Last Reviewed: September 2026
The AAMA Marketing Data Ethics Checklist is designed to help marketers, advertisers, agencies, researchers, analysts, media professionals, technology teams, brands, students, and organizational leaders evaluate whether consumer data are being collected, combined, analyzed, shared, targeted, retained, and used responsibly.
Modern marketing can involve information from websites, apps, customer relationships, purchases, loyalty programs, advertising platforms, research panels, third-party vendors, data brokers, connected devices, artificial intelligence, customer-service systems, and inferred behavioral characteristics. The existence of these capabilities does not mean every available use of the data is appropriate.
This checklist focuses on professional judgment as well as compliance. Privacy laws and regulatory requirements vary by jurisdiction and industry, and particular forms of information may be governed by specialized rules. This resource is educational and should not be treated as legal advice.
1. Identify the Business Purpose
Why are these data being collected or used?
Every material data practice should have a recognizable business purpose.
Possible purposes may include:
- Completing a transaction
- Providing a service
- Measuring a campaign
- Understanding customer behavior
- Improving a product
- Conducting research
- Personalizing communication
- Preventing fraud
- Managing customer relationships
Avoid collecting information simply because a platform, form, vendor, or technology makes it possible.
If the organization cannot explain why it needs a data element, reconsider whether it should collect it.
2. Define the Intended Use Before Collection
Is the organization clear about how the information will be used?
Data should not be collected without considering its intended purpose.
Ask:
- What decision will this information support?
- Which teams will use it?
- Which systems will receive it?
- How long will it remain useful?
- Will it be shared externally?
Defining use before collection reduces the risk of accumulating information without a legitimate operational purpose.
3. Practice Data Minimization
Are you collecting only what is necessary?
The FTC has long advised businesses to keep only the personal information they need and to avoid collecting sensitive information without a legitimate business reason.
Review every field, identifier, behavioral signal, and enrichment source.
Ask whether the same objective could be achieved with:
- Less information
- Aggregated information
- Anonymous information
- Shorter retention
- Fewer data sources
Additional data create additional privacy, security, governance, and reputational risk.
4. Do Not Collect Data “Just in Case”
Is future hypothetical usefulness the only justification?
Organizations sometimes collect information because it might become useful later.
That approach can create repositories of customer information with no defined purpose.
A better standard is:
Collect information because a current legitimate need exists, not because somebody might eventually think of a use for it.
Future uses can be evaluated when they arise.
5. Inventory the Data
Does the organization know what marketing data it possesses?
Maintain an inventory of significant consumer-data categories.
This may include:
- Names
- Email addresses
- Phone numbers
- Postal addresses
- Customer IDs
- Purchase history
- Website activity
- App activity
- Advertising identifiers
- Location
- Survey responses
- Loyalty data
- Customer-service records
- Inferred interests
Organizations cannot manage data responsibly when they do not know what they have.
6. Identify Where the Data Came From
Is the source known?
Record whether information came from:
- Customer submission
- Transaction
- Website
- App
- Survey
- CRM
- Advertising platform
- Data provider
- Public record
- Research panel
- Business partner
- Modeled inference
Data provenance matters because the appropriate use of information can depend heavily on how it was originally obtained.
7. Distinguish Provided, Observed & Inferred Data
Does the organization understand how the characteristic was created?
Consumer information may be:
Provided: The person directly supplied it.
Observed: The organization recorded behavior such as purchases or website activity.
Inferred: A system predicted a characteristic based on other information.
These categories should not be treated as equivalent.
Do not state that a consumer “told us” something when the characteristic was actually inferred by an algorithm.
8. Evaluate Consumer Expectations
Would the person reasonably expect this use?
A data practice can create concern even when a technical permission exists if the use is far removed from the context in which the information was provided.
Ask:
Would an ordinary customer reasonably expect us to use this information this way?
If the answer is probably not, additional transparency, permission, limitation, or reconsideration may be appropriate.
9. Apply the Explanation Test
Could you explain the practice clearly to the customer?
Describe the data practice without legal or technical language.
For example:
“We use your purchase history to determine which products we advertise to you.”
If the organization would be uncomfortable stating the practice plainly, the practice deserves additional review.
