Operationalizing consumer-protection and vulnerability safeguards in campaigns
The flag that arrives four hours too late
A customer rings the contact centre on Tuesday at 08:40, says she has just lost her job, and asks to pause her payment. The agent sets a hardship flag in the servicing system. At 09:00 she receives an email offering a credit limit increase, because the audience was assembled from a warehouse snapshot taken at midnight and handed to the email platform before anyone was awake.
No one wrote a bad rule. The rule existed and did not fire. Consumer protection breaks at the seams: between the system that learns something about a customer and the system that decides who gets the send. This lesson is about closing those seams. Which targeting categories are off limits for credit, which flags have to survive the trip through the data pipelinedata pipelineETL (Extract, Transform, Load) is a data integration process that pulls data from sources, reshapes it into a consistent format, and writes it into a target system.View full definition →, and how suppression gets wired so it executes at send time instead of living in a policy document.
What has to be encoded, and where
Restricted targeting categories for credit
Since 2019, credit offers on Facebook and Instagram have to be booked under the Special Ad Category. Inside it you lose age, gender and ZIP-code targeting, the tightest geographic radius available is 15 miles, and most detailed interest and behaviour options vanish from the picker. The restriction followed the March 2019 charge brought by the US Department of Housing and Urban Development over ad tools that let advertisers exclude users by proxies for protected classes. In 2022 Meta settled with the Department of Justice, retired Special Ad Audiences (the lookalike substitute it had built), and agreed to a delivery-variance system for housing ads, with credit and employment named as extensions.
Treat the platform restriction as the floor. It constrains what you can type into an ad account; it does nothing about the audience file you upload, the list you push to your ESP, or the model that scores your own base. Your restricted-variable register has to cover those too, and it should name the proxies as well as the protected classes: ZIP or postcode at fine granularity, preferred language, device age, benefits receipt, first-name frequency tables, branch catchment. A retail bank can defend targeting a personal loan on estimated income and existing product holdings. It cannot defend a credit-builder card audience whose only distinguishing variable is Spanish-language app locale.
Working rule: every credit audience is built from a declared variable list. Anything outside the register needs a written business reason attached to the audience definition itself, not to a deck that gets lost.
Vulnerability flags
The FCA's guidance on vulnerable customers (FG21/1) groups the drivers into four: health, life events, resilience and capability. Its Financial Lives research puts roughly half of UK adults in scope of at least one characteristic at any time, which tells you the operational shape of the problem. Vulnerability is a state that switches on and off, not a segment you build once. In the US there is no equivalent single duty, but the abusive prong of the CFPB's UDAAP standard reaches the same conduct: taking unreasonable advantage of someone's inability to protect their own interests. The CFPB's examination material sits here: CFPB on UDAAP.
Four sources feed the flag, and they arrive at different speeds:
- Servicing systems: hardship arrangements, forbearance, bereavement notification, collections status.
- Customer-set product controls, such as the gambling block HSBC and other UK banks expose in the mobile app. A customer who has switched that on has told you something; a limit-increase or overdraft campaign should read it.
- Behavioural signals from the account: persistent overdraft use, repeated failed direct debits, minimum-payment-only cycles.
- Third-party instruments: power of attorney, debt-management plan notification, court orders.
One design decision matters more than the taxonomy. Marketing systems should receive a boolean plus an effective date, never the reason. "Suppress from credit promotions, set 2025-03-04" is enough to run a campaign. Pushing "bereavement" or "gambling block" into a hashed audience upload sends special-category-adjacent data to an ad platform for no operational gain. Suppress locally, then send the residue.
Affordability flags
Affordability is the flag most often computed and least often connected. Banks model it for underwriting, then market from a separate list built by a growth team on different infrastructure. If the modelled figure does not reach the campaign layer, the suppression cannot happen. The fix is unglamorous: the affordability score gets a home in the same customer table the audience builder queries, with a refresh date attached, and audiences that ignore it are rejected at build.
Rules that fire, not rules that advise
Suppression runs last, and fails closed. Sequence matters. Build the audience, apply exclusions, then re-check flags in the minutes before dispatch, not at build time. If the flag service times out, the send does not go. Fail-open suppression is the default in most marketing stacks and it is the wrong default here.
One identity key, agreed in advance. A hardship flag keyed to a customer ID will not remove a record from an email list keyed to an address, and neither will remove the hashed phone number sitting in a custom audience on a social platform. Most suppression leaks are join failures, not policy failures. Pick the key, resolve everything to it, and test the resolution rate rather than assuming it.
Freshness windows with teeth. Decide the maximum age of the data behind any credit audience (24 hours is a reasonable ceiling; weekly snapshots are not) and have the build fail when the source table is staler than that. Batch audience syncs in a CDPCDPSoftware that unifies customer data from every source into one persistent profile that marketing, sales and service teams can act on.View full definition → such as Segment, which sells the tooling in question, are measured in hours, so a nightly cadence plus a queued send can put a full day between the flag and the inbox.
