3 ms·
It sounds like you just made a simple log into something that definitely belongs to the GDPR ruleset! But that's just my interpretation. Can anyone, with cita
by kalms 9y ago
It sounds like you just made a simple log into something that definitely belongs to the GDPR ruleset!
But that's just my interpretation.
Can anyone, with citation, please shed some light on this. What's fair use, in broad terms, when it comes to simple HTTP logs or similar structures?
- kuschku 9y agoFor HTTP logs, allowed use would be e.g. stripping the last octet of an IPv4, or stripping the last 64 to 80 bytes of an IPv6. That’s generally not identifying a single person anymore, and usually good enough for anything else.
- iovrthoughtthis 9y agoThis does not make the data not PII as if used in conjunction with some other data it could still be used to identify a natural person.
- kuschku 9y agoIf you have such additional data, yes. In the general case (e.g. hosting a simple website where you strip user identifiers and the last octet out of the nginx logs) it becomes no PII then.
- eadmund 9y ago> For HTTP logs, allowed use would be e.g. stripping the last octet of an IPv4, or stripping the last 64 to 80 bytes of an IPv6. > That’s generally not identifying a single person anymore, and usually good enough for anything else. 'Usually'? Even if true (highly doubtful), that's not the same as 'always.' The whole purpose of logs is to be truthful accounts of pertinent data. A full IP address is a pertinent datum. I'm going to step up on my soapbox and assert that any law which forbids me from indelibly recording that 192.0.2.17 requested /all-your-records-are-belong-to-us is a bad law.
- lokedhs 9y agoThe GDPR does not forbid you to do those things. It does require you to treat the information as PII, which is going to give you some hassles, but you are not banned from recording it.
- eadmund 9y agoI'm banned from recording it immutably, which is the only proper way to record a log (it should be impossible to alter a log after it's written). If I want to record that a particular address accessed my system forever, that is my right. Interestingly, the GDPR exempts records required for legal compliance. So it's okay to hold onto data for the law's purposes, but not my own? That's a bit one-sided.
- detaro 9y agoIf it contains full IPs or other identifiers, then yes it does. You should either not collect full IPs in the first place, or clean them after some time e.g. during logrotate (Since you might need them for a while, e.g. to detect or count abusive requests, which likely would be a valid reason to keep them around temporarily)