Short answer: Buy customer data platform software only after a proof of value ingests representative web, mobile, transaction, CRM, support, loyalty, advertising, and offline events with documented schemas, freshness, quality, and source rights; resolves anonymous and known identities with measured false-merge and missed-match rates; shows field provenance and reversible profile changes; enforces lawful basis, purpose, consent, opt-out, regional, age, sensitive-data, minimization, retention, and deletion rules before segmentation and activation; builds reproducible audiences with versioned logic and counts; activates and suppresses destinations with measured latency and closed-loop delivery evidence; separates attribution claims from experimental incrementality; secures profiles, connectors, and operator access; and supports full export and deletion without hidden copies. A large unified profile is a liability unless every attribute and use is necessary, explainable, permitted, accurate, and removable.

A CDP collects customer and prospect data, resolves identity, maintains profiles, creates audiences, and activates them to downstream systems. Its business value and privacy risk come from the same concentration of behavioral, transactional, and identity data, so proof must cover governance as deeply as marketer usability.
Do not use only a polished vendor sample. Seed conflicting identifiers, shared devices, anonymous-to-known transitions, consent changes, opt-outs, deletions, late events, duplicate events, destination failure, and sensitive attributes, then test the entire lifecycle.
Prove Source, Event, Schema, And Quality Coverage
Define web, mobile, CRM, commerce, POS, support, email, loyalty, ads, offline, batch, streaming, APIs, SDKs, identifiers, event schemas, consent context, timestamps, late and duplicate events, source rights, freshness, and quality. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require source-to-field matrix, event reconciliation, schema validation, freshness percentiles, duplicate and late-event results, source-rights review, and data-quality dashboard. A source connector can ingest events while dropping consent context, changing meanings, duplicating conversions, or using data outside the permitted source purpose. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Validate Identity Resolution And Profile Provenance
Define anonymous IDs, login IDs, emails, phones, loyalty IDs, device and browser IDs, households, shared devices, deterministic and probabilistic rules, graph links, thresholds, conflicts, splits, merges, history, and source provenance. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require a labeled identity corpus with false merges, missed matches, segment results, field provenance, reversible merge and split, and regression tests. False identity merges expose one person's data or preferences to another and corrupt audiences, while missed links distort customer journeys. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Enforce Consent, Purpose, Minimization, And Retention
Define lawful basis, purpose, granular consent, withdrawal, opt-out, direct marketing objection, regional rules, age, sensitive data, data minimization, collection limits, use limits, retention, deletion, legal hold, and policy version. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require policy decision matrix with allowed and denied scenarios, consent change propagation, source collection block, retention expiry, deletion trace, and privacy approval. A consent flag stored on the profile is insufficient if collection, resolution, segmentation, export, suppression, and deletion do not obey it consistently. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Test Segment Logic, Reproducibility, And Governance
Define real-time and batch segments, nested rules, sequences, frequency, recency, lookback, exclusions, suppressions, calculated attributes, SQL, predictions, approvals, versioning, preview, count drift, dependencies, ownership, and deprecation. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require known-population segment tests, repeatable counts, version diff, exclusion evidence, approval workflow, dependency impact, and rollback. Opaque or mutable audience logic can silently include opted-out, ineligible, sensitive, or wrong customers and cannot be audited after activation. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Verify Activation, Suppression, And Destination Delivery
Define email, ads, CRM, service, personalization, analytics and warehouses, profiles and events, batch and streaming, destination identifiers, hashing, consent, suppression, frequency, latency, retries, duplicates, rate limits, API versions, failures, and deletion. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require end-to-end activation tests with receipt reconciliation, latency percentiles, opt-out and suppression priority, destination outage recovery, duplicate control, and deletion propagation. A platform can mark an audience sent while the destination receives the wrong IDs, late changes, duplicates, or no suppression update. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Separate Attribution From Incremental Measurement
Define exposure, conversion, attribution windows, identity, deduplication, offline outcomes, holdouts, randomized tests, control groups, selection bias, channel overlap, modeled claims, data latency, and metric definitions. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require metric lineage, reconciled conversions, holdout or experiment workflow, known test campaign, documented assumptions, and result reproducibility. Attributed conversions are not proof that activation caused incremental outcomes, especially when the CDP defines both audience and measurement. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Secure Profiles, Connectors, Users, And Deletion
Define roles, field access, masking, service accounts, API scopes, connector tokens, encryption, keys, tenant separation, regional processing, support access, audit logs, exports, public links, incident response, backups, deletion, and downstream copies. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require role and field tests, secret rotation, audit export, regional data-flow map, incident exercise, full deletion trace, and backup retention evidence. A CDP is a high-value identity and behavior store, and broad marketer or support access can expose sensitive profiles and downstream credentials. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Model Operations, Portability, And Total Cost
Define profiles, events, attributes, audiences, destinations, queries, storage, retention, real-time features, compute, data egress, SDK maintenance, identity tuning, data engineering, privacy review, campaign operations, support, renewal, and exit. The buying brief should name users, workflows, data, integrations, administration, exclusions, assumptions, and the condition that changes the requirement.