Reinstatement is a decision, not a timeout. Flags that never expire quietly shrink your addressable base and push teams to work around them. Flags that expire automatically re-target people mid-difficulty. Write the rule down per flag family: collections status clears on account cure plus a cooling-off period; bereavement suppression usually runs on a fixed window with a manual release; a customer-set gambling block clears only when the customer clears it.
No manufactured urgency on credit. Countdown timers and "2 left" mechanics push someone past the point where they weigh a borrowing decision, which is exactly the conduct the abusive standard describes. Genuine, factual deadlines are fine and should be stated as such. Everything about how the rate and the material terms are then presented belongs to the disclosure craft the fee-tables lesson covers.
A worked suppression rule: the affordability screen
You are promoting a card with a $10,000 limit. You need a filter that removes people the offer would predictably strain. Debt-to-income (monthly debt payments over gross monthly income) is the usual guardrail. What follows is a marketing suppression rule, not a lending decision.
Assume minimum monthly payment ~ 3% of a used balance.
Prospect at modelled DTI 45%, plausible $200/month on the new card
-> post-offer DTI approaches the ~50% zone many lenders treat as high risk.
Rule set (evaluated in order, first match wins):
1. hardship_flag OR collections_status -> suppress, no override
2. gambling_block_on -> suppress from credit + overdraft
3. modelled_post_offer_DTI > 50% -> suppress
4. affordability_score_age > 30 days -> suppress (stale, cannot assert)
5. else -> eligible
Log the rule number that removed each record. Counts by rule are the
artefact you can show later.Rule 4 is the one teams argue about and the one that saves them. Missing data is not clean data. If you cannot assert affordability, you have not screened for it.
Wiring it so it cannot be skipped
Policy that depends on someone remembering is not a control. Four checks make the pipelinepipelineAll active sales opportunities across the stages of the sales process, together with their combined potential value and probability of closing.View full definition → testable:
- Seed records. Maintain a small set of synthetic customers carrying each flag type, injected into every credit audience. If a seed reaches the seed inbox, the suppression layer is broken and the send is quarantined.
- Reconciliation. Compare records built, records suppressed by rule, and records dispatched. The three numbers should tie. A gap of even 0.3% on a 400,000-record file is over a thousand people you cannot account for.
- Identity-resolution coverage. Report the share of the audience where the suppression key resolved. Anything unresolved is treated as suppressed, not as eligible.
- Partner reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.View full definition →-back. Suppression files pushed to affiliates, aggregators and ad platforms need a confirmed timestamp, because a list you sent three weeks ago is still being mailed.
What gets retained and who signs it off is the evidence pack the pre-launch checklist lesson specifies. The point here is narrower: the counts have to exist before anyone can sign anything.
Knowledge check
1. A marketing team builds a mortgage campaign audience map that, while not explicitly referencing race, ends up excluding neighborhoods that are predominantly composed of minority residents. What fair-lending concept does this most directly illustrate?
2. Why does the lesson emphasize that 'your audience-selection logic is a fair-lending decision'?
3. The lesson notes that much of the harm in the Wells Fargo settlement traced back to how products were 'sold and communicated, not just how they were priced.' What broader principle does this illustrate for marketers?
4. A bank shows a high-cost credit-builder card to one ZIP code cluster and a premium rewards card to another, where the split correlates with race. Which practice does this best exemplify?
5. Select ALL correct answers about how fair-lending law (ECOA and FHA) applies to marketing campaigns.
Select all the correct answers.
6. Select ALL correct answers about the consumer-protection duties that shape banking campaigns.
Select all the correct answers.
Where teams actually get caught
The lookalike loop. A seed list of "good customers" fed into a lookalike model reproduces whatever skew the existing base has, then amplifies it across acquisition. Facebook's Special Ad Category and the retirement of Special Ad Audiences removed part of this on one platform; the same mechanic survives in every in-house propensity model and in most programmatic setups. For credit, prefer broad reach with hard affordability suppression over narrow amplification, and audit the seed list composition before the model ever runs.
Reactivation of dormant distress. A "we miss you" campaign to lapsed customers picks up people who lapsed because they got into trouble. The suppression flag frequently sits in the collections system, which is often the one database the reactivation query never touches.
The adtech and affiliate blind spot. Partners writing their own copy ("guaranteed approval") create exposure that lands on you. The CFPB's August 2022 interpretive rule on digital marketing providers made the point sharply: firms that use ad platforms and lead generators for targeting and delivery are dealing with service providers, and the responsibility travels. Contract for creative control, receive the suppression confirmation, and sample live placements rather than approved mockups.
Key takeaways
- Suppression that runs at build time is decoration. Re-check flags minutes before dispatch, and fail closed when the check does not return.
- Credit targeting operates under restricted categories on the platform side (Special Ad Category removes age, gender and tight geography) and needs an equivalent restricted-variable register for your own lists and models.
- Vulnerability flags should travel as a boolean plus an effective date. Suppress locally; never ship the reason to an ad platform.
- Most leaks are identity-resolution failures. Agree one key, measure the resolve rate, and treat unresolved records as suppressed.
- Missing affordability data is a suppression trigger, not a pass. Log which rule removed each record so the counts exist when someone asks.