Meta 'Activity from other businesses': a data-governance playbook for marketers
Short answer: Treat Meta's 'Activity from other businesses' change as a reason to re-document what your business shares with Meta and how that data may be used across personalization surfaces. Meta says it will use information businesses already share to personalize content such as Feed and AI responses in addition to ads, while consolidating user controls under 'Activity from other businesses' and saying the update does not collect new categories of data by itself. Businesses should map their own data flows, consent basis, event purposes and opt-out implications instead of assuming the platform announcement resolves their compliance obligations.
Start with the documented platform change
Meta's June 2026 announcement says information that businesses already share with Meta can be used more broadly for personalization, including content and AI responses as well as ads.
Meta also says it is expanding the 'Activity from other businesses' setting and discontinuing the older 'Your activity off Meta technologies' setting.
The company states that it is not collecting new data as part of this update.
Those are platform claims about Meta's processing and controls. They do not replace a business's own inventory of what it sends.
Step 1: map every business-to-Meta data flow
Create a source register covering systems such as:
- Meta Pixel;
- Conversions API;
- app events;
- offline conversions;
- CRM uploads;
- customer lists;
- commerce/catalog integrations;
- lead-form sync;
- server-side event pipelines.
For each source, record owner, fields, event names, purpose, frequency and retention expectations.
Do not rely on a generic statement that 'the website sends analytics data.'
Step 2: classify the purpose of each event
A single event can be useful for measurement, optimization, audience creation or personalization.
Use fields such as:
measurement_purpose;ads_optimization_purpose;audience_purpose;commerce_purpose;personalization_context;consent_basis;policy_owner.
The goal is to know why the business sends the signal before platform use expands or user controls change.
Step 3: separate Meta's statement from your legal basis
Meta says users remain in control of how this information is used for personalization and says the update does not involve collecting new data.
A business still needs to determine whether its own collection and sharing are properly disclosed and permitted under applicable law and policy.
Review:
- privacy notice;
- cookie/consent configuration;
- contractual terms;
- data-processing roles;
- regional restrictions;
- sensitive-data exclusions;
- retention practices.
Route legal interpretation to qualified counsel rather than deriving it from a product announcement.
Step 4: re-test consent and control behavior
When user-facing controls change names or scope, operational documentation can become stale.
Test relevant journeys for:
- consent granted;
- consent denied;
- changed personalization preference;
- logged-in versus logged-out state where relevant;
- regional variations;
- event suppression or continued transmission;
- downstream audience/measurement effects.
Record observed behavior instead of assuming the control operates identically in every market.
Step 5: update support and privacy documentation
Customer-support, privacy and marketing teams should use consistent terminology.
Update internal documents that reference the discontinued control name.
Useful artifacts include:
- user-support FAQ;
- privacy request workflow;
- consent troubleshooting guide;
- event-source inventory;
- marketing data map;
- escalation contacts.
Old terminology can create confusion even if the technical integration is unchanged.
Step 6: preserve measurement boundaries
A platform may use a business signal for personalization beyond the original ad interaction context while the advertiser still receives only certain reporting outputs.
Keep separate:
- data sent by the business;
- Meta's documented platform use;
- metrics returned to the advertiser;
- modeled or attributed outcomes;
- observed CRM/business results.
Do not infer visibility into how an individual signal affected a specific Feed or AI response unless the platform provides that evidence.
Step 7: audit sensitive or unnecessary fields
Data minimization remains an operational control.
Review whether integrations send fields that are:
- unnecessary for the defined purpose;
- sensitive;
- redundant;
- stale;
- accidentally included through URL parameters or free-text fields;
- not supported by current documentation.
Remove unnecessary sharing through a governed change process, not by breaking production tracking ad hoc.
Step 8: version the data map
Platform policies and business integrations both change.
Maintain:
- schema version;
- effective date;
- platform-policy reference;
- integration owner;
- consent configuration version;
- fields added/removed;
- validation result;
- next review date.
A historical map is useful when investigating why measurement or audience behavior changed.
Step 9: define incident triggers
Escalate when:
- unexpected events appear in Meta tools;
- consent-denied users still generate prohibited signals;
- sensitive fields are detected;
- a platform control changes materially;
- audience size changes without business explanation;
- CRM uploads contain wrong fields;
- an integration vendor modifies schema silently.
Each incident should preserve evidence before remediation.
Step 10: keep vendor statements scoped
Meta says the update uses data businesses already share and does not collect new data as part of the change.
Treat that as Meta's description of the platform update.
Do not convert it into a broader statement that your business has no new privacy, notice or governance work to perform. Your own data flows and jurisdiction determine that analysis.
Governance states
Use states such as:
DATA_FLOW_MAPPED;PURPOSE_VERIFIED;CONSENT_REVIEW_REQUIRED;CONTROL_BEHAVIOR_TESTED;DOCUMENTATION_UPDATED;DATA_MINIMIZATION_REVIEW;INCIDENT_OPEN;LEGAL_REVIEW_REQUIRED.
The governance rule
When a platform expands how existing business signals can support personalization, the right response is better provenance and purpose documentation, not assumption.
Map what you send, why you send it, which controls apply and what your business actually observes. Keep Meta's product-policy statements separate from your own legal obligations and measurement interpretation.
Sources reviewed
- https://about.fb.com/news/2026/06/better-personalization-and-changes-to-controls-for-your-activity-from-other-businesses/