1. Map data flows and responsibilities
Which events does the app need, which parameters leave the device, and which destinations receive them? Document Analytics, advertising links and BigQuery exports separately, checking applicable terms, processing agreements and transfers for each service. A product name or a DPA alone does not establish a compliant configuration.
2. Distinguish Analytics from Firebase resource regions
Firebase's location documentation distinguishes resource regions from the Analytics reporting location. The latter represents the organization's country and affects reporting options; it does not determine where Google processes or stores data. An EU Firestore or Storage region therefore does not establish EU-only Analytics processing.
Do not recreate a Firebase project as a supposed Analytics residency fix. Review service-specific processing information, contractual arrangements and exports separately.
3. Control collection before the first event
For iOS, Google documents FIREBASE_ANALYTICS_COLLECTION_ENABLED in Info.plist and Analytics.setAnalyticsCollectionEnabled(...) at runtime. The runtime choice persists across app restarts. Test first installation, restart and withdrawal. Disabling automatic screen events does not replace collection controls. Implementation depends on platform and SDK version: configure data collection.
For advertising identifiers, also check the SDK modules actually included and Apple's ATT requirements. ATT and the assessment of a lawful basis serve different purposes; installing Firebase does not mean every app needs the same prompt.
4. Test consent signals and destinations
Consent Mode for apps distinguishes analytics_storage, ad_storage, ad_user_data and ad_personalization. Document defaults, updates and behavior at each connected destination. Test rejection, partial consent and withdrawal as well as full acceptance.
The Consent Mode guide explains the distinction between consent state and actual tag behavior. A technical check does not determine the lawful basis.
5. Limit data and retention
Set retention periods by purpose. Analytics and BigQuery exports each need settings and deletion processes. Keep health information and other sensitive content out of event names, URLs and custom parameters. Those use cases need a domain and privacy review before instrumentation.
Measurement & Consent Engineering covers implementation.
Context
For web analytics, see the separate GDPR analytics comparison. This article provides technical guidance; a privacy review must assess the specific app setup.
