Privacy is very important and should always be considered when you work with data.
My experience so far is that on the web people are very quick to click (without reading) OK to whatever pops up when you arrive on a site, hence they agree that data is used for personalisation. In subscription-based sites, the user also agrees for her data to be used.
A different approach is to completely leave the user out of the equation and look at sessions instead. In this case, you can look at session-based recommendations or sequence-based recommendations.