168

Regional privacy restrictions

privacy

Location-data privacy law varies by jurisdiction (GDPR/ePrivacy in the EU, CCPA/CPRA in California, and others), so a pipeline using a single global minimum-aggregation or consent policy can be non-compliant in stricter regions or needlessly conservative in others.

Detection

Pipeline configuration has one privacy policy constant with no per-jurisdiction override keyed to the data subject's region.

Mitigation

Affected conversions