3 ms·
Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?
by epicmellon 8y ago
Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?
- hsljekskfh 8y agohow about instead, we err on the side of privacy instead of billion dollar companies that don’t pay taxes for once.
- Karunamon 8y agoDoubly so when legal precedent exists that IP isn’t sufficient enough to identify a person.
- bulatb 8y agoCurrent guidance, although not definitive, is that IPs and similar identifiers are personal data iff the processor/controller can identify a natural person by combining them with other data it can legally access.
- bhaak 8y agoThere's also legal precedent that IPs can be sufficient enough to identify a person.
- wooter 8y agoand its absurd, rejected, and overturned. if i use your laptop, am i you?
- Dylan16807 8y agoMaybe not to a "reasonable doubt" threshold, but it's a pretty strong identifier.
- hannasanarion 8y agoNot to conclusively for all time identify a person, but that's not what we're talking about. It's still PII: personally identifiable information. Things that can be used to identify a person. A first and last name is also insufficient to identify a person, are you going to argue that names aren't personal?
- jkaplowitz 8y agoThe GDPR only does so when it can be used to identify a specific human, in which circumstance it's not ridiculous. It would be ridiculous as an absolute unqualified rule.
- duxup 8y agoWhat does that have to do with the article?
- epicmellon 8y agoWell if the USA were to have a law that is GDPR "like", that's in there.
- duxup 8y agoI'm not trying to be dense here.... but what do you mean exactly?
- angott 8y agoNo, it is not ridiculous. Yes, an IP alone is probably worthless. But take an IP together with even a seemingly insignificant piece of information, and you have the potential to know a lot more. I think that's why the EU regulators decided to consider IPs as personal data. Example: you run a website and in your log file you only collect IP addresses, apparently anonymous. Log lines come with a timestamp. You now know that a user at IP X visited your website at time Y. Sounds like this should be personal information in my opinion, and that log file should be protected.
- zerostar07 8y agoAnd then take one step forward and make them actually untraceable by requiring anonymization/obfuscation at the ISP level? Seriously the reason why GDPR considers them PII is because the ECJ has judged that if you have access to the ISP you can look them up. https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...
- Spivak 8y agoWhy? For residential users a single IP address is connected to either a single person or a small set of individuals. When websites use IP addresses as an authentication factor because they change so infrequently that it's when it does it's hard to argue that you can't identify users by the source of their traffic. Plus the addresses themselves betray personal information. If you use my service I can know a great deal about you by your source addresses. * You shop at Target, but sometimes Wal Mart when you're in a rush. * You get coffee at the Starbucks on 5th every morning. * You live on 2365 Chestnut Dr. * I know where all your friends live and how often you visit them. * You used to go to this one apartment a lot late at night, but not anymore. How are you dealing with the breakup? * You work in the office building on Main. * You went to a Mercedes dealership. You deserve it after all emotional stress you've been though. * You went to a fancy restaurant yesterday, date night? * You're coming from a couples retreat in Cali, I'm so happy for you! Getting back out there.
- jellicle 8y agoI would guess most home internet users could be uniquely and instantly identified by their IP address. Google, Facebook, the NSA, Experian, Transunion, Equifax, no doubt many other entities could run this function: identify_home_user(1.2.3.4) and get your name, address, SSN, etc. Even if the identification is not unique, it probably narrows down to a married couple, rarely as many as 5-6 adults. That's pretty good ID from one number.
- reilly3000 8y agoWith nothing but an IP address it’s possible to purchase data append services that reveal a user’s email address, physical address and more. Large sites sell login data to data brokers, keying user account info to IPs. Marketers upload lists of IPs and get back an enriched list with a full profile. Obviously it can get fuzzy with multiple people under the same IP. But in many cases it’s all that is needed for identification.