4 ms·
That's only the case if you store personally identifiable information in your logs. IPs don't count as long as you're collecting them for security purposes and
by edaemon 8y ago
That's only the case if you store personally identifiable information in your logs. IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP. Plus, if you rotate out your logs and clean them up regularly, you don't really need to worry about it. (That's what the EU lawyers at my work told us.)
Database backups are only a problem if you save them forever, though it sounds like you are. GDPR generally requires that you regularly archive, rotate out, and clean up old data.
- joering2 8y agoI spent near to $10,000 in 6 lawyers 2 in usa 4 in different european countries and all wrote detailed report for me negating what you just said. IP is one of the most PII identifiable elements of an internet user. Exception is when you can prove such IP is a merely a proxy. please get some other lawyers opinion!!
- edaemon 8y agoNote that I didn't say IPs aren't PII; I said they don't count as long as you are collecting them for the specific purpose of security and don't have any way to identify the person using that IP. Pretty much by definition that is not PII. That came from the legal departments from our German, UK, and French entities.
- kasey_junk 8y agoPII is not the standard for GDPR compliance.
- edaemon 8y agoThat's correct, but PII is what the person I replied to was talking about.
- kerng 8y agoYou contradict yourself, either its PII or not. Common understanding in the industry is that it is. Purpose of security doesn't change if its PII or not. Although security/auditing might allow to hold on for longer because you need the PII as a feature (which you should be transparent about). For pure telemetry you don't need it, I'd claim.
- edaemon 8y agoIPs can be PII under certain circumstances, but not the ones I laid out. > Purpose of security doesn't change if its PII or not. Security is the legitimate interest, an important part of collection under GDPR.
- deleted 8y ago[deleted]
- raverbashing 8y agoHere's your problem, you have 6 lawyers. If you're too worried about this, remove the last octet from the IP or and/or it with a mask. And especially don't associate the IP with the user (by default you can't find out who's the user only by IP).
- kasey_junk 8y agoThe GDPR faq disagrees: https://www.eugdpr.org/gdpr-faqs.html https://www.eugdpr.org/gdpr-faqs.html
- edaemon 8y agoIt doesn't. It says: > Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, ... or a computer IP address. Emphasis mine. I said: > IPs don't count as long as you're collecting them for security purposes and don't have a way to identify a person using the IP.
- kasey_junk 8y agoYou are making a claim to one of 2 things: - the ip addresses never uniquely identify someone or - you have a legitimate interest to collecting this data. Neither provides carte blanche for collecting IP address.
- edaemon 8y agoI'm actually saying that both are a requirement for logging IPs in the circumstances being discussed here, but I certainly don't mean to suggest that either would grant you "carte blanche" to collect and log IPs.
- kasey_junk 8y agoI suspect that logging IP only for security purposes is fine, but the idea that it is a bulletproof defense is just wrong, we have no idea. Current indicators are that regulators think IP is personal & that legitimate interest defenses are suspect.
- KirinDave 8y agoHello, not a lawyer, but mine said you're wrong. You might be thinking of this pseudonymization stuff. My advice is not to play with it. Just delete your logs after a month unless you have a demonstrable and immediate security need for them.