3 ms·
GDPR adds a lot of regulatory red tape to things that were previously simple. It is not only for nefarious reasons that you might want to avoid GDPR. Want to s
by unknown_library 7y ago
GDPR adds a lot of regulatory red tape to things that were previously simple. It is not only for nefarious reasons that you might want to avoid GDPR.
Want to store logs? Now you need to make sure you're scrubbing any type of personal information from the logs. Want to use a third-party service? Now you need to make sure that you are using their GDPR-compliant plan, and that you are using their Amsterdam endpoints. Maybe you need to renegotiate your contract with them.
- asutekku 7y agoI mean you shouldn’t store any personal information in the logs to begin with.
- marcinzm 7y agoMost places would log the IP (for spam prevention, security tracking, etc) which is personal information under GDPR.
- DarkWiiPlayer 7y ago> which is personal information under GDPR Not exactly; it's up to the judges to decide whether IP addresses count as personal information as defined by the GDPR (in my opinion they're not, but I can see why one would think differently), so the flaw isn't as much inherent to the GDPR as to the fact that people just don't understand the internet.
- vonmoltke 7y agoRecital 30 specifically calls out IP addresses: https://gdpr-info.eu/recitals/no-30/ https://gdpr-info.eu/recitals/no-30/ While the wording of the Recital leaves some ambiguity as to whether an IP is automatically Personal Data under the GDPR, its specific call-out would make arguing that it is not difficult. This would particularly be the interpretation of American lawyers, who tend to assume that no connection is too tenuous to be held against their client by a shrewd prosecutor or regulator and will thus advise their client to treat all IPs in all situations as Personal Data.
- tjoff 7y agoIt depends on the context. An ISP can trivially map an IP to a person. So can Amazon/whoever if they saved the IP alongside other customer information. But a naked ip->person lookup would require a warrant.
- MattConfluence 7y agoYes, but if you are logging the IP for spam prevention, security tracking, etc, then you are in the clear per Article 6, section 1, point f [1]. However, you can't also use the IP for fingerprinting, ad targeting, etc, without acquiring informed consent, per section 1, point a. You can put the IP in your security logs because that is necessary to secure the service. Just have a routine to scrub the logs once they are too old to be useful anymore. You can't put the IP in your shadow profile database and sell it to shady marketing companies, unless the user has explicitly agreed to that. The question isn't only whether something is personal information or not, it is also a question of what you intend to do with the data. [1] https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/
- vonmoltke 7y agoArticle 6 establishes lawful purposes for data processing that do not require consent from the data subject. All other provisions of the GDPR (including, but not limited to, the maximum time you are allowed to hold the data) apply, since it is still Personal Data. The only way to avoid having to deal with GDPR entirely is to collect absolutely no Personal Data, which is almost impossible unless your web server has no logs.
- DarkWiiPlayer 7y ago> Want to store logs? Now you need to make sure you're scrubbing any type of personal information from the logs. What?! I'm not allowed to store my users name, address and credit card number in my unencrypted syslogs anymore? HOW DARE THEY, THOSE DAMN BEUROCRATS! Seriously though, while there are problems (like IP address being considered personal information, which they really aren't), the general idea is very positive. You shouldn't be able to store just any information of a person that only gave you this data for a specific purpose. Servers do get hacked, employees do abuse their access to systems and old hardware doesn't always get disposed of properly. When I'm done using a service, I want my data gone from their servers ASAP, no buts.
- bakuninsbart 7y agoBasically you are just describing the bare minimum of good practice + respecting your users privacy.
- cosmodisk 7y agohttps://temp-mail.org/privacy-policy https://temp-mail.org/privacy-policy Have a look at the list of companies and other websites this service uses/shares data with. No wonder some websites rather block users all together instead of showing that they are selling data left and right.