Forrester's June 2025 analysis of the B2C CDP market declares a new phase: CDPs have moved past their data-collection adolescence and entered a "utility era" defined by outcomes. Marketers want CDPs that power AI models, enable real-time personalization, and drive measurable revenue, not merely aggregate profiles. The framing is accurate as far as it goes. But it stops short of the more uncomfortable reality enterprise teams now face. Every outcome a modern CDP promises, from propensity scoring to cross-channel orchestration to generative content assembly, depends on data usage rights that most organizations have never properly codified. The utility era is, whether Forrester names it or not, a compliance era.
This matters because the gap between what CDPs can technically do and what they are legally permitted to do is widening, not narrowing. As AI-driven activation becomes the default expectation, the privacy infrastructure underlying customer data platforms becomes the binding constraint on marketing performance.
1. Historical context
The CDP category emerged around 2013 as a response to a real operational pain: marketing teams could not unify customer records scattered across email platforms, CRM systems, web analytics tools, and point-of-sale databases. The original value proposition was identity resolution and profile unification. Get all the data into one place. The privacy question was largely an afterthought.
This was partly a product of timing. The General Data Protection Regulation would not take effect until May 2018. The California Consumer Privacy Act followed in January 2020. When early CDPs like Tealium, Segment, and mParticle were establishing the category, marketers operated under a relatively permissive consent regime. Third-party cookies were abundant. Email opt-out (rather than opt-in) was the norm in most jurisdictions outside the EU. Data collection was cheap and consequences for misuse were rare.
The first wave of CDP adoption, roughly 2015 through 2019, focused on ingestion. How many data sources could you connect? How fast could you resolve identities? How complete was the unified profile? Vendors competed on connector libraries and ingestion throughput. Privacy was a checkbox, not an architecture.
The second wave, from 2020 through 2024, added activation. CDPs began competing on their ability to push segments to advertising platforms, trigger real-time messages, and feed machine learning models. Salesforce, Adobe, and Oracle embedded CDP capabilities into their marketing clouds. The standalone CDP and the suite CDP began a territorial war that David Raab of the CDP Institute has tracked in detail for years.
Forrester's new "utility era" framing describes what is supposed to be the third wave: CDPs as outcome engines. But this wave arrives into a regulatory environment that has changed enormously since the category was born. The EU's Digital Markets Act, Brazil's LGPD, India's Digital Personal Data Protection Act, and a patchwork of US state laws (Colorado, Connecticut, Virginia, Texas, Oregon, and others) now constrain how unified profiles can be built, stored, activated, and shared. AI-specific regulation, including the EU AI Act, adds another layer of requirements around automated decision-making and profiling.
The category's architecture, designed for maximum data ingestion, now operates inside a system of rules designed to limit it. As we discussed in our analysis of how personalization fails without operational support, the gap between ambition and execution is usually an infrastructure problem. In the CDP context, that infrastructure is increasingly about consent management and data governance.
Source: IAPP US State Privacy Legislation Tracker, 2025
"Customer data platforms can only perform well when they're built on a foundation of clean, consented, well-governed data. Without that, all the AI and analytics in the world won't help."
2. Technical analysis
The technical shift Forrester identifies is real. CDPs are being asked to do more than store and segment. They are expected to serve as the data substrate for AI models that generate audiences, predict churn, recommend content, and optimize send times. This changes the engineering requirements in three ways that have direct privacy implications.
From batch segmentation to real-time decisioning
Traditional CDP workflows operated on batch cycles. Ingest data overnight, build segments in the morning, push to channels by afternoon. Consent checks could happen at segment-build time with reasonable confidence. Real-time activation, where a CDP feeds a next-best-action model that fires within milliseconds of a behavioral signal, compresses the window for consent validation to near zero. The system must know, at query time, whether a given profile has the appropriate permissions for a given use case in a given jurisdiction. This requires consent to be stored as a structured, queryable attribute on the profile itself, not in a separate compliance database that gets checked asynchronously.
Most enterprise CDP implementations do not work this way. Consent records are often maintained in a separate system of record (frequently the CRM or a dedicated consent management platform) and synchronized to the CDP on a schedule. The latency between a consent change and its reflection in the CDP can range from minutes to hours. In a batch world, this was acceptable. In a real-time activation world, it creates a window during which the system may act on data it no longer has permission to use.
