3 ms·
Wouldn't using cloudfront be compliant, because it's your bucket? Turn off the logs, then it's anonymous. Or did I miss anything?
by Lunatic666 8y ago
Wouldn't using cloudfront be compliant, because it's your bucket? Turn off the logs, then it's anonymous. Or did I miss anything?
- discordianfish 8y agoIANAL but I think you still need to sign a data processing agreement with them and have your users confirm that they'll have access to their data.
- Grollicus 8y agoDoes Amazon do unreasonable things with your users' data? Because otherwise you wouldn't need consent.
- darrenkopp 8y agoThe terms are broad in GDPR, so you need the DPA just for Amazon to store it, as that's "processing". However, you don't need your users to confirm that, they agree to share the information with you (controller) and you'll have some sort of terms in your privacy policy allowing you to share personal information with 3rd parties you regularly interact with for legitimate purposes who will be bound by the terms set forth in your own privacy policy.
- antsar 8y agoIt may be your bucket, but Amazon is still a third party. Does turning off logs disable all logging on the Amazon side, or just your copy of those logs?
- icedchai 8y agoYou really think Amazon doesn't have logs for security and troubleshooting? What about all the networks between you and Amazon?
- detaro 8y agoNo, you still need a processing agreement with Amazon, but that's not a problem.
- wooter 8y agoyour own bucket wouldn't benefit from browser url-based caching of common assets (libraries, fonts, etc)