Learn the four types of customer data businesses collect, how to gather each one responsibly, and how to stay GDPR and CCPA compliant.
Summary:
If you search "customer data collection," you'll find plenty of guides on survey methodology: how to write questions, pick a distribution channel, and avoid low response rates. That's useful, but it only covers one slice of what "customer data" actually means. For a deep dive on survey mechanics specifically, see the SurveyMonkey guide on how to collect data with surveys.
This guide takes a step back and answers a different question: what kinds of customer data exist, why each type matters, and how do you collect all of them without violating GDPR, CCPA, or your customers' trust?
Customer data collection is not one activity. It's a portfolio of behavioral, transactional, attitudinal, and first-party CRM data, each with its own collection method, its own risk profile, and its own compliance requirements.
Customer data is any information a business gathers about the people who buy from it, use its product, or interact with its brand.
That definition covers a lot of ground, from a click on a pricing page to a survey response about customer satisfaction to a credit card transaction. Because the sources are so different, treating "customer data" as a single bucket leads to messy systems, duplicate records, and compliance blind spots.
A useful framework splits customer data into four categories:
| Customer data type | Description |
| Behavioral data | How customers act, including website clicks, app usage, and email engagement |
| Transactional data | What customers buy, including order history, payment method, and purchase frequency |
| Attitudinal data | What customers think and feel, including survey responses, reviews, and support ticket sentiment |
| First-party CRM data | Identity and relationship data a business collects directly and owns, including contact details, account history, and consent records |
Each type answers a different business question. Behavioral data tells you what customers do. Transactional data tells you what they buy. Attitudinal data tells you why. CRM data ties all three together into a single customer record your teams can act on.
Behavioral data captures the digital footprint customers leave as they interact with your website, app, or product.
This includes page visits, click paths, feature usage, cart abandonment, and email open rates. Marketing and product teams rely on behavioral data to spot friction points and personalize the next best action.
You typically collect behavioral data through:
Behavioral data is powerful because it's passive. Customers don't have to answer a question for you to learn something. That same passivity is why it carries the highest privacy scrutiny: customers often don't realize how much behavioral data is being logged, which is exactly what GDPR and CCPA are designed to address.
Transactional data is the record of what customers have actually purchased: order history, transaction amounts, payment methods, subscription tier, and purchase frequency. It's the most concrete data type because it reflects a completed action rather than an opinion or a click.
Common sources include:
Transactional data is the backbone of customer lifetime value calculations, churn prediction, and upsell targeting. It's also sensitive: payment details fall under stricter handling rules (like PCI DSS) on top of general privacy law, so this data type usually lives in more locked-down systems than behavioral or attitudinal data.
Attitudinal data captures opinions, satisfaction, and intent rather than actions. It answers questions behavioral and transactional data can't: why did a customer churn, how likely are they to recommend you, what almost stopped them from buying.
You collect attitudinal data through:
This is the one data type customers give you directly and knowingly, which makes it both the most reliable signal of intent and the easiest to collect with full, informed consent.
A well-built customer satisfaction survey using a customer satisfaction survey template can surface attitudinal insight in a single distribution cycle. For a deeper methodology on the survey mechanics behind attitudinal data collection, refer back to the survey-specific guide linked above rather than reinventing that process here.
CRM data, sometimes called first-party data, is the identity and relationship information a business collects directly from its own customers and owns outright: name, email, phone number, account status, communication preferences, and consent history. It's called "first-party" because it comes straight from the customer to you, with no data broker or third-party cookie in between.
First-party CRM data typically comes from:
First-party data has become the connective tissue for the other three data types. As third-party cookies phase out across major browsers, first-party CRM data is what lets a business tie a behavioral click, a transactional purchase, and an attitudinal survey response back to the same real person, with consent on record for each.
Collecting customer data responsibly means matching your collection method to two things: the type of data you're gathering, and the consent standard that data type requires. A few practical guardrails apply across the board.
