Marketing Data Ethics Checklist: Privacy, Targeting, Consent & AI | AAMA

Printed worksheets outlining customer data governance and analytics processes

Last Reviewed: September 2026

The AAMA Marketing Data Ethics Checklist is designed to help marketers, advertisers, agencies, researchers, analysts, media professionals, technology teams, brands, students, and organizational leaders evaluate whether consumer data are being collected, combined, analyzed, shared, targeted, retained, and used responsibly.

Modern marketing can involve information from websites, apps, customer relationships, purchases, loyalty programs, advertising platforms, research panels, third-party vendors, data brokers, connected devices, artificial intelligence, customer-service systems, and inferred behavioral characteristics. The existence of these capabilities does not mean every available use of the data is appropriate.

This checklist focuses on professional judgment as well as compliance. Privacy laws and regulatory requirements vary by jurisdiction and industry, and particular forms of information may be governed by specialized rules. This resource is educational and should not be treated as legal advice.

1. Identify the Business Purpose

Why are these data being collected or used?

Every material data practice should have a recognizable business purpose.

Possible purposes may include:

  • Completing a transaction
  • Providing a service
  • Measuring a campaign
  • Understanding customer behavior
  • Improving a product
  • Conducting research
  • Personalizing communication
  • Preventing fraud
  • Managing customer relationships

Avoid collecting information simply because a platform, form, vendor, or technology makes it possible.

If the organization cannot explain why it needs a data element, reconsider whether it should collect it.

2. Define the Intended Use Before Collection

Is the organization clear about how the information will be used?

Data should not be collected without considering its intended purpose.

Ask:

  • What decision will this information support?
  • Which teams will use it?
  • Which systems will receive it?
  • How long will it remain useful?
  • Will it be shared externally?

Defining use before collection reduces the risk of accumulating information without a legitimate operational purpose.

3. Practice Data Minimization

Are you collecting only what is necessary?

The FTC has long advised businesses to keep only the personal information they need and to avoid collecting sensitive information without a legitimate business reason.

Review every field, identifier, behavioral signal, and enrichment source.

Ask whether the same objective could be achieved with:

  • Less information
  • Aggregated information
  • Anonymous information
  • Shorter retention
  • Fewer data sources

Additional data create additional privacy, security, governance, and reputational risk.

4. Do Not Collect Data “Just in Case”

Is future hypothetical usefulness the only justification?

Organizations sometimes collect information because it might become useful later.

That approach can create repositories of customer information with no defined purpose.

A better standard is:

Collect information because a current legitimate need exists, not because somebody might eventually think of a use for it.

Future uses can be evaluated when they arise.

5. Inventory the Data

Does the organization know what marketing data it possesses?

Maintain an inventory of significant consumer-data categories.

This may include:

  • Names
  • Email addresses
  • Phone numbers
  • Postal addresses
  • Customer IDs
  • Purchase history
  • Website activity
  • App activity
  • Advertising identifiers
  • Location
  • Survey responses
  • Loyalty data
  • Customer-service records
  • Inferred interests

Organizations cannot manage data responsibly when they do not know what they have.

6. Identify Where the Data Came From

Is the source known?

Record whether information came from:

  • Customer submission
  • Transaction
  • Website
  • App
  • Survey
  • CRM
  • Advertising platform
  • Data provider
  • Public record
  • Research panel
  • Business partner
  • Modeled inference

Data provenance matters because the appropriate use of information can depend heavily on how it was originally obtained.

7. Distinguish Provided, Observed & Inferred Data

Does the organization understand how the characteristic was created?

Consumer information may be:

Provided: The person directly supplied it.

Observed: The organization recorded behavior such as purchases or website activity.

Inferred: A system predicted a characteristic based on other information.

These categories should not be treated as equivalent.

Do not state that a consumer “told us” something when the characteristic was actually inferred by an algorithm.

8. Evaluate Consumer Expectations

Would the person reasonably expect this use?

A data practice can create concern even when a technical permission exists if the use is far removed from the context in which the information was provided.

Ask:

Would an ordinary customer reasonably expect us to use this information this way?

If the answer is probably not, additional transparency, permission, limitation, or reconsideration may be appropriate.

9. Apply the Explanation Test

Could you explain the practice clearly to the customer?

Describe the data practice without legal or technical language.