Complexity should not become a substitute for transparency.
10. Review Privacy Representations
Does actual practice match what the organization tells people?
Review:
- Privacy policies
- Consent notices
- Signup language
- App permissions
- Advertising disclosures
- Customer-service explanations
- Vendor agreements
Do not promise one level of privacy while operating another system internally.
A privacy statement is an advertising and trust commitment as well as a legal document.
11. Make Consent Meaningful
Is consent understandable and freely given where it is required?
Consent should not depend on confusion.
Review whether the person can understand:
- What they are agreeing to
- Which data are involved
- Why the data are being used
- Whether data will be shared
- How to change the choice
Consent becomes less meaningful when the interface is intentionally designed to produce agreement without understanding.
12. Avoid Manipulative Consent Interfaces
Is the interface steering people unfairly toward the organization’s preferred choice?
Review for:
- Preselected boxes
- Hidden decline options
- Repeated interruptions
- Confusing button labels
- Misleading colors
- Unequal visual prominence
- Complicated opt-out paths
A choice should remain a genuine choice.
Do not design privacy controls primarily to wear people down until they agree.
13. Make Declining Reasonable
Can someone refuse without navigating an obstacle course?
If a marketing preference can be accepted in one click but requires multiple screens to decline, reconsider the design.
The objective should be to capture a real preference rather than maximize nominal consent.
14. Separate Necessary Processing From Marketing
Is optional marketing being bundled with something required?
A customer may need to provide information to:
- Complete an order
- Create an account
- Receive a service
- Obtain customer support
That does not automatically mean every subsequent marketing use is necessary.
Distinguish operational data requirements from optional promotional uses where appropriate.
15. Review First-Party Data
Is first-party data being treated as automatically risk-free?
Information obtained directly through the customer relationship may include valuable behavioral history.
Examples include:
- Purchases
- Website activity
- App usage
- Loyalty behavior
- Email engagement
First-party status does not eliminate privacy obligations or ethical concerns.
The use should still be relevant, proportionate, secure, and consistent with reasonable customer expectations.
16. Review Third-Party Data
Do you understand where purchased or licensed data originated?
Before using third-party information, ask:
- Who collected it?
- From whom?
- For what purpose?
- What permissions existed?
- Was the information inferred?
- How current is it?
- Can the provider document provenance?
- What uses does the license permit?
Do not assume a data vendor has resolved every privacy concern simply because it sells the dataset commercially.
17. Evaluate Data Brokers Carefully
Is the organization buying audience information it could not comfortably collect directly?
Third-party audience products can contain detailed behavioral, demographic, geographic, and inferred information.
Marketers should understand both the usefulness and the provenance of those data.
If a dataset reveals information that would feel intrusive if requested directly from customers, that is a reason for more scrutiny, not less.
18. Verify Vendor Claims About Data Sources
Can the provider substantiate how the data were obtained?
Marketing vendors sometimes make extraordinary claims about their ability to identify behavior, conversations, interests, or customer intent.
Require evidence.
Ask:
- What is actually measured?
- What is modeled?
- Which devices are involved?
- What permissions exist?
- Is the capability technically demonstrated?
- Is the vendor’s explanation internally consistent?
Do not repeat unusual vendor claims to clients without verification.
19. Review Sensitive Information
Are the data especially private or consequential?
Sensitive categories may include information involving:
- Health
- Finances
- Precise location
- Children
- Government identifiers
- Biometrics
- Sexual activity
- Major life circumstances
- Other highly personal matters
Additional restrictions may apply legally, but ethical review should begin even before reaching the legal question.
Ask whether the marketing purpose genuinely justifies using the information.
20. Use Health Information With Extra Care
Could the data reveal a health condition or concern?
Health-related information can arise outside hospitals or medical practices.
It may come from:
- Apps
- Search behavior
- Purchases
- Wearable devices
- Surveys
- Customer-service conversations
- Inferred interests
Do not assume health information is ethically unrestricted simply because the organization is not covered by HIPAA.
Specialized federal and state requirements may still apply.
21. Protect Precise Location Data
Does the marketing objective genuinely require exact location?
Precise location can reveal highly sensitive behavior.