Applied to each data type, this means behavioral tracking needs a clear cookie consent banner and an honest description of what's tracked.
Transactional systems need role-based access so only the people who need payment data can see it. Attitudinal surveys need to state upfront how the feedback will be used and who will see it. CRM systems need a documented, auditable consent trail for every contact record.
GDPR and CCPA take different approaches to consent, and that difference should shape how you design your collection forms.
GDPR (EU) requires an opt-in consent standard. You need a clear, affirmative action from the customer before you collect and process most personal data, and that data can only be used for the specific purpose stated when it was collected.
CCPA (California) works on an opt-out standard. You can collect and use personal data by default, but you must tell consumers what you collect and give them a genuine right to opt out of having it sold or shared.
As of 2026, CCPA has added new obligations: businesses must run risk assessments for high-risk data processing, disclose and allow opt-outs for automated decision-making, complete annual cybersecurity audits, and show a visible confirmation once an opt-out request has been processed. Data collected from anyone under 16 is now treated as sensitive personal information, which requires affirmative opt-in consent rather than a simple opt-out right.
If you operate in both jurisdictions, or don't know where your customers are located, the safest approach is to build your collection systems to the stricter opt-in standard by default and layer on the specific disclosure and audit requirements each law adds. A few practices apply regardless of which law governs a given customer:
Once you've collected clean, consented customer data across all four types, personalization is where it pays off.
That combination is what makes personalization feel relevant instead of creepy: a product recommendation based on actual purchase history, a support response informed by a recent low satisfaction score, an email campaign that respects the channel preference a customer explicitly chose. Data collected without consent, or data siloed away from the rest of the customer record, can't support this kind of personalization safely or effectively.
The terms get used interchangeably, but there's a meaningful distinction.
| Data Type | Description |
| Customer data | Information collected from people who have an existing relationship with your business, such as those who have bought from you, signed up for your product, or opened a support ticket. |
| Consumer data | Broader data about people who may have never interacted with your company directly, often gathered by data brokers, ad networks, or third-party aggregators. |
The compliance stakes differ too.
Because customer data comes from a direct relationship, businesses generally have clearer grounds and more direct consent to collect and use it.
Consumer data sourced from third parties carries more legal exposure, since the end business often can't verify how or whether consent was originally obtained.
This is one more reason first-party customer data, collected directly and transparently, is the more defensible foundation to build on.
The right tool depends on the data type:
For the attitudinal layer specifically, and for building consent-aware intake and feedback forms, the SurveyMonkey data governance and admin controls let you manage who can access survey data, track consent, and keep your feedback collection aligned with the same compliance standards you apply to the rest of your customer data.
If you're building a customer feedback program from scratch, start with the customer satisfaction survey template referenced above rather than drafting questions from a blank page.
Treating customer data as four distinct types, rather than one undifferentiated pile, makes it easier to collect the right information, store it securely, and stay ahead of GDPR and CCPA requirements as they evolve. Attitudinal data is the piece most businesses under-invest in, even though it's the type customers are most willing to hand over directly and knowingly, provided you ask clearly and use it responsibly.
If survey-based feedback is the gap in your customer data strategy, the data governance and admin controls referenced above can help you collect attitudinal data with the same consent tracking and access control you already expect from your CRM. For attitudinal data specifically tied to loyalty, many teams start with an NPS survey, then expand into broader satisfaction and product feedback programs from there.
NPS, Net Promoter & Net Promoter Score are registered trademarks of Satmetrix Systems, Inc., Bain & Company and Fred Reichheld.

SurveyMonkey can help you do your job better. Discover how to make a bigger impact with winning strategies, products, experiences, and more.

VoC marketing turns customer feedback into sharper messaging and campaigns. Learn how to use Voice of the Customer data and try it for free.

Learn what creative testing is, the metrics it measures, and how to test ads, video, and messaging before you launch a campaign.

Use these 38 post purchase survey questions, organized by the decision each one informs, to learn why customers bought and whether they'll buy again.