I was thinking about GA (Google Analytics) the other day, and how I can follow the GDPR guidelines. The articles I read, both from Google and other sources said to not use user IDs to identify users without consent, to anonymize IP addresses, and to not send PII information to Google, such as in URLs. Ok, that sounds simply enough, but then... I started thinking about it more.
1. User profiles can't be sent to GA. For example, hacker news has /user?id=JohnDoe for profiles, and that contains a username, which is personal data that should not be shared with GA. Ok, so I could rewrite my profile URLs before sending them to GA without the usernames.
2. I haven't heard a single source mention referrals. If I'm on a user profile on my site and click a link, that's going to send /user?id=JohnDoe to GA as the referral. I would need to overwrite the referrals before sending them to GA as well.
3. What about 404 pages that I make up? What if I visit https://www.example.com/JohnDoe? That's sending my personal name to GA again. Hmm, ok, the site could exclude GA from 404 pages.
4. What about search boxes? What if I use the search field on a blog? https://www.example.com/posts?search=JohnDoe. Hmm, that's my personal data being sent again. Ok, we need to make sure any data from search boxes is now stripped and not sent to GA.
5. What if I manually add a query parameter or modify one? A homepage might have https://www.example.com/?page=2, but what if I change it to https://www.example.com/?page=JohnDoe. Hmm, yes, that's personal data being sent again. I guess I need to validate the page parameter to ensure it's an integer before sending the URL to GA. What if I then type in a personal phone number as the page number?