Identity Graph

Data & Tracking

Also: Identity Resolution · Customer Identity Graph

What it doesLinks your identifiers into one profile
Built fromEmail, device ID, cookies, login events
Watch forConfident matches aren't always correct
Depends onFirst-party data quality

Quick definition

An identity graph is a database that links the different digital identifiers belonging to one person, such as an email address, device ID, cookie and login, into a single profile. It's how a business recognises the same customer across a phone, a laptop and an email click, even though each of those leaves a different digital footprint.

How it varies across Australia

Identity graph maturity varies widely across Australian businesses. Retail and financial services brands with strong login systems tend to build usable graphs from first-party data. Smaller businesses relying mostly on cookies and ad-platform identifiers have thinner, less reliable graphs and lean harder on probabilistic matching.

See data and tracking maturity across Australian industries

What it actually means

Picture a customer who reads your email on their phone at breakfast, browses your site on a work laptop at lunch, then buys on their phone again that evening. Without an identity graph, that's three strangers to your analytics. With one, it's a single person doing three normal things.

Identity graphs stitch identifiers together using two methods. Deterministic matching links identifiers you can prove belong to the same person, like a login, a hashed email, or a loyalty card scan. Probabilistic matching guesses based on patterns, like the same IP address and device type showing up at similar times. Deterministic matches are trustworthy. Probabilistic matches are estimates dressed up as facts.

The quality of a graph depends entirely on how much first-party data feeds it. A business with strong logins, a CRM and consistent email capture can build a graph that's mostly deterministic. A business relying on cookies and third-party data has a thinner graph that leans on inference, which is exactly the kind of matching that's getting harder as cookies disappear and privacy rules tighten.

Identity graphs sit underneath attribution, segmentation and lifetime value calculations. Get the graph wrong and every metric built on top of it inherits the error.

An identity graph is only as honest as its weakest match. Confidence and correctness are not the same thing.

How it shows up

Identity graphs show up wherever a business claims to know a customer across channels. The 'welcome back' message that recognises you on a new device. The retargeting ad that follows you from your phone to your laptop. The customer relationship management (CRM) record that merges a web visitor with an email subscriber and a past buyer into one row.

It also shows up when it fails. Duplicate customer records, an email campaign sent twice to the same person under two different addresses, or a lifetime value figure that's split across three profiles instead of counted once. Fragmented identity is usually invisible until someone tries to calculate a customer-level metric and the numbers don't add up.

The Australian context

The Privacy Act amendments and tightening rules around third-party cookies are pushing Australian businesses toward deterministic identity resolution built on consented first-party data. Businesses that ask for logins, run loyalty programmes or capture verified email addresses are building durable graphs. Businesses still leaning on third-party cookie matching will find their graphs degrading as browser restrictions widen, regardless of what platform they've bought.

Where people get this wrong

Trusting probabilistic matches as if they were deterministic.A probabilistic match is a confident guess, not proof. Treating it as certain leads to wrong personalisation, wasted spend and inflated retention numbers.
Buying an identity resolution platform to fix thin first-party data.No platform can stitch together identifiers you never collected. The graph is only as strong as the data feeding it, and that data comes from your own forms, logins and CRM.
Never auditing for duplicate or merged profiles.Bad merges silently distort lifetime value, churn rate and segmentation. A profile that's wrongly split or wrongly combined poisons every metric calculated from it.

Identity Graph vs First-Party Data

Identity GraphFirst-Party Data
What it isA linked set of identifiers for one personData a business collects directly from its own audience
RelationshipBuilt from first-party data, plus other signalsThe strongest raw material for building it
Can exist without the other?Weakly, using probabilistic signals onlyYes, first-party data can exist with no graph built on top
Main riskFalse matches linking the wrong people togetherCollecting it without a clear consent or usage plan

Related terms

Common questions

What's the difference between deterministic and probabilistic identity matching?

Deterministic matching links identifiers using verified proof, like a login or a hashed email address, so it's trustworthy. Probabilistic matching guesses based on patterns like shared device type or timing, so it's an estimate. Businesses should know which type of match is behind any personalisation or reporting they rely on.

Do I need an identity graph if I'm a small business?

Not necessarily a dedicated platform. Many small businesses get most of the benefit from a clean CRM, consistent email capture and a single source of truth for customer records. Dedicated identity graph tools usually pay off once you're running personalisation or attribution across several channels at volume.

How does the end of third-party cookies affect identity graphs?

It removes a major source of probabilistic matching data, particularly for cross-site advertising. Graphs built mostly on first-party logins, email and CRM data are largely unaffected. Graphs that leaned heavily on cookie-based inference will get thinner and less reliable.

Can an identity graph get things wrong?

Yes. A shared household device, a work laptop used by several employees or a stale cookie can cause two different people to be merged into one profile, or one person to be wrongly split into two. Regular auditing catches this before it distorts metrics like lifetime value or churn rate.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →