Technote

Security Practical

Series No measurement, no improvement Part 6 of 8

Analytics and privacy: collecting the minimum, honestly disclosed

Showing a banner is not the same as obtaining consent. You should be able to explain what you collect and why — and a retention period ought to be a decision, not neglect.

Privacy usually turns up last in a conversation about analytics, and usually as “we need to add a banner”. But showing a banner and obtaining consent are different things, and treating them as the same thing increases the risk — you end up with the paperwork in place while quietly collecting data you cannot explain.

Marketers need to understand this for a practical reason rather than a legal one: the person who decides the scope of collection is the marketer. Which events exist, and which values travel with them, is settled by whoever designed the measurement, not by a developer.

Reduce first — collect the minimum

The most reliable protection is not receiving it in the first place. Data you never took cannot leak, does not need destroying and requires no disclosure. Before attaching one more value to an event, ask which decision becomes impossible without it. No answer means no field.

Swap the left for the right and the metric survives while the exposure disappears

A genuinely common incident is form values travelling into the analytics tool: an email address riding along as an event parameter, or submitted values appended to the redirect URL so that the page address itself contains personal data. After wiring up an event, submit the form yourself once and look at what is actually transmitted.

Disclosure — what belongs in the policy

A privacy policy is a legal requirement, but written properly it is also the document in which you check what you are actually doing. For analytics, four things belong in it.

Four things the policy must say about analytics

The fourth is the one most often missed. Using an external analytics service means visitor data travels to that company’s servers, and that is disclosable. Naming the tools you use is both the most honest option and the simplest.

Consent is behaviour, not a banner

If you decide to ask for consent, then nothing should be collected before it is given. A banner displayed while the tags are already running is decoration, and worse than nothing because it creates the impression that disclosure happened.

Refusal should also be as easy as acceptance. A large accept button with the refusal buried two screens deep satisfies the form but hardly offers a choice. This is ultimately a question of how the business wants to behave — and a business that sells trust has the most to gain by getting it right.

Retention has to be decided

This is the setting most often left alone. Analytics tools have a data retention period, and if nobody touches it, the default becomes your policy. That is not a policy; it is neglect.

The same applies to lead data from your forms. Personal data that has served its purpose should be destroyed on a defined schedule, and the schedule in the policy should be the one you actually keep. A stated period that does not match practice is the worst of all outcomes.

The server and account side of handling collected data safely lives in the Security archive, and a tidy-up covering access, logging and vulnerability review is part of our optimization program.

Next part

With collection settled, it is time to use it. The next part is reporting — not a document that lists numbers, but one that leaves the reader with a decided next action.

More on this topic

All technotes

Security Practical

Lead data is an asset and a liability at once

A contact list is a marketing asset and personal data at the same time. Collect the minimum, set a retention period, and actually delete when it expires.

Marketers 6 min read

₩270,000 · Join the program