Require volume-based three-year scenarios, operating RACI, measured build and review effort, capacity limits, contract protections, full profile and event export, and destination removal test. Event growth, premium activation, identity tuning, engineering, and exit constraints can make a CDP more expensive than the apparent per-profile price. Preserve the result in the scored demo, security review, implementation plan, contract, and renewal record so acceptance is auditable.
Review The Platform From First Event To Verified Deletion
Prove Data Rights, Identity, And Profile Accuracy
Prove Source, Event, Schema, And Quality Coverage
Confirm web, mobile, CRM, commerce, POS, support, email, loyalty, ads, offline, batch, streaming, APIs, SDKs, identifiers, event schemas, consent context, timestamps, late and duplicate events, source rights, freshness, and quality; retain source-to-field matrix, event reconciliation, schema validation, freshness percentiles, duplicate and late-event results, source-rights review, and data-quality dashboard.
Validate Identity Resolution And Profile Provenance
Confirm anonymous IDs, login IDs, emails, phones, loyalty IDs, device and browser IDs, households, shared devices, deterministic and probabilistic rules, graph links, thresholds, conflicts, splits, merges, history, and source provenance; retain a labeled identity corpus with false merges, missed matches, segment results, field provenance, reversible merge and split, and regression tests.
Prove Security, Portability, And Sustainable Operations
Secure Profiles, Connectors, Users, And Deletion
Confirm roles, field access, masking, service accounts, API scopes, connector tokens, encryption, keys, tenant separation, regional processing, support access, audit logs, exports, public links, incident response, backups, deletion, and downstream copies; retain role and field tests, secret rotation, audit export, regional data-flow map, incident exercise, full deletion trace, and backup retention evidence.
Model Operations, Portability, And Total Cost
Confirm profiles, events, attributes, audiences, destinations, queries, storage, retention, real-time features, compute, data egress, SDK maintenance, identity tuning, data engineering, privacy review, campaign operations, support, renewal, and exit; retain volume-based three-year scenarios, operating RACI, measured build and review effort, capacity limits, contract protections, full profile and event export, and destination removal test.
CDP Software Buying Test Scorecard
| Buying area | What to confirm | Why it matters |
|---|---|---|
| Prove Source, Event, Schema, And Quality Coverage | web, mobile, CRM, commerce, POS, support, email, loyalty, ads, offline, batch, streaming, APIs, SDKs, identifiers, event schemas, consent context, timestamps, late and duplicate events, source rights, freshness, and quality. | A source connector can ingest events while dropping consent context, changing meanings, duplicating conversions, or using data outside the permitted source purpose. |
| Validate Identity Resolution And Profile Provenance | anonymous IDs, login IDs, emails, phones, loyalty IDs, device and browser IDs, households, shared devices, deterministic and probabilistic rules, graph links, thresholds, conflicts, splits, merges, history, and source provenance. | False identity merges expose one person's data or preferences to another and corrupt audiences, while missed links distort customer journeys. |
| Enforce Consent, Purpose, Minimization, And Retention | lawful basis, purpose, granular consent, withdrawal, opt-out, direct marketing objection, regional rules, age, sensitive data, data minimization, collection limits, use limits, retention, deletion, legal hold, and policy version. | A consent flag stored on the profile is insufficient if collection, resolution, segmentation, export, suppression, and deletion do not obey it consistently. |
| Test Segment Logic, Reproducibility, And Governance | real-time and batch segments, nested rules, sequences, frequency, recency, lookback, exclusions, suppressions, calculated attributes, SQL, predictions, approvals, versioning, preview, count drift, dependencies, ownership, and deprecation. | Opaque or mutable audience logic can silently include opted-out, ineligible, sensitive, or wrong customers and cannot be audited after activation. |
| Verify Activation, Suppression, And Destination Delivery | email, ads, CRM, service, personalization, analytics and warehouses, profiles and events, batch and streaming, destination identifiers, hashing, consent, suppression, frequency, latency, retries, duplicates, rate limits, API versions, failures, and deletion. | A platform can mark an audience sent while the destination receives the wrong IDs, late changes, duplicates, or no suppression update. |
| Separate Attribution From Incremental Measurement | exposure, conversion, attribution windows, identity, deduplication, offline outcomes, holdouts, randomized tests, control groups, selection bias, channel overlap, modeled claims, data latency, and metric definitions. | Attributed conversions are not proof that activation caused incremental outcomes, especially when the CDP defines both audience and measurement. |
Questions To Ask Before Approval
- How will the proposal define web, mobile, CRM, commerce, POS, support, email, loyalty, ads, offline, batch, streaming, APIs, SDKs, identifiers, event schemas, consent context, timestamps, late and duplicate events, source rights, freshness, and quality and prove it with source-to-field matrix, event reconciliation, schema validation, freshness percentiles, duplicate and late-event results, source-rights review, and data-quality dashboard?
