6 ms·
The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.
by quohM0Ho 8y ago
The easiest way to comply is to not collect any PII. That is only a problem for companies that make data collection their core business.
- VMG 8y agoor anyone who has a public httpd with default log settings
- dboreham 8y agoDefault logging settings retain log files forever?
- VMG 8y agoI don't know how long you are allowed to store PII under GDPR (I'm not a lawyer) This article indicates that default settings are problematic: https://www.ctrl.blog/entry/gdpr-web-server-logs https://www.ctrl.blog/entry/gdpr-web-server-logs > All of these logs contains personal information by default under the new regulation. IP addresses are specifically defined as personal data per Article 4, Point 1; and Recital 49. The logs can also contain usernames if your web service use them as part of their URL structure, and even the referral information that is logged by default can contain personal information (e.g. unintended collection of sensitive data; like being referred from a sensitive-subject website).
- peteretep 8y ago> Article 4, Point 1 Article 4 Point 1 is: > (1) 'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; It is very far from clear that that covers IP addresses, which tend to be recycled, and would need a police warrant + actual evidence to then map to a specific human > and Recital 49 http://www.privacy-regulation.eu/en/r49.htm http://www.privacy-regulation.eu/en/r49.htm Failing to see the relevance
- VMG 8y agohttps://eugdprcompliant.com/personal-data/ https://eugdprcompliant.com/personal-data/ > [...] The conclusion is, all IP addresses should be treated as personal data, in order to be GDPR compliant. https://privacylawblog.fieldfisher.com/2016/can-a-dynamic-ip-address-constitute-personal-data https://privacylawblog.fieldfisher.com/2016/can-a-dynamic-ip... > What does the GDPR say? > [...] Recital 30 clarifies that "online identifier" includes IP addresses. http://www.privacy-regulation.eu/en/r30.htm http://www.privacy-regulation.eu/en/r30.htm > (30) Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags.
- quohM0Ho 8y ago> It is very far from clear that that covers IP addresses, which tend to be recycled Enter stage left: Address van Six, carrying an EUI64 card in his right hand.
- dboreham 8y agoA quick read of that article suggests to me that it is just wrong.
- mrweasel 8y agoI was actually looking for a way to configure something like filebeat to replace IPs with country codes, before shipping the logs of to a central logging server. On the face of it, it was more trouble than I could be bothered to deal with at the time, but now I may have to take another look.
- yjftsjthsd-h 8y agoFor that matter, could you just slice it down to a /16 or /24?
- mrweasel 8y agoThat would be equally good. I just want to avoid shipping complete IPs to a log-host.
- rebelde 8y agoIP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.
- TeMPOraL 8y agoReconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.
- ldjb 8y agoThat's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging. Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.
- salvar 8y agoWas there anything stopping people taking legal action against website operators before GDPR?
- ldjb 8y agoNo, but with the GDPR, they'd have more of a case, and it's easier to file a complaint. Whether that's a good or bad thing is a matter of perspective.
- salvar 8y agoWould they have more of a case even when they direct the complaint to the wrong business?
- ldjb 8y agoWhether it's the right business or the wrong business would be something decided upon in court. The prosecution could make the argument that the business in question broke the law. If the defence does not present a strong case and the judge sides with the prosecution, the business could still be reprimanded, regardless of whether they feel it is just or not.