Depending on context, it may indicate visits to:
- Medical facilities
- Religious institutions
- Schools
- Homes
- Political events
- Support services
Consider whether broader geographic information would accomplish the objective.
The ability to identify where someone physically went should not automatically become an advertising opportunity.
22. Review Children’s Data
Could the audience or dataset involve children?
Children’s personal information requires specialized treatment.
The FTC’s updated Children’s Online Privacy Protection Rule applies to covered services involving children under 13 and includes requirements involving consent, data use, disclosure, retention, and targeted advertising.
Marketing teams should identify child-directed products and services early rather than discovering the issue after data collection begins.
23. Avoid Using Children as Behavioral Targets Without Appropriate Review
Does targeting rely on detailed behavioral information about children?
Even where a campaign appears commercially attractive, additional legal, ethical, developmental, and parental-consent considerations can apply.
Children may have less ability to understand:
- Advertising intent
- Data collection
- Behavioral profiling
- Persuasive design
- Long-term consequences
Treat children’s data as a specialized high-risk category.
24. Review Data About Vulnerable Circumstances
Is targeting based on distress or reduced bargaining power?
Examples may include inferred information involving:
- Debt
- Job loss
- Addiction
- Serious illness
- Bereavement
- Housing insecurity
- Crisis
Ask whether the strategy provides genuinely useful relevance or primarily exploits vulnerability.
A person’s difficulty should not automatically become a conversion opportunity.
25. Review Behavioral Targeting
Is the targeting proportionate to the marketing objective?
Behavioral targeting may improve relevance by using signals such as:
- Browsing
- Purchases
- Content consumption
- Search behavior
- App usage
Evaluate:
- Data source
- Consumer expectations
- Sensitivity
- Frequency
- Transparency
- Ability to control preferences
Relevant advertising does not require unlimited surveillance.
26. Review Audience Inferences
Are modeled characteristics being treated as facts?
Algorithms may infer:
- Income
- Interests
- Purchase intent
- Household characteristics
- Lifestyle
- Likelihood to convert
These are probabilistic predictions.
Avoid using them in ways that assume certainty, particularly when the consequence to the person is significant.
27. Review Proxy Variables
Could an apparently neutral variable stand in for something sensitive?
Variables such as:
- ZIP code
- Device type
- Shopping behavior
- Language
- Browsing patterns
can correlate with demographic or sensitive characteristics.
Models may therefore create outcomes that were never explicitly requested.
Review what the targeting system actually does, not simply which variables were intentionally supplied.
28. Check for Discriminatory Outcomes
Could targeting unfairly exclude people from opportunities?
Pay particular attention when marketing involves areas such as:
- Employment
- Housing
- Credit
- Education
- Financial services
- Other consequential opportunities
Review who receives and does not receive advertising.
A system can create problematic outcomes even without an explicit instruction to discriminate.
29. Audit Outcomes
Are you checking the actual distribution of the campaign?
Do not evaluate only inputs.
Where appropriate, review:
- Geographic delivery
- Demographic patterns
- Offer distribution
- Exclusions
- Conversion patterns
- Audience composition
Responsible data practice includes examining consequences.
30. Review Lookalike Audiences
Do you understand what the model is optimizing for?
Lookalike and predictive audiences may identify patterns invisible to the marketer.
That can improve campaign performance while also introducing hidden correlations.
Use additional caution when the seed audience or advertising category involves sensitive or consequential characteristics.
31. Review Retargeting
Does the retargeting remain useful rather than intrusive?
Repeatedly advertising the same product after someone has viewed a page can become uncomfortable or wasteful.
Review:
- Frequency
- Recency
- Purchase status
- Sensitive categories
- Campaign duration
Someone who already purchased the product usually should not continue receiving acquisition advertising indefinitely.
32. Control Frequency
Does behavioral data allow the same person to be targeted excessively?
More impressions are not automatically better.
Excessive targeting can produce:
- Irritation
- Privacy concerns
- Negative brand perception
- Wasted spending
Use frequency limits where appropriate and evaluate the experience from the customer’s perspective.
33. Review Cross-Device Tracking
Would consumers reasonably understand that their activity is being connected across devices?