For example:

“We use your purchase history to determine which products we advertise to you.”

If the organization would be uncomfortable stating the practice plainly, the practice deserves additional review.

Complexity should not become a substitute for transparency.

10. Review Privacy Representations

Does actual practice match what the organization tells people?

Review:

  • Privacy policies
  • Consent notices
  • Signup language
  • App permissions
  • Advertising disclosures
  • Customer-service explanations
  • Vendor agreements

Do not promise one level of privacy while operating another system internally.

A privacy statement is an advertising and trust commitment as well as a legal document.

11. Make Consent Meaningful

Is consent understandable and freely given where it is required?

Consent should not depend on confusion.

Review whether the person can understand:

  • What they are agreeing to
  • Which data are involved
  • Why the data are being used
  • Whether data will be shared
  • How to change the choice

Consent becomes less meaningful when the interface is intentionally designed to produce agreement without understanding.

12. Avoid Manipulative Consent Interfaces

Is the interface steering people unfairly toward the organization’s preferred choice?

Review for:

  • Preselected boxes
  • Hidden decline options
  • Repeated interruptions
  • Confusing button labels
  • Misleading colors
  • Unequal visual prominence
  • Complicated opt-out paths

A choice should remain a genuine choice.

Do not design privacy controls primarily to wear people down until they agree.

13. Make Declining Reasonable

Can someone refuse without navigating an obstacle course?

If a marketing preference can be accepted in one click but requires multiple screens to decline, reconsider the design.

The objective should be to capture a real preference rather than maximize nominal consent.

14. Separate Necessary Processing From Marketing

Is optional marketing being bundled with something required?

A customer may need to provide information to:

  • Complete an order
  • Create an account
  • Receive a service
  • Obtain customer support

That does not automatically mean every subsequent marketing use is necessary.

Distinguish operational data requirements from optional promotional uses where appropriate.

15. Review First-Party Data

Is first-party data being treated as automatically risk-free?

Information obtained directly through the customer relationship may include valuable behavioral history.

Examples include:

  • Purchases
  • Website activity
  • App usage
  • Loyalty behavior
  • Email engagement

First-party status does not eliminate privacy obligations or ethical concerns.

The use should still be relevant, proportionate, secure, and consistent with reasonable customer expectations.

16. Review Third-Party Data

Do you understand where purchased or licensed data originated?

Before using third-party information, ask:

  • Who collected it?
  • From whom?
  • For what purpose?
  • What permissions existed?
  • Was the information inferred?
  • How current is it?
  • Can the provider document provenance?
  • What uses does the license permit?

Do not assume a data vendor has resolved every privacy concern simply because it sells the dataset commercially.

17. Evaluate Data Brokers Carefully

Is the organization buying audience information it could not comfortably collect directly?

Third-party audience products can contain detailed behavioral, demographic, geographic, and inferred information.

Marketers should understand both the usefulness and the provenance of those data.

If a dataset reveals information that would feel intrusive if requested directly from customers, that is a reason for more scrutiny, not less.

18. Verify Vendor Claims About Data Sources

Can the provider substantiate how the data were obtained?

Marketing vendors sometimes make extraordinary claims about their ability to identify behavior, conversations, interests, or customer intent.

Require evidence.

Ask:

  • What is actually measured?
  • What is modeled?
  • Which devices are involved?
  • What permissions exist?
  • Is the capability technically demonstrated?
  • Is the vendor’s explanation internally consistent?

Do not repeat unusual vendor claims to clients without verification.

19. Review Sensitive Information

Are the data especially private or consequential?

Sensitive categories may include information involving:

  • Health
  • Finances
  • Precise location
  • Children
  • Government identifiers
  • Biometrics
  • Sexual activity
  • Major life circumstances
  • Other highly personal matters

Additional restrictions may apply legally, but ethical review should begin even before reaching the legal question.

Ask whether the marketing purpose genuinely justifies using the information.

20. Use Health Information With Extra Care

Could the data reveal a health condition or concern?

Health-related information can arise outside hospitals or medical practices.

It may come from:

  • Apps
  • Search behavior
  • Purchases
  • Wearable devices
  • Surveys
  • Customer-service conversations
  • Inferred interests

Do not assume health information is ethically unrestricted simply because the organization is not covered by HIPAA.

Specialized federal and state requirements may still apply.

