3 ms·
I don’t think the only factor considered is whether or not something is PII, rather even the intent is considered. If you were storing IP addresses to track an
by anang 6y ago
I don’t think the only factor considered is whether or not something is PII, rather even the intent is considered.
If you were storing IP addresses to track and market to users, you need consent.
If you’re using them for logging and security purposes, I think that falls under legitimate interest.
- speleding 6y agoJust Google "IP addresses GDPR" and you will see several different conclusions. I actually looked at the site of the enforcement authority in my country and they say you can only store the first 3 bytes of an IP address. But enforcement authorities in other countries may claim differently. My point is: it's really not that easy. It should be easy to get clear guidance on something straightforward like this, and not have to resort to Stack overflow answers.