3 ms·
To be clear, I am only talking about the interpretation of the regulation, not my own considerations. The article made it sound like IP addresses are always pe
by ptype 9y ago
To be clear, I am only talking about the interpretation of the regulation, not my own considerations.
The article made it sound like IP addresses are always personal data. My point is that, if I run a website and keep generic nginx log files, is it really personable data with regards to my website?
Yes, the ISP can link that IP address back to a person, but if that person came to me as the website administrator and asked for all data held for that person, I would actually not be able to make the connection.
- detaro 9y agoYes, it is. That you don't necessarily have the ability to make that connection doesn't matter, although if it turns out you have it of course makes matters worse. (This also isn't new under GDPR, current european law interpretation already supports this. See http://curia.europa.eu/juris/document/document.jsf?text=&docid=184668&doclang=EN http://curia.europa.eu/juris/document/document.jsf?text=&doc... for the court decision firmly establishing this: Since the visitors provider has the data, and will share this data in some cases, it's possible to establish the link and the dat thus has to be protected accordingly)
- ptype 9y agoWell actually this analysis by White & Case of the same case[1], seems to suggest that it may not be (paragraph “impact on businesses”) personal data if the business has no means of linking the addresses to users. [1] https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...
- detaro 9y agoInteresting, commentary I saw interpreted that more widely. Thanks for the link!