
Stack Planning
Customer data platforms in a marketing stack
See where a CDP fits in a marketing stack, what it needs from source systems, and how to judge whether a specific use case justifies one.
Use a customer data platform (CDP) when a team needs to connect customer information from several systems and make the resulting record useful elsewhere in the stack. Start with a recurring task that the current systems handle poorly. If the team cannot describe the records, the intended use and who will maintain the rules, it has more work to do before choosing a platform.
Give the CDP a job
Suppose a campaign should exclude recent purchasers, but purchase information sits outside the sending tool. Identify where a purchase is recorded, which identifier could connect it to a customer, when the exclusion must take effect and which destination needs it. Check whether an existing connection could do the job.
A CDP can maintain customer context across sources, but it also creates ongoing work: monitoring feeds, managing identity rules, controlling access and resolving errors. The purchase exclusion is a hypothetical use case, not evidence that a CDP is necessary for every team.
The CDP Institute defines a CDP as software that maintains a persistent, unified customer record accessible to other systems. Its role includes taking primary responsibility for customer identity and record structure over time, not merely collecting data or passing it between tools.
CDP vs. Alternative Solutions for Customer Data Integration
- Customer Data Platform (CDP)Maintains a persistent, unified customer record; manages identity resolution; supports cross-system use; requires ongoing governance.
- Data Warehouse + Custom ScriptsStores raw data from multiple sources; requires in-house development for linking and enrichment; less automated identity management.
- CRM with Manual SyncsCentralises customer interactions but lacks automation across channels; prone to duplication and outdated information.
- Marketing Automation Tool with Built-in SegmentationLimited to internal data; weak identity resolution across devices or platforms; restricted by vendor-specific logic.
Place it between sources and uses
| Part of the stack | Decision to make |
|---|---|
| Source systems | Which events and attributes may be supplied, and who corrects them? |
| Customer-data layer | How are records linked, reconciled and made available? |
| Destination systems | Which fields or audiences may they receive, and when? |
| Operating team | Who investigates a failed feed or an unexpected audience change? |
A CRM may remain the place where staff manage sales or service work. The CDP may combine selected CRM data with other sources and provide an agreed attribute or audience to another tool. Decide the purpose and direction of each exchange; avoid letting two systems overwrite the same field without a conflict rule.
The CDP label does not promise one architecture. The CDP Institute describes services that may be provided within the product or composed with a warehouse and other components. Ask a supplier which parts its proposal provides, which depend on other systems and who operates each part.
A CDP may restructure source data, calculate values such as trends or model scores, and share results in formats other systems can use. Common access methods include APIs, database queries and file extracts. Ask which method carries each proposed output and whether the destination can accept that format.
Pros and Cons of Using a CDP in an Australian Marketing Stack
- ProsEnables consistent customer profiles across touchpoints; improves targeting accuracy; supports compliance with Australian Privacy Principles (APPs); facilitates GDPR and local privacy law alignment.
- ConsRequires significant ongoing governance; increases complexity in data flows; potential for identity errors if matching rules are poorly defined; risk of non-compliance if cross-border transfers are not managed.
Define a usable profile
List the identifiers the organisation collects and whether they are stable, shared or likely to change. A household email or shared browser can connect different people; one person can also have several valid identifiers. Decide which signals can establish a person-level match and which should leave a relationship unresolved.
Matching records is separate from choosing the value displayed when sources disagree. Agree which source owns each important attribute and how a correction reaches the profile and any destination using it. A large number of merged records says little about whether the links are correct.
A unified record may draw mainly on information collected through the organisation's own systems, and may also include external-source data or information about anonymous people. The CDP Institute notes that a CDP can retain all input details indefinitely, but users may restrict what is stored and for how long. Make those retention choices explicit in profile rules.
Check the proposed data use
Have the organisation's privacy owner assess the actual collection, use and disclosure before personal information is moved or activated. For an entity covered by Australian privacy rules, the assessment may involve the collection purpose, direct-marketing conditions and any disclosure to an overseas recipient. An available connector does not authorise a data transfer.
Collect only fields needed for the task. Set access, correction, retention and opt-out routes across the connected systems. The applicable obligations depend on the entity and data flow.
For an APP entity, APP 6 generally limits use or disclosure to the purpose for which personal information was collected, unless an exception applies, such as consent or a related purpose the individual would reasonably expect. For sensitive information, that secondary purpose must be directly related to the primary purpose.
Under APP 7, where an organisation is permitted to use or disclose personal information for direct marketing, it must provide a way to opt out and honour the request. On request, it must also provide the information's source unless impracticable or unreasonable.
Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps in the circumstances to ensure the recipient does not breach the APPs in relation to that information, subject to applicable exceptions.
Key Statistics on CDP Adoption and Compliance in Australia
- Required Opt-Out MechanismMust be provided under APP 7 for direct marketing; must be honoured promptly.
- Cross-Border Disclosure RequirementReasonable steps must be taken to ensure overseas recipients comply with APPs.
- Primary Purpose LimitationUse or disclosure generally limited to original collection purpose unless consented or reasonably expected.
Evaluate the complete path
Give candidates the same safe sample records and expected result. Ask them to show ingestion, identity decisions, the resulting profile and the output sent to the intended destination. Include a late event, a doubtful match, a correction and an opt-out. Record the edition, connected components, permissions and processing delay shown, plus any step the supplier cannot demonstrate.
A prepared demonstration establishes what happened in that account. The purchase decision depends on whether the proposed path solves a recurring problem and whether the organisation can keep its data and rules reliable. Repairing identifiers or an existing connection may be the better next step.
For each candidate, trace any capability that depends on an external component through to the destination output. Include that component and its operator in the tested path and record whether the end-to-end result meets the expected outcome.
In this guide
- A CDP versus a CRM: where the responsibilities differCompare the working responsibilities of a CDP and CRM, then assign ownership for customer records, identity, corrections and audiences.
- Checking identity resolution during a CDP evaluationUse known record relationships, shared-identifier cases and a case log to assess CDP identity matching and profile reconciliation.
- Assessing whether a team is ready for a CDPAssess CDP readiness through one use case, essential data, a privacy assessment route and named operating owners, then choose the next step.



