
As I shared in my RetailNOW 2025 recap, one of the biggest takeaways from this year’s show is that data truly is the new gold. The idea of turning the huge amount of data your software gathers into a source of revenue is pretty exciting. After all, you’re growing your software company, and you’re sitting on a treasure chest of valuable information. Your system logs, transaction histories, and user behavior insights give you a detailed understanding of your end-users. It’s a powerful asset, and the push to turn it into a revenue stream is probably coming from your board, your investors, or even your own internal team.
The appeal is clear: data is a renewable asset that can be packaged and sold to generate new revenue. However, as I’ve learned through my deeper exploration of the topic, the path to monetizing this data is filled with dangers. While the potential rewards are high, the risks can be much greater. As a software leader, your role is not only to develop the technology but also to serve as the voice of reason, helping the company navigate the complex legal, ethical, and technical issues. A quick revenue boost today could lead to long-term brand damage.
The regulatory and legal minefield
First and foremost, you must understand that the regulatory environment is more hostile than ever toward monetizing user data. It’s no longer the Wild West. You have two major issues: GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act), not to mention the many other state and international regulations that are following suit.
These regulations shift the burden of proof to you. They require you to be transparent, to provide an easy-to-understand privacy policy, and, most importantly, to honor the user’s rights. These rights include the ability to know what data you’re collecting, to have it deleted, and to opt out of its sale. Failing to comply isn’t just a slap on the wrist; it can lead to monumental fines, the kind that can cripple a growing business, and the possibility of civil litigation. Your engineers might be technically brilliant, but a single misstep in data handling could make them a liability.
The technical challenge here is immense. You need to build robust systems for data governance that can track, manage, and process these user requests at scale. Simply having a “privacy policy” on your website isn’t enough; your engineering and data teams need to architect the entire data lifecycle around these legal requirements.
The ethical and reputational catastrophe
A fine from a regulatory body is one thing, but a loss of trust from your customers is a far more existential threat. This is where the long-term thinking of a leader is critical. Once your customers feel that their data is being used in a way they didn’t consent to, or that you’re treating their personal information as a commodity to be sold, their trust in your brand will evaporate.
This is a lesson many companies have learned the hard way. A classic example is a major retailer who, years ago, used purchasing data to predict a teenager’s pregnancy and sent her coupons for baby products. While technically a brilliant use of analytics, the perceived invasion of privacy led to a massive public relations disaster.
The ethical considerations don’t stop there. When you monetize data, you’re also responsible for the downstream use of that data. If your data is used in a way that leads to biased outcomes or discriminatory practices, your company will be complicit. Your engineering team needs to think deeply about how the data is collected, anonymized, and structured to mitigate these risks before it ever leaves your control.
The security burden
Finally, there’s the technical burden of securing this data. If you are going to sell or share data, you are fundamentally expanding your attack surface. You are no longer just responsible for protecting your own systems; you are now entrusting that data to a third party.
This means you need airtight security protocols, robust anonymization and pseudonymization techniques, and a clear understanding of the chain of custody. A data breach, which is a risk for any company, becomes an order of magnitude more dangerous when you’re trafficking in valuable, aggregated user data. If a breach occurs on your end or a partner’s, you will be the one on the hook, not just for the data that was stolen but for the legal and reputational fallout as well.
The true value in data is not necessarily in selling it, but in using it to improve your own business and the customer experience. This is what’s known as indirect monetization. Using data to optimize your product, personalize the customer experience, or drive internal efficiencies is a powerful, low-risk way to create value. Before you make a move to sell off a core asset, ask yourself and your team if the promise of a short-term revenue boost is worth the long-term risk of losing the very thing that makes your business valuable: the trust of your customers.













