Glossary

First-party data

First-party data is information you collect yourself, directly from people using your own website or product: the pages they view, the forms they fill in, what they buy. It differs from third-party data, which another company gathers across many sites. You know where it came from and you are accountable for it.

AlbiUpdated 8 October 2026

First, second and third party

The names describe who collected the data and how it reached you.

  • First-party data you collect yourself, from your own site, app or customers. Page views, sign-ups, orders, support questions.
  • Second-party data is someone else's first-party data, which you receive by agreement. A partner shares who bought through their checkout.
  • Third-party data is gathered by a company with no direct relationship to the person, often by following them across many sites, and then sold or used for ad targeting.

"First party" also describes a way of delivering a script or cookie. A cookie set by your own domain is first-party in the technical sense, and one set by an ad network's domain while on your page is third-party. The two meanings overlap but are not the same thing: your own cookie can still hold data about a person, and sharing first-party data with an ad vendor makes it flow to a third party.

Why it has become the default

Safari and Firefox block third-party cookies by default, and people have grown wary of being followed across the web. Data collected on your own site, by your own tooling, is what remains dependable. It is also the data you understand: you know what you asked for and what it means.

What it does not mean

First-party data is not automatically free of obligations. If it relates to an identifiable person, the GDPR applies to it as to any personal data: you need a lawful basis, you owe people information, and you must keep it only as long as needed. A page view with a stored id is personal data in the legal sense. Using your own domain does not change that.

It also does not make a cookie banner unnecessary. Rules about reading and storing on a device apply to your own cookies, too, unless an exemption covers them. See our guide to when analytics needs a banner.

What this means for analytics

Choose a tool that keeps data about your visitors on your side of the fence. Check three things.

  1. Who else sees it. Does the vendor use your visitors' data for its own purposes, or pass it to advertisers?
  2. Where it lives. A region you can name, and a retention period you set.
  3. What it takes from the device. An approach that stores nothing, like cookieless tracking, leaves less to explain.

A simple test is to ask whether you could describe, in a paragraph of your privacy notice, everything the tool does with a visitor's data. If you can, you are close to the point of first-party data. If you cannot, the tool is doing more than you are able to answer for.

Try it in trckable

trckable loads nothing from another company on your pages, and Cloud data is hosted in the EU. What it counts stays in your own record of your own site. Read the GDPR guide

Related terms

Read more

The newsletter

Notes on measuring what matters.

Occasional emails from Albi: new posts, one chart worth reading, what changed in trckable.

We send one email to confirm your address, and nothing more until you confirm. Every newsletter has a link to leave. What we keep, and who sends it: privacy.

Counted, never watched.