Privacy audit: how to close the analytics risk for good

The questionnaire lands in your inbox on a Tuesday.

Twelve tabs. One of them is called Third party processors. Somewhere in it there is a row for web analytics and a column asking what personal data leaves the organisation.

You know the honest answer is complicated. You also know that writing the complicated answer will cost you a week of chasing people who do not report to you.

I have watched compliance leads solve this problem twice. The first time they document their way through it. The second time they notice that one of the rows can simply stop existing.

This article is about the second approach. It starts with what the auditor actually asks, because you cannot shorten a process you have not seen written down.

One note first. This is not legal advice and your own counsel decides what applies to you. It is a map of the questions.

No time to read this?

Sign up, paste two lines of code and see your real traffic without a cookie banner. No credit card, live in minutes.

Get my free account

The six questions an auditor asks about analytics

They are always the same, in roughly this order.

1. What personal data does the tool process? IP addresses and device identifiers count. So does anything you push into a custom dimension, which is where surprises usually live.

2. What is your lawful basis? For non essential analytics in the EU this is normally consent and consent has to meet a standard rather than exist as a checkbox.

3. Where does the data go? Which company, which country, which servers.

4. Who else can access it? Sub processors, support staff, the vendor's own analytics on your analytics.

5. How long do you keep it? A retention period you can name and that the tool actually enforces.

6. Can you prove all of the above? This is the one that turns a two hour conversation into a two week project.

Notice that the first five are questions about the tool and the sixth is a question about you.

The paperwork each answer triggers

Every yes creates an artefact you have to produce, keep current and defend.

  • A processing record entry. GDPR Article 30 requires a record of processing activities. Analytics is one row, with purpose, categories of data, recipients and retention.
  • A data processing agreement. Article 28 requires one with every processor handling personal data for you.
  • A transfer assessment, if data leaves the EEA. The current adequacy framework simplifies this for certified US recipients but the assessment is still a document someone has to own.
  • Consent records. You must be able to demonstrate that consent was given. That means storing it and being able to produce it for a specific visitor on request.
  • A DPIA, if the processing is high risk. Large scale behavioural profiling can push you over that line.
  • A line in the privacy notice that matches all of the above and stays matched when someone changes a tag.

That is six living documents for one tool. None of them makes your marketing better. All of them need an owner.

"Ensure that personal data are automatically protected in any given IT system or business practice, so that if an individual does nothing, their privacy still remains intact."

Ann Cavoukian, Privacy by Design: The 7 Foundational Principles, on privacy as the default setting

Cavoukian wrote that in 2009. The GDPR later codified the idea in Article 25, data protection by design and by default.

The point worth taking from it is structural. Protection that depends on someone configuring a setting correctly is weaker than protection that exists because there is nothing to protect.

Still with me? Good, because this is where the two paths separate.

Why documenting is the expensive path

Documentation is not a one time cost. It is a subscription.

The tool ships a feature and your record is out of date. Someone adds a tag for a campaign and forgets to remove it. A sub processor changes and nobody tells the person who owns the register.

Then there is the part nobody budgets for. Every one of those documents has to be found again at the next audit, at the next enterprise deal and every time a client sends you their own vendor questionnaire.

In a company of thirty people this is usually one person's part time job that nobody named.

The shortcut: remove the category

Here is the version that takes an afternoon instead of a quarter.

If your analytics processes no personal data and stores nothing on the visitor's device, most of the six questions collapse.

  • Question one has a short answer. No personal data.
  • Question two disappears. There is no processing of personal data to find a basis for and no device storage to ask consent for.
  • Question three is one line if the servers are inside the EU.
  • Question five matters less when the retained data cannot be linked to a person.
  • Question six gets much easier, because there are no consent records to produce.

You have not made the paperwork better. You have removed the rows that generated it.

That is the difference between a control and an elimination and auditors treat the two very differently. A control has to be tested. An elimination has to be verified once.

What you still have to do

I would be misleading you if I said the answer is zero paperwork.

You still keep a processing record entry, even if it says the data is not personal, because the assessment itself is worth writing down.

You still need a contract with the vendor. You still describe the tool in your privacy notice and that description still has to match reality.

And you still have every other system in the questionnaire. Analytics is one row of twelve tabs. Closing it properly just means you can spend the week on the rows that genuinely need judgement.

How to verify it in ten minutes

Do not take a vendor's word for this, including mine. Check it the way an auditor would.

Open your site in a private window and look at Cookies and Local storage in the developer tools. Empty is empty.

Watch the network request the analytics sends. Look at what is in it. If you cannot tell what is being sent, that is your answer.

Ask where the servers are and get the country in writing.

Ask what the vendor stores about the visitor's IP address. Storing it and using it transiently to derive a country are different things and the difference matters.

Those four checks produce evidence you can attach to the file. That is worth more than any compliance page on a vendor website.

Where StatJolt fits in

StatJolt was built so that the analytics row stops being interesting to an auditor.

It sets no cookies and writes nothing to the visitor's device so there is no consent to collect and no consent records to produce.

It collects no personal data and builds no visitor profiles so there is no lawful basis question to answer for personal data.

The servers are inside the EU, in Germany and Finland so the transfer question does not arise regardless of what happens to the current adequacy framework.

For your questionnaire that turns a row full of caveats into a row with a short answer, plus evidence you can verify yourself in ten minutes.

If you only read one box

An auditor asks six questions about analytics and each yes creates a document you then have to maintain forever. Documenting your way through is a subscription cost that nobody in the company owns properly. Removing the personal data and the device storage collapses most of the questions instead of managing them and that is the difference between a control an auditor has to test and an elimination they verify once.

Replace GA4 in 2 minutes

Just paste the code and see how much clearer it gets. No cookies, no banner, no consent tool. 0 EUR until 2027, at any traffic level.

Or keep the other path: maintaining a consent tool, modelled data and half an hour a month spent digging through reports.

Get my free account

Back