- How will the proposal define anonymous IDs, login IDs, emails, phones, loyalty IDs, device and browser IDs, households, shared devices, deterministic and probabilistic rules, graph links, thresholds, conflicts, splits, merges, history, and source provenance and prove it with a labeled identity corpus with false merges, missed matches, segment results, field provenance, reversible merge and split, and regression tests?
- How will the proposal define lawful basis, purpose, granular consent, withdrawal, opt-out, direct marketing objection, regional rules, age, sensitive data, data minimization, collection limits, use limits, retention, deletion, legal hold, and policy version and prove it with policy decision matrix with allowed and denied scenarios, consent change propagation, source collection block, retention expiry, deletion trace, and privacy approval?
- How will the proposal define real-time and batch segments, nested rules, sequences, frequency, recency, lookback, exclusions, suppressions, calculated attributes, SQL, predictions, approvals, versioning, preview, count drift, dependencies, ownership, and deprecation and prove it with known-population segment tests, repeatable counts, version diff, exclusion evidence, approval workflow, dependency impact, and rollback?
- How will the proposal define email, ads, CRM, service, personalization, analytics and warehouses, profiles and events, batch and streaming, destination identifiers, hashing, consent, suppression, frequency, latency, retries, duplicates, rate limits, API versions, failures, and deletion and prove it with end-to-end activation tests with receipt reconciliation, latency percentiles, opt-out and suppression priority, destination outage recovery, duplicate control, and deletion propagation?
- How will the proposal define exposure, conversion, attribution windows, identity, deduplication, offline outcomes, holdouts, randomized tests, control groups, selection bias, channel overlap, modeled claims, data latency, and metric definitions and prove it with metric lineage, reconciled conversions, holdout or experiment workflow, known test campaign, documented assumptions, and result reproducibility?
- How will the proposal define roles, field access, masking, service accounts, API scopes, connector tokens, encryption, keys, tenant separation, regional processing, support access, audit logs, exports, public links, incident response, backups, deletion, and downstream copies and prove it with role and field tests, secret rotation, audit export, regional data-flow map, incident exercise, full deletion trace, and backup retention evidence?
- How will the proposal define profiles, events, attributes, audiences, destinations, queries, storage, retention, real-time features, compute, data egress, SDK maintenance, identity tuning, data engineering, privacy review, campaign operations, support, renewal, and exit and prove it with volume-based three-year scenarios, operating RACI, measured build and review effort, capacity limits, contract protections, full profile and event export, and destination removal test?
Buying Red Flags
A unified customer count without false-merge and missed-match results does not prove identity quality.
A consent field that does not block collection, profiling, activation, suppression changes, and downstream use is not lifecycle enforcement.
Attribution dashboards presented as incremental lift without holdouts or experimental controls overstate marketing impact.
Source Links
- FTC privacy and security business guidance
- NIST Privacy Framework
- EDPB lawful personal data processing guidance
- ICO direct marketing profiling guidance
FAQ
How is a CDP different from CRM?
CRM manages sales and service relationships; a CDP combines multichannel events and identities for profiles, audiences, and activation. Their data and workflows often integrate.
What is identity resolution in a CDP?
It links identifiers and events believed to belong to the same person or household. Test false merges, missed matches, shared devices, provenance, and reversibility.
Does a CDP make data use compliant?
No. The organization still needs lawful basis, purpose, notice, consent where applicable, minimization, security, rights handling, retention, and accountable decisions.
How fast should CDP activation be?
Set use-case-specific latency targets and measure event-to-profile-to-segment-to-destination delivery. Real-time branding does not guarantee end-to-end freshness.
Can CDP attribution prove campaign impact?
Attribution assigns credit under rules; incremental impact requires credible controls such as randomized holdouts or well-designed experiments.
What should a CDP deletion test cover?
Trace the subject through source collection, identity graph, profiles, events, segments, exports, destinations, logs, caches, backups, suppression obligations, and evidence of completion.
Related Software Buyer Guide Guides
- CRM software migration checklist
- Consent management software checklist
- Data subject request software checklist
Approve a CDP only when identity, consent, purpose, profile, segment, activation, suppression, measurement, security, and deletion stay correct across the full customer data lifecycle.