Lead data hygiene best practice: Preserve submissions with unique identifiers and separate corrections; Follow APP 3 & APP 5 for proportionate personal info collection under OAIC guidance; Reconcile distinct submissions to genuine enquiries with clear exclusion labels
Image: Lead Generation Desk

Lead Reporting

Lead generation data hygiene

Keep lead records accurate and useful with clear rules for duplicate submissions, missing sources, personal data and reporting exclusions.

Lead generation data hygiene keeps received enquiries accurate, traceable and usable without collecting more personal information than the work requires. Keep submitted details separate from later corrections. Preserve genuine requests through classification, and make the rules behind reporting counts clear.

Keep submissions and enquiries distinct

A submission is an inbound contact received through a form, phone call, email or other channel. An enquiry is the request a team assesses and answers. Someone may retry a form after an uncertain confirmation, or return later with different work.

Preserve each distinct received submission while it is needed, then decide whether it belongs to an existing enquiry. Processing the same submission identifier twice should not create a second arrival.

A useful intake record has an identifier, received time, route, request as received, available reply details and the enquiry it was linked to. Record corrections and classification decisions separately. Leave absent information unknown; label an inference as an inference.

Data issueDecisionEvidence to keep while needed
Repeated submissionSame request or new work?Arrival times and any new wording
Missing trackingWhich source was observed or reported?Values, provenance and unknowns
Suspected test or spamIs exclusion justified?Review decision and a proportionate audit record
Unneeded personal detailIs it needed for the task?Handling decision without wider copying

These are enquiry-record decisions. An analytics event or CRM contact count cannot settle them on its own.

Preserve source provenance

Capture page and campaign details actually received where appropriate. Keep them separate from what the person says brought them to the business. A colleague's recommendation and a website session with no clear referrer can both be true.

Where source information is absent or ambiguous, keep it unknown in the enquiry record rather than assigning it to a campaign.

Collect and retain for a purpose

Ask for a detail when it changes the first reply, service assessment or routing decision. A broad location might establish whether a site visit is possible; an exact address may be needed only after a visit is arranged. Allow a description of the work, but discourage confidential documents through a general form.

For organisations covered by the Australian Privacy Principles, APP 3 applies to solicited personal information. The OAIC says proportionality is implicit in its requirements and advises a data-minimisation approach. APP 5 requires reasonable steps to notify people of specified collection matters or ensure they are aware of them. Coverage and appropriate steps depend on the organisation and collection.

Limit access to detailed requests. APP 11 requires covered entities to take reasonable steps to protect personal information they hold from misuse, interference and loss, and unauthorised access, modification or disclosure. Reasonable steps include technical and organisational measures.

Review whether messages, attachments and duplicate copies still need to be held. Subject to exceptions, covered entities must take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed under the APPs.

Exceptions apply where information is part of a Commonwealth record or retention is required by Australian law or a court or tribunal order. Preserving an audit trail does not require retaining every personal detail indefinitely.

APP 3 treats information as solicited when an entity explicitly asks an individual or another entity to provide it, or takes active steps to collect it. Where an entity has taken no active steps to collect personal information, the OAIC directs readers to APP 4.

This distinction helps identify which collection rules apply to information received through an intake process.

For an organisation covered by the APPs, personal information other than sensitive information may be collected only where it is reasonably necessary for the organisation's functions or activities. Collection must be by lawful and fair means, and should generally be from the individual concerned unless that is unreasonable or impracticable. Sensitive information has an added consent requirement unless an exception applies.

APP 5 matters include the collecting entity's identity and contact details, the fact and circumstances of collection, why information is collected, and whether collection is required or authorised by law. They also include consequences of not providing it, usual disclosures, information about the entity's APP Privacy Policy, and likely overseas disclosures and countries where practicable.

The OAIC says reasonable steps to notify or ensure awareness should be taken before or when information is collected, or as soon as practicable afterwards if that is not practicable. What is reasonable depends on circumstances such as the information's sensitivity, possible adverse consequences, an individual's special needs and practicability. More rigorous steps may be needed where sensitivity or risk is greater.

Applicable Australian Privacy Principles (APPs) and their key requirements

  • APP 3: Collection of Solicited Personal InformationOnly collect personal information that is reasonably necessary for functions or activities. Must be collected by lawful and fair means, generally from the individual.
  • APP 5: Notification of CollectionReasonable steps to notify individuals about collection, including purpose, identity of collector, disclosure details, consequences of non-provision, and privacy policy availability.
  • APP 11: Security of Personal InformationTake reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Includes technical and organisational measures.

Explain exclusions and counts

Use distinct labels for confirmed tests, spam, repeated genuine submissions, genuine requests outside service scope and cases awaiting review. A short message is not proof of spam, and a repeat may contain an important correction.

For each reporting period, reconcile distinct received submissions to distinct genuine enquiries. Show test and spam exclusions, repeats and pending classifications under non-overlapping rules. Record the reason and effective date for a rule change. Keep only the information needed to explain an exclusion, subject to applicable retention requirements.

If analytics events are used, document their definitions and reconcile them with intake records before comparing totals.

Key data hygiene metrics for lead reporting

Total distinct submissions received
Not specified – depends on intake volume
Genuine enquiries confirmed
Reconciled from submissions after exclusion review
Excluded as spam/test
Documented with reason and effective date
Repeated submissions with new information
Retained and linked to existing enquiry
Pending classifications
Under review – not yet assigned

Review recurring errors

Sample each intake route. Check that genuine requests reached the right record, repeats retained new information, unknown sources stayed unknown, exclusions have defensible reasons and access to personal details is appropriate. Compare the resulting enquiry count with its stated definition. When a pattern recurs, correct the relevant intake or classification rule and date the change.

Lead data hygiene workflow for compliance and accuracy

  1. Receive submission via form, call, email or other channelCapture identifier, timestamp, source, content and route
  2. Assess for duplicates, spam or test activityUse rules with documented justification; retain audit trail
  3. Link to existing enquiry or create new onePreserve new information in repeat submissions
  4. Record source provenance accuratelyKeep actual referrer or page data; mark unknown sources as such
  5. Review monthly for recurring errorsCorrect intake or classification rules where patterns emerge

In this guide

  1. Deduplicating repeated form submissionsDecide when repeated form submissions belong to one enquiry, preserve new details and report distinct requests accurately.
  2. Recording source information when tracking data is missingKeep observed, self-reported and unknown enquiry sources separate so missing tracking does not become invented attribution.
  3. Keeping personal data collection proportionateReview why each enquiry detail is collected, handle unsolicited information and limit access and retention under applicable Australian privacy rules.
  4. Removing test and spam submissions from reportingClassify test and spam submissions carefully, reconcile raw and genuine enquiry counts, and check analytics filter limits.

More from Lead Reporting