Cross-device systems can combine activity from:
- Phones
- Computers
- Tablets
- Connected televisions
- Other devices
Understand how identities are resolved and whether the approach aligns with privacy representations and applicable requirements.
The technical ability to connect devices does not eliminate the need for responsible governance.
34. Review Identity Resolution
How certain is the organization that records belong to the same person?
Identity systems can produce incorrect matches.
Errors may cause:
- Misdirected personalization
- Incorrect profiles
- Privacy exposure
- Faulty attribution
Understand the confidence and limitations of deterministic and probabilistic identity methods.
35. Review Personalization
Does personalization provide value without revealing too much?
Useful personalization might involve:
- Remembering preferences
- Recommending related products
- Providing relevant content
Uncomfortable personalization may reveal details the customer did not expect the marketer to know.
Ask:
Does this improve the experience, or does it mainly demonstrate how much information we have collected?
36. Avoid Creepy Precision
Could a less specific message accomplish the same objective?
An advertiser may know that someone:
- Visited a location
- Purchased a sensitive product
- Searched a particular topic
- Experienced a life event
It is rarely necessary to expose that knowledge directly in the advertisement.
Subtle relevance may provide the same marketing benefit without creating a sense of surveillance.
37. Review Personalized Pricing
Is personal data influencing the price or offer shown to an individual?
Personalized pricing deserves heightened scrutiny because data may affect the economic terms offered to different consumers.
As of September 2026, the FTC is seeking public comment on a proposed enforcement policy statement addressing personalized pricing and the possibility that failure to disclose material use of personal data in setting prices could violate laws the Commission enforces.
Organizations considering personalized pricing should obtain appropriate legal review and think carefully about transparency, fairness, data provenance, and customer expectations.
38. Distinguish Personalization From Price Discrimination
Is data changing content, or changing economic terms?
Showing different product recommendations is different from using personal information to determine how much a particular person may be willing to pay.
Document when algorithms affect:
- Price
- Discount
- Credit
- Eligibility
- Offer value
Higher-consequence personalization deserves stronger review.
39. Review Customer Segmentation
Are segments useful without becoming stereotypes?
Segments can help marketers understand patterns.
They should not be treated as though every person within a group has identical:
- Interests
- Values
- Motivations
- Behavior
Use segmentation as a planning tool rather than a complete description of an individual.
40. Review Research Data
Is information collected for research being reused for unrelated marketing?
People participating in research may expect their responses to be used differently from information submitted for a sales inquiry.
Review whether survey, interview, focus-group, or panel data are being repurposed beyond the context in which they were obtained.
Research participation should not quietly become sales targeting unless that use is appropriate and disclosed.
41. Protect Research Participants
Are individual responses being unnecessarily exposed?
Where individual identity is not required, consider:
- Aggregation
- Anonymization
- Restricted access
- Removal of identifiers
Do not place identifiable customer quotations or research records into marketing materials without appropriate permission.
42. Limit Internal Access
Does every employee who can access marketing data actually need it?
Use role-based access where practical.
Not every employee needs access to:
- Full customer records
- Behavioral profiles
- Research responses
- Precise location
- Sensitive information
Reducing unnecessary access reduces the potential consequences of mistakes and misuse.
43. Review Agency Access
What information does an external agency actually need?
Agencies may require data for:
- Media
- Analytics
- Research
- Campaign execution
Provide information proportionate to the work.
Do not give outside partners unrestricted access to entire customer databases when aggregated or limited data would accomplish the same objective.
44. Review Vendor Access
Which third parties can access consumer information?
Maintain awareness of:
- Analytics providers
- Advertising platforms
- CRM systems
- Email platforms
- Research companies
- Cloud providers
- AI services
- Customer-service platforms
The number of organizations receiving data can grow quickly.
Each connection should have a legitimate purpose.
45. Understand Subprocessors
Can the vendor itself share the data with additional providers?
Review vendor documentation and contracts where appropriate.
An organization may believe it is sharing information with one vendor while the processing chain includes several additional companies.
Understanding the data flow is part of understanding the practice.
46. Review Vendor Retention
How long will third parties keep the data?
Do not evaluate only your organization’s retention policy.
