4 ms·
You can still set up a site and not have to worry about much, as long as you're not processing other peoples personally identifiable information without their e
by iddqd 9y ago
You can still set up a site and not have to worry about much, as long as you're not processing other peoples personally identifiable information without their explicit consent.
- smhg 9y agoBut then you don't consider the IP address personally identifiable information? The GDPR does.
- iddqd 9y agoYou can serve web content without storing the IP address of the user. If you need to use it for anonymous correlation of requests, you can hash it first.
- smu 9y agoIn addition, you can store the IP address if you want to use it for infosec (such as, finding out who to block in case of a ddos attack). See https://gdpr-info.eu/recitals/no-49/ https://gdpr-info.eu/recitals/no-49/ The recital also mentions "accidental events that compromise availability, integrity, authenticity,..." That seems to cover debugging for me. No need to ask for consent. To do certain analytics like page count, you don't need the IP, so that seems ok for me. To track individual customers however, that's something else. PS: according to GDPR, a hashed IP will be "pseudonimisation", not anonymisation because you can have a key to go back to the original value. True anonymisation removes all info (the IP in this case)
- cromwellian 9y agoMost small web sites don’t have the resources for this. Many don’t even know if they will have analytics in the beginning, or info sec. People tend to set up sites and just stash web logs in the beginning. They then learn later what their business needs are and may decide to post process their logs. You're suggesting a new site pay all of these costs up front to comply with these regulations, you can’t time shift concerns by collecting data and deciding whether you need it later. Granted, you could argue that this is bad practice anyway, but many startups work exactly like this, maximum logging early, dropping rention later after beta. If you are not physically hosting in the EU, how many people want to even read the GDPR? A lot of sites don’t even know where their users are coming from until they run analytics.
- smu 9y agoActually, I was trying to point out ways to not have to remove/prune your logs...
- cromwellian 9y agoRight but these days, if you rent a cloud hosted docker container with say, nginx or httpd, you'll get HTTP logs via fluentd with full IP address information, and a lot of people will push these into storage like S3 or GCP buckets for analysis later. If you say, use a point-and-click installation of Wordpress on AWS/GCP/Azure, you're going to get IP logs being held. I'm just pointing out that the regulations impose a lot of costs and expose people to huge risks. I mean, can I be held liable if I use an open source downstream dependency from npm or Maven, and it just so happens to have debug logs that are storing info, and I didn't know about this logging cause I didn't audit every line of code from a downstream dependency? For large companies, this isn't going to be a problem, but the entire open source ecosystem operates on a system that for the most part, you aren't exposed to legal liability by them, except in cases like patent violations or copyright infringement, but now there's a huge cognitive burden being levied on top by a massively complicated new regulatory framework.
- ecesena 9y agoThe IP space is so tiny that hashing doesn't make any difference. In addition, watch out for logs. By default all web servers log requests with the IP address, and depending on what you do with these logs, the IP are there.
- cromwellian 9y agoOr as long as nothing on my site insults the Thai king, or mentions the Armenian genocide, or Tiananmen Square? There is a process for international regulations, we sign treaties like with copyright, and I get some legal representation in these regulations from my elected representatives. I didn’t elect the European Parliament. If you don’t like my website, don’t use it. I mean, obviously you’d say that if you physically flew to the US and bought something in a store, those store only need to obey US regulations. Or if you ordered an international package and had it delivered. So why do you think sending packets to my geographic location suddenly imposed restrictions on my sovereignty? Virtual goods require more regulations than physical ones? Even if I agreed with the spirit of these regulations, the idea that you can force your local regulations on a global audience without negotiation opens up a real slippery slope. By what ethical or legal argument are European regulations any more relevant to Chinese, Thai, or Turkish? Doesn’t Saudi Arabia have an equal right to claim you can’t run a site that slanders the prophet Mohammed and you have Saudi Citizens on your site? Why are your regulations more relevant than anyone else’s? What if my country rules that running a web site is protected free speech? Any kind of international regulation of the internet must be agreed to by international treaty.