Journal · 22 January 2026
A privacy-respecting event taxonomy
A tracking plan is a legal document that happens to look like engineering. Treat it that way and half the arguments disappear.
Most taxonomies begin as a spreadsheet of hoped-for questions. “We might want to know the search string.” “We might want the message body.” Might is how warehouses fill with material you have no purpose for. In the United Kingdom, purpose is not a vibe. If you cannot state a lawful basis and a retention period for a property, do not emit it.
We ask teams to write events as claims in the past tense and to attach a purpose code: product improvement, security, billing support, or a named research project with an end date. “Analytics” is not a purpose; it is a department. Product improvement can justify knowing that a checkout completed. It rarely justifies a free-text field copied from a customer-support form.
Identity fields deserve the same suspicion. A stable advertising identifier has a different risk profile from an internal account key. Hashing is not a personality. If you hash a message and keep the hash, you may still have personal data. Counsel should see the list before the SDK does.
Version control is kinder than a wiki. When an event is renamed, the old name must remain in a changelog with a sunset date, or historical funnels become folklore. Quiet Instrumentation spends a morning on sunsets because nobody else wants that meeting.
Refusal is part of the craft. The house keeps a short list of properties we will not help you instrument: precise location for a non-location product, imported address books, and anything that reconstructs a conversation. If that list feels precious, you may be building a different business than the one on your homepage.