5 ms·
Yes; It might not be clear, but my argument is that these sorts of logs are usually personal data (as they usually include IP-address or other person/device-ide
by eivarv 6y ago
Yes; It might not be clear, but my argument is that these sorts of logs are usually personal data (as they usually include IP-address or other person/device-identifier) – but if you have URLs too you run the risk of storing SENSITIVE personal data ("special category").
- mytailorisrich 6y agoIn general IP addresses are not personal data in themselves because the controller has no means to link them to individuals: If I operate a website I can log the IP addresses of visitors but I have no way of identifying those visitors (unless e.g. they are customers with accounts and can log in). It is certainly good practice to treat logs as if they were personal data when it comes to handling and securing them but whether they are in fact personal data needs to be considered for each specific case.
- eivarv 6y agoYou're incorrect – the GDPR mentions IP addresses specifically as an example of personal data in recital 30 [0]. The EU Commission also mentions [0] it as an example of personal data. [0]: https://gdpr-info.eu/recitals/no-30/ https://gdpr-info.eu/recitals/no-30/ [1]: https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- mytailorisrich 6y agoOf course IP addresses can be personal data. But in themselves they aren't. The GDPR do not claim otherwise, including recital 30. The links you provide list examples of what may be personal data. As already mentioned, and also actually stated in your second link, for something to be personal data it must be related to an identified or identifiable person. Their first paragraph summarises it well (the definition is of course the one in the GDPR): "Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data." So if you have IP addresses and nothing else, you most likely do not have personal data. But if you have IP addresses of identified individuals (e.g. logged users personally identified) you most likely have personal data. This is in line with an ECJ ruling from 2016 and the GDPR have not changed that. A problem is that people make shortcuts so "IP addresses can be personal data" becomes "IP addresses are personal data".
- eivarv 6y agoSorry, but I still don't think you're right. In fact, your understanding doesn't sound like anything I've heard from anyone else. The link doesn't give examples of what can be, but what is personal data. "Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data." This says something about the data, and how it relates to a person in itself – not what practical ways you have in a certain context, limited only to other information you have immediately available in that same context. It's about whether the individual is identifiable – the ICO says [0]: "You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual." Otherwise, this next part wouldn't make sense: "Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR." It isn't an issue of whether you're able to identify the person given only the information you have available – but whether the candidate can be theoretically identified. [0]: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/what-is-personal-data/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- mytailorisrich 6y agoWell, I'm just describing what the GDPR and previous ECJ rulings say. The GDPR do not state in absolute terms that IP addresses are personal data. Another problem is that on these issues a lot of the material available uses the shortcut I described and/or is plain wrong. Then they all copy each other and a consensus emerges but it is based on an incorrect starting point. I would also disagree with you when you say that your links list examples of what are absolutely personal data. Recital 30 uses "may be identified", because indeed that may or may not be the case depending on the context. The article from the Commission states the definition very clearly and only then lists examples. You cannot consider that list without reading the definition first. The definition of personal data is that they must be linked to a identified of identifiable. That's the key. You always need to ask yourself if that's the case. "This says something about the data, and how it relates to a person in itself – not what practical ways you have in a certain context, limited only to other information you have immediately available in that same context. It's about whether the individual is identifiable" Whether an individual is identifiable depend on the context, and therefore many pieces of information are personal data only depending on the context and not in absolute terms. Again, the link to the ICO you provide, and quote, explains this, as you say it is about whether the individual is identifiable (and the ECJ ruling below also addresses this). You'll also note that they are careful and refrain from stating in absolute terms that IP addresses identify individuals and are personal data: "What identifies an individual could be as simple as a name or a number or could include other identifiers such as an IP address or a cookie identifier, or other factors. If it is possible to identify an individual directly from the information you are processing, then that information may be personal data. If you cannot directly identify an individual from that information, then you need to consider whether the individual is still identifiable. You should take into account the information you are processing together with all the means reasonably likely to be used by either you or any other person to identify that individual." As said, this is in line with the ECJ ruling I mentioned [1]. If you are a normal website operator you have no way of identifying people from logged IP addresses unless these relate to your users (if you identify them personally) and you have no legal means to get that information. In this context IP addresses are unlikely to be personal data, but in the context of identified users then IP addresses are likely to be personal data. [1] https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases https://www.whitecase.com/publications/alert/court-confirms-...