4 ms·
You can tie such visit to a real person. For example, if this is a Facebook user, and your site includes resources from facebook.com, Facebook will know exactly
by mixedbit 9y ago
You can tie such visit to a real person. For example, if this is a Facebook user, and your site includes resources from facebook.com, Facebook will know exactly which real person visited your site, and the user did not give you consent to share such info with Facebook.
- paulddraper 9y agoIsn't that in Facebook's court though? They acquired your name, birthdate, address, etc. And they didn't aquire it through your website. Calling IP address or screen size "person" identifying information seems a stretch to me.
- PeterStuer 9y agoNo, since you are the controller of your site hosting the Facebook component. Facebook is in that workflow 'merely' a data-processor. Advertising companies have lobbied long and hard to drive an interpretation of the GDPR in which they would be considered a 'controller', resulting in 'nothing changes for the business, realy'. AFAIK, they (thankfully, from a privacy perspective) failed. It realy is very much like environmental regulation. Before things like the EPA etc. came to be, it was a toxic 'everything goes' type of environment. Transition to a regime where businesses are held to data responsibility might be painful at first, but ultimately hugely beneficial to all.
- zaarn 9y agoIf you embed a Facebook like button and Facebook loads their scripts into YOUR site then it is YOUR responsibility to make sure Facebook is compliant with the law. The same goes for ad networks. YOU are responsible for making sure the ad network is compliant. If you include a non-GDPR complaint ad network script on your site and somebody complaints, then you are in for it because you were ultimately responsible for that network being able to track the user on YOUR webpage. If Facebook is GDPR compliant and has consent from the user then you are in the clear. If Facebook is not GDPR compliant and tracking people who aren't users then a EU or local court will set up a campfire under their asses (German courts already have). IP addresses are definitely personal data (PII and Personal Data are different, the GDPR defines and cares only about the later, PII is mostly an US term used interchangeably with PD on the internet) German and EU courts have ruled that since an IP can be traced back to a person, it's personal data. Unless you have a good reason to log it (hint: firewall and webserver logs) then you need consent for it.