Quant Memo
Core

Alternative Data Diligence and Consent

Before a firm trades on a new alternative dataset, it has to establish that the data was collected and can be used legally — including whether the people the data describes ever consented to it being sold at all.

A vendor offers to sell a fund anonymized credit-card transaction data that predicts a retailer's quarterly sales before the retailer reports them. The signal looks great in backtest. The question a compliance-minded firm asks before touching it isn't "does it work" — it's "how did the vendor get this data, and were we allowed to." Alternative data diligence is the process of answering that question for every new dataset, before it's allowed into a strategy.

There are two separate risks bundled into that question. The first is legal: does the vendor actually have the right to collect and resell this data, or did it scrape a website in violation of the site's terms of service, or buy it from an employee who wasn't authorized to sell it? A firm that trades on illegally obtained data can be exposed to legal liability even if the firm itself never broke a law directly — courts and regulators have shown they'll look at whether a buyer should reasonably have known the data was tainted. The second risk is about the people described in the data. Credit-card records, location data, and app usage logs describe real individuals, and increasingly the question is whether those individuals ever consented to their data being aggregated and sold for this purpose, even in anonymized or aggregated form.

A practical diligence process asks the vendor directly: where does the raw data originate, what consent (if any) was obtained from the underlying individuals or companies, has the data been through a legal review, and can the vendor produce documentation rather than just an assurance. Firms that take this seriously will decline datasets where the provenance is vague or where the vendor is reluctant to explain how the data was sourced — a reluctance that is itself informative.

This isn't just a legal formality bolted onto research. A dataset with murky provenance can be pulled by the vendor, banned by a regulator, or become the subject of a lawsuit at any point, and a strategy built around it can lose its edge or its legality with no warning. Diligence upfront is cheaper than unwinding a position in a dataset the firm should never have licensed.

Alternative data diligence checks two things before a dataset is used: whether the vendor legally has the right to sell it, and whether the individuals or companies it describes ever consented to that use — with vague or undocumented provenance treated as a reason to decline the data, not just a caveat.

A vendor who can't clearly explain where their data comes from is giving you the answer, even if they never say "no" directly.

Related concepts

Further reading

  • Federal Reserve SR 11-7, Guidance on Model Risk Management
ShareTwitterLinkedIn