Hyper-personalisation of services vs data protection: a new trend or a threat to privacy

15 January 2024 | Knowledge, News, The Right Focus

Personalised communications and marketing messages tailored to the individual customer are now an fundamental and routine tool of modern and effective marketing.

Customised content, advertising on social media, or even shopping recommendations in online shops – messages and products that are tailored to the customer and meet his or her needs, or even create needs that the customer is often not even aware of – are the basis of marketing activities.

Hyper-personalisation: a world where machines know more about us than we do

Personalisation is already standard, but what happens when we move to the level of hyper-personalisation?

When marketing messages no longer rely on simple data analysis based on gender, age and past purchases, but are the result of advanced algorithms, machine learning and big data analytics. When we are talking about large-scale activities where consumer data collected from multiple sources (such as social media, purchase history, website activity, geolocation, etc.) is analysed by algorithms capable of detecting patterns and relationships invisible to the human eye (often even to the individual), privacy risks cannot be overlooked.

The resulting detailed behavioural profile of the user captures the user’s preferences, interests and behaviours and, based on this, predicts their future needs and customises content and services.

If we consider that we are not only talking about shopping preferences in a clothing store, but also a personalised workout plan in a fitness app, a shopping history in an online drugstore (often linked to a pharmacy), a streaming platform that suggests movies and series (based on previous choices), personalised newsletters, information portals (where a universal layout is replaced each time by information tailored to the user), it becomes clear that in almost every aspect of our lives and daily choices, our decisions are significantly influenced by marketing messages derived from advanced analytics.

If we combine the above examples, it is clear to the naked eye how pervasive this intrusion can be and how wide the range of our data is now available to service and product providers.

Hyper-personalisation and GDPR

The more data, the greater the risk of breaches, leakages or misuse. Despite the fact that GDPR regulations are now several years old, there are still many organisations that apply the data protection rules in an inadequate or even inappropriate manner.

The vagueness of the rules (which is in many ways an advantage of the new regulations) is also undoubtedly a gateway to abuse and irregularities. Moreover, the risks associated with hyper-personalisation include not only potential privacy violations, but also manipulation by using the collected data to influence consumer decisions.

The fact is, however, that deep personalisation is on the rise. Studies have shown that consumers are in favour of a personalised approach. And they see this kind of unique treatment as something positive that strengthens their commitment to their relationship with a particular brand.

Hyper-personalisation is a sign of the times

The new phenomenon of hyper-personalisation is the result of technological amplification, whereby previous personalisation, limited in its simplicity by technological capabilities, takes on a new dimension by fully exploiting the potential of AI, ML or Big Data.

The process of deep personalisation is also one of continuous, real-time optimisation. Algorithms fed by data are in a constant learning mode, allowing for continuous improvement and ever more accurate customisation of content.

Hyper-personalisation is certainly a powerful tool that has the potential to revolutionise the way we use and are targeted by services and products.

At the same time, it will undoubtedly reinforce the information bubbles in which we already live and will also be a powerful intrusion into our privacy.

These threats can be addressed through appropriate legislation or education to raise consumer awareness of the risks and consequences of operating in the digital world and handling personal data.

The future of hyper-personalisation therefore depends on how well we can balance these two aspects.

Product and service providers will certainly have to pay increasing attention to the protection of personal data and transparency in their operations, allowing consumers to have control over their data and full knowledge of how it is used.

 

Questions? Contact us

 Natalia Kotłowska-Wochna

Latest Knowledge

NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.

Contact us:

Natalia Kotłowska-Wochna

Natalia Kotłowska-Wochna

Attorney-at-Law / Partner/ New Tech, IP, Trade & Logistics Practice Group / Head of New Tech M&A

+48 606 689 185

n.kotlowska@kochanski.pl