3 ms·
In this article the author states: "The latter definition is important for developers. It includes things like IP addresses, mobile device IDs, browser fingerpr
by setra 9y ago
In this article the author states: "The latter definition is important for developers. It includes things like IP addresses, mobile device IDs, browser fingerprints, RFID tags, MAC addresses, cookies, telemetry, user account IDs, and any other form of system-generated data which identifies a natural person.". This information does NOT automatically qualify as personal data. Information being unique is not the same as personally identifiable. A random cookie sent by the browser is not PII. A cookie stored in conjunction with say an email address could be.
Certain information can be classified as PII if it possible to cross reference it with other stored information to identity a user. For example a European court in a recent ruling stated that a full IP address could be considered PII because an ISP would have a record of IP address and time with a persons name.
- robin_reala 9y agoAre you mixing up ‘personal data’ and ‘personally identifiable information’ (a US legal concept that differs from the EU definition of personal data)?
- setra 9y agoNo, I am simply using shortened text not the USA PII legal concept. GDPR has many more restrictions than the USA concept of PII.
- _o_ 9y agoTo me it seems quite simple, if the information can be used to identify user it is personal information and you need explanation why you need it and opt in. If this is a problem for you, maybe avoid collecting what you don't need. The idea of "collect everything and audio & canvas fingerprint them, maybe I will need it later" wont pass, you will never get consent. Collect only what you really need.
- deleted 9y ago[deleted]
- gnfurlong 9y agoThis doesn't make sense to me. Wouldn't that make every id that is one to one or one to many with a customer PII? That seems absurd. A user alias on some random site would meet that criteria, assuming they took name/address/etc when you signed up. Unless PII has some other significance than I'm interpretting it to have?
- freeone3000 9y agoRight. So you'd have to have a business case for the user to have a persistent login, if you want to offer login functionality, beyond simply "track the user to see what they want". It's ridiculous.
- mark_edward 9y agoSounds good to me. Screw you data vampires.
- x0x0 9y agocookies is about the only thing in there that may not qualify as personal data as defined by the gdpr.