There is a moment in every channel research project that nobody plans for. The study lands, the findings are good, and someone asks the obvious follow-up question: "That is fascinating, can we go back to the twelve people who said it and ask what they meant?"
And the answer is no. Not no because of budget, or timing, or because the panel is exhausted. No because those twelve people were never yours to contact in the first place. A distributor sold to them. A marketplace processed the payment. A dealer installed the product. You have their words and none of their identity, and the law that governs the gap is not on your side.
Answer first
When you sell through a channel, every customer finding you produce is terminal: correct or not, you cannot ask the next question of the same person. Three separate things have to be true before a follow-up is possible, and intermediated selling breaks all three at once. You need to know who the person is, you need a lawful basis to contact them, and you need a route that reaches them. A distributor, retailer or marketplace holds all three, and none of them transfers to you by default, by contract, or even by regulatory intervention.
It is the third structural limit in a set: the channel record cannot identify a customer, more channel data amplifies rather than clarifies, and the finding you do manage to produce cannot be followed up.
This is why channel research so often feels like it never compounds. Each study starts from zero, because the previous study left behind no reachable population. The fix is prospective, not analytical: capture identity and consent yourself at the point of the conversation, or accept that every insight you buy is a dead end.
The three things you do not own
1. Identity
The sales record identifies the account that ordered, which is your partner. Your registration database contains the subset of end customers motivated enough to fill in a form, which is a self-selected and systematically cheerful sample. Between those two lies the overwhelming majority of your customers, who are, from your systems point of view, anonymous.
2. The lawful basis, which belongs to whoever made the sale
This is the part most teams discover late, and it is unusually precise in European law. The so-called soft opt-in, which lets a business email its own customers without prior consent, is set out in Article 13(2) of the ePrivacy Directive (2002/58/EC). The wording is worth reading slowly, because every clause in it is doing work:
"Notwithstanding paragraph 1, where a natural or legal person obtains from its customers their electronic contact details for electronic mail, in the context of the sale of a product or a service ... the same natural or legal person may use these electronic contact details for direct marketing of its own similar products or services..."
Obtains from its customers. In the context of the sale. The same natural or legal person. If your distributor made the sale and obtained the contact details, the distributor is that person, and you are not. The exemption does not travel up the supply chain with the goods. The default rule in Article 13(1) then applies: electronic mail for direct marketing "may only be allowed in respect of subscribers who have given their prior consent."
Research contact is not identical to direct marketing, and the analysis differs by jurisdiction and purpose. But the structural point survives every version of the analysis: the permission was created by a transaction you were not party to.
3. The route, and what happens if a partner simply hands you a list
The tempting shortcut is to ask the distributor for their customer list. Set aside whether they will agree, because commercially most will not: the list is the asset that keeps you dependent on them. Assume they do.
You have not acquired a relationship. You have acquired an obligation. Article 14 of the GDPR (Regulation (EU) 2016/679) governs exactly this case, and its title states the scope precisely: "Information to be provided where personal data have not been obtained from the data subject." You must tell each person you now hold their data, and under Article 14(2)(f) you must disclose "from which source the personal data originate". Article 14(3)(a) gives you a deadline: "within a reasonable period after obtaining the personal data, but at the latest within one month".
So the first message you send to a list acquired from a partner is a notification that you obtained their data from that partner. That is a defensible thing to do, and it is a poor opening move in a relationship you were hoping to build.
Even the regulator's remedy stops short of re-contact
The most interesting evidence that this problem is structural is that lawmakers have already tried to fix a version of it, and the fix deliberately does not include the thing you want.
The Digital Markets Act (Regulation (EU) 2022/1925) forces the largest platforms to open up data to the businesses selling through them. Article 6(10) requires a gatekeeper to provide business users with "effective, high-quality, continuous and real-time access to, and use of, aggregated and non-aggregated data, including personal data, that is provided for or generated in the context of the use of the relevant core platform services ... by those business users and the end users engaging with the products or services provided by those business users."
That is an extraordinarily strong data-access right, and it is a real change: it exists because platforms historically did not give sellers this data at all. But read the sentence that immediately follows it:
"With regard to personal data, the gatekeeper shall provide for such access to, and use of, personal data only where the data are directly connected with the use effectuated by the end users in respect of the products or services offered by the relevant business user through the relevant core platform service, and when the end users opt in to such sharing by giving their consent."
Even here, at the outer limit of what regulation has been willing to compel, the customer identity moves only if the customer agrees. The DMA also grants end users portability of their own data under Article 6(9), which again places the decision with the person, not the seller. Legislators looked directly at the problem of the intermediated customer relationship and concluded that consent is the only key. There is no version of this where the identity arrives as a side effect of selling.
This is not the same problem as an unanswerable dataset
It is worth separating this from a failure mode it superficially resembles. In feedback analytics, a closed corpus produces findings you cannot resolve because the text is frozen and the question set was fixed when it was collected. We wrote about that as the cost of the next question: the ambiguity is real, but a live instrument would resolve it.
