5 ms·
I have submitted this because it is frequent to see on HN claims that IP addresses are personal data under GDPR. I’m yet to see a good source for this blanket s
by ptype 8y ago
I have submitted this because it is frequent to see on HN claims that IP addresses are personal data under GDPR. I’m yet to see a good source for this blanket statement, and this link contains a more nuanced analysis, essentially saying that IP addresses are only personal data in some cases, where they can be used to identify a person (without involvement of the ISP).
- lurker456 8y agoGDPR is more recent and supersedes this.
- tjoff 8y agoThough the exact same reasoning applies.
- killjoywashere 8y agoI'm fairly certain the US legal system, when interpreting domestic cases (the purview of HIPAA) doesn't care about the GDPR. If a case crossed international boundaries, sure, but to say GDPR supersedes HIPAA is false. They apply to different jurisdictions, which are mostly, if not entirely, separate.
- lurker456 8y agoAgreed, the US is more lax. I was responding to the parent comment "I have submitted this because it is frequent to see on HN claims that IP addresses are personal data under GDPR"
- killjoywashere 8y agoIP addresses are also considered PHI under HIPAA. This is new to the GDPR.
- zaroth 8y agoIP addresses are not themselves PHI, but the presence of IP addresses is considered to make PHI “individually identifiable”. IP addresses must be removed when you are de-identifing PHI. You also, by the way, must remove any geographic information more specific than a state, such as ZIP codes. So it doesn’t say much to include IP addresses in the deidentification list.
- c3tru 8y agoIt's important to note that only IP adresses in combination with a timestamp are considered personal data under GDPR.
- Matticus_Rex 8y agoCitation? That wasn't mentioned in the WP29 draft guidance I read.
- c3tru 8y agohttp://curia.europa.eu/juris/document/document.jsf?text=&docid=184668&pageIndex=0&doclang=en http://curia.europa.eu/juris/document/document.jsf?text=&doc... That's the detailed version of the ruling. The ruling refers to IP adresses with time and date, as explained in point 37.
- Buge 8y agoIt says IP address and time are necessary for it to be personal data, but not sufficient. To be personal data you also have to have access to some mapping to map those back to actual people. For example if you have an agreement with ISPs that allows you to map IP+time to person, then the IP+time is personal data. In the absence of such agreement, it isn't necessarily personal data.
- c3tru 8y agoYou do not need access to the mapping. It's only important if such a mapping is possible.
- apple4ever 8y agoNo access important. Mapping is possible only with access. So IPs and time stamps are not PII by themselves.
- Buge 8y agoIt says access to the mapping is required. Point 49. >a dynamic IP address registered by an online media services provider [...] constitutes personal data within the meaning of that provision, in relation to that provider, where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person.
- jve 8y agoWe are at datacenter business and we rent hardware/vps. For our case, lawyer at our company said that IP is personal data only when it is written in contract, i.e. when you lease a server and we assign you a static IP. In other cases you cannot create a 1:1 mapping between IP address and physical person. Even when that IP is assigned to a household - still that cannot be PII because multiple people may use that IP.
- clarry 8y ago> ... cannot be PII because multiple people may use that IP. I think such reasoning is a little unfortunate. Multiple people share my name. Multiple people could live in or visit my household. So is my name and address not PII? I don't think that underlining all the cases where some given bit of information may fail to identify a person is the right approach when it comes to making a blanket statement about whether said info is PII. I don't think courts would follow that reasoning either, especially when there will be lots and lots of counterexamples where following that trail of information leads to facts that most people would conclude as identifying a person exactly (at least with a very high degree of certainty).
- zerostar07 8y agoBut they say it is relevant data if there IS involvement of the ISP
- Boulth 8y agoHow about this: > Examples of personal data > [...] > an Internet Protocol (IP) address; Source: https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- Tomte 8y agoThis does not concern the GDPR, as the article clearly states, at issue was the interpretation of the old Directive.
- acqq 8y agoIn making the submission, the submitter faked the title. The title on HN is at the moment: " Court confirms that IP addresses are personal data only in some cases" whereas there is no "only" word anywhere on the linked page. So the title on HN is misleading. Especially given the most important part of the article: "The CJEU decided that a dynamic IP address will be personal data in the hands of a website operator if: - there is another party (such as an ISP) that can link the dynamic IP address to the identity of an individual; and - the website operator has a "legal means" of obtaining access to the information held by the ISP in order to identify the individual." And it's known that the "legal means of obtaining access to that information" is very often present.