Independent architectural comparison · 2026

Zero-Party Data vs Zero Data Protocol

Zero-party data is information a person intentionally provides to an organization—often preferences, intentions or personal context used for personalization. Zero Data Protocol asks a different question: should that information be collected, retained or exploited at all?

By Lajos NagyZero Data ProtocolUpdated August 2026
Short answer

Zero-party data and Zero Data Protocol are not equivalent. Zero-party data improves transparency by replacing hidden inference with information knowingly supplied by a person. But it is still collected data. ZDP goes further through Zero Collection, Zero Retention and Zero Exploitation.

What is zero-party data?

Forrester defines zero-party data as information that a customer intentionally and proactively shares with a brand. It can include preference-center choices, purchase intentions, personal context and instructions about how the customer wants to be recognized.

The term is mainly used in marketing and customer-experience systems. Instead of silently inferring that someone prefers a particular product, a company can ask the person directly through a survey, quiz, preference center or onboarding question.

The word “zero” does not mean zero collection. It refers to the direct relationship between the person and the organization receiving the declared information.

Common zero-party data examples

PreferencesPreferred topics, colors, sizes, communication channels, product categories or service options.
Purchase intentionsWhat a customer plans to buy, when a purchase may occur and which problem the person wants to solve.
Personal contextGoals, interests, lifestyle details, dietary requirements, budget ranges or declared professional needs.
Recognition choicesHow the person wants an organization to address, identify, remember or personalize interactions.
Direct feedbackSurvey answers, satisfaction responses, product reviews and explanations supplied in the customer’s own words.
Preference-center settingsSelected message topics, contact frequency, notification options and channel permissions.

How organizations collect and activate it

1Ask a direct questionA quiz, poll, form or preference center invites the person to state a need or preference.
2Offer a value exchangeThe organization promises a more relevant recommendation, service, reward or experience.
3Link the answerThe declared information is commonly attached to a profile, account, session or customer identifier.
4Distribute the recordCRM, customer-data platforms, analytics and campaign tools may receive the preference.
5Personalize an outcomeThe data influences recommendations, content, offers, service interactions or segmentation.
6Retain and updateThe organization keeps the preference until it expires, is replaced, withdrawn or deleted under its rules.

Zero-, first-, second- and third-party data

Data typeHow it is obtainedTypical examplesMain concern
Zero-party dataIntentionally supplied by the personPreferences, intentions, context, survey answersPurpose, retention and downstream activation
First-party dataObserved through the organization’s own channelsClicks, purchases, app activity, service historyTracking, profiling and inference
Second-party dataAnother organization’s first-party data is sharedPartner audience or transaction informationTransparency, provenance and compatible purpose
Third-party dataAcquired from outside brokers or aggregatorsDemographics, interests, intent signalsAccuracy, consent, legality and uncontrolled circulation

The categories describe provenance, not automatic privacy quality. Directly supplied information can be sensitive, persist for years, spread across many systems and support intensive profiling.

What zero-party data improves

Less hidden inferenceOrganizations can ask a person directly instead of guessing preferences from behavioral surveillance.
More relevant experiencesDeclared needs can improve recommendations and reduce irrelevant messages or offers.
Greater transparencyThe person can understand which answer produced a personalized result.
Potentially better accuracyCurrent self-reported intent may be more useful than an old or probabilistic third-party profile.

These benefits depend on restraint. Forrester recommends short, simple experiences with a clear value exchange. Asking too many questions turns a transparent interaction into another form of data extraction.

What zero-party data does not guarantee

Voluntary is not unlimitedProviding one preference does not authorize every future use, recipient, model or marketing channel.
Direct is not anonymousThe answer is often connected to an email address, loyalty account, customer profile or device identity.
Declared is not permanentPreferences, intentions and circumstances change. Old answers can become inaccurate or harmful.
Consent is context-specificA voluntary answer and a legally valid consent are related concepts but are not automatically the same thing.

Zero-party data can also reveal sensitive traits. Health goals, political interests, financial concerns, family circumstances or religious preferences do not become low-risk merely because the individual typed them into a quiz.

What Zero Data Protocol adds

Zero Data Protocol evaluates whether a system can provide its function without creating an enduring personal-data dependency:

Zero CollectionDo not ask for a preference, intention or personal detail unless the immediate function genuinely requires it.
Zero RetentionUse the answer transiently or keep it only for the shortest justified period instead of building a permanent profile.
Zero ExploitationDo not convert a declared preference into unrelated targeting, training, scoring, sale or cross-context profiling.

