Web Analytics with Google Analytics 4Campaign tracking, consent and privacy · Lesson 12 of 20
Privacy by design and data governance
Video lecture
Privacy by design and data governance
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Privacy by design
Here's an uncomfortable truth. Many G A four properties contain personal data that nobody meant to collect. An email address in a thank-you page URL. A customer's name in a page title. A phone number in a search query. Nobody decided to collect it. It leaked. In this lecture you'll learn privacy by design for analytics: the principles, how personal data leaks and how to stop it, the settings that support privacy, the regulatory landscape at a high level, and a monthly scan that finds leaks before a regulator or client does.
0:40 Why by design
Why build privacy in rather than bolt it on? Because teams that treat privacy as a legal checkbox discover problems at the worst time: during a regulator query, a client audit or a data breach. Google's terms prohibit sending personally identifiable information to G A four at all. And privacy failures destroy trust fast. Privacy by design means collecting the minimum necessary, protecting it, and respecting user rights from the start. It's cheaper, safer and, frankly, better analytics, because clean data is easier to use.
1:17 The kitchen layout
Here's the analogy. Think of your analytics like a restaurant kitchen with a health inspector. You don't clean only when the inspector calls. You design the kitchen so raw chicken never touches the salad station. Privacy principles are the kitchen layout. Purpose limitation: collect for defined purposes. Data minimization: prefer aggregated or banded values. Transparency: your privacy notice names your tools and purposes. Storage limitation: retention matched to real needs. Security: least privilege and secure exports. And user rights: be able to handle deletion and access requests.
1:55 How PII leaks
How does personal data leak? Rarely on purpose. Through URLs, like a thank-you page with the email in the query string, or search results pages with names in the query. Through page titles, like welcome back followed by a name. Through form values captured by overly broad click tracking. And through custom parameters added by well-meaning developers. Regional identifiers leak too, like Pakistan's C N I C or Saudi Arabia's iqama numbers in a form that uses GET.
2:29 Defenses
The defenses, in order. Configure forms to use POST rather than GET, so values don't appear in URLs. Use G A four's data redaction settings for email addresses and specified query parameters in web streams. Strip sensitive query parameters in the tag manager before sending page location, as a second line of defense. Add a personal data check to your QA script. And if personal data does reach G A four, use the data deletion request feature, delete any copies, and fix the source.
3:06 Supporting settings
Settings that support privacy. Data retention, set deliberately rather than defaulting to maximum. Google signals, which since June twenty twenty-six only affects behavioral reporting, reviewed alongside your privacy notice. Granular location and device data collection, which can be limited per region. Ads personalization controls. And user deletion for individuals when needed. Also note that G A four doesn't log or store IP addresses for reporting, although IPs are still transmitted in requests and used to derive location at collection time.
3:41 Regulatory landscape
The regulatory landscape, at a high level. In the E U and U K, G D P R and U K G D P R require a lawful basis, consent for non-essential cookies under e-privacy rules and P E C R, data subject rights and transfer rules. In the U S, state laws like California's, as amended, focus on opt-out rights and sensitive data, and more states keep passing laws. The U A E has a federal personal data protection law, with separate regimes in some financial free zones. Saudi Arabia has its Personal Data Protection Law. Pakistan's dedicated legislation has been in development. Check the current status with counsel.
4:29 Example 1: Dubai property search
First example, a simple one. A property portal in Dubai lets users search by owner name, so URLs look like search, q equals mohammed ali villa. The team adds q to G A four's query parameter redaction list, or strips it in the tag manager, and sends a separate search event with a search category parameter, like villa or apartment, instead of the raw term. They still learn what categories people search for, without storing names. And search pages join the monthly personal data audit.
5:06 Example 2: UK charity donations
Second example, a business case. A UK charity finds donor emails in page location, because its donation form used GET. The team switches the form to POST, adds email and donor to the redaction list, strips them in the tag manager as a second defense, submits a data deletion request for the affected period, deletes matching rows from its BigQuery dataset, and adds the scan to its monthly routine. The incident report is short, because they can show exactly what happened and what was fixed.
