7 ms·
This isn't true. You can use cookies for necessary operations of the website, which this almost certainly is. Also, country level location data isn't PII, and
by fasteddie 8y ago
This isn't true.
You can use cookies for necessary operations of the website, which this almost certainly is. Also, country level location data isn't PII, and also doing a geoip lookup that you don't store anywhere also isn't in violation.
- tremon 8y agoThis isn't true either. If you're using an IP lookup to determine the user's current country, that's still processing PII (since many courts have already ruled that an IP address is unique enough to identify a person -- technical challenges notwithstanding). However, you have a clear and stated use case for processing that PII so consent is not required, but you are required to mention this processing in your privacy policy. Not publishing this processing is (strictly speaking) a violation of the GDPR, but the processing itself isn't.
- davidfischer 8y agoFor the purpose of the GDPR, an IP is PII. However, one can get rough location using an anonymized version of an IP address (say one that has zeroed out the last octet or two). From Recital 26 (https://gdpr-info.eu/recitals/no-26/ https://gdpr-info.eu/recitals/no-26/): > The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.