4 ms·
I’m not convinced IP addresses are automatically personal data. Granted, they CAN be personal data, if they can be linked to a specific person. But assuming I j
by ptype 9y ago
I’m not convinced IP addresses are automatically personal data. Granted, they CAN be personal data, if they can be linked to a specific person. But assuming I just keep generic log files, and that I would not in a subject access request be able to tell someone the IP addresses that the user has used, is it really personal data? Also, it is not clear to me what other laws require in terms of keeping log files. It is possible that by keeping no log files at all, you risk breaking some other law (UK).
- CydeWeys 9y agoIt doesn't matter what you consider IP addresses to be, it matters what European regulatory authorities consider them to be. And yes, many IP addresses can be linked to a specific person. I don't doubt that, by being logged in to Google, Facebook, and a bunch of other services, and by having an ISP that provides a unique IP address per subscriber, that the majority of sites out there that use 3rd party tracking know who I am just by my IP address at any given time.
- ptype 9y agoTo be clear, I am only talking about the interpretation of the regulation, not my own considerations. The article made it sound like IP addresses are always personal data. My point is that, if I run a website and keep generic nginx log files, is it really personable data with regards to my website? Yes, the ISP can link that IP address back to a person, but if that person came to me as the website administrator and asked for all data held for that person, I would actually not be able to make the connection.
- detaro 9y agoYes, it is. That you don't necessarily have the ability to make that connection doesn't matter, although if it turns out you have it of course makes matters worse. (This also isn't new under GDPR, current european law interpretation already supports this. See http://curia.europa.eu/juris/document/document.jsf?text=&docid=184668&doclang=EN http://curia.europa.eu/juris/document/document.jsf?text=&doc... for the court decision firmly establishing this: Since the visitors provider has the data, and will share this data in some cases, it's possible to establish the link and the dat thus has to be protected accordingly)
- ptype 9y agoWell actually this analysis by White & Case of the same case[1], seems to suggest that it may not be (paragraph “impact on businesses”) personal data if the business has no means of linking the addresses to users. [1] https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...
- detaro 9y agoInteresting, commentary I saw interpreted that more widely. Thanks for the link!
- Azeralthefallen 9y agoA stupid question, does this mean i now need to figure out a way to mask any IP addresses in any AWS logs? Like ELB/Cloudfront/VPC logs?
- CydeWeys 9y agoThis is going to be a much bigger problem for Amazon than it is for you personally, so it'll be interesting to see what AWS logs even look like come May 25th. If you don't have consent and a compelling business reason to store this PII then they definitely don't. To give you one idea of how things will change in a post-GDPR world, I can tell you a story about how things are going in my industry: Most PII is going to be removed from domain WHOIS information.
- molf 9y agoGDPR defines "personal data" as "any information relating to an identified or identifiable natural person". [1] The GDPR definition of personal data is VERY broad, and it includes things like: * name, email, date of birth, etc (probably no surprise here) * any user behaviour (what you look at, what you click on) * uploaded content (what you write, your uploaded avatar etc) * ip addresses, device ids * beliefs, ethnicity, sexuality, health data (additional restrictions apply here) * biometric data, genetic data (additional restrictions apply here) [1] https://gdpr-info.eu/art-4-gdpr/ https://gdpr-info.eu/art-4-gdpr/
- ptype 9y agoIf I can make a connection between an IP address and a person, yes then it is personal data, no doubt.