5:43 Watch me do it, part 1
Watch me run the monthly scan. In BigQuery, I pull page location, page referrer and page title from page view events for the last thirty days. Then I search the combined text with a regular expression for anything that looks like an email address, or a query parameter named email, phone, name, C N I C or iqama. I group and count the matches, and sort by hits. The result is a list of exact URLs and titles to investigate. On a clean property, it returns nothing, and that's the goal.
6:23 Privacy with AI tools
One more privacy habit, because this course is about AI too. Before pasting analytics exports into an AI assistant, remove identifiers you don't need, aggregate where possible, and use tools and plans your organization has approved for that data, checking retention and training settings. A table of sessions and key events by channel and week is almost always enough for AI-assisted analysis. You rarely need user-level rows, and you should almost never paste them into a chat.
6:56 Common mistakes
Common mistakes. Assuming anonymous analytics means no privacy obligations. Exporting user-level data into spreadsheets shared by email. Keeping ex-employees and ex-agencies on the property. Never reading the privacy notice to check it matches reality. And pasting raw exports into unapproved AI tools.
7:14 Privacy health
How do you measure privacy health? Monthly: the PII scan returns nothing. Quarterly: access is reviewed, the privacy notice matches the tools actually running, and retention has a documented reason. And for every incident, the time from discovery to fix and deletion. Those are the numbers that let you answer an auditor calmly.
7:37 Recap
Recap. Collect the minimum data needed for defined purposes. Personal data usually leaks through URLs, titles and parameters, so use POST, redaction and tag manager stripping. Set retention deliberately and review settings like Google signals. Know the regimes in your markets and review them with counsel. Scan monthly. And keep user-level data out of AI chats.
8:01 Try this now
Try this now. Audit one G A four property for personal data. Review page paths with query strings, page titles and custom parameters, or run the BigQuery scan from the lesson. Document every leak, its source and the fix, and add the scan to your monthly routine.
Privacy is a design constraint, not a clean-up task
Analytics teams that treat privacy as a legal checkbox usually discover problems at the worst time — during a regulator query, a client audit or a data breach. Privacy by design means building measurement that collects the minimum data necessary, protects it, and respects user rights from the start.
Core principles applied to analytics
| Principle | What it means in practice |
|---|---|
| Purpose limitation | Collect data for defined purposes in your measurement plan, not "just in case" |
| Data minimization | Prefer aggregated or banded values; avoid identifiers you do not need |
| Transparency | Your privacy notice names analytics and advertising tools and purposes |
| Storage limitation | Set retention to what your analysis genuinely needs |
| Security | Least-privilege access, removal of leavers, secure exports |
| User rights | Be able to handle deletion and access requests where applicable |
No PII in GA4 — and how it leaks
Google's terms prohibit sending personally identifiable information to GA4. PII rarely arrives on purpose; it leaks through:
- URLs:
/thank-you?email=sara@example.comor search result pages with names in the query. - Page titles: "Welcome back, Ahmed Khan".
- Form field values captured by overly broad click tracking.
- Custom parameters added by well-meaning developers.
Defences:
- Configure forms to use POST rather than GET so values do not appear in URLs.
- Use GA4's data redaction settings for email addresses and specified query parameters in web data streams (review current options in your property).
- Strip sensitive query parameters in the tag manager before sending
page_location. - Add a PII check to your QA script.
- If PII does reach GA4, use the data deletion request feature and fix the source.
Settings that support privacy
- Data retention: set deliberately rather than defaulting to maximum.
- Google signals: enables cross-device insights and demographics for signed-in Google users who allow ad personalization; review with your privacy notice, and be aware of thresholding effects in reports.
- Granular location and device data collection: can be limited per region.
- Ads personalization controls: can be disabled per region.
- User deletion: individual users can be deleted using the user explorer or APIs when needed.
GA4 does not log or store IP addresses for reporting, though IP addresses are still transmitted in network requests and used to derive geolocation at collection time.
The regulatory landscape (high level)
- EU GDPR / UK GDPR: lawful basis, consent for non-essential cookies (via ePrivacy/PECR), data subject rights, international transfer rules.
