Key considerations for EU-facing projects: lawful basis, minimization, retention, and collector obligations in plain language.
Privacy-first collection means collecting only fields you will use. Over-broad briefs create compliance debt and confuse collectors.
Document lawful basis and retention in the project description. Collectors need to communicate the same purpose to participants when human subjects are involved.
Minimize identifiers in exports. Pseudonymous IDs and coarse geo are often enough for model training.
Honor deletion requests downstream. If your training set retains personal data, map which batches must be purged when users withdraw consent.
Written by
James Okonkwo
Trust & Safety