21. Protect Precise Location Data

Does the marketing objective genuinely require exact location?

Precise location can reveal highly sensitive behavior.

Depending on context, it may indicate visits to:

  • Medical facilities
  • Religious institutions
  • Schools
  • Homes
  • Political events
  • Support services

Consider whether broader geographic information would accomplish the objective.

The ability to identify where someone physically went should not automatically become an advertising opportunity.

22. Review Children’s Data

Could the audience or dataset involve children?

Children’s personal information requires specialized treatment.

The FTC’s updated Children’s Online Privacy Protection Rule applies to covered services involving children under 13 and includes requirements involving consent, data use, disclosure, retention, and targeted advertising.

Marketing teams should identify child-directed products and services early rather than discovering the issue after data collection begins.

23. Avoid Using Children as Behavioral Targets Without Appropriate Review

Does targeting rely on detailed behavioral information about children?

Even where a campaign appears commercially attractive, additional legal, ethical, developmental, and parental-consent considerations can apply.

Children may have less ability to understand:

  • Advertising intent
  • Data collection
  • Behavioral profiling
  • Persuasive design
  • Long-term consequences

Treat children’s data as a specialized high-risk category.

24. Review Data About Vulnerable Circumstances

Is targeting based on distress or reduced bargaining power?

Examples may include inferred information involving:

  • Debt
  • Job loss
  • Addiction
  • Serious illness
  • Bereavement
  • Housing insecurity
  • Crisis

Ask whether the strategy provides genuinely useful relevance or primarily exploits vulnerability.

A person’s difficulty should not automatically become a conversion opportunity.

25. Review Behavioral Targeting

Is the targeting proportionate to the marketing objective?

Behavioral targeting may improve relevance by using signals such as:

  • Browsing
  • Purchases
  • Content consumption
  • Search behavior
  • App usage

Evaluate:

  • Data source
  • Consumer expectations
  • Sensitivity
  • Frequency
  • Transparency
  • Ability to control preferences

Relevant advertising does not require unlimited surveillance.

26. Review Audience Inferences

Are modeled characteristics being treated as facts?

Algorithms may infer:

  • Income
  • Interests
  • Purchase intent
  • Household characteristics
  • Lifestyle
  • Likelihood to convert

These are probabilistic predictions.

Avoid using them in ways that assume certainty, particularly when the consequence to the person is significant.

27. Review Proxy Variables

Could an apparently neutral variable stand in for something sensitive?

Variables such as:

  • ZIP code
  • Device type
  • Shopping behavior
  • Language
  • Browsing patterns

can correlate with demographic or sensitive characteristics.

Models may therefore create outcomes that were never explicitly requested.

Review what the targeting system actually does, not simply which variables were intentionally supplied.

28. Check for Discriminatory Outcomes

Could targeting unfairly exclude people from opportunities?

Pay particular attention when marketing involves areas such as:

  • Employment
  • Housing
  • Credit
  • Education
  • Financial services
  • Other consequential opportunities

Review who receives and does not receive advertising.

A system can create problematic outcomes even without an explicit instruction to discriminate.

29. Audit Outcomes

Are you checking the actual distribution of the campaign?

Do not evaluate only inputs.

Where appropriate, review:

  • Geographic delivery
  • Demographic patterns
  • Offer distribution
  • Exclusions
  • Conversion patterns
  • Audience composition

Responsible data practice includes examining consequences.

30. Review Lookalike Audiences

Do you understand what the model is optimizing for?

Lookalike and predictive audiences may identify patterns invisible to the marketer.

That can improve campaign performance while also introducing hidden correlations.

Use additional caution when the seed audience or advertising category involves sensitive or consequential characteristics.

31. Review Retargeting

Does the retargeting remain useful rather than intrusive?

Repeatedly advertising the same product after someone has viewed a page can become uncomfortable or wasteful.

Review:

  • Frequency
  • Recency
  • Purchase status
  • Sensitive categories
  • Campaign duration

Someone who already purchased the product usually should not continue receiving acquisition advertising indefinitely.

32. Control Frequency

Does behavioral data allow the same person to be targeted excessively?

More impressions are not automatically better.

Excessive targeting can produce:

  • Irritation
  • Privacy concerns
  • Negative brand perception
  • Wasted spending

Use frequency limits where appropriate and evaluate the experience from the customer’s perspective.

