What is an identity graph?
A database that links the many different identifiers belonging to the same person or household — cookies, device IDs, email addresses, phone numbers, account logins — so that a fragmented set of signals can be recognised as one individual.
The problem. One person might interact with a brand on a work laptop, a phone, a tablet and a television, in several browsers, sometimes logged in and sometimes not. Each produces a different identifier. Without linking them, measurement counts four people, frequency capping fails, personalisation resets, and attribution assigns a journey to strangers.
The two approaches, which differ fundamentally in reliability:
Deterministic matching. Links identifiers through a known, verified connection — most commonly a logged-in account, or a hashed email address supplied at purchase. If someone signs in on two devices, those devices are the same person, with certainty.
Accurate but limited in reach, since it only covers authenticated interactions. This is a central reason platforms push so hard for account creation and logged-in experiences.
Probabilistic matching. Infers a link from patterns — IP address, device characteristics, location, timing, behavioural similarity. A phone and a laptop repeatedly appearing on the same home network at the same times are probably one person.
Greater reach, lower accuracy, and it is the approach most affected by privacy changes. Several jurisdictions and platform policies now restrict the fingerprinting techniques it depends on.
Where identity graphs sit: platforms maintain their own from logged-in users; retailers build them from purchase and loyalty data; and independent providers offer them as a service, with variable quality.
The privacy position. An identity graph is by definition a system for linking data about individuals, so it engages data protection law directly — requiring a lawful basis, transparency, and honouring deletion requests across every linked identifier, which is technically demanding.
The direction of travel: away from third-party probabilistic graphs, toward first-party identity built on logged-in relationships and hashed email, with clean rooms used to match across parties. The practical implication for most businesses is that encouraging customers to log in has become a measurement strategy, not just a product one.