The channel case is worse, and worse in a specific way. There, the obstacle is the data; here, the obstacle is the person. A better analysis tool cannot help, because no analysis of any corpus recovers a contactable human being. Even a perfect research platform pointed at your channel data hits the same wall. That is what makes it a structural limit rather than a tooling gap, and it is why the remedy has to be applied before the evidence is collected rather than after.
| Touchpoint | Who holds identity | Who holds consent | Can you follow up? |
|---|---|---|---|
| Distributor or dealer sale | Partner | Partner | No |
| Marketplace order | Platform | Platform | Only with platform consent flow |
| Warranty or product registration | You | You, if you asked properly | Yes, for the self-selected subset |
| Your own app or portal | You | You | Yes |
| Interview link you issue | You | You, captured at the conversation | Yes |
The bottom two rows are the entire strategy. Everything else in the table is a one-way street.
How to build a population you can go back to
The practical answer is to stop trying to recover identity after the fact and start creating it at the only moment you reliably control: the research conversation itself.
An interview link is a touchpoint you own, even when the partner distributes it. If a dealer emails your interview link to their customers, or it appears on a card in the box, or a QR code sits on the installation sheet, then the person arrives at your instrument. Consent is captured by you, at that point, for the purpose you state. The distributor keeps their commercial relationship and their list, which is what they actually care about protecting, and you acquire a research population that you can lawfully approach again.
That reframes the partner negotiation from "give us your customer list", which they will refuse, to "distribute this link", which costs them nothing and often improves their standing with the manufacturer. It is a materially easier conversation.
This is where AI-moderated research does something traditional fieldwork cannot. Because there is no moderator to schedule, an interview link can sit passively in a channel for weeks and convert whenever a customer is willing, rather than requiring simultaneous availability of a participant and a researcher. Koji runs the conversation, probes the interesting answers, and applies automatic thematic analysis across everything that comes back, with a one-click report at the end. Volume that would be economically impossible with human moderators becomes routine, which matters when your conversion through a partner channel is inevitably a small fraction of the customers reached. And while you are building that first-party population, you are not stuck waiting for it. Recruitment is built into Koji: describe the market, the demographics and the screening you want, approve a live per-respondent quote in credits, and Koji recruits respondents for you.
Two specifics worth planning around:
- Capture the structured fields while you have them. Koji supports six question types (open_ended, scale, single_choice, multiple_choice, ranking and yes_no), so the same interview that gets you the reasoning also gets you the ranked consideration set, the satisfaction scale and the yes/no on repurchase intent. Given that re-contact may be difficult even with consent, the discipline is to leave nothing obvious for a follow-up wave.
- Get the consent scope right the first time. Because the whole point is future contact, the consent you capture should cover it. Our guides to GDPR-compliant AI user research and research consent form templates cover the wording, and intake forms and consent covers the mechanics at the start of a study.
Over two or three studies this compounds into the thing channel businesses almost never have: a first-party research population, recruited through partners, contactable by you. That is a durable asset, and it is built the same way every time, one consented conversation at a time. Our participant panel guide covers how to maintain it once it exists, and panel conditioning covers the trap of over-using the same respondents once you have them.
Koji starts free with 10 credits and no card, and there is no subscription to sign after that. Interviews start as low as €1 per qualified interview, and you pay only for the conversations your study actually uses. Only conversations scoring 3 or higher consume credits, so the interviews that fail to complete in a passive channel placement do not bill you.
Frequently asked questions
Can I email customers who bought my product through a distributor?
Generally not on the basis of the sale itself. The soft opt-in in Article 13(2) of the ePrivacy Directive applies to a person who obtains contact details from its own customers in the context of the sale, which is the distributor rather than you. Absent your own consent from that individual, the default prior-consent rule in Article 13(1) applies.
What happens if my channel partner gives me their customer list?
You take on Article 14 GDPR obligations for data not obtained from the data subject. You must inform each person, disclose the source the data came from, and do so within one month at the latest. You acquire a compliance duty rather than a research relationship.
Does the Digital Markets Act give me access to marketplace customers?
It gives business users strong rights to aggregated and non-aggregated data under Article 6(10), which is a genuine change. But access to personal data is conditioned on end users opting in by giving consent, so it does not hand you a contactable customer list.
Why does channel research never seem to compound?
Because each study leaves behind no reachable population. Without identity and consent captured at the point of the conversation, every project restarts recruitment from zero and no finding can be followed up, however important it turns out to be.
How do I recruit end customers through a partner without asking for their list?
Ask the partner to distribute a link rather than to hand over data. The customer arrives at your instrument, you capture consent directly for the purpose you state, and the partner retains the commercial relationship they were protecting. This is usually a far easier ask than a list transfer.
What should I capture in a channel interview that I might not get a second chance at?
Treat every conversation as potentially the only one. Alongside open-ended reasoning, capture the countable fields that a follow-up would otherwise chase: the ranked consideration set, a satisfaction or likelihood scale, the yes/no on repurchase, and explicit consent for future contact.