3 ms·
In addition, you can store the IP address if you want to use it for infosec (such as, finding out who to block in case of a ddos attack). See https://gdpr-info.
by smu 9y ago
In addition, you can store the IP address if you want to use it for infosec (such as, finding out who to block in case of a ddos attack). See https://gdpr-info.eu/recitals/no-49/ https://gdpr-info.eu/recitals/no-49/
The recital also mentions "accidental events that compromise availability, integrity, authenticity,..." That seems to cover debugging for me. No need to ask for consent.
To do certain analytics like page count, you don't need the IP, so that seems ok for me. To track individual customers however, that's something else.
PS: according to GDPR, a hashed IP will be "pseudonimisation", not anonymisation because you can have a key to go back to the original value. True anonymisation removes all info (the IP in this case)
- cromwellian 9y agoMost small web sites don’t have the resources for this. Many don’t even know if they will have analytics in the beginning, or info sec. People tend to set up sites and just stash web logs in the beginning. They then learn later what their business needs are and may decide to post process their logs. You're suggesting a new site pay all of these costs up front to comply with these regulations, you can’t time shift concerns by collecting data and deciding whether you need it later. Granted, you could argue that this is bad practice anyway, but many startups work exactly like this, maximum logging early, dropping rention later after beta. If you are not physically hosting in the EU, how many people want to even read the GDPR? A lot of sites don’t even know where their users are coming from until they run analytics.
- smu 9y agoActually, I was trying to point out ways to not have to remove/prune your logs...
- cromwellian 9y agoRight but these days, if you rent a cloud hosted docker container with say, nginx or httpd, you'll get HTTP logs via fluentd with full IP address information, and a lot of people will push these into storage like S3 or GCP buckets for analysis later. If you say, use a point-and-click installation of Wordpress on AWS/GCP/Azure, you're going to get IP logs being held. I'm just pointing out that the regulations impose a lot of costs and expose people to huge risks. I mean, can I be held liable if I use an open source downstream dependency from npm or Maven, and it just so happens to have debug logs that are storing info, and I didn't know about this logging cause I didn't audit every line of code from a downstream dependency? For large companies, this isn't going to be a problem, but the entire open source ecosystem operates on a system that for the most part, you aren't exposed to legal liability by them, except in cases like patent violations or copyright infringement, but now there's a huge cognitive burden being levied on top by a massively complicated new regulatory framework.