From first-party profiles to AI training data
When a CDP supplies data to train or fine-tune machine learning models, the data's role changes. It is no longer being used to send a specific message to a specific person. It is being used to derive statistical patterns that inform decisions about other people. Under GDPR's purpose limitation principle (Article 5(1)(b)), this is a different processing purpose that requires its own legal basis. The EU AI Act's requirements around transparency in automated decision-making add further obligations.
Few CDPs currently distinguish between "data available for direct activation" and "data available for model training" in their permission models. The profile is either active or suppressed. This binary approach does not map to the multi-purpose consent frameworks that regulations now demand.
From single-tenant to composable architectures
The rise of composable CDPs, where the data warehouse itself (Snowflake, Databricks, BigQuery) serves as the CDP's storage layer, introduces new questions about data residency and processing jurisdiction. When a CDP operates as a SaaS platform, data residency is (at least theoretically) controlled by the vendor's infrastructure choices. When the CDP is a computation layer sitting on top of a customer's own warehouse, the compliance boundary shifts. The customer is now responsible for ensuring that the warehouse's configuration, access controls, and cross-border data transfer mechanisms meet regulatory requirements. This is an improvement in some respects: organizations retain more control. But it also transfers compliance engineering from the CDP vendor to the customer's data team, which may not have privacy expertise.
As we examined in the data trust crisis and operational neglect, the organizations best positioned to manage these shifts are those that treat data governance as an operational discipline, not a periodic audit.
3. Strategic implications
For enterprise marketing operations leaders, the convergence of CDP ambition and privacy constraint creates several strategic pressures.
Consent architecture becomes a performance variable
Organizations that build granular, real-time consent infrastructure will have access to more data for activation and model training than those with coarse, batch-processed consent. This inverts a long-standing assumption: privacy engineering is not a cost center that restricts marketing. It is a capability that expands the usable data surface. A well-implemented privacy compliance framework, with granular purpose-based consent captured at the point of collection and enforced at the point of activation, yields a larger pool of permission-validated profiles than a blunt opt-in/opt-out binary.
Consider two organizations with identical databases of one million contacts. Organization A captures consent for four distinct purposes (email marketing, behavioral analytics, AI-driven personalization, and third-party data sharing) and maintains consent at the attribute level. Organization B captures a single "marketing consent" flag. When a new AI personalization model requires training data, Organization A can query for all profiles with purpose-specific consent and proceed. Organization B must either re-consent its entire database or risk processing data without adequate legal basis. Organization A's usable dataset for the new use case may be 600,000 profiles. Organization B's may be zero.
CDP selection becomes a privacy architecture decision
The CDP market's ongoing consolidation, with suite vendors embedding CDP features into their clouds and pure-play vendors differentiating on composability, means that CDP selection now carries privacy architecture implications that persist for years. An organization that chooses Salesforce Data Cloud inherits Salesforce's consent model and data residency infrastructure. An organization that chooses a composable approach on Snowflake inherits responsibility for building its own. Neither is inherently superior, but the decision shapes the organization's privacy engineering burden for the life of the implementation.
This is analogous to the dynamics we analyzed in how email platform selection has become a revenue architecture decision. The platform choice is not a feature comparison. It is a structural commitment.
AI governance and marketing operations converge
As CDPs become the data layer for AI-driven marketing, marketing operations teams find themselves responsible for AI governance questions they were never trained to handle. Which models have access to which data? How are automated decisions logged and auditable? What happens when a model's output produces discriminatory targeting? These questions belong to a discipline that barely existed five years ago. Enterprise teams that do not build this competency internally will find themselves dependent on vendors whose incentives may not align with compliance.
"Privacy is not a feature. It's a social contract."
4. Practical application
Enterprise teams preparing for this convergence should focus on four operational workstreams.
Audit consent granularity against activation use cases
Map every current and planned CDP activation (email personalization, web content adaptation, ad audience syndication, AI model training, predictive scoring) to its required legal basis under each applicable regulation. Identify where existing consent mechanisms are too coarse to support planned use cases. This audit typically reveals that organizations have consent for email sends but lack explicit consent for behavioral profiling, AI training, or cross-channel identity matching. A structured privacy assessment can surface these gaps before they become enforcement risks.
