4 ms·
It really isn't that easy. Something like an IP address is considered personally identifiable information, and most web servers and frameworks log that by defau
by speleding 6y ago
It really isn't that easy. Something like an IP address is considered personally identifiable information, and most web servers and frameworks log that by default. If you really want to comply it takes quite a bit of effort you are not accidentally logging IP addresses somewhere. You can argue you need that info for the operation of your site, but it's been established that you would still need to ask permission in that case, did you do that?
Of course, they are unlikely to come after a startup for an infringement like that, but the point is that they could if they wanted to.
- skinkestek 6y agoSpeculation here, but informed speculation: I highly doubt you as a non shady actor will be punished because of your server logs as such. Start selling or otherwise sharing them with ad companies, directly or indirectly and you deserve and should expect a GDPR fine as soon as they can if you are in a jurisdiction where GDPR applies. Same if you involuntary leak data because of gross negligence: passwords in cleartext, unnecessary data collected and stored and later leaked etc etc In many cases I understand authorities will even contact companies first and try to guide them toward a compliant solution first instead of fining tjem right away. That said I wish there were some clarifications given wrt to server logs and IP addresses; running without is in many cases gross negligence in itself. Basic logging is first year defense against black arts curriculum.
- anang 6y agoI don’t think the only factor considered is whether or not something is PII, rather even the intent is considered. If you were storing IP addresses to track and market to users, you need consent. If you’re using them for logging and security purposes, I think that falls under legitimate interest.
- speleding 6y agoJust Google "IP addresses GDPR" and you will see several different conclusions. I actually looked at the site of the enforcement authority in my country and they say you can only store the first 3 bytes of an IP address. But enforcement authorities in other countries may claim differently. My point is: it's really not that easy. It should be easy to get clear guidance on something straightforward like this, and not have to resort to Stack overflow answers.
- Silhouette 6y agoYou can argue you need that info for the operation of your site, but it's been established that you would still need to ask permission in that case, did you do that? Where and how was that established? There are obvious operational and security reasons why the operator of a website might reasonably log access information, and there are lawful bases for processing data under the GDPR other than having the subject's explicit consent.