- US: state-level laws such as California's CCPA as amended by the CPRA, with opt-out rights and sensitive-data rules; more states continue to pass laws.
- UAE: federal personal data protection law, plus separate regimes in some financial free zones.
- Saudi Arabia: Personal Data Protection Law, enforced by the national data authority, including rules on transfers outside the Kingdom.
- Pakistan: dedicated personal data protection legislation has been in development; sector rules and contractual obligations still apply.
Laws change and details matter. Maintain a short register of markets you operate in and have counsel review it periodically.
Server-side, first-party data and the future
Browsers increasingly restrict tracking (shorter cookie lifetimes, link-decoration stripping, tracking protection modes). Resilient measurement relies on:
- First-party data collected with clear consent (accounts, preferences, purchases).
- Aggregated measurement — modeling, experiments, marketing mix modeling — rather than tracking every individual.
- Clean implementations so the consented data you do have is accurate.
Worked example: redacting a search results page
A property portal in Dubai lets users search by owner name. URLs look like /search?q=mohammed+ali+villa. The team:
- Adds
qto GA4's query-parameter redaction list (or strips it in the tag manager). - Sends a separate
searchevent with asearch_categoryparameter (villa, apartment) instead of the raw term. - Adds "search pages" to the monthly PII audit.
They still learn what categories people search for, without storing names.
Hands-on: a monthly PII scan in BigQuery
GA4's data redaction (for email addresses and chosen query parameters in web streams) helps, but check what actually arrived. This query scans page locations, referrers and page titles for email-like strings and sensitive query parameters:
WITH pages AS (
SELECT
(SELECT value.string_value FROM UNNEST(event_params) WHERE key = 'page_location') AS loc,
(SELECT value.string_value FROM UNNEST(event_params) WHERE key = 'page_referrer') AS ref,
(SELECT value.string_value FROM UNNEST(event_params) WHERE key = 'page_title') AS title
FROM `my-project.analytics_123456789.events_*`
WHERE event_name = 'page_view'
AND _TABLE_SUFFIX >= FORMAT_DATE('%Y%m%d', DATE_SUB(CURRENT_DATE(), INTERVAL 30 DAY))
)
SELECT loc, ref, title, COUNT(*) AS hits
FROM pages
WHERE REGEXP_CONTAINS(CONCAT(IFNULL(loc,''), ' ', IFNULL(ref,''), ' ', IFNULL(title,'')),
r'[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}|[?&](email|phone|name|cnic|iqama)=')
GROUP BY 1, 2, 3
ORDER BY hits DESC
LIMIT 100;If rows appear: fix the source (form method, template, parameter), add the parameter to redaction or strip it in the tag manager, then request deletion of the affected data in GA4 and in any BigQuery copies.
Using AI on analytics data, privately
Before pasting exports into an AI assistant, remove identifiers you do not need, aggregate where possible, and use tools and plans your organization has approved for that data (check retention and training settings). Aggregated tables such as "sessions and key events by channel and week" are almost always enough for AI-assisted analysis.
Second worked example: a UK charity's donation forms
A charity finds donor emails in page_location because its donation form used GET. The team switches the form to POST, adds email and donor to GA4's query parameter redaction list, strips them in GTM as a second line of defense, submits a data deletion request for the affected period, deletes the matching rows from its BigQuery dataset, and adds the PII scan to its monthly routine. The incident report is short because the team can show exactly what happened and what was fixed.
Common mistakes
- Assuming "anonymous" analytics means no privacy obligations.
- Exporting user-level data to spreadsheets shared by email.
- Keeping ex-employees and ex-agencies on the property.
- Never reading the privacy notice to check it matches reality.
Governance checklist
Key takeaways
- Collect the minimum data needed for defined purposes.
- PII usually leaks via URLs, page titles and parameters — audit and redact.
- Know the regimes in your markets and review them with counsel.
- Resilient measurement relies on consented first-party data and aggregated methods.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Audit one GA4 property for PII: review page paths with query strings, page titles and custom parameters, and document any leaks and fixes.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.