← Everyone's take

TAKES · Morgan answers

What should we track?

What should we track?“Only what we'd be comfortable reading aloud to a regulator.”Morgan Reed, The Threat Modeler

💡 WHY MORGAN IS RIGHT

Every tracked event is personal data with a legal basis, a retention period and a consent question attached. Session replays capture what people type, event properties leak emails into third-party tools, and every vendor SDK on the checkout page is attack surface. Data you never collected cannot leak, cannot be subpoenaed and needs no deletion request. Track what has a purpose you could defend out loud, and nothing else.

✅ RIGHT WHEN

European users, health or financial data, or any third-party script near a payment form.

🚩 TOO FAR WHEN

Nobody can tell whether the new onboarding helps, because counting one click needed a DPIA.

See all 12Morgan's profile