All Posts
Remarketing·3 min read

GDPR-Compliant Remarketing: Using Customer Data Safely

How to stay GDPR/KVKK compliant when uploading CRM data to Google Customer Match and Meta Custom Audiences — consent, anonymization, and retention.

RemarketingGDPRData PrivacyCompliance
GDPR-Compliant Remarketing: Using Customer Data Safely

Using your existing customer data for remarketing can turn into a compliance risk if it's not done right. Short answer: before uploading CRM data to Google Customer Match or Meta Custom Audiences, you need to be clear on three things — what consent the data was collected under, how it will be anonymized, and how long it will be retained. This guide walks through those three steps and the mistakes teams make most often.

What Data Can Actually Be Used for Remarketing?

GDPR Article 6 (and KVKK Article 5 in Turkey) requires a clear legal basis for processing personal data — consent, contract performance, legitimate interest, and so on. In practice, the safest basis for marketing profiling and ad targeting is explicit consent — a "legitimate interest" defense usually doesn't hold up for ad targeting, especially under GDPR.

Usable data is data the user has explicitly agreed to in ways like:
- Checking a consent box when signing up for marketing emails
- Accepting the "marketing/advertising" category in a cookie consent banner
- Agreeing to "I consent to my data being processed for marketing purposes" on a form

Not usable: Data collected purely to deliver a service (e.g., a billing address, support ticket content) can't be used for marketing by default — that requires separate consent.

A consent toggle switch lighting up on a tablet screen

Before building a remarketing segment, you need to be able to clearly identify which contacts in your CRM have given marketing consent. A practical checklist:

  • Does every contact record have a "marketing consent" field, or is everyone included by default?
  • Is when and through which channel (form, checkbox, signup) consent was given recorded?
  • Are people who withdraw consent automatically removed from segments?

If you can't answer these three clearly, you need to run a consent audit on your CRM before building a segment — otherwise you risk pulling non-consenting contacts into a custom audience by mistake.

Step 2: Anonymize the Data Correctly

Scattered data reorganizing into a clean, ordered structure

Google Customer Match and Meta Custom Audiences process the email and phone data you upload as hashed (one-way encrypted) — the platform never sees the raw data. But you still need to handle a few things on your end before uploading:

  1. Only upload the fields you need (email, phone) — don't include extras like name or address
  2. Normalize the data to the platform's standard format before uploading (lowercase, no whitespace)
  3. Securely delete or restrict access to the source file after upload

Step 3: Plan Retention and Refresh

GDPR and KVKK both require that data be kept "limited to purpose and for as long as necessary." In practice, that means you can't leave a custom audience open indefinitely:

  • Google Customer Match audiences go stale if not refreshed regularly — keep that cadence aligned with your consent policy
  • Define a process (manual or automated) for removing someone from an audience once they withdraw consent
  • Review annually which segments are still backed by active consent

Common Mistakes

  • Uploading the entire CRM database at once — includes non-consenting contacts, a direct compliance risk
  • Using a category the user rejected in the cookie banner anyway — if a user declined "advertising" cookies, their data shouldn't enter a remarketing audience
  • Keeping consent language generic — instead of vague wording like "we may process your data," clearly state that data will be used for remarketing specifically
  • Not updating your privacy notice — once you start remarketing, your privacy policy needs to explicitly disclose this use

Conclusion

A properly built consent and anonymization process is both the legal and ethical foundation of remarketing — and done right, it also strengthens campaign performance, because you're only reaching people who are genuinely interested. For the technical side of segment setup, see our ROAS optimization post, or reach out about our remarketing service for a compliant setup.

Frequently Asked Questions

Generally no — marketing profiling requires explicit consent. Narrow exceptions (e.g., within an existing contractual relationship) should be assessed with legal counsel.

Once consent status updates in your CRM, remove that contact from your segment list and re-upload the updated list to the platform; some integration tools can automate this.

Do the same rules apply to B2B data?

Yes, GDPR/KVKK apply whenever personal data is involved (including a work email address); that said, legitimate interest may be interpreted somewhat more broadly in a B2B context than B2C.

Is uploading hashed data protection enough on its own?

Hashing prevents the platform from seeing raw data, but it doesn't remove the consent requirement — hashing is a technical safeguard, not a substitute for a legal basis.

30 Minutes · Free

Ready to Get Started?

Let's discuss your business needs in a free call.

No credit card required · No commitment · Let's get started