Implement consent as a real-time data attribute
Move consent from a separate compliance database into the CDP's profile schema as a structured, real-time attribute. Each profile should carry machine-readable consent records that specify the purpose, the legal basis, the date of capture, the version of the privacy notice in effect, and the channel of collection. This enables consent-aware activation at query time rather than batch-synchronized suppression. For organizations running Oracle Eloqua, this often involves tighter integration between the platform's subscription management and the CDP layer, work that benefits from data services designed around governance.
Establish data purpose taxonomies
Create a formal taxonomy of data processing purposes that maps to both regulatory requirements and marketing use cases. "Marketing" is too broad to serve as a purpose under GDPR or the EU AI Act. A taxonomy might include: transactional communication, promotional email, behavioral segmentation, AI-driven content recommendation, predictive lead scoring, third-party audience syndication, and aggregate analytics. Each purpose should have a defined legal basis, a retention period, and a set of permissible data attributes. This taxonomy becomes the governance layer that sits between the CDP and every downstream activation system.
Build audit trails for AI-driven decisions
When a CDP feeds data into a model that generates a recommendation (which product to show, which email to send, which lead score to assign), the decision chain must be logged. Under the EU AI Act's requirements for high-risk AI systems, and under GDPR's Article 22 provisions on automated decision-making, individuals may have the right to understand how a decision was made and to challenge it. Marketing operations teams should work with their data engineering counterparts to ensure that model inputs, outputs, and the consent status of the data used are recorded in a queryable audit log. This is not a theoretical concern. The European Data Protection Board's 2024 guidance on AI and data protection explicitly addresses profiling for marketing purposes.
5. Future scenarios
Looking 18 to 24 months ahead, three scenarios are plausible.
Consent-as-a-service becomes a CDP feature category
CDP vendors will begin competing on the sophistication of their consent management capabilities, much as they once competed on connector libraries. Expect to see native support for purpose-based consent schemas, real-time consent propagation across activation channels, and consent analytics dashboards that show the revenue impact of consent gaps. Vendors like OneTrust and TrustArc, currently positioned as standalone consent platforms, may find their functionality absorbed into CDP suites, or they may pivot to become the consent orchestration layer that sits above multiple CDPs.
Regulatory divergence fragments the unified profile
As privacy regulations proliferate and diverge (India's DPDP Act differs materially from GDPR, which differs from US state laws), the dream of a single unified global customer profile may become legally untenable. CDPs may need to maintain jurisdiction-specific profile views, where the data available for activation in the EU differs from the data available in the US or India, based on the consent and legal basis applicable in each jurisdiction. This fragments the unified profile into a set of jurisdiction-aware profiles, increasing architectural complexity and operational cost.
Privacy infrastructure becomes a competitive moat
Organizations that invest in consent engineering and data governance now will, by 2027, have access to significantly larger pools of permission-validated data for AI training and activation than those that delay. In a world where AI model performance depends on data quality and quantity, consent infrastructure becomes a direct contributor to marketing performance. The organizations with the best privacy architectures will have the best AI models, and therefore the best personalization, and therefore the highest conversion rates. Privacy engineering becomes a revenue investment.
This trajectory reinforces what we have observed across the MarTech stack: the organizations treating privacy compliance as an operational capability rather than a legal obligation are the ones building durable competitive advantages.
6. Takeaways
-
Forrester's "utility era" framing for CDPs is accurate on the capability axis but incomplete on the constraint axis. AI-powered activation creates privacy engineering requirements that most CDP implementations do not yet satisfy.
-
Real-time activation compresses the window for consent validation to near zero, requiring consent to be a structured, queryable attribute on the customer profile, not an asynchronous suppression list.
-
CDP selection now carries multi-year privacy architecture implications. Suite CDPs and composable CDPs distribute compliance responsibility differently, and the choice shapes operational burden.
-
Consent granularity is a performance variable, not a compliance checkbox. Organizations with purpose-specific consent for AI training, behavioral profiling, and cross-channel activation will have access to larger usable datasets than those with binary opt-in/opt-out models.
-
Enterprise teams should build formal data purpose taxonomies that map regulatory requirements to marketing use cases, and implement audit trails for AI-driven decisions before enforcement actions force them to.
-
Within 18 to 24 months, privacy infrastructure will function as a competitive moat. The organizations with the best consent architectures will have the best AI models, the best personalization, and the highest conversion rates.