Ask whether vendors:
- Retain records
- Create backups
- Train systems on the data
- Create derivative profiles
- Allow deletion
Data are not truly deleted from the marketing ecosystem if downstream partners continue retaining them unnecessarily.
47. Review AI Tools
Is customer or confidential data being entered into an approved AI system?
Before providing information to an AI service, understand:
- Retention
- Training use
- Security
- Access
- Contractual protections
- Deletion
- Data location
Do not paste customer databases, confidential research, or proprietary client information into unapproved AI tools.
Related AAMA Resource: Responsible AI in Advertising & Marketing Guide
48. Minimize AI Inputs
Does the AI system require identifiable data to perform the task?
Where possible, use:
- Aggregated information
- De-identified records
- Synthetic examples
- Limited fields
Do not provide more information than the system actually needs.
49. Review AI-Generated Profiles
Are AI inferences being used responsibly?
AI may predict:
- Churn
- Purchase likelihood
- Customer value
- Interests
- Sentiment
These outputs can appear precise while containing meaningful uncertainty.
Do not treat a model score as unquestionable truth about a person.
50. Review Marketing Automation
Is automation making decisions that deserve human oversight?
Automated systems can control:
- Audience selection
- Lead scoring
- Personalization
- Offer selection
- Message timing
- Budget allocation
Determine where human review is necessary.
The more consequential the outcome, the stronger the case for oversight.
51. Review Lead Scoring
Could the scoring model unfairly disadvantage certain people or businesses?
Understand which variables contribute to the score.
Review whether:
- Historical data contain bias
- Proxy variables are being used
- Scores are treated as certainty
- Sales teams understand limitations
Lead scoring should help prioritize effort without pretending to know more than the evidence supports.
52. Review Automated Suppression
Who is being excluded automatically?
Marketing systems may suppress audiences because of:
- Low predicted value
- Previous behavior
- Geography
- Model score
- Engagement
Review whether exclusion remains appropriate, especially when the offer involves a meaningful opportunity rather than ordinary consumer promotion.
53. Protect Passwords & Credentials
Are authentication details ever entering marketing datasets?
Customer data exports should not contain:
- Passwords
- Security answers
- Authentication tokens
- Unnecessary account credentials
Marketing teams generally have no legitimate reason to access this information.
Keep authentication systems separate from ordinary marketing analysis.
54. Protect Payment Information
Does marketing genuinely need access to payment credentials?
Marketing analysis may require:
- Purchase value
- Product
- Date
- Customer ID
It generally does not require full payment-card information.
Limit access to transaction information necessary for analysis.
55. Establish Retention Periods
How long is each category of marketing data needed?
Retention should reflect:
- Business purpose
- Legal requirements
- Customer relationship
- Analytical value
- Sensitivity
- Security risk
“Forever” should not be the default retention period.
The FTC also advises businesses not to keep sensitive personal information longer than necessary.
56. Delete Data That No Longer Has a Purpose
Is old information accumulating indefinitely?
Review:
- Former customers
- Abandoned leads
- Expired campaigns
- Old research
- Historical audience files
- Duplicate records
Information that no longer provides legitimate value continues creating risk.
Create practical deletion schedules where appropriate.
57. Review Backup Retention
Does deletion include relevant backup systems?
A record removed from the CRM may continue to exist in:
- Exports
- Shared drives
- Analytics systems
- Vendor platforms
- Backups
Understand what deletion actually means across the data environment.
58. Secure Marketing Exports
Are customer lists being downloaded unnecessarily?
CSV and spreadsheet exports are easy to create, email, copy, and forget.
Reduce unnecessary local copies and establish procedures for:
- Storage
- Sharing
- Access
- Deletion
An otherwise secure CRM can be undermined by uncontrolled spreadsheet exports.
59. Avoid Sending Sensitive Data Through Ordinary Email
Is information being shared through an appropriate channel?
Email may not be the right method for transferring sensitive customer datasets.
Use approved secure systems when appropriate.
Convenience should not determine the security standard.
60. Maintain Data Quality
Is the information accurate enough for its intended use?
Poor data can create privacy and fairness problems as well as bad marketing.
