The weak version of privacy work is treating compliance as a brake.

The useful version is treating it as an architecture constraint.

What data should be collected? Which platform should receive it? Under what consent state? At what granularity? From browser, server, CRM, or warehouse? With which matching fields? For which business objective?

Those questions are technical, legal, and commercial at the same time. If they are answered separately, the result is either risky tracking or compliant underperformance.

Good tracking architecture has to make those tradeoffs explicit.