5 ms·
SSL/TLS-Decryption and the GDPR
- mytailorisrich 6y agoPersonal data are so if they can be linked to an identified or identifiable person. So in itself an URL would need to not only contain information that may be deemed personal but also information to identify that person. In the case of logs I think the criteria are most likely met when considering that time, IP address, and metadata such as URLs are often collected to stored together. These 3 pieces of information together may then most likely become (sensitive) personal data.
- eivarv 6y agoYes; It might not be clear, but my argument is that these sorts of logs are usually personal data (as they usually include IP-address or other person/device-identifier) – but if you have URLs too you run the risk of storing SENSITIVE personal data ("special category").
- mytailorisrich 6y agoIn general IP addresses are not personal data in themselves because the controller has no means to link them to individuals: If I operate a website I can log the IP addresses of visitors but I have no way of identifying those visitors (unless e.g. they are customers with accounts and can log in). It is certainly good practice to treat logs as if they were personal data when it comes to handling and securing them but whether they are in fact personal data needs to be considered for each specific case.
- eivarv 6y agoYou're incorrect – the GDPR mentions IP addresses specifically as an example of personal data in recital 30 [0]. The EU Commission also mentions [0] it as an example of personal data. [0]: https://gdpr-info.eu/recitals/no-30/ https://gdpr-info.eu/recitals/no-30/ [1]: https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- mytailorisrich 6y agoOf course IP addresses can be personal data. But in themselves they aren't. The GDPR do not claim otherwise, including recital 30. The links you provide list examples of what may be personal data. As already mentioned, and also actually stated in your second link, for something to be personal data it must be related to an identified or identifiable person. Their first paragraph summarises it well (the definition is of course the one in the GDPR): "Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data." So if you have IP addresses and nothing else, you most likely do not have personal data. But if you have IP addresses of identified individuals (e.g. logged users personally identified) you most likely have personal data. This is in line with an ECJ ruling from 2016 and the GDPR have not changed that. A problem is that people make shortcuts so "IP addresses can be personal data" becomes "IP addresses are personal data".
- eivarv 6y agoSorry, but I still don't think you're right. In fact, your understanding doesn't sound like anything I've heard from anyone else. The link doesn't give examples of what can be, but what is personal data. "Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data." This says something about the data, and how it relates to a person in itself – not what practical ways you have in a certain context, limited only to other information you have immediately available in that same context. It's about whether the individual is identifiable – the ICO says [0]: "You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual." Otherwise, this next part wouldn't make sense: "Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR." It isn't an issue of whether you're able to identify the person given only the information you have available – but whether the candidate can be theoretically identified. [0]: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/what-is-personal-data/ https://ico.org.uk/for-organisations/guide-to-data-protectio...