion probability than a contact collected through generic forms. In Italian e-commerce, where the average conversion rate sits around 2.5%, even increases of a few percentage points produce significant economic impact.

A representative case is an Italian retail e-commerce business that implements a product profiling quiz in the clothing category. Before implementation, the conversion rate is 2%. After introducing a quiz that collects style preferences, budget and occasions of use, users who complete profiling show a 3.5% conversion rate. On ten thousand monthly visitors with an average basket of fifty euros, the increase generates around seven thousand euros of additional monthly revenue.

Reducing customer acquisition cost is the long-term strategic impact. Advertising campaigns based on audiences built through consent-based collection show higher response rates because targeting is more precise. These are explicit declarations, not behavioural inferences: if a user declares an interest in sustainable products with a budget above one hundred euros, a campaign on that specific category does not waste impressions on unqualified users.

GDPR compliance in the Digital Omnibus era

Regulatory compliance for consent-based collection rests on three pillars: a transparent notice, a solid legal basis and a technically implemented right of withdrawal. The notice must explain in clear language which data is collected, for which specific purposes it will be processed, how long it is kept and whether it is shared with third parties. Consent must be granular: specific choices for different purposes, not a single acceptance for everything.

The legal basis under Article 6 of the GDPR is explicit consent for marketing and profiling. This means consent cannot be pre-selected: the user must take an active step such as ticking a checkbox. Consent must also be withdrawable as easily as it was given, a requirement many implementations neglect, limiting themselves to cumbersome withdrawal procedures.

The most common mistakes in SME implementations concern exactly these aspects. Pre-selected consents, purposes described vaguely such as improving our services, missing information on retention periods, unclear or technically broken withdrawal procedures. Each of these shortcomings exposes a company to user complaints and potential sanctions, which can reach 4% of global turnover for serious breaches.

The Digital Omnibus, while promising simplifications, will not remove these fundamental obligations. Its stated goal is to reorganise existing rules to make them more applicable, not to reduce protections for data subjects. For small companies this means specialised legal advice during setup remains necessary: installing a tool and starting to collect data is not enough.

When it makes sense to invest in zero-party data

Zero-party data collection is not a universal strategy for any business. It requires a minimum traffic volume to generate statistically significant datasets. A company with fewer than a thousand monthly visitors will hardly benefit immediately from complex profiling quizzes: the absolute numbers of qualified leads will be too low to justify the design and implementation investment.

The signals that indicate maturity for this approach include a customer return rate above 30%, a lifetime value per customer above five hundred euros and a marketing strategy already oriented towards personalisation. If the company still sends the same newsletter to the entire database without segmentation, the problem is using better what is already available, not collecting more data.

The low-cost alternative to test the approach is progressive forms: instead of asking for all information at the first interaction, build the profile gradually through successive micro-interactions. Each time the user returns to the site, a simple question in exchange for a small benefit. This reduces initial friction and lets you validate user interest in voluntary profiling mechanics without substantial investment.

The preliminary assessment needed to decide whether to proceed requires skills beyond operational marketing: understanding of existing data flows, the ability to estimate ROI on conservative assumptions, and knowledge of legal implications. Professional support in the diagnostic phase can prevent ineffective investments or, worse, non-compliant implementations that create regulatory liabilities instead of strategic value.

Have a project in mind?

Do you know where to start?

The goal is to pin down the problem, the priorities and the timing.

Book a first call

Frequently asked questions

What are zero-party data?

Information users intentionally and proactively share with a company, for example by filling in a profiling quiz or expressing preferences in a preference centre. Unlike first-party data, collected passively, zero-party data come from a deliberate user action.

Why are they more solid than third-party data?

Because they rest on the data subject's explicit consent for specific purposes under Article 6(1)(a) of the GDPR, and because they do not depend on cross-site tracking cookies, which are being phased out.

Do small companies need expensive platforms?

No. Tools such as Typeform, Jotform or Tally allow collection at low or zero cost. What they do not provide is an integrated ecosystem that processes data across the whole stack, so a clear strategy on which data to collect and how to use it is essential.

When is investing in zero-party data worthwhile?

When there is a minimum traffic volume, a customer return rate above 30%, a lifetime value above five hundred euros and a marketing strategy already oriented towards personalisation. Below that, it is better to use the data already available more effectively.

Sources

Salesforce — The State of the Connected Customer report, consumer transparency expectations: https://www.salesforce.com/resources/research-reports/state-of-the-connected-customer/

European Commission — Digital Omnibus package, presented November 2025: https://digital-strategy.ec.europa.eu/en/policies/digital-omnibus

Regulation (EU) 2016/679 (GDPR), Article 6 — lawfulness of processing: https://eur-lex.europa.eu/eli/reg/2016/679/oj

Osservatorio Netcomm-Politecnico di Milano — Italian e-commerce conversion rates: https://www.osservatori.net