24 ms·
The GDPR explicitly allows for the processing of personal information without consent in the event that such processing is required for ensuring network securit
by staticfloat 6y ago
The GDPR explicitly allows for the processing of personal information without consent in the event that such processing is required for ensuring network security and availability, see [1], [2] and [3] for more reading on this. Note that I am not a lawyer, and you should consult a lawyer (as we did) to ensure that all policies fall within GDPR laws.
That is precisely what the logged IP addresses are used for (an example: nginx access logs), and is one of the reasons why we would much rather use a random number generated by the client machine than an IP address; because the bits themselves have no meaning, unlike IP addresses.
As mentioned in the linked thread, NumFocus has worked with a legal team that specializes in this type of law, this plan is all in compliance with the GDPR.
[1] https://gdpr-info.eu/recitals/no-49/ https://gdpr-info.eu/recitals/no-49/ (The actual GDPR text regarding security concerns)
[2] https://blogs.akamai.com/2018/08/dispelling-the-myths-surrounding-security-technology-and-gdpr.html https://blogs.akamai.com/2018/08/dispelling-the-myths-surrou... (Akamai legal team confirming that this interpretation of logging IP addresses for security purposes is valid)
[3] https://law.stackexchange.com/a/28609 https://law.stackexchange.com/a/28609 (Stack exchange post pointing out that even more exceptions exist beyond just security)
- bencollier49 6y agoFrom the first paragraph of TFA: 'The goal is to answer the question “How many Julia users are there?”' This is a commercial concern, nothing to do with security, and to my understanding at least, is not a valid reason for collecting PII. There doesn't appear to be a security argument for collecting this data without consent.