Financial services is where martech meets genuine legal constraint. Most of the standard playbook, hashed email to an ad platform, third-party enrichment, behavioural retargeting on product pages, needs careful thought when the behaviour in question reveals someone is in debt, unwell, or shopping for life insurance. Special category data and vulnerable customer duties are not edge cases here.

The result is usually one of two failure modes. Either compliance says no to everything and marketing operates blind, or marketing implements the standard approach and nobody checks what is being transmitted. Both are avoidable, and the way through is architectural: decide deliberately what leaves your estate, rather than letting a third-party tag decide for you.

Consumer Duty raised the bar on all of it. Marketing that could be defended as merely lawful now has to be defended as delivering good outcomes and not exploiting customers in vulnerable circumstances, and that standard applies to retargeting and personalisation as much as to product design. The firms doing this well have stopped treating it as a constraint on marketing and started treating it as the specification for how marketing data should be built.

Who we work with in financial services

The marketer who needs measurement to work, and the compliance lead who needs to be able to evidence it.

  • Head of Digital Acquisition
  • Head of CRM and Retention
  • Marketing Technology lead
  • DPO and Data Protection lead
  • Compliance and Conduct lead

What tends to break

What you may legitimately send an ad platform

A retargeting pixel on a product page can imply a great deal about someone’s financial circumstances. Server-side collection matters here more than anywhere else, because it is the only way to control precisely which fields leave your estate rather than letting a browser script take what it likes.

Consent that has to hold up

Consent in this sector is not a banner exercise. It has to be captured properly, propagated to every downstream system, honoured on withdrawal, and evidenced afterwards. Most estates can honour it at capture and fail at propagation.

Quote abandonment at scale

Insurance and lending funnels lose the overwhelming majority of starts. Recovering even a small share is highly valuable, but doing it without being intrusive, and without retargeting someone declined for credit, requires a genuinely careful design.

Long, fragmented customer relationships

A customer may hold a current account, a mortgage and a policy on three systems that have never spoken. Renewal and cross-sell depend on resolving that, and the resolution has to respect the permissions attached to each product.

The aggregator owns the first interaction

In personal lines insurance and much of consumer lending, the customer arrives from a comparison site with a quote already in hand and very little consented data attached. Your first genuine data capture is at application, and renewal a year later is the first time you can market to a customer you know. The estate has to be designed around that gap rather than pretending the customer started with you.

What we get asked to do

  • Server-side collection architecture that gives you explicit, auditable control over what is shared with each ad platform, delivered through martech and adtech implementation.
  • Consent capture, propagation and evidencing across the estate, including withdrawal handling and downstream suppression.
  • Quote and application funnel measurement, with abandonment recovery designed around vulnerability and eligibility rules.
  • Identity resolution across product lines, respecting per-product permissions and retention rules, usually as part of CDI and CDP implementation.
  • Value-based bidding using approved, aggregated outcome data rather than raw customer records.
  • Renewal, retention and cross-sell journeys with the compliance sign-off path built into the process, delivered as personalisation and activation.
  • Consumer Duty evidence for marketing data: documenting what is collected, why, what leaves the estate and how vulnerability flags suppress activity, in a form compliance can sign and a regulator can read.
  • Renewal and retention measurement where the first meaningful consented relationship starts at policy inception rather than at quote.

The first questions we ask a regulated marketer

Most of these are also the first questions your compliance team will ask us, which is the point.

  1. 01Can you list, today, every field that leaves your estate for each ad platform, and under what lawful basis?
  2. 02When a customer withdraws consent, how long does it take to reach every downstream system, and can you prove it did?
  3. 03What suppresses a declined applicant or a customer flagged as vulnerable from retargeting, and is that enforced in the architecture or in a campaign setting?
  4. 04At what point does compliance see a marketing proposal: at architecture stage or at approval stage?
  5. 05What share of new business arrives via aggregators, and what do you know about those customers at inception?
  6. 06Which parts of your measurement still rely on a browser script deciding what to send?

Not sure what your tags are actually transmitting?

The Martech & Adtech Health Check audits what leaves your estate, how consent propagates and where the measurement gaps are, and hands back a prioritised plan your DPO can read. Stack Teardown from £1,950, full Health Check from £6,500.

See what it covers

Common questions

Can we use Conversions API and still be compliant?

In most cases yes, and it usually improves your position rather than worsening it. Server-side collection means you decide exactly which fields are transmitted instead of a browser script scraping whatever is available. What matters is the data protection assessment behind it: lawful basis, what is sent, what is hashed, retention, and whether the customer would reasonably expect it. We build the implementation; your DPO signs off the basis.

Compliance blocks most of what marketing proposes. How do you get past that?

Do you have real experience in this sector?

Do you give legal or regulatory advice?

Trying to make measurement work inside the rules rather than around them? Let’s talk.

Get in touch