Review:
- Duplicates
- Incorrect identities
- Old addresses
- Incorrect attributes
- Outdated preferences
- Wrong household matches
Data ethics includes avoiding decisions based on information the organization knows may be unreliable.
61. Allow Reasonable Corrections
Can inaccurate customer information be corrected when appropriate?
Organizations should establish processes consistent with applicable requirements for handling data-access or correction requests.
Even outside formal rights processes, obvious data errors should not be intentionally preserved simply because they support a convenient marketing profile.
62. Respect Opt-Out Choices
Are customer preferences propagated across systems?
An opt-out is ineffective if one system stops marketing while another continues.
Coordinate preferences across:
- CRM
- SMS
- Advertising
- Customer-service systems
- Agencies
- Vendors
Preference management should function as a system, not as an isolated checkbox.
63. Do Not Quietly Restore Opted-Out Users
Could a later data import overwrite the person’s choice?
Merges, migrations, enrichment services, and new marketing platforms can accidentally reactivate suppressed contacts.
Preserve preference history during system changes.
A technical migration should not erase a deliberate customer decision.
64. Review Data Sharing
Is information being shared beyond what is necessary?
Before sending information externally, ask:
- Who needs it?
- Why?
- Which fields?
- For how long?
- Under what restrictions?
Sharing a complete customer record because a partner needs one attribute is poor data discipline.
65. Review Data Sale or Commercial Exchange
Does the organization financially benefit from providing customer information to others?
Where information is sold, licensed, exchanged, or otherwise monetized, additional legal and ethical considerations may apply.
The practice should receive specialized review because customers may evaluate commercial data sharing differently from ordinary service processing.
66. Review Measurement Partners
What information does campaign measurement expose?
Advertising measurement can involve:
- Customer identifiers
- Conversion events
- Purchases
- Device data
- Website activity
Use only the information necessary to measure the campaign.
A measurement objective should not become a reason to transmit unrestricted customer records.
67. Review Data Clean Rooms
Does the technology reduce risk without eliminating governance?
Data clean rooms may allow organizations to compare or analyze datasets with greater restrictions on direct access.
They do not make every underlying data practice ethical automatically.
Organizations still need to evaluate:
- Data provenance
- Purpose
- Permissions
- Outputs
- Reidentification risk
Technical controls supplement responsible governance.
68. Review Customer-Match Advertising
Are customer identifiers being uploaded to advertising platforms appropriately?
Customer-match products may use information such as:
- Phone
- Customer identifiers
Confirm that use aligns with organizational policies, applicable requirements, platform terms, and customer expectations.
Do not upload every available customer list simply because the platform provides the feature.
69. Review Suppression Lists Carefully
Can privacy-preserving suppression accomplish the objective?
Sometimes customer information is shared with a platform to prevent existing customers from receiving acquisition advertising.
This can be a legitimate operational objective.
Still review the minimum information required and how the platform handles the resulting identifiers.
70. Review Attribution Systems
Does attribution require more individual tracking than the decision actually needs?
Marketers often pursue increasingly detailed attribution.
Ask whether the organization truly needs to know the exact individual path across every interaction.
Aggregated measurement may sometimes provide enough information for budget decisions with lower privacy impact.
Perfect attribution is rarely achievable, and pursuing it can create disproportionate surveillance.
71. Do Not Overstate Attribution
Does the data justify the causal story being told?
A tracking system may identify that a person encountered several marketing touchpoints before converting.
That does not automatically establish that each touchpoint caused the conversion.
Data ethics also includes honest interpretation.
Do not turn granular tracking into false certainty about human decision-making.
72. Review Experiment Data
Are marketing experiments protecting participants appropriately?
A/B testing can involve behavior at individual level.
Avoid experiments that create inappropriate:
- Price disparities
- Deception
- Sensitive targeting
- Customer harm
The fact that a platform can randomly assign an experience does not mean every possible experiment should be run.
Related AAMA Resource: A/B Testing Guide for Marketers
73. Review Data From Public Sources
Does public availability automatically justify commercial profiling?
No.
Information being technically public does not eliminate concerns involving:
- Context
- Scale
- Aggregation
- Sensitivity
- Reasonable expectations
Collecting thousands of public records into a detailed behavioral profile can create a substantially different privacy impact from viewing one public record individually.
