Privacy by Design

An approach that embeds data protection and privacy considerations into the design and architecture of systems and processes from the start, rather than adding them as afterthoughts.

Why privacy by design matters

Privacy by Design is a requirement under GDPR and a best practice globally. It means considering privacy implications at every stage of product development - from choosing what to track to how data flows through your systems.

For analytics teams, this means building your tracking plan with privacy in mind: starting with the minimum necessary data, securing transmission and storage, and providing easy consent and deletion mechanisms.

The newsletter

Join our KISS newsletter

One short read a week on what actually moves revenue, in a free email. Read by 10,000+ operators and founders.

No spam. Unsubscribe in one click.

Common Mistakes

  • -Treating privacy as a compliance checkbox rather than a design principle
  • -Building the tracking system first and adding privacy controls later
  • -Not involving privacy stakeholders in analytics architecture decisions

Pro Tips

  • +Run a privacy impact assessment before implementing new tracking
  • +Default to not collecting data - require justification for each new event or property
  • +Build data deletion capabilities into your architecture from day one

Related Terms

Further Reading

KISSmetrics

Build your business intelligence layer for free.

First-party tracking KISSmetrics installs itself, so the data is yours and the person-level view survives the blockers that break third-party pixels.