Tally 2.4 is out: scheduled reports and a 3× faster API
Privacy

GDPR for product teams: a plain-language guide

A legal basis, less data, people’s rights and a six-point checklist for your analytics.

GDPR for product teams: a plain-language guide
On this page

If your product has users in Europe, the General Data Protection Regulation, or GDPR, applies to your analytics. Many product teams find it confusing, so they either ignore it or collect nothing. Neither is necessary. This guide explains the parts that matter for product analytics, in plain language.

⚖️
This is a practical guide, not legal advice. For decisions about your own product, talk to a lawyer or your data protection officer.
The regulation is long. The ideas behind it are short.
The regulation is long. The ideas behind it are short.

The basic idea

The GDPR protects personal data: any information that can identify a person, directly or indirectly. A name and email are personal data. So is a user ID that you can connect to an account, and often an IP address. Analytics that track individual users usually involve personal data.

The law does not forbid this. It asks you to have a good reason, to collect only what you need, to keep it safe and to let people control it.

You need a legal basis for processing personal data. For product analytics, teams usually rely on one of two:

  1. Consent. The person agrees, freely and clearly, usually through a banner or a setting. They must be able to say no without losing access to the product, and to change their mind later.
  2. Legitimate interest. You have a real need, such as improving your product, that does not override the person's rights. You must write down why, and people must be able to object.

Separate rules about storing information in browsers, often called the cookie rules, may also require consent before you set a cookie, whatever your legal basis for the analytics itself.

Collect less

The principle of data minimisation asks you to collect only what you need. In practice: do not send names or emails to your analytics tool, do not record every property just in case, and remove data you no longer use.

The safest data is the data you never collected.

Maya Chen
Consent must be a clear choice. A box that is already ticked does not count.
Consent must be a clear choice. A box that is already ticked does not count.

People's rights

People can ask to see the data you hold about them, to correct it and to have it deleted. You must answer within one month. Make sure your analytics tool can find and delete one person's data; in Tally, this is a single request in Settings → Privacy or through the API.

A short checklist

  • List what you send to your analytics tool, and why.
  • Remove anything that directly identifies a person.
  • Decide your legal basis and write it down.
  • Mention analytics in your privacy notice, in plain words.
  • Sign a data processing agreement with your analytics provider.
  • Test that you can delete one person's data, everywhere.

Where the data lives

Moving personal data outside the European Economic Area adds rules. The simplest answer is to store it inside. Tally offers a European region, and every customer can choose it when they create a workspace.

Do I need consent for cookieless analytics?

Often not for the cookie rules, because nothing is stored in the browser. Your other obligations still apply.

Is a user ID personal data?

Usually yes, if you or your analytics provider can connect it to a person.

Great! Check your inbox and click the link to confirm.