A ZDP-oriented service can still ask a question. The difference is that it prefers an immediate, local or session-bound answer over an ever-growing centralized customer profile.

Zero-party data vs ZDP

DimensionZero-party dataZero Data Protocol
Primary objectiveObtain accurate declared information for personalization and engagementRemove unnecessary personal-data dependence from system design
Meaning of “zero”Information comes directly from the customer rather than another data partyZero unnecessary collection, retention and exploitation
Starting pointAsk the customer for useful informationAsk whether the information is necessary at all
CollectionIntentional and proactive disclosureAvoid collection unless functionally required
IdentityFrequently linked to a known customer or prospectPrefer anonymous, local or unlinkable operation where possible
RetentionOften stored in profiles, preference centers and customer-data platformsPersistent retention challenged at every layer
UsePersonalization, recommendations, segmentation and marketingUse restricted to the declared and necessary function
Secondary exploitationPossible unless purpose and governance controls prevent itUnrelated exploitation is structurally rejected
TypeMarketing and customer-data categoryIndependent architectural framework
RelationshipZero-party data can reduce covert inference, but it supports ZDP only when collection, retention and use remain strictly minimized

The decisive difference: permission to share versus necessity to know

Zero-party data emphasizes how information is obtained: the person knowingly provides it rather than having it inferred or purchased from elsewhere.

ZDP emphasizes whether the system needs the information, how long it must exist and whether it can be used beyond the immediate purpose. A transparent question can still create an unnecessary permanent record.

In one sentence: zero-party data replaces guessing with asking; Zero Data Protocol asks whether the system needs to remember the answer.

Three more structural ways to use a preference

Session-only personalizationUse the answer immediately without attaching it to a durable identity or account history.
Local preference storageKeep the setting on the user’s device and transmit only the minimum instruction needed for each interaction.
Revocable preference tokenRepresent the chosen experience through a narrow token instead of preserving the full personal explanation.
Purpose-specific separationPrevent support, personalization, analytics and advertising systems from automatically sharing the same declared data.

A ZDP-oriented zero-party data checklist

  1. Justify every question. Remove questions that are merely interesting rather than necessary for the promised result.
  2. Explain the immediate value. State what the person receives in return and avoid manipulative incentives.
  3. Separate optional from required. Do not make personalization questions a hidden condition for basic service access.
  4. Minimize identity linkage. Use anonymous, session-bound or local preferences whenever a named profile is unnecessary.
  5. Limit recipients. Prevent automatic distribution to every CRM, CDP, analytics platform and advertising partner.
  6. Set expiration dates. Preferences and intentions should be refreshed or deleted when they are no longer reliable.
  7. Provide control. Let people inspect, change, withdraw and delete what they intentionally shared.
  8. Block secondary exploitation. Do not turn a useful answer into unrelated training data, behavioral scoring or cross-context profiling.

Frequently asked questions

What is zero-party data?

It is information a person intentionally and proactively gives to an organization, such as preferences, intentions, personal context or instructions about the desired experience.

Why is it called zero-party data?

The term distinguishes directly declared information from first-party behavioral observations and data received from second or third parties. It does not mean that zero data is collected.

Is zero-party data always anonymous?

No. It is frequently stored inside an identified customer, loyalty, CRM or marketing profile.

Is voluntarily supplied data the same as legal consent?

Not automatically. Valid consent and other legal bases depend on applicable law, purpose, information provided, freedom of choice, withdrawal and the specific processing involved.

Can zero-party data support ZDP?

Yes, when asking directly replaces hidden surveillance and when the answer is minimized, narrowly used and quickly deleted. It is not sufficient by itself.

Is zero-party data the same as Zero Data Protocol?

No. Zero-party data is a data-source category. ZDP is a structural framework based on Zero Collection, Zero Retention and Zero Exploitation.

About the author and framework
Lajos Nagy develops and documents Zero Data Protocol as an independent architectural framework. ZDP is not a product certification, a regulatory approval or a substitute for legal and security assessment.

Editorial notice: Forrester, Salesforce, Tealium and their terminology or products are cited for identification and independent comparative analysis only. No affiliation, endorsement or equivalence with Zero Data Protocol is claimed. Privacy obligations depend on the actual data, purposes, jurisdiction and implementation; obtain appropriate professional advice where required.