33. Review Cross-Device Tracking

Would consumers reasonably understand that their activity is being connected across devices?

Cross-device systems can combine activity from:

  • Phones
  • Computers
  • Tablets
  • Connected televisions
  • Other devices

Understand how identities are resolved and whether the approach aligns with privacy representations and applicable requirements.

The technical ability to connect devices does not eliminate the need for responsible governance.

34. Review Identity Resolution

How certain is the organization that records belong to the same person?

Identity systems can produce incorrect matches.

Errors may cause:

  • Misdirected personalization
  • Incorrect profiles
  • Privacy exposure
  • Faulty attribution

Understand the confidence and limitations of deterministic and probabilistic identity methods.

35. Review Personalization

Does personalization provide value without revealing too much?

Useful personalization might involve:

  • Remembering preferences
  • Recommending related products
  • Providing relevant content

Uncomfortable personalization may reveal details the customer did not expect the marketer to know.

Ask:

Does this improve the experience, or does it mainly demonstrate how much information we have collected?

36. Avoid Creepy Precision

Could a less specific message accomplish the same objective?

An advertiser may know that someone:

  • Visited a location
  • Purchased a sensitive product
  • Searched a particular topic
  • Experienced a life event

It is rarely necessary to expose that knowledge directly in the advertisement.

Subtle relevance may provide the same marketing benefit without creating a sense of surveillance.

37. Review Personalized Pricing

Is personal data influencing the price or offer shown to an individual?

Personalized pricing deserves heightened scrutiny because data may affect the economic terms offered to different consumers.

As of September 2026, the FTC is seeking public comment on a proposed enforcement policy statement addressing personalized pricing and the possibility that failure to disclose material use of personal data in setting prices could violate laws the Commission enforces.

Organizations considering personalized pricing should obtain appropriate legal review and think carefully about transparency, fairness, data provenance, and customer expectations.

38. Distinguish Personalization From Price Discrimination

Is data changing content, or changing economic terms?

Showing different product recommendations is different from using personal information to determine how much a particular person may be willing to pay.

Document when algorithms affect:

  • Price
  • Discount
  • Credit
  • Eligibility
  • Offer value

Higher-consequence personalization deserves stronger review.

39. Review Customer Segmentation

Are segments useful without becoming stereotypes?

Segments can help marketers understand patterns.

They should not be treated as though every person within a group has identical:

  • Interests
  • Values
  • Motivations
  • Behavior

Use segmentation as a planning tool rather than a complete description of an individual.

40. Review Research Data

Is information collected for research being reused for unrelated marketing?

People participating in research may expect their responses to be used differently from information submitted for a sales inquiry.

Review whether survey, interview, focus-group, or panel data are being repurposed beyond the context in which they were obtained.

Research participation should not quietly become sales targeting unless that use is appropriate and disclosed.

41. Protect Research Participants

Are individual responses being unnecessarily exposed?

Where individual identity is not required, consider:

  • Aggregation
  • Anonymization
  • Restricted access
  • Removal of identifiers

Do not place identifiable customer quotations or research records into marketing materials without appropriate permission.

42. Limit Internal Access

Does every employee who can access marketing data actually need it?

Use role-based access where practical.

Not every employee needs access to:

  • Full customer records
  • Behavioral profiles
  • Research responses
  • Precise location
  • Sensitive information

Reducing unnecessary access reduces the potential consequences of mistakes and misuse.

43. Review Agency Access

What information does an external agency actually need?

Agencies may require data for:

  • Media
  • Analytics
  • Research
  • Campaign execution

Provide information proportionate to the work.

Do not give outside partners unrestricted access to entire customer databases when aggregated or limited data would accomplish the same objective.

44. Review Vendor Access

Which third parties can access consumer information?

Maintain awareness of:

  • Analytics providers
  • Advertising platforms
  • CRM systems
  • Email platforms
  • Research companies
  • Cloud providers
  • AI services
  • Customer-service platforms

The number of organizations receiving data can grow quickly.

Each connection should have a legitimate purpose.

45. Understand Subprocessors

Can the vendor itself share the data with additional providers?

Review vendor documentation and contracts where appropriate.

An organization may believe it is sharing information with one vendor while the processing chain includes several additional companies.

Understanding the data flow is part of understanding the practice.

