In recent years, the way marketers acquire, store, and utilise data has gone through a fundamental transformation. The initial gold rush of every datapoint being up for grabs ended exactly four years ago when, in May 2018, GDPR became official here in the UK. At the same time, customers were already becoming more aware and wary about sharing their information, and scandals like Cambridge Analytica brought spotlights onto the matter.
On the technology side, we saw a transition from the DMP to the CDP approach. For some, DMPs represent the wild west of third-party cookies, with very little regulation about consent or access for the customers. Now, the platform everyone talks about is the CDP. The focus has changed, the customer has gone from being the amalgamation of third-party, unregulated data, to being a empowered and consenting owner of the first-party data they allow brands to store for the purpose of serving them.
You see, this shift is not just about how we approach data in a post-GDPR landscape. It’s also about how consumers are becoming increasingly aware of their privacy rights, which in part gives them the right to access or delete their personal data (i.e., the right to be forgotten). What was previously the odd data deletion request is growing into a task that can not only be time-consuming, but that needs to be done carefully at the risk of facing substantial penalties and fines.
Consequences of Siloed Data
“The cost of processing Data Subject Requests [has] more than doubled.”
— DataGrail
A 2022 survey by DataGrail reported that “the number of Data Subject Access Requests (DSARs) nearly doubled year over year” and that at the same time “the cost of DSARs more than doubled.” It stands to reason that this trend may continue, and what might currently go under the radar as a simple annoyance may quickly become a thorn in the side of many unprepared businesses.
In recent years, the way marketers acquire, store, and utilise data has gone through a fundamental transformation. The initial gold rush of every datapoint being up for grabs ended exactly four years ago when, in May 2018, GDPR became official here in the UK. At the same time, customers were already becoming more aware and wary about sharing their information, and scandals like Cambridge Analytica brought spotlights onto the matter.
On the technology side, we saw a transition from the DMP to the CDP approach. For some, DMPs represent the wild west of third-party cookies, with very little regulation about consent or access for the customers. Now, the platform everyone talks about is the CDP. The focus has changed, the customer has gone from being the amalgamation of third-party, unregulated data, to being a empowered and consenting owner of the first-party data they allow brands to store for the purpose of serving them.
You see, this shift is not just about how we approach data in a post-GDPR landscape. It’s also about how consumers are becoming increasingly aware of their privacy rights, which in part gives them the right to access or delete their personal data (i.e., the right to be forgotten). What was previously the odd data deletion request is growing into a task that can not only be time-consuming, but that needs to be done carefully at the risk of facing substantial penalties and fines.
“UK businesses spend, on average, £1.59 Million and 14 person years annually processing DSARs.”
— GRC World Forums PrivSec Report
Recommendation for DSARs Cost-Reduction
To avoid being sucked down an expensive and arduous DSARs rabbit hole, we recommend completing a customer data audit before it becomes an issue. For example, look at how access requests are handled in practice, how complete they are, how right to be forgotten is managed (including in the context of back-ups), and how opt-outs are stored for the purpose of future exclusion. These are just a few examples of legally grey areas, which, when combined with data silos, could cost dearly.
The heydays of cheap data and few responsibilities are indeed over. Marketers need to ensure their data is centralised and democratised so that it is comprehensive, joined up and easily accessible to reduce any avoidable costs of data deletion and access requests.
Get in touch to learn how Plinc can help you join your data together, providing you with a consolidated Single Customer View that is accessible across the business.
Blog posts
Before You Hand Decisions to AI, Read This
AI will make decisions with whatever data you give it. Most CRM teams are not ready for that. Here is what needs to be true before you hand over the wheel.
Decisions, Decisions: Getting Ready for AI Decisioning
Stuart Russell, Chief Strategy Officer at Plinc, hosted a 30-minute webinar cutting through the AI decisioning conversation to focus on what CRM and loyalty…
The Decisions Behind the Decisions: What AI in CRM Really Depends On
Insights from Plinc’s breakfast briefings in London and Manchester, where senior CRM leaders from Space NK, Secret Escapes, Currys, Secret Sales and Crew…
CRM Resources That Landed Best This Year
CRM leaders are navigating rising expectations around personalisation, prioritisation, and AI decisioning, while trying to focus effort on what will…
Inside the Personalisation Payoff Report: What Customers Really Value in 2025
Personalisation has been at the top of marketing agendas for more than a decade. Yet despite the time, technology and effort invested, many brands are still…
Personalisation in Practice: What We Learned from CRM Leaders in London
Insights from Plinc’s breakfast briefing in London, where senior CRM leaders from Moonpig, Anthropologie Europe and The Body Shop discussed how to build…