4 ms·
Correct, storing PII is against GA’s TOS. Which doesn’t at all mean it isn’t ingested somehow or another (and Google can trivially integrate it back to a person
by generj 4y ago
Correct, storing PII is against GA’s TOS. Which doesn’t at all mean it isn’t ingested somehow or another (and Google can trivially integrate it back to a person if they wanted to). PII is a very malleable term depending on the jurisdiction.
So long as website operators are creating URLs and the data layers published into analytics there’s no way to ensure the data is truly anonymized. It just takes one slip up with a username being placed into a query string, or some other small mistake. In many organizations marketing runs the analytics, and they try to do as much as possible without developers who might notice these types of errors.
It could be interesting to have browsers avoid sending user agents and otherwise minimize HTTP headers to a list of analytics domains.
- alkonaut 4y agoIs the key then perhaps to NOT use the default functionality of this type of analytics? I don't use this I use a pseudonymous "hand rolled" analytics method which is simply logging specific events in the program when a feature is used, and tagging those with a random session id and a persistent random pseudonym. E.g. "user 291281223233 used feature print_document in session 129871209182 ". But I guess some of the attraction of a package like GA is that you don't have to spend weeks instrumenting your app? But I can certainly see the problem if ANY urls are sent. And I can see how weak GA would be if by default NO urls, no IPs, no User agent string are sent. You'd need to add quite a few "user_visited_page('pagename')" to your site code...