Why GDPR Made Me a Better Product Manager

May 8, 2026

What is the cleanest (data) product question you can ask a team?

For me, it is this one: “what data do we actually need to deliver the value we promise?”

The reason it is clean is that everyone in the room can answer it from their own discipline. Engineering knows what is technically minimum. Data science knows what signal is actually useful. Commercial knows what the customer is paying for. The PM’s job is to bring those three answers into one decision.

I came to appreciate this question through GDPR, which is why I think the regulation has done something more interesting than most people give it credit for.

When GDPR arrived, the early conversation was all about compliance. Cookie banners, privacy notices, audits. That part was real but it was not the important part. What was important was that GDPR forced product teams to ask the data question above, in a serious way, with the full team in the room. Engineers, designers, commercial, legal. Everyone.

For PMs, this was a quiet gift. Because that question, “do we really need this,” is one of the most useful framings a PM can introduce, and it is much easier to introduce when there is institutional weight behind it. GDPR provided that weight. It gave product conversations a shared anchor that did not depend on any one person’s conviction.

What this means is that teams who took GDPR seriously got something beyond compliance. They got a habit. The habit of pausing before adding a new data flow, of justifying what gets logged, of asking whether a feature actually serves the user or just captures more signal in case it might be useful later.

Teams that built that habit became better at product. Not slower. Better.

The user-first lens, in the legitimate sense There is a version of “user-first” that lives on slides and a version that lives in the work. The slide version says we put the customer at the heart of everything we do. The work version makes a hundred small decisions a quarter, each one weighed against whether it actually serves the people on the other end.

I believe in the second version. I think products exist for the long-term benefit of their users, and that benefit includes their dignity, their time, their privacy, and their interest, not only their conversion rate. This is not a controversial position when you say it out loud. It becomes interesting when a launch deadline is two weeks away and the easy path skips the question.

The PMs I admire most are the ones who can hold this line in a way that the team welcomes rather than resents. Not by being the conscience above the room, but by translating the user perspective into something engineers and stakeholders can actually use. A specific test. A clearer success metric. A better-shaped feature. The discipline of user-first works best when it shows up as craft, not as principle.

GDPR helped this kind of PM enormously. Because once “what data do we really need” became a question the whole team had to answer together, the PM could stop being the only one asking it. It became a shared muscle.

The same muscle is now what AI demands

Every product team I work with is currently shipping AI features under pressure. The pressure to capture more user data to feed the models. The pressure to ship before the evaluation work is done. The pressure to put AI in the headline because the market expects it.

The teams that internalized GDPR-era discipline are not having to invent a process for this. They already know how to ask “do we really need this data,” “what happens when the model is wrong,” “who is accountable when an automated decision affects a user.” These questions sound new in 2026 but they are GDPR-era questions in different clothes.

This is why I think the regulation, whatever its imperfections, was good for product management. It built the muscle that AI now demands. The companies that treated it as overhead are scrambling. The companies that treated it as practice are moving faster, with more trust from their customers, on a foundation that compounds.

The point

GDPR is not perfect, and I am not arguing that it is the right model for every market or every product.

I am arguing that the underlying ethos, build for the long-term good of the user even when the short-term incentives push the other way, is what produces products people stay with. The teams that put this ethos into shared practice, with everyone in the room, build something durable. The teams that leave it as a slogan or a compliance task pay for it later.

The good news is that this is a team capability, not a hero move. The PM does not have to carry it alone. The whole team gets better at product when the question gets asked together.

(User-first, in the legitimate sense, was always good product management. GDPR just made it everyone’s job.)

Thanks for reading The Product Perspective! Subscribe for free to receive new posts and support my work.