
Stack Planning
Part of Customer data platforms in a marketing stack
Assessing whether a team is ready for a CDP
Assess CDP readiness through one use case, essential data, a privacy assessment route and named operating owners, then choose the next step.
Assess readiness by checking one customer-data use case, the data needed to deliver it, the privacy decisions that govern its use and the people who will operate it. The result should be one of three: evaluate a CDP, repair a prerequisite first or reuse customer-data services already available.
Start with one decision
Write a use case with an owner and an observable result. For example: exclude customers who recently bought a product from a related acquisition audience.
Define the purchase event, the relevant period, where it originates, how quickly the exclusion must update and which campaign system needs it.
Describe the current failure. Is the purchase data missing, delayed, inconsistently defined or difficult to match? If nobody can point to a consequential problem, gather that evidence before adding another platform.
Check the essentials
| Readiness question | Evidence to gather |
|---|---|
| Does the team understand the data for this task? | Sources, field meanings, identifiers and known gaps. |
| Can it define a correct customer record? | Matching, conflict and correction decisions for the use case. |
| Is there a route to assess the proposed data use? | Privacy owner and assessment of the intended destination and marketing use. |
| Can it operate the service? | Owners for feeds, rules, access, incidents and destination changes. |
For the use case, identify the source systems, field meanings and known gaps, then name a persistent customer identifier expected to link records for the same identified person. Define what a successful match must make possible for the use case.
A CDP maintains a persistent, unified customer record accessible to other systems and takes responsibility for customer identity and record structure over time. Check that the proposed service can provide the needed output in a format the destination can use.
Record the collection purpose and intended use, and check how those purposes are described in the organisation’s APP privacy policy. Under APP 3, an organisation may collect personal information only where it is reasonably necessary for its functions or activities; collecting sensitive information has an additional consent requirement unless an exception applies.
Under APP 6, personal information can generally be used or disclosed for the purpose for which it was collected; a secondary purpose needs an applicable exception. If direct marketing is planned, check APP 7: where an exception permits it, the organisation must allow people to opt out and comply with their requests.
The Privacy Act 1988 includes the Australian Privacy Principles (APPs), with guidance from the Office of the Australian Information Commissioner (OAIC). An owner should check which requirements apply to the organisation and data flow before personal information is used.
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. When the information is no longer needed for a permitted purpose, reasonable steps must be taken to destroy or de-identify it, except where an applicable retention requirement or Commonwealth record exception applies.
Before an APP entity discloses personal information to an overseas recipient, APP 8.1 requires reasonable steps to ensure the recipient does not breach the APPs in relation to that information. The entity is accountable for the recipient’s relevant acts or practices under section 16C, subject to exceptions.
Australian Privacy Principles (APPs) Relevant to CDP Use
- 3APP – Collection — Personal information must be reasonably necessary for functions; sensitive data requires consent.
- 6APP – Use and Disclosure — Use only for original purpose unless exception applies.
- 7APP – Direct Marketing — Must allow opt-out; comply with requests.
- 8APP – Cross-Border Disclosure — Ensure overseas recipients comply with APPs; entity remains accountable.
- 11APP – Security — Take reasonable steps to protect data; destroy or de-identify when no longer needed.
Find the operating capacity
Name who will notice a stopped feed, blank identifier or unexpected audience change, and who can investigate each one. The work may span marketing operations, data, IT, privacy and the destination team.
If maintaining another customer-data layer relies on time nobody has committed, that is a readiness gap. Check that the proposed destination can use the required output and timing.
An advertised connector does not establish which fields transfer, how often they update or how failures appear. Ask for those details as evidence during an evaluation.
Choose the next step
- Evaluate a bounded use casewhen the task, essential data, responsible people and route for assessing data use are clear. Use safe records and list what still needs proving.
- Repair a prerequisitewhen the need is real but a critical identifier, definition, correction route or owner is missing. Give the repair a checkable result.
- Use an existing routewhen current systems can complete the task through an agreed process or connection. Reassess a CDP if later work needs the same customer context across more systems.
Evaluate when the use case, source data, identifier, privacy decision and operating owners are clear, but a consequential problem remains for a CDP to address. A preliminary evaluation using safe synthetic records may proceed while a real-data privacy question is being resolved; real-data use requires the applicable decision first.
Repair first when a prerequisite is unresolved: clarify source fields or events, confirm the identifier and intended use, or assign the people responsible for ongoing operation. Reassess readiness after the gap is addressed.
Reuse when existing customer-data services can meet the use case and deliver the required output. Data warehouses, software suites and marketing clouds may provide functions similar to a CDP, and CDP services may also be composed from external systems.
Keep a short readiness record: use case, current failure, source and destination, essential identifiers, privacy decision owner, operating owners, unresolved prerequisites and next decision date. It gives the team a defined starting point for evaluation or a clear reason to defer.



