Back to the episode map

Research Note

Marketing Personalization and Privacy Research Note

Marketing personalization becomes risky when a message reveals more inference than the customer expected the company to make. Legal permission, model accuracy, and custom

Aug 4, 20263 min readBy Dalton Anderson

Marketing Personalization and Privacy Research Note

Marketing personalization becomes risky when a message reveals more inference than the customer expected the company to make. Legal permission, model accuracy, and customer comfort are separate questions.

Data and inference layers

Observed data records what happened, such as a purchase, page view, return, or subscription. Declared data records what the customer chose to provide. Derived data combines records into a score or segment. Inferred data predicts a preference, life event, identity, or future action.

The farther a message moves from observed or declared context, the more explanation and caution it needs. A recommendation based on a recently viewed product may feel useful. A message that appears to infer health, income, pregnancy, religion, or distress may feel invasive even if the model is statistically accurate.

Pew Research Center's study of Facebook advertising categories found that many users did not know the platform maintained category and political-affinity records about them. The study is about Facebook in 2018, not ecommerce email in 2026. It remains a useful example of the gap between technical inference and user expectation.

Purpose and minimization

The product team should define why each signal is needed and which decisions it may influence. More data can increase apparent precision while also increasing security, privacy, discrimination, and surprise risk.

NIST's Privacy Framework treats privacy as an organizational risk-management problem. It supports data mapping, governance, control, communication, and protection across the lifecycle.

For direct marketing, the UK Information Commissioner's profiling guidance is useful but jurisdiction-specific. It discusses collecting information, generating leads, profiling, transparency, and direct-marketing rules. It should not be presented as controlling U.S. law.

Customer experience controls

A personalization system should avoid language that exposes a sensitive or uncertain inference. It should use broad context when narrow context adds little value. Customers should be able to change preferences, reduce personalization, unsubscribe, and correct important assumptions.

Suppression can be as valuable as selection. The system should recognize when not to personalize, when not to use a recent event, and when an audience is too small or sensitive.

The FTC's dark patterns report warns about designs that obscure choices, make cancellation difficult, or steer users into sharing data. Personalization controls should not use friction or confusing language to keep customers enrolled.

Email compliance and truthfulness

The FTC's CAN-SPAM compliance guide explains requirements for commercial email, including accurate headers, non-deceptive subject lines, identification, postal address, opt-out mechanisms, and prompt honoring of opt-outs.

The FTC's advertising FAQ explains the general principle that advertising must be truthful, not misleading, and supported when appropriate. Personalization does not change that obligation. A generated claim still needs a reasonable basis.

Testing for value and harm

A personalization experiment should measure more than immediate clicks. Useful guardrails include complaints, unsubscribes, deliverability, refunds, customer-service contacts, correction requests, and longer-term retention.

Segment-level results can hide harm to smaller groups. Teams should inspect error and outcome patterns across meaningful populations without creating new sensitive profiles merely for analysis.

Publication boundary

The public article should not reduce creepiness to a tone problem. It is often a signal that the data source, inference, purpose, disclosure, or power relationship is wrong.

It should distinguish U.S. federal advertising and email rules from state privacy law and from UK guidance. Any jurisdiction-specific compliance recommendation needs current legal review. The editorial recommendation is operational: use expected context, minimize sensitive inference, preserve choice, test customer harm, and make correction easy.

Sources

Follow the evidence.

  1. backstroke.com: privacy policybackstroke.com
  2. nysenate.gov: Anysenate.gov
  3. aicpa-cima.com: system and organization controls soc suite of servicesaicpa-cima.com
  4. investor.shutterstock.com: 9e2d2604 6e02 43e3 a57c 9bf992b970eainvestor.shutterstock.com
  5. ftc.gov: can spam act compliance guide businessftc.gov
  6. trust.backstroke.comtrust.backstroke.com
  7. spec.c2pa.org: Harms Modellingspec.c2pa.org
  8. sec.gov: d548951dex991sec.gov
  9. gov.uk: the green book 2026gov.uk
  10. ftc.gov: advertising faqs guide small businessftc.gov
  11. microsoft.com: the benefits of controlled experimentation at scalemicrosoft.com
  12. NIST AI Risk Management Frameworknist.gov
  13. backstroke.combackstroke.com
  14. nysenate.gov: 396 Bnysenate.gov
  15. backstroke.com: backstroke soc 2 type ii certifiedbackstroke.com
  16. ftc.gov: ftc report shows rise sophisticated dark patterns designed trick trap consumersftc.gov
  17. salesforce.com: salesforce com completes acquisition of exacttargetsalesforce.com
  18. oecd.org: c6392a59 enoecd.org
  19. backstroke.com: how it worksbackstroke.com
  20. linkedin.com: rjtalyorlinkedin.com
  21. ftc.gov: ftc staff report finds large social media video streaming companies have engaged vast surveillanceftc.gov
  22. pewresearch.org: facebook algorithms and personal datapewresearch.org
  23. NIST Privacy Frameworknist.gov
  24. backstroke.com: teambackstroke.com
  25. legislation.nysenate.gov: A8887Blegislation.nysenate.gov
  26. gov.uk: summary effective contracting of employment and health servicesgov.uk
  27. gov.uk: risk allocation and pricing approaches guidance note htmlgov.uk
  28. highalpha.com: founder stories meet pattern89highalpha.com
  29. microsoft.com: online experimentation at microsoftmicrosoft.com
  30. backstroke.com: introducing backstroke s l5 agentic enginebackstroke.com
  31. backstroke.com: ai content statementbackstroke.com
  32. NIST: Artificial Intelligence Risk Management Framework, Generative Artificial Intelligence Profilenist.gov
  33. backstroke.com: ethics policybackstroke.com
  34. sec.gov: et12312012form10 ksec.gov
  35. backstroke.com: terms of servicebackstroke.com
  36. nysenate.gov: Bnysenate.gov
  37. copyright.gov: Copyright and Artificial Intelligence Part 2 Copyrightability Reportcopyright.gov
  38. governor.ny.gov: governor hochul announces first nation law requiring disclosure when advertisements include aigovernor.ny.gov
  39. spec.c2pa.org: C2PA Specificationspec.c2pa.org
  40. ico.org.uk: collect information and generate leadsico.org.uk
  41. backstroke.com: reimagining messaging in the generative ai erabackstroke.com
  42. shutterstock.com: Shutterstock Announces Formation Of 19871shutterstock.com
  43. sec.gov: d567274ds8possec.gov
  44. highalpha.com: r j talyor joins high alpha as operating partnerhighalpha.com
Marketing Personalization and Privacy Research Note