Study first
Review the ideas behind the questions
Review the privacy decisions behind a useful measurement plan. The goal is to know what can be collected, matched, anonymised, reported, and caveated before the team trusts the dashboard.
Plan Data Use First
A measurement plan should define why personal information is needed before tags, files, or partner matches are added.
- Plan how personal information will be protected before direct-marketing measurement starts.
- Name the lawful basis before using personal information for marketing activity.
- Explain clearly how collected information will be used.
In Practice
Write The Measurement Purpose
If a report needs personal data, write the purpose and lawful basis before the data is collected or shared.
Separate Nice-To-Have Data
A measurement field should earn its place. If the report works without it, collect less or anonymise where possible.
Common mistakes
Adding measurement tags or files first and asking privacy questions later.
Plan the personal-data use, lawful basis, transparency, and responsibility before collection or matching starts.
Q&A
What should be clear before personal data is collected for measurement?
The purpose, lawful basis, responsibility, and privacy information should be clear before collection starts.
Respect Preferences And Limits
Privacy-safe measurement does not mean every available person or identifier can be used in every report.
- Respect opt-outs and objections before using people in direct-marketing measurement.
- Use only personal information that is necessary for the specific measurement purpose.
- Do not keep personal information after it is no longer needed for the marketing purpose.
In Practice
Suppression Affects Measurement
A person who opted out should not be pulled back into a matching file just because the team wants more complete attribution.
Retention Needs A Reason
Trend reporting is not a free pass to keep identifiers forever. Keep a retention reason or use anonymised data.
Common mistakes
Treating a larger matched audience as automatically better measurement.
A larger file is not better if it ignores opt-outs, unnecessary fields, retention limits, or transparency duties.
Q&A
Can an opted-out person be added back for attribution matching?
No. Respect the opt-out and keep the measurement file inside the allowed audience.
What should happen when old identifiers are no longer needed?
Delete or anonymise them, and keep only what is justified for the measurement purpose.
Report Aggregates Honestly
Privacy-safe reporting often gives useful aggregate evidence, not a complete person-by-person history.
- Anonymising personal data still needs a lawful purpose and clear information during the anonymisation process.
- Privacy-preserving attribution can produce aggregate statistics without exposing individual user identity.
- Privacy-conscious measurement should still lead to comparable insight across exposure, reach, engagement, and outcomes.
In Practice
Aggregate Does Not Mean Exact
An aggregate conversion report can guide decisions, but it should not be described as a full identity-level path.
Caveat Missing Signals
If privacy choices or consent rules remove part of the audience from measurement, label the dashboard boundary.
Common mistakes
Calling aggregate privacy-safe results a complete person-by-person journey.
Report aggregate results as aggregate evidence and state the limits created by privacy controls.
Q&A
What should a privacy-safe attribution report avoid claiming?
Avoid claiming a complete user-level path when the evidence is aggregate or privacy-limited.