74. Avoid Reidentification Where It Is Unnecessary
Is the organization attempting to identify people within supposedly anonymous data?
If analysis can be completed without knowing who an individual is, avoid unnecessary reidentification.
The objective of analytics should be understanding useful patterns, not identifying every possible person.
75. Review Security Responsibilities
Is retained marketing data protected according to its sensitivity?
Security should reflect:
- Data type
- Volume
- Sensitivity
- Access
- Consequences of exposure
Privacy and security are closely connected.
Collecting information creates responsibility for protecting it.
76. Plan for Incidents
Does the organization know what happens if marketing data are exposed or misused?
An incident plan should identify:
- Who investigates
- Who can restrict access
- Who contacts vendors
- Who determines notification obligations
- How affected systems are preserved
- How practices are corrected
Incident response should be established before an incident occurs.
77. Document High-Risk Decisions
Can the organization explain why the data practice was approved?
For higher-risk uses, preserve information about:
- Purpose
- Data involved
- Vendor
- Risks
- Safeguards
- Reviewers
- Approval
- Review date
Documentation encourages deliberate decision-making and provides institutional memory.
78. Assign a Data Owner
Who is accountable for the marketing use?
Responsibility may involve several functions, including:
- Marketing
- Privacy
- Legal
- Security
- Analytics
- Technology
Still, someone should understand who owns the use case and who can stop or change it.
Avoid a system where every team assumes another team evaluated the data practice.
79. Reevaluate Existing Practices
Is a long-established practice still appropriate?
Do not assume that a data practice is acceptable because the organization has done it for years.
Technology, laws, expectations, vendors, and risks change.
Periodically review:
- Tracking
- Targeting
- Consent
- Retention
- Vendor sharing
- AI
- Personalization
Legacy practices deserve the same scrutiny as new ones.
80. Use a Privacy Risk Management Framework
Does the organization have a structured way to identify and manage privacy risk?
The NIST Privacy Framework provides a voluntary framework for organizations seeking to identify and manage privacy risk.
As of September 2026, NIST is developing Privacy Framework 1.1, with the current Version 1.1 materials still identified as an Initial Public Draft rather than a completed final replacement for Version 1.0.
Organizations do not need to reproduce the entire framework to benefit from structured privacy-risk thinking.
The important principle is to identify data processing, evaluate risk to individuals and organizations, establish safeguards, and review performance over time.
81. Apply the Necessity Test
Ask:
Do we actually need these data to accomplish the marketing objective?
If the answer is no, do not collect or use them.
This simple question can eliminate many unnecessary privacy risks before they require complicated controls.
82. Apply the Proportionality Test
Ask:
Is the amount and sensitivity of information proportionate to the value of the marketing activity?
Collecting an email address for a newsletter and building a highly detailed behavioral profile for the same newsletter create very different privacy impacts.
Use the least intrusive approach reasonably capable of accomplishing the legitimate objective.
83. Apply the Expectation Test
Ask:
Would a reasonable customer expect this use based on the relationship they have with us?
Unexpected use is not automatically prohibited, but it deserves additional scrutiny.
Trust can be damaged when customers discover practices they never imagined were occurring.
84. Apply the Transparency Test
Ask:
Could we describe this practice publicly in plain English without changing how it sounds?
If the explanation depends on euphemisms such as:
- Enhanced personalization
- Audience intelligence
- Advanced insights
rewrite it in literal operational terms.
Transparency becomes meaningful when people can understand what actually happens.
85. Apply the Vulnerability Test
Ask:
Does this strategy become more effective because the person is vulnerable?
If effectiveness depends primarily on financial distress, illness, fear, addiction, crisis, or another vulnerability, stronger ethical review is appropriate.
Relevant marketing and exploitation are not the same thing.
86. Apply the Reversal Test
Ask:
Would we be comfortable if another company used our own employees’ or families’ data this way?
Reversing perspective can make intrusive practices easier to recognize.
A standard should remain defensible when applied to people the decision-maker personally cares about.
87. Apply the Breach Test
Ask:
If these data became public tomorrow, would we still believe collecting them was worth the risk?
