Consent and privacy feel like they block personalisation because most teams store permission far from the profile it governs. The fix is to treat consent as a first-class data type inside the customer record, captured once and enforced everywhere downstream. Do that, and privacy stops fighting revenue.
A marketer builds a segment, runs the campaign, and then legal asks one simple question. Can you prove every person in that list opted in for this use. Silence. Nobody can, because consent sits in one system and the segment was built in another. So the team does the safe thing and stops personalising. That is how privacy quietly kills revenue.
Why consent feels like it kills personalisation
Consent is usually captured well and stored badly. A cookie banner or a preference centre records the permission, writes it to a consent log, and there it stays. The profile that drives your campaigns never sees it. The activation systems never read it. So when a team wants to personalise, they cannot tell, per person, what they are allowed to do.
Faced with that uncertainty, people freeze. They either over-collect and risk a breach, or they under-use good data out of fear. Both cost money. The one who freezes leaves revenue on the table. The one who guesses wrong invites a fine.
The rules make the freeze worse, because they differ by region and keep changing. GDPR in Europe, PDPA in Singapore, a different rule in the next market. Any team that hard-codes a fixed compliance build finds it out of date on arrival. So they treat every campaign as a legal question rather than a data one. That is the real tax on personalisation, and it is self-inflicted.
The evidence
Half of companies feel this drag directly. 50% say recent privacy regulation has made personalisation harder (Twilio/Segment, via Contentful). That is not marketers inventing an excuse. The friction is real.
But look at where it comes from. The rules did not remove your right to personalise. They removed your right to do it without recorded permission. The companies that struggle are the ones who cannot answer, at the individual level, what they are allowed to do. The companies that cope have made consent part of the customer record, so the answer is already there when they need it.
I ran loyalty programmes where permission was the whole basis of the relationship. At dunnhumby, Tesco Clubcard worked because millions of people had knowingly opted in, and that permission travelled with the record. Consent was not a compliance afterthought. It was the asset. Treated that way, it enabled personalisation rather than blocking it.
Is this you?
Five quick checks. Answer each yes or no.
- If legal asked today, could you prove consent for every person in your last campaign?
- Does your consent live in a separate tool that your profile and activation systems never read?
- When someone opts out in one channel, do they still get messaged in another?
- Do your teams under-use good customer data because nobody is sure what is allowed?
- Is your privacy handling a hard-coded build rather than a rule you can change when the law does?
Three or more yes answers means consent is a source of risk and hesitation, not a source of confidence.
What it costs
The cost of getting this wrong runs two ways, and both are expensive.
On one side, exposure. A campaign sent to people who never agreed is a breach waiting to be reported. Regulators fine it, customers remember it, and trust does not come back cheap. On the other side, timidity. Teams so unsure of the rules that they stop personalising at all, and hand the advantage to a competitor who solved the plumbing.
Then there is the drag in between. Every campaign that stalls while someone checks the legal position by hand. Every segment rebuilt because the first one could not be verified. This is not a fine. It is friction, paid daily, and it caps how fast you can act.
Three moves that get you unblocked
The direction is simple to state. Make consent behave like any other trusted field on the profile.
Put consent on the profile. Consent should live on the customer record, next to email and purchase history, with the purpose and region attached. Not in a log nobody queries. When permission is a field on the profile, every downstream system can read it before it acts. This is the same discipline as ending fragmentation: one master record everything defers to, covered in fragmented customer data.
Enforce it everywhere downstream. Capture once, enforce everywhere. The activation systems, the email tool, the ad platform, all read the consent field before they send. An opt-out in one channel suppresses the person in all of them. That single rule removes most of the breach risk and most of the hesitation in one move.
Store the rule, not the build. Regions differ and the law keeps moving, so never hard-code compliance into a fixed system. Keep consent as data, let policy decide what each region and purpose permits, and change the policy when the law changes. The data model stays stable while the rules move under it.
Done well, this also answers a related fear. Personalisation that respects recorded consent is personalisation customers agreed to, which is the opposite of the creepiness problem covered in personalising without the creepiness.
Get the full consent-as-a-data-type playbook.
Manage it. Do not let it own you.
Here is the opinion I will defend. Consent is a solved discipline, and that is exactly why it should not consume your roadmap. The category is well understood and well staffed. Consent platforms exist, policy teams exist, the patterns are known. The marginal return on more consent work is lower than the return on fixing fragmentation or closing the gap between insight and action.
So get consent to first-class-data-type standard, keep it clean, and stop there. Privacy is a floor you build once and maintain, not a project you keep reopening. The revenue is in what you do with the permission you have earned. Spend your best people there.
Go deeper on customer data maximization
Three ways forward. Pick the one that fits where you are.
- Get the playbook. Practical notes on turning the customer data you already own into revenue, straight to your inbox. Join the newsletter at the foot of this page.
- Take the assessment. Score your customer data maximization in four minutes and see your top revenue blockers. Start the assessment →
- Book a meeting. Bring your data problem. Leave with a prioritised fix, not a platform pitch. Book a call →
Post 5 of 25 in the Customer Data Maximization series. Previous: Why does data governance fail, and how do you make it drive revenue?. Next: Is the third-party cookie back? What the reversal really means.
Frequently asked questions
Does privacy regulation actually make personalisation harder?
Half of companies say it does. 50% report that recent privacy regulation has made personalisation harder (Twilio/Segment, via Contentful). The friction is real, but most of it comes from storing consent apart from the profile it governs, not from the rules themselves. Fix the plumbing and the friction drops.
What does treating consent as a data type mean?
It means consent lives on the customer profile as a field, next to email and purchase history, not in a separate consent tool nobody queries. Every downstream system reads that field before it acts. Capture the permission once, enforce it everywhere, and no campaign runs on a person who said no.
Do you need a consent management platform?
Most teams already have one, and that is fine. The platform captures and records consent well. The gap is enforcement: the permission has to reach the profile and the activation systems that read it. A platform that logs consent but does not feed the profile leaves you exposed and slow.
How do you handle privacy rules that differ by region?
Store the rule, not a hard-coded build. Regions differ and change, so any fixed compliance build is out of date on arrival. Keep consent as data on the profile, with the region and purpose attached, and let policy decide what each region permits. The data model stays stable while the rules move.
Is consent worth heavy investment compared to other data problems?
Manage it well, but do not let it crowd out activation. The discipline is well understood and well staffed, so marginal effort returns less than fixing fragmentation or the activation gap. Get consent to first-class-data-type standard, keep it clean, then put your energy where the revenue is.