GDPR for product teams: a plain-language guide
A legal basis, less data, people’s rights and a six-point checklist for your analytics.
On this page
If your product has users in Europe, the General Data Protection Regulation, or GDPR, applies to your analytics. Many product teams find it confusing, so they either ignore it or collect nothing. Neither is necessary. This guide explains the parts that matter for product analytics, in plain language.

The basic idea
The GDPR protects personal data: any information that can identify a person, directly or indirectly. A name and email are personal data. So is a user ID that you can connect to an account, and often an IP address. Analytics that track individual users usually involve personal data.
The law does not forbid this. It asks you to have a good reason, to collect only what you need, to keep it safe and to let people control it.
A legal basis
You need a legal basis for processing personal data. For product analytics, teams usually rely on one of two:
- Consent. The person agrees, freely and clearly, usually through a banner or a setting. They must be able to say no without losing access to the product, and to change their mind later.
- Legitimate interest. You have a real need, such as improving your product, that does not override the person's rights. You must write down why, and people must be able to object.
Separate rules about storing information in browsers, often called the cookie rules, may also require consent before you set a cookie, whatever your legal basis for the analytics itself.
Collect less
The principle of data minimisation asks you to collect only what you need. In practice: do not send names or emails to your analytics tool, do not record every property just in case, and remove data you no longer use.
The safest data is the data you never collected.
Maya Chen

People's rights
People can ask to see the data you hold about them, to correct it and to have it deleted. You must answer within one month. Make sure your analytics tool can find and delete one person's data; in Tally, this is a single request in Settings → Privacy or through the API.
A short checklist
- List what you send to your analytics tool, and why.
- Remove anything that directly identifies a person.
- Decide your legal basis and write it down.
- Mention analytics in your privacy notice, in plain words.
- Sign a data processing agreement with your analytics provider.
- Test that you can delete one person's data, everywhere.
Where the data lives
Moving personal data outside the European Economic Area adds rules. The simplest answer is to store it inside. Tally offers a European region, and every customer can choose it when they create a workspace.