46. Review Vendor Retention

How long will third parties keep the data?

Do not evaluate only your organization’s retention policy.

Ask whether vendors:

  • Retain records
  • Create backups
  • Train systems on the data
  • Create derivative profiles
  • Allow deletion

Data are not truly deleted from the marketing ecosystem if downstream partners continue retaining them unnecessarily.

47. Review AI Tools

Is customer or confidential data being entered into an approved AI system?

Before providing information to an AI service, understand:

  • Retention
  • Training use
  • Security
  • Access
  • Contractual protections
  • Deletion
  • Data location

Do not paste customer databases, confidential research, or proprietary client information into unapproved AI tools.

Related AAMA Resource: Responsible AI in Advertising & Marketing Guide

48. Minimize AI Inputs

Does the AI system require identifiable data to perform the task?

Where possible, use:

  • Aggregated information
  • De-identified records
  • Synthetic examples
  • Limited fields

Do not provide more information than the system actually needs.

49. Review AI-Generated Profiles

Are AI inferences being used responsibly?

AI may predict:

  • Churn
  • Purchase likelihood
  • Customer value
  • Interests
  • Sentiment

These outputs can appear precise while containing meaningful uncertainty.

Do not treat a model score as unquestionable truth about a person.

50. Review Marketing Automation

Is automation making decisions that deserve human oversight?

Automated systems can control:

  • Audience selection
  • Lead scoring
  • Personalization
  • Offer selection
  • Message timing
  • Budget allocation

Determine where human review is necessary.

The more consequential the outcome, the stronger the case for oversight.

51. Review Lead Scoring

Could the scoring model unfairly disadvantage certain people or businesses?

Understand which variables contribute to the score.

Review whether:

  • Historical data contain bias
  • Proxy variables are being used
  • Scores are treated as certainty
  • Sales teams understand limitations

Lead scoring should help prioritize effort without pretending to know more than the evidence supports.

52. Review Automated Suppression

Who is being excluded automatically?

Marketing systems may suppress audiences because of:

  • Low predicted value
  • Previous behavior
  • Geography
  • Model score
  • Engagement

Review whether exclusion remains appropriate, especially when the offer involves a meaningful opportunity rather than ordinary consumer promotion.

53. Protect Passwords & Credentials

Are authentication details ever entering marketing datasets?

Customer data exports should not contain:

  • Passwords
  • Security answers
  • Authentication tokens
  • Unnecessary account credentials

Marketing teams generally have no legitimate reason to access this information.

Keep authentication systems separate from ordinary marketing analysis.

54. Protect Payment Information

Does marketing genuinely need access to payment credentials?

Marketing analysis may require:

  • Purchase value
  • Product
  • Date
  • Customer ID

It generally does not require full payment-card information.

Limit access to transaction information necessary for analysis.

55. Establish Retention Periods

How long is each category of marketing data needed?

Retention should reflect:

  • Business purpose
  • Legal requirements
  • Customer relationship
  • Analytical value
  • Sensitivity
  • Security risk

“Forever” should not be the default retention period.

The FTC also advises businesses not to keep sensitive personal information longer than necessary.

56. Delete Data That No Longer Has a Purpose

Is old information accumulating indefinitely?

Review:

  • Former customers
  • Abandoned leads
  • Expired campaigns
  • Old research
  • Historical audience files
  • Duplicate records

Information that no longer provides legitimate value continues creating risk.

Create practical deletion schedules where appropriate.

57. Review Backup Retention

Does deletion include relevant backup systems?

A record removed from the CRM may continue to exist in:

  • Exports
  • Shared drives
  • Analytics systems
  • Vendor platforms
  • Backups

Understand what deletion actually means across the data environment.

58. Secure Marketing Exports

Are customer lists being downloaded unnecessarily?

CSV and spreadsheet exports are easy to create, email, copy, and forget.

Reduce unnecessary local copies and establish procedures for:

  • Storage
  • Sharing
  • Access
  • Deletion

An otherwise secure CRM can be undermined by uncontrolled spreadsheet exports.

59. Avoid Sending Sensitive Data Through Ordinary Email

Is information being shared through an appropriate channel?

Email may not be the right method for transferring sensitive customer datasets.

Use approved secure systems when appropriate.

Convenience should not determine the security standard.

60. Maintain Data Quality

Is the information accurate enough for its intended use?

