Online measurement has changed from a marketing-tool question into a governance question.
Browsers, operating systems, regulation and public expectations have reduced the reliability and acceptability of some cross-site tracking. At the same time, financial services firms need evidence about journeys, communications and client outcomes.
The source tells this story through old Apple opt-out figures, smartphone market share, Google's third-party-cookie plans and unsupported financial performance claims. Those facts are either unstable, superseded or too broad. A current response begins with purpose, the information already held and the controls around each measurement use.
The rule is wider than cookies
In April 2026, the UK Information Commissioner's Office finalised its guidance on storage and access technologies. It covers how PECR, and where relevant UK data-protection law, apply to technologies that store information on or access information from a person's device, including cookies, pixels, scripts, tags and fingerprinting.
Teams should use that current official guidance and qualified advice for their implementation. The applicable treatment depends on purpose, technology and circumstances; calling something “analytics” or “first party” does not decide the legal basis or exemption.
Inventory what every site and app deploys. Record:
- Technology and supplier
- Purpose and owner
- Information stored or accessed
- Personal data and linkage
- Recipients and transfers
- Retention
- Consent or exemption relied upon
- User controls
- Evidence the use remains necessary
Remove tags nobody can explain. A consent platform cannot govern unknown technology.
First-party data is not a free category
The source correctly distinguishes a direct relationship from third-party surveillance, then implies data supplied directly is largely unrestricted. That is unsafe.
Client, prospect and user data still needs a defined purpose, appropriate legal basis, transparency, minimisation, accuracy, security, retention and respect for rights. Financial services duties, confidentiality, contracts and vulnerability can add constraints.
A direct relationship can improve context and trust when the firm asks for information the client understands and receives clear value in return. It does not create permission to combine every interaction across portal, website, CRM, advice and service records.
Create a purpose map. For each business question, identify the minimum events and attributes needed. Keep service operation, regulatory records, experience research, personalisation and advertising distinct where their purposes differ.
Measure decisions instead of identities
Many useful questions do not require following a named individual across the internet.
A firm can examine:
- Whether a prospect finds a relevant service and contact route
- Where an onboarding task fails
- Which authenticated task drives support demand
- Whether a communication reaches the intended audience
- How long a client waits for a document or response
- Whether an accessibility repair improves task completion
Use aggregated or less identifiable data where it can answer the question. Sampling, qualitative research and operational records may provide better explanations than adding another tracking tag.
Data quality remains critical. Consent loss, blocked scripts, multiple devices, shared accounts and implementation errors can make digital analytics incomplete. State those limits. A dashboard does not turn partial observation into a complete client journey.
Connect systems only for a defined purpose
The source urges firms to integrate as much data as they sensibly can because more should improve prediction. More data can increase noise, exposure, unfair inference and operating cost.
Before connecting website, portal, CRM, transaction or advice records, ask:
- Which decision will this connection improve?
- Which people could be affected?
- Is the information comparable and accurate enough?
- Are permissions and purpose compatible?
- What bias, exclusion or unexpected use could follow?
- Who validates the output?
- When will the connection be removed?
Bring Data Protection, Security, Compliance, Legal and relevant model-risk owners into higher-consequence uses. Conduct appropriate assessments before processing, rather than after a prediction has entered workflow.
Prediction needs a safe baseline
The source advises starting prediction early and accepting rough output. That may be reasonable for a low-consequence internal experiment and dangerous for underwriting, fraud, pricing, eligibility or treatment of a client.
Define the outcome, comparator and affected decision. Use representative data, test variation across relevant groups and keep qualified human authority. Set thresholds for pause. Monitor drift, data change, feedback and unintended consequences.
A model can become wrong as conditions change, as the source notes. It can also be wrong at launch or appear accurate while harming a subgroup. Maintenance includes governance and outcome review, rather than retraining alone.
The source's Monzo valuation, team-growth and predictive-profit figures do not support a financial-services strategy and have been removed.
Privacy can become part of service quality
Explain data use in language people can act on. Give meaningful controls and avoid making rejection harder than acceptance where consent is required. Make essential service access available without unnecessary tracking.
Trust comes from conduct:
- Collecting less where less is sufficient
- Separating purposes
- Protecting access
- Correcting data
- Respecting choices
- Explaining material automated or assisted use
- Providing a human route
Marketing should not overstate privacy as a competitive claim while the technology estate remains poorly inventoried.
Build a resilient measurement plan
For every critical business measure, identify:
- Decision it informs
- Primary and secondary evidence
- Known gaps
- Owner and review cadence
- Legal and ethical controls
- Response if the signal disappears
Use server and operational data only where lawful, necessary and transparent; moving collection away from a browser does not remove data-protection responsibility. Avoid trying to recreate a disappearing third-party signal through more opaque fingerprinting.
Test the plan when a supplier, tag or consent category is removed. Which decisions become impossible, which can use another source and which were never important enough to justify collection? This exercise exposes reports that exist from habit and single-vendor dependencies disguised as measurement maturity. It also gives Finance and Compliance a clearer account of the value attached to each data flow.
The source's closing question remains strong: if every third-party signal disappeared tomorrow, how much would the firm know about clients through legitimate, useful relationships?
The answer should not be “everything”. A financial services firm should know what it needs for defined services and decisions, understand what it does not know and resist collecting data simply because it might become useful later.
Worth talking through? Book a short discovery call with the team at Distinction - no pitch, just an honest read on your data foundations.



