❗PLEASE PROVE ME WRONG ❗
Deep in the #GA4 configuration, there is this gem of #dataprivacy issue…
Under Web stream details/Configure tag settings/Allow user-provided data capabilities, this option is ON by default. Congrats Google for another lack of #privacybydefault! Go have a look NOW!
Oh! But rest assured, “data surfaced by this feature will be hashed to keep it private”—which is utter bs since the hashed value can easily be recouped by #Google with other data they have, making it non-anonymous.
Anyone currently using GA4 is potentially in breach of the #GDPR for collecting personal data. Worse, even when cookies are rejected, the so-called “consent mode“ of GA4 still sends a ping to Google. I wonder if those hashed values are still sent when that’s the case… (I haven’t had a chance to build a test case for it.)
Note: the #Facebook pixel has a similar feature on by default. It’s called “automatic configuration” and should always be disabled (in #GTM, that’s why you might see a form_start event whenever a page is loaded)
#NoConsentNoTracking #privacy #privacycompliance #digitalmarketing #digitalanalytics