Poor data can create privacy and fairness problems as well as bad marketing.

Review:

  • Duplicates
  • Incorrect identities
  • Old addresses
  • Incorrect attributes
  • Outdated preferences
  • Wrong household matches

Data ethics includes avoiding decisions based on information the organization knows may be unreliable.

61. Allow Reasonable Corrections

Can inaccurate customer information be corrected when appropriate?

Organizations should establish processes consistent with applicable requirements for handling data-access or correction requests.

Even outside formal rights processes, obvious data errors should not be intentionally preserved simply because they support a convenient marketing profile.

62. Respect Opt-Out Choices

Are customer preferences propagated across systems?

An opt-out is ineffective if one system stops marketing while another continues.

Coordinate preferences across:

  • CRM
  • Email
  • SMS
  • Advertising
  • Customer-service systems
  • Agencies
  • Vendors

Preference management should function as a system, not as an isolated checkbox.

63. Do Not Quietly Restore Opted-Out Users

Could a later data import overwrite the person’s choice?

Merges, migrations, enrichment services, and new marketing platforms can accidentally reactivate suppressed contacts.

Preserve preference history during system changes.

A technical migration should not erase a deliberate customer decision.

64. Review Data Sharing

Is information being shared beyond what is necessary?

Before sending information externally, ask:

  • Who needs it?
  • Why?
  • Which fields?
  • For how long?
  • Under what restrictions?

Sharing a complete customer record because a partner needs one attribute is poor data discipline.

65. Review Data Sale or Commercial Exchange

Does the organization financially benefit from providing customer information to others?

Where information is sold, licensed, exchanged, or otherwise monetized, additional legal and ethical considerations may apply.

The practice should receive specialized review because customers may evaluate commercial data sharing differently from ordinary service processing.

66. Review Measurement Partners

What information does campaign measurement expose?

Advertising measurement can involve:

  • Customer identifiers
  • Conversion events
  • Purchases
  • Device data
  • Website activity

Use only the information necessary to measure the campaign.

A measurement objective should not become a reason to transmit unrestricted customer records.

67. Review Data Clean Rooms

Does the technology reduce risk without eliminating governance?

Data clean rooms may allow organizations to compare or analyze datasets with greater restrictions on direct access.

They do not make every underlying data practice ethical automatically.

Organizations still need to evaluate:

  • Data provenance
  • Purpose
  • Permissions
  • Outputs
  • Reidentification risk

Technical controls supplement responsible governance.

68. Review Customer-Match Advertising

Are customer identifiers being uploaded to advertising platforms appropriately?

Customer-match products may use information such as:

  • Email
  • Phone
  • Customer identifiers

Confirm that use aligns with organizational policies, applicable requirements, platform terms, and customer expectations.

Do not upload every available customer list simply because the platform provides the feature.

69. Review Suppression Lists Carefully

Can privacy-preserving suppression accomplish the objective?

Sometimes customer information is shared with a platform to prevent existing customers from receiving acquisition advertising.

This can be a legitimate operational objective.

Still review the minimum information required and how the platform handles the resulting identifiers.

70. Review Attribution Systems

Does attribution require more individual tracking than the decision actually needs?

Marketers often pursue increasingly detailed attribution.

Ask whether the organization truly needs to know the exact individual path across every interaction.

Aggregated measurement may sometimes provide enough information for budget decisions with lower privacy impact.

Perfect attribution is rarely achievable, and pursuing it can create disproportionate surveillance.

71. Do Not Overstate Attribution

Does the data justify the causal story being told?

A tracking system may identify that a person encountered several marketing touchpoints before converting.

That does not automatically establish that each touchpoint caused the conversion.

Data ethics also includes honest interpretation.

Do not turn granular tracking into false certainty about human decision-making.

72. Review Experiment Data

Are marketing experiments protecting participants appropriately?

A/B testing can involve behavior at individual level.

Avoid experiments that create inappropriate:

  • Price disparities
  • Deception
  • Sensitive targeting
  • Customer harm

The fact that a platform can randomly assign an experience does not mean every possible experiment should be run.

Related AAMA Resource: A/B Testing Guide for Marketers

73. Review Data From Public Sources

Does public availability automatically justify commercial profiling?

No.

