PLG OS

Implementation worksheet · 6 min read

A customer data minimization worksheet for in-app prompts

For every attribute your application sends to an in-app guidance or survey layer, record which targeting rule, personalization token or report uses it. If nothing uses it, stop sending it. If a rule only needs a derived value (plan tier rather than billing details, 'signed up more than 14 days ago' rather than a signup timestamp), send the derived value. Then set retention for prompt responses and free-text answers. GDPR Article 5(1)(c) describes personal data as 'adequate, relevant and limited to what is necessary' for the purposes of processing. This worksheet documents your reasoning against that principle; it isn't a legal assessment, so check with counsel.

In-app SDKs make it easy to pass the whole user object at initialization and sort out targeting later. That's how a tooltip ends up holding an email address, a phone number and a revenue band it never uses. The actor is the product or growth team configuring prompts; engineering owns the identify call, and a privacy or legal reviewer signs off. Scope: attributes sent to the in-app layer, responses it collects, and how long both are kept.

Put it into practice

1. Capture the payload as it is today

Record the actual identify call from a production-like session with a test account, not the spec. Payloads collect fields added for one campaign years ago. List every attribute with its type and an example value.

2. Map each attribute to a live use

Targeting rule, personalization token in copy, report breakdown, or none. Count only rules that are currently published. An attribute used by a retired campaign has no use.

3. Replace raw values with derived ones where the rule allows

Days since signup instead of the signup timestamp. Plan tier instead of billing data. Country code instead of address. The rule behaves the same and the layer holds less.

4. Treat free text as a high-risk field

Survey answers collect whatever people type, including colleagues' names, account numbers and health details. Ask narrower questions, add a line asking respondents not to include personal details, set a shorter retention, and limit who can export raw text.

5. Set retention for responses and exposure logs

Decide how long raw responses, dismissals and exposure events are kept, and whether they are aggregated afterwards. Article 5(1)(e), storage limitation, is the principle this touches for identifiable data.

6. Default new attributes to excluded

A new attribute joins the payload only with a named use and an owner. That mirrors Article 25(2), which asks for measures ensuring that by default only personal data necessary for each specific purpose are processed. Whether your in-app vendor acts as a processor, and what your contract says, is a question for counsel and your vendor agreement.

7. Review on every targeting change and keep the dated copy

When a rule is retired, its attributes lose their justification. Re-run the worksheet on each targeting change or at least quarterly, and keep each dated version. Article 5(2) makes the controller responsible for being able to demonstrate compliance with these principles, and a dated worksheet is part of that record.

Attribute minimization worksheet

Copy this structure into your review document and record your observed result for each row.

Attribute minimization worksheet
Attribute sentUsed byDecisionReplacement or retention
emailNo published rule or tokenStop sendingInternal user ID is enough for identity
first_nameGreeting token in the welcome tourKeepDrop if the greeting is removed
signup_dateRule: show checklist for the first 14 daysDeriveSend days_since_signup instead
planRule: hide upgrade tips from paid plansKeepTier only; no billing details
company_revenue_bandCampaign retired last yearStop sendingRemove from the identify call
phoneNo use foundStop sendingRemove from the identify call
roleRule: admin-only setup tourKeepFixed list of values, not free text
countryRule: tax-form tip in one countryKeepTwo-letter country code only
NPS free-text answerMonthly product feedback reviewKeep, restricted exportRaw text kept 12 months (illustrative), then deleted
Tour exposure eventsExperiment analysisKeepAggregated once the experiment closes

A failure worth checking

Minimizing the payload and forgetting the logs. The team trims the identify call to five attributes, then finds that debug logging switched on during setup has been writing full user objects to a log store with no retention limit. The worksheet has to follow the data wherever the in-app layer sends it: the vendor, your own event pipeline, application logs and analyst exports. A lean payload feeding an unbounded log isn't minimization.

Common questions

Does minimizing data make targeting worse?

Only if a rule actually used the data you removed, and the worksheet shows which rules do. If a planned rule needs a new attribute, add it together with that rule and its owner, not in advance just in case.

Is this worksheet enough to show GDPR compliance?

No. It documents reasoning for one principle in one system. Lawful basis, transparency, processor agreements, international transfers and data subject rights are separate questions. Check with counsel.

Basis and scope

This is a proposed implementation method using illustrative examples, not a measured benchmark or a customer case study. Prepared with AI assistance. Validate product-specific behavior against current documentation and your own test environment.

Continue with PLG OS

Explore onboarding →