8 ms·
IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.
by rebelde 8y ago
IP addresses are PII, as defined in the law. Every website you visit gets your IP. HN has yours now, and now had a headache to deal with.
- TeMPOraL 8y agoReconfigure your server to stop logging IPs, and/or stop storing logs forever. Here, done.
- ldjb 8y agoThat's not always possible. A number of shared hosting services will automatically log IP addresses and do not provide a means to prevent logging. Of course, in that situation an argument could be made that the web host is the data controller, but that won't stop people taking legal action against the website's operator.
- salvar 8y agoWas there anything stopping people taking legal action against website operators before GDPR?
- ldjb 8y agoNo, but with the GDPR, they'd have more of a case, and it's easier to file a complaint. Whether that's a good or bad thing is a matter of perspective.
- salvar 8y agoWould they have more of a case even when they direct the complaint to the wrong business?
- ldjb 8y agoWhether it's the right business or the wrong business would be something decided upon in court. The prosecution could make the argument that the business in question broke the law. If the defence does not present a strong case and the judge sides with the prosecution, the business could still be reprimanded, regardless of whether they feel it is just or not.
- chopin 8y agoIf that's the case, you'll need to switch your provider. I am pretty sure that any of the big providers who want to make business in the EU offers the possibility to prevent logging. If not, there is hope that they will soon.
- henrikschroder 8y ago> but that won't stop people taking legal action against the website's operator. The GDPR doesn't allow individuals to take legal action against non-compliant companies. It allows individuals to report companies to their local data protection agency.
- ldjb 8y agoYes, reporting to the data protection agency was what I meant. My use of the term "legal action" was probably incorrect. Thanks for pointing that out.
- VMG 8y agoDon't forget to scrub the headers! Your software stack might store something as well.
- lexs 8y agoYou can store IP addresses for security reasons and then delete them when not needed anymore and would be compliant. https://gdpr-info.eu/recitals/no-49/ https://gdpr-info.eu/recitals/no-49/ Also you don't have to log the IPs if you don't need them...
- JorgeGT 8y agoEvery website you visit can elect not to store IP addresses. In fact if you had German users their IPs were already protected, it's just that nobody cared to comply with individual EU member's privacy laws until they combined their weight into GDPR: https://blog.philippklaus.de/2011/05/modify-apache-logging-to-comply-to-german-privacy-law https://blog.philippklaus.de/2011/05/modify-apache-logging-t...
- ptaipale 8y agoNot necessarily. They may even be required to store access information, due to legal regulations in some countries. Also, providing service may become practically impossible if it is not possible to keep logs and similar data.
- quohM0Ho 8y agoOther legal requirements trump the GDPR data minimization. In that case you only need to provide that data when the user wants a data export.
- JorgeGT 8y agoExactly, if you're providing a special service that requires logging (financial, etc.) then you need to follow other laws that trump GDPR, same as you need to obey traffic lights except if you drive an ambulance and there's an emergency, at which point other laws trump the general driving code.
- dangerface 8y agoYea, they cover that: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- Sean1708 8y agoAt which point it becomes "Legitimate Interests" (or whatever the correct term is).
- peteretep 8y ago> IP addresses are PII, as defined in the law. No, that's far from fucking clear, but appears to have been repeated over and over and over again.
- kasey_junk 8y agoIt’s in the faq, you can’t be upset with people repeating it. https://www.eugdpr.org/gdpr-faqs.html https://www.eugdpr.org/gdpr-faqs.html [edit] faq linked has been changed in the last weeks. How about this one https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- pjc50 8y ago"IP address" does not appear in that text.
- kasey_junk 8y agoThey changed it. Edited comment.
- peteretep 8y ago> This website ... is NOT an official EU Commission website.
- kasey_junk 8y agoNew link in comment to European Commission Page. It clearly lists IP address.
- rebelde 8y agoI would love for you to be right. A search for "gdpr are ip addresses personal data" only shows me articles that confirm what I said, including a ECJ ruling.
- xxs 8y agoDefine retention policies and explain you would keep IP addresses up to xxx months to ensure service operation/troubleshoot/etc. Prune the logs. There you have it.
- thecatspaw 8y ago"IP addresses are logged to ensure we can comply with requests from law officers"
- xxs 8y agoEven then, you have to delete them at some point, b/c the retention policy has to specify duration.
- rebelde 8y agoSounds like a legal headache for anybody who wants to set up a personal blog or blog for their company, with a penalty of up to 20 million euros if you get it wrong.
- Dylan16807 8y ago> with a penalty of up to 20 million euros if you get it wrong Much like if you set up your billing software wrong, you could go to jail for years for fraud. Or you could violate a safety regulation and get shut down for months. Staring at the worst possible punishment is hopelessly hyperbolic.
- FooBarWidget 8y agoWhat? You can setup log rotation in 1 minute. In 3 minutes you can write a small paragraph that explains you only use IP addresses for security reasons and only store them for a few weeks. Also, the claim that you immediately get the maximum fine of 20 million euro for every small detail that you get wrong, is false: https://www.joyfulbikeshedding.com/blog/2018-04-17-should-non-eu-websites-ban-eu-visitors-under-the-gdpr.html https://www.joyfulbikeshedding.com/blog/2018-04-17-should-no... (claim backed up by a book written by an IT lawyer)
- pjc50 8y agoAgain, let's read the text. "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them. An IP address is an "identifier". However, an IP address does not identify a natural person; you know that, I know that, and even the GDPR knows that. However, if you start building a map of IP addresses to user real names, or some other form of profile construction, then the IP addresses become personal information.
- rebelde 8y agoSo truncating logs is an overreaction? There is no need to do that for GDPR? I see many people saying the opposite.
- pjc50 8y agoIt's not strictly necessary but it's a good idea anyway, even outside of GDPR. The key question is, what kind of processing are you doing on the logs? If you're using it to build user profiles that needs careful consideration. You should also think about whether the URL in a web log contains personal data that affects that: if you know that 192.168.100.blah has accessed "/logged-in-user/joe-bloggs", then that IP address may now be personal data.