Information being technically public does not eliminate concerns involving:

  • Context
  • Scale
  • Aggregation
  • Sensitivity
  • Reasonable expectations

Collecting thousands of public records into a detailed behavioral profile can create a substantially different privacy impact from viewing one public record individually.

74. Avoid Reidentification Where It Is Unnecessary

Is the organization attempting to identify people within supposedly anonymous data?

If analysis can be completed without knowing who an individual is, avoid unnecessary reidentification.

The objective of analytics should be understanding useful patterns, not identifying every possible person.

75. Review Security Responsibilities

Is retained marketing data protected according to its sensitivity?

Security should reflect:

  • Data type
  • Volume
  • Sensitivity
  • Access
  • Consequences of exposure

Privacy and security are closely connected.

Collecting information creates responsibility for protecting it.

76. Plan for Incidents

Does the organization know what happens if marketing data are exposed or misused?

An incident plan should identify:

  • Who investigates
  • Who can restrict access
  • Who contacts vendors
  • Who determines notification obligations
  • How affected systems are preserved
  • How practices are corrected

Incident response should be established before an incident occurs.

77. Document High-Risk Decisions

Can the organization explain why the data practice was approved?

For higher-risk uses, preserve information about:

  • Purpose
  • Data involved
  • Vendor
  • Risks
  • Safeguards
  • Reviewers
  • Approval
  • Review date

Documentation encourages deliberate decision-making and provides institutional memory.

78. Assign a Data Owner

Who is accountable for the marketing use?

Responsibility may involve several functions, including:

  • Marketing
  • Privacy
  • Legal
  • Security
  • Analytics
  • Technology

Still, someone should understand who owns the use case and who can stop or change it.

Avoid a system where every team assumes another team evaluated the data practice.

79. Reevaluate Existing Practices

Is a long-established practice still appropriate?

Do not assume that a data practice is acceptable because the organization has done it for years.

Technology, laws, expectations, vendors, and risks change.

Periodically review:

  • Tracking
  • Targeting
  • Consent
  • Retention
  • Vendor sharing
  • AI
  • Personalization

Legacy practices deserve the same scrutiny as new ones.

80. Use a Privacy Risk Management Framework

Does the organization have a structured way to identify and manage privacy risk?

The NIST Privacy Framework provides a voluntary framework for organizations seeking to identify and manage privacy risk.

As of September 2026, NIST is developing Privacy Framework 1.1, with the current Version 1.1 materials still identified as an Initial Public Draft rather than a completed final replacement for Version 1.0.

Organizations do not need to reproduce the entire framework to benefit from structured privacy-risk thinking.

The important principle is to identify data processing, evaluate risk to individuals and organizations, establish safeguards, and review performance over time.

81. Apply the Necessity Test

Ask:

Do we actually need these data to accomplish the marketing objective?

If the answer is no, do not collect or use them.

This simple question can eliminate many unnecessary privacy risks before they require complicated controls.

82. Apply the Proportionality Test

Ask:

Is the amount and sensitivity of information proportionate to the value of the marketing activity?

Collecting an email address for a newsletter and building a highly detailed behavioral profile for the same newsletter create very different privacy impacts.

Use the least intrusive approach reasonably capable of accomplishing the legitimate objective.

83. Apply the Expectation Test

Ask:

Would a reasonable customer expect this use based on the relationship they have with us?

Unexpected use is not automatically prohibited, but it deserves additional scrutiny.

Trust can be damaged when customers discover practices they never imagined were occurring.

84. Apply the Transparency Test

Ask:

Could we describe this practice publicly in plain English without changing how it sounds?

If the explanation depends on euphemisms such as:

  • Enhanced personalization
  • Audience intelligence
  • Advanced insights

rewrite it in literal operational terms.

Transparency becomes meaningful when people can understand what actually happens.

85. Apply the Vulnerability Test

Ask:

Does this strategy become more effective because the person is vulnerable?

If effectiveness depends primarily on financial distress, illness, fear, addiction, crisis, or another vulnerability, stronger ethical review is appropriate.

Relevant marketing and exploitation are not the same thing.

86. Apply the Reversal Test

Ask:

Would we be comfortable if another company used our own employees’ or families’ data this way?

Reversing perspective can make intrusive practices easier to recognize.

A standard should remain defensible when applied to people the decision-maker personally cares about.

