Web Analytics with Google Analytics 4Campaign tracking, consent and privacy · Lesson 12 of 20

Privacy by design and data governance

Article · 10 min · 8 min lecture

Video lecture

Privacy by design and data governance

15 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 15

Privacy by design

  • Principles for analytics
  • How PII leaks
  • Settings that help
  • The regulatory landscape
  • A monthly PII scan

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Privacy is a design constraint, not a clean-up task

Analytics teams that treat privacy as a legal checkbox usually discover problems at the worst time — during a regulator query, a client audit or a data breach. Privacy by design means building measurement that collects the minimum data necessary, protects it, and respects user rights from the start.

Core principles applied to analytics

PrincipleWhat it means in practice
Purpose limitationCollect data for defined purposes in your measurement plan, not "just in case"
Data minimizationPrefer aggregated or banded values; avoid identifiers you do not need
TransparencyYour privacy notice names analytics and advertising tools and purposes
Storage limitationSet retention to what your analysis genuinely needs
SecurityLeast-privilege access, removal of leavers, secure exports
User rightsBe able to handle deletion and access requests where applicable

No PII in GA4 — and how it leaks

Google's terms prohibit sending personally identifiable information to GA4. PII rarely arrives on purpose; it leaks through:

  • URLs: /thank-you?email=sara@example.com or search result pages with names in the query.
  • Page titles: "Welcome back, Ahmed Khan".
  • Form field values captured by overly broad click tracking.
  • Custom parameters added by well-meaning developers.

Defences:

  1. Configure forms to use POST rather than GET so values do not appear in URLs.
  2. Use GA4's data redaction settings for email addresses and specified query parameters in web data streams (review current options in your property).
  3. Strip sensitive query parameters in the tag manager before sending page_location.
  4. Add a PII check to your QA script.
  5. If PII does reach GA4, use the data deletion request feature and fix the source.

Settings that support privacy

  • Data retention: set deliberately rather than defaulting to maximum.
  • Google signals: enables cross-device insights and demographics for signed-in Google users who allow ad personalization; review with your privacy notice, and be aware of thresholding effects in reports.
  • Granular location and device data collection: can be limited per region.
  • Ads personalization controls: can be disabled per region.
  • User deletion: individual users can be deleted using the user explorer or APIs when needed.

GA4 does not log or store IP addresses for reporting, though IP addresses are still transmitted in network requests and used to derive geolocation at collection time.

The regulatory landscape (high level)

  • EU GDPR / UK GDPR: lawful basis, consent for non-essential cookies (via ePrivacy/PECR), data subject rights, international transfer rules.
  • US: state-level laws such as California's CCPA as amended by the CPRA, with opt-out rights and sensitive-data rules; more states continue to pass laws.
  • UAE: federal personal data protection law, plus separate regimes in some financial free zones.
  • Saudi Arabia: Personal Data Protection Law, enforced by the national data authority, including rules on transfers outside the Kingdom.
  • Pakistan: dedicated personal data protection legislation has been in development; sector rules and contractual obligations still apply.

Laws change and details matter. Maintain a short register of markets you operate in and have counsel review it periodically.

Server-side, first-party data and the future

Browsers increasingly restrict tracking (shorter cookie lifetimes, link-decoration stripping, tracking protection modes). Resilient measurement relies on:

  • First-party data collected with clear consent (accounts, preferences, purchases).
  • Aggregated measurement — modeling, experiments, marketing mix modeling — rather than tracking every individual.
  • Clean implementations so the consented data you do have is accurate.

Worked example: redacting a search results page

A property portal in Dubai lets users search by owner name. URLs look like /search?q=mohammed+ali+villa. The team:

  1. Adds q to GA4's query-parameter redaction list (or strips it in the tag manager).
  2. Sends a separate search event with a search_category parameter (villa, apartment) instead of the raw term.
  3. Adds "search pages" to the monthly PII audit.

They still learn what categories people search for, without storing names.

Hands-on: a monthly PII scan in BigQuery

GA4's data redaction (for email addresses and chosen query parameters in web streams) helps, but check what actually arrived. This query scans page locations, referrers and page titles for email-like strings and sensitive query parameters:

WITH pages AS (
  SELECT
    (SELECT value.string_value FROM UNNEST(event_params) WHERE key = 'page_location') AS loc,
    (SELECT value.string_value FROM UNNEST(event_params) WHERE key = 'page_referrer') AS ref,
    (SELECT value.string_value FROM UNNEST(event_params) WHERE key = 'page_title')    AS title
  FROM `my-project.analytics_123456789.events_*`
  WHERE event_name = 'page_view'
    AND _TABLE_SUFFIX >= FORMAT_DATE('%Y%m%d', DATE_SUB(CURRENT_DATE(), INTERVAL 30 DAY))
)
SELECT loc, ref, title, COUNT(*) AS hits
FROM pages
WHERE REGEXP_CONTAINS(CONCAT(IFNULL(loc,''), ' ', IFNULL(ref,''), ' ', IFNULL(title,'')),
        r'[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}|[?&](email|phone|name|cnic|iqama)=')
GROUP BY 1, 2, 3
ORDER BY hits DESC
LIMIT 100;

If rows appear: fix the source (form method, template, parameter), add the parameter to redaction or strip it in the tag manager, then request deletion of the affected data in GA4 and in any BigQuery copies.

Using AI on analytics data, privately

Before pasting exports into an AI assistant, remove identifiers you do not need, aggregate where possible, and use tools and plans your organization has approved for that data (check retention and training settings). Aggregated tables such as "sessions and key events by channel and week" are almost always enough for AI-assisted analysis.

Second worked example: a UK charity's donation forms

A charity finds donor emails in page_location because its donation form used GET. The team switches the form to POST, adds email and donor to GA4's query parameter redaction list, strips them in GTM as a second line of defense, submits a data deletion request for the affected period, deletes the matching rows from its BigQuery dataset, and adds the PII scan to its monthly routine. The incident report is short because the team can show exactly what happened and what was fixed.

Common mistakes

  • Assuming "anonymous" analytics means no privacy obligations.
  • Exporting user-level data to spreadsheets shared by email.
  • Keeping ex-employees and ex-agencies on the property.
  • Never reading the privacy notice to check it matches reality.

Governance checklist

Key takeaways

  • Collect the minimum data needed for defined purposes.
  • PII usually leaks via URLs, page titles and parameters — audit and redact.
  • Know the regimes in your markets and review them with counsel.
  • Resilient measurement relies on consented first-party data and aggregated methods.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Where does PII most commonly leak into GA4?
  2. A search page URL includes people's names in the q parameter. What is the best fix?
  3. Which principle is being violated when a team collects every possible field 'in case it is useful later'?

Put it into practice

Audit one GA4 property for PII: review page paths with query strings, page titles and custom parameters, and document any leaks and fixes.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.