This does not mean every dataset that could cause embarrassment should be prohibited.
It forces the organization to account for the consequences created by collecting and retaining information.
88. Apply the Permanence Test
Ask:
Are we treating temporary behavior as a permanent fact about the person?
Consumer circumstances change.
A search, purchase, visit, or temporary financial situation should not automatically follow someone indefinitely through a marketing profile.
Review whether old signals should expire.
89. Apply the Human Consequence Test
Ask:
What happens to the person if the data or model is wrong?
An incorrect product recommendation has limited consequences.
An incorrect inference affecting access to a consequential opportunity can be much more serious.
Risk review should reflect the potential human impact of error.
90. Final Marketing Data Ethics Review
Before approving a significant marketing-data use, confirm:
- The business purpose is defined
- Only necessary data are collected
- Data sources are known
- Provided, observed, and inferred data are distinguished
- Consumer expectations have been considered
- Privacy representations match actual practice
- Consent is meaningful where required
- Declining is reasonably easy
- Third-party data provenance has been reviewed
- Vendor claims have been verified
- Sensitive information receives additional protection
- Children’s data receive specialized review
- Vulnerability is not being exploited
- Behavioral targeting is proportionate
- Inferred characteristics are not treated as certainty
- Proxy variables and discriminatory outcomes have been considered
- Retargeting frequency is appropriate
- Personalization does not expose unnecessary knowledge
- Personalized pricing receives specialized review
- Research data are used consistently with their purpose
- Internal access is limited appropriately
- Agency and vendor access is proportionate
- AI tools are approved for the data involved
- Automated decisions receive appropriate oversight
- Retention periods are established
- Old data are deleted when no longer necessary
- Customer exports are controlled
- Data quality is sufficient
- Opt-out choices are preserved across systems
- External sharing has a legitimate purpose
- Measurement uses only necessary information
- Customer-match practices have been reviewed
- Attribution does not create unnecessary surveillance
- Public data are not assumed to be unrestricted
- Security controls are appropriate
- An incident-response process exists
- High-risk decisions are documented
- An accountable owner has been assigned
- Existing practices are periodically reevaluated
- The organization could explain the practice clearly to the customer
If the marketing objective cannot justify the privacy impact, the correct response is to redesign the practice rather than search for a more persuasive explanation of it.
Good Data Strategy Uses Restraint
More data do not automatically produce better marketing.
Poorly governed information can create:
- Noise
- False confidence
- Security exposure
- Privacy risk
- Customer distrust
- Unnecessary cost
Strong data strategy identifies which information genuinely improves decisions and ignores information that does not.
Professional maturity sometimes means deciding not to collect something.
Customer Data Are Borrowed Trust
Organizations often describe customer information as an asset.
That description is incomplete.
Customer data also represent information entrusted to an organization within a particular commercial relationship.
The organization may technically possess the database, but the records continue to describe real people whose interests can be affected by how those data are combined, interpreted, shared, and used.
Responsible marketing treats that trust as part of the value of the customer relationship.
Responsible Data Use Can Improve Marketing
Ethical limits do not prevent useful personalization, research, measurement, or targeting.
They encourage marketers to focus on data that:
- Improve relevance
- Answer legitimate questions
- Reduce waste
- Serve customer needs
- Support better decisions
A disciplined data strategy can be both more respectful and more useful because it reduces irrelevant collection and forces organizations to identify what actually matters.
Related AAMA Resources
Continue reviewing responsible marketing practices with the Advertising Ethics Guide, Responsible AI in Advertising & Marketing Guide, Advertising Claims Checklist, Influencer & Sponsored Content Disclosure Guide, Marketing Research Methods Guide, How to Design a Marketing Survey, A/B Testing Guide for Marketers, Landing Page Evaluation Checklist, Marketing Research & Consumer Data Sources, and Government Data Sources for Marketers. These resources provide additional guidance for consumer research, privacy, targeting, automation, measurement, evidence, and responsible professional decision-making.
The AAMA Resource Library will continue reviewing this checklist as privacy regulation, advertising technology, artificial intelligence, consumer expectations, and data practices evolve.