87. Apply the Breach Test

Ask:

If these data became public tomorrow, would we still believe collecting them was worth the risk?

This does not mean every dataset that could cause embarrassment should be prohibited.

It forces the organization to account for the consequences created by collecting and retaining information.

88. Apply the Permanence Test

Ask:

Are we treating temporary behavior as a permanent fact about the person?

Consumer circumstances change.

A search, purchase, visit, or temporary financial situation should not automatically follow someone indefinitely through a marketing profile.

Review whether old signals should expire.

89. Apply the Human Consequence Test

Ask:

What happens to the person if the data or model is wrong?

An incorrect product recommendation has limited consequences.

An incorrect inference affecting access to a consequential opportunity can be much more serious.

Risk review should reflect the potential human impact of error.

90. Final Marketing Data Ethics Review

Before approving a significant marketing-data use, confirm:

  • The business purpose is defined
  • Only necessary data are collected
  • Data sources are known
  • Provided, observed, and inferred data are distinguished
  • Consumer expectations have been considered
  • Privacy representations match actual practice
  • Consent is meaningful where required
  • Declining is reasonably easy
  • Third-party data provenance has been reviewed
  • Vendor claims have been verified
  • Sensitive information receives additional protection
  • Children’s data receive specialized review
  • Vulnerability is not being exploited
  • Behavioral targeting is proportionate
  • Inferred characteristics are not treated as certainty
  • Proxy variables and discriminatory outcomes have been considered
  • Retargeting frequency is appropriate
  • Personalization does not expose unnecessary knowledge
  • Personalized pricing receives specialized review
  • Research data are used consistently with their purpose
  • Internal access is limited appropriately
  • Agency and vendor access is proportionate
  • AI tools are approved for the data involved
  • Automated decisions receive appropriate oversight
  • Retention periods are established
  • Old data are deleted when no longer necessary
  • Customer exports are controlled
  • Data quality is sufficient
  • Opt-out choices are preserved across systems
  • External sharing has a legitimate purpose
  • Measurement uses only necessary information
  • Customer-match practices have been reviewed
  • Attribution does not create unnecessary surveillance
  • Public data are not assumed to be unrestricted
  • Security controls are appropriate
  • An incident-response process exists
  • High-risk decisions are documented
  • An accountable owner has been assigned
  • Existing practices are periodically reevaluated
  • The organization could explain the practice clearly to the customer

If the marketing objective cannot justify the privacy impact, the correct response is to redesign the practice rather than search for a more persuasive explanation of it.

Good Data Strategy Uses Restraint

More data do not automatically produce better marketing.

Poorly governed information can create:

  • Noise
  • False confidence
  • Security exposure
  • Privacy risk
  • Customer distrust
  • Unnecessary cost

Strong data strategy identifies which information genuinely improves decisions and ignores information that does not.

Professional maturity sometimes means deciding not to collect something.

Customer Data Are Borrowed Trust

Organizations often describe customer information as an asset.

That description is incomplete.

Customer data also represent information entrusted to an organization within a particular commercial relationship.

The organization may technically possess the database, but the records continue to describe real people whose interests can be affected by how those data are combined, interpreted, shared, and used.

Responsible marketing treats that trust as part of the value of the customer relationship.

Responsible Data Use Can Improve Marketing

Ethical limits do not prevent useful personalization, research, measurement, or targeting.

They encourage marketers to focus on data that:

  • Improve relevance
  • Answer legitimate questions
  • Reduce waste
  • Serve customer needs
  • Support better decisions

A disciplined data strategy can be both more respectful and more useful because it reduces irrelevant collection and forces organizations to identify what actually matters.

Related AAMA Resources

Continue reviewing responsible marketing practices with the Advertising Ethics Guide, Responsible AI in Advertising & Marketing Guide, Advertising Claims Checklist, Influencer & Sponsored Content Disclosure Guide, Marketing Research Methods Guide, How to Design a Marketing Survey, A/B Testing Guide for Marketers, Landing Page Evaluation Checklist, Marketing Research & Consumer Data Sources, and Government Data Sources for Marketers. These resources provide additional guidance for consumer research, privacy, targeting, automation, measurement, evidence, and responsible professional decision-making.

The AAMA Resource Library will continue reviewing this checklist as privacy regulation, advertising technology, artificial intelligence, consumer expectations, and data practices evolve.