Reviewing data collection and privacy for AEM as a Cloud Service RUM script
This article describes the data collected by the auto-injected Real User Monitoring (RUM) script in Adobe Experience Manager as a Cloud Service, how to review telemetry for your environment, and provides information on privacy and data retention for compliance purposes.
Description description
Environment
Adobe Experience Manager as a Cloud Service (AEMaaCS) (all versions)
Symptoms
Organizations conducting privacy and consent reviews require details about the data collected by the auto-injected Operational Telemetry (RUM) script.
Common requests include:
- A list of referrer URLs captured by the RUM script for the relevant AEM site or environment, to verify that no sensitive data is present in transmitted URLs.
- The data retention period for telemetry collected by the script.
No error messages are present; this is a documentation and compliance review scenario.
Cause
Privacy and compliance teams require confirmation of the RUM script’s data collection scope and retention policy. The script is designed to avoid collecting sensitive or personally identifiable information, and data retention is limited to support analytics needs.
Resolution resolution
Follow the steps below to review data collection and privacy for the RUM script:
-
Review the data collected by the RUM script:
-
The RUM script collects anonymized, sampled telemetry including:
-
Host name
-
Page URL (without query parameters)
-
Referrer URL (without query parameters)
-
Coarse device category
-
Performance metrics
-
No IP addresses or personally identifiable information are stored, processed, or retained.
-
-
Access collected telemetry for your AEM site or environment:
-
Use the Adobe Operational Telemetry Explorer to review telemetry collected for your environment.
-
Documentation: Operational Telemetry
-
The Explorer provides access to available Operational Telemetry insights for the specified environment. It doesn’t provide access to AEM environments, Cloud Manager, Adobe databases, or other tenants’ data.
-
-
Reviewing referrer URLs:
-
The Explorer allows review of telemetry fields, including referrer URLs as captured by the RUM script. You can manually inspect these fields for your privacy review.
-
There is currently no standard customer-facing report that automatically provides a distinct inventory of all referrer URLs collected for a given environment. Customers can review available telemetry via the Explorer, but can’t export a unique list directly.
-
-
Data retention period:
- Operational Telemetry data is retained for 761 days (a little over two years) to support year-over-year analysis.
-
Third-party processing:
- Adobe is the third-party processor for this telemetry. Infrastructure providers (CDN, logging, storage) are used to route and store anonymized, sampled data in accordance with privacy-preserving design.
-
Verification:
- After reviewing the telemetry in the Explorer, confirm that the collected fields match your privacy requirements and that no sensitive or personally identifiable information is present.