Conversion & analytics · Site analytics

Data minimization audit

We audit what visitor data you collect, store and share — and where you collect too much. We give recommendations on what to reduce, anonymize or stop collecting, to lower privacy risks and keep only what is needed. Honestly upfront: this is an audit and recommendations (a snapshot at the time of the check), not the fix itself and not a legal guarantee of compliance — the legal assessment is given by your lawyer.

Price
$3,000
Duration
usually 4–7 business days; implementing fixes — separately

Data minimization audit — overview

Data minimization audit — price, timeline & scope

Data minimization audit is a one-off check: we inventory collection across the site and systems (analytics, tags, forms, pixels, integrations, logs), look at which personal and sensitive data is collected, where it is sent (third parties), how long it is stored, and compare with the minimization principle — collect only what is really needed for the stated purpose. We deliver a report: where too much is collected, where data is stored longer than necessary, where it is shared with third parties without clear need, plus prioritized recommendations. Honestly about the essence, this is key: this is an AUDIT and RECOMMENDATIONS, NOT implementing fixes — switching off collection, setting retention periods, removing extra pixels is separate work (we can do it separately); the audit shows what and where, but fixing must be done by you or us as a separate task. Honestly about the legal side: we assess technically and by the minimization principle, but this is NOT a legal opinion and NOT a guarantee of GDPR/152-FZ compliance — the lawfulness of purposes, the basis for processing and the sufficiency of measures are assessed by your lawyer; we do not replace a legal audit. Honestly about coverage: we check configured/accessible systems; what is hidden or out of access (server-side processes, offline exports, shadow integrations) we may not see. It is a snapshot at the time of the check — after changes the picture changes. Requirements: access to systems and a description of collection purposes. An important boundary: this is a minimization audit, not privacy setup (separate), not real-time privacy monitoring (separate) and not a legal audit. If you collect almost nothing, the audit may be brief. Picture this: instead of 'we collect lots of data just in case and don't know the risks' you get a list of what is excess and what to reduce. The base price starts from 15,000 ₽ per audit; it depends on the number of systems and integrations.

Problems we solve

  • You collect and store data 'just in case' without knowing the risks.
  • You do not know which personal data goes where.
  • Data is stored indefinitely and shared with unnecessary services.
  • There is no understanding of what can be safely reduced.

What's included in the Data minimization audit service

  • Inventory of collection (analytics, tags, forms, pixels, integrations)
  • A map: what data, where it is sent, how long it is stored
  • Comparison with the minimization principle
  • A list of excess collection and over-retention
  • Prioritized recommendations on reduction
  • Flagging legal-risk areas (assessment — by a lawyer)
  • A report and review with you
  • An indication of what to fix (implementation — separately)

What you get

  • You understand what is collected and stored and where
  • You see what is excess and what can be reduced
  • Fewer privacy risks after implementation (implementation — separately)
  • A base for a talk with a lawyer and for privacy setup

How the work goes: steps

  • We clarify systems and collection purposes; collect access
  • We inventory collection, build a data map, look for redundancy
  • We compile a report with recommendations, review with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Will you fix the excess data collection?

    No, the audit identifies and recommends. Switching off collection, setting retention periods, removing extra pixels is separate work (privacy setup) that can be done by you or us as a separate task. The audit shows what and where.

  • Is this a legal opinion on compliance?

    No. We assess technically and by the minimization principle, but the lawfulness of purposes, the basis for processing and the sufficiency of measures are assessed by your lawyer. It is not a replacement for a legal audit or a guarantee of compliance.

  • Will you see all the data I collect?

    We check configured and accessible systems. The hidden or out-of-access (server-side processes, offline exports, shadow integrations) we may not see. It is a snapshot at the time of the check — after changes the picture changes.

About the provider

The «Data minimization audit» service is provided by PDV Expert — a team specialising in «Conversion & analytics». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated