4 ms·
> Are you making this more complicated than it needs to be? I'm not sure. I guess if one trusts the default logging settings on the server software to be comp
by throwhauser 5y ago
> Are you making this more complicated than it needs to be?
I'm not sure. I guess if one trusts the default logging settings on the server software to be compliant, and only uses static HTML, maybe that's adequate? But as soon as any third-party code or data provided by some other server gets involved, it's hard to know what might be logged elsewhere as a result of visiting your site.
I mean, would an old-fashioned web visitor counter be compliant? It's tracking something in order to provide that number.
- jrochkind1 5y agoYou tell us you have no idea what third-party code you add might be tracking from users. And say this is a reason why you/they should be allowed to do it? (With "it" being... anything the third-party sites want to at all?)
- corobo 5y agoYou can +1 a database `views` column without storing anything at all about the user. If you’re just doing that you’re good to go
- erulabs 5y agoI mean, most "unique view counters" store the users IP address, so that would be right out. I'm fairly sure even being aware of what complying with a complex legal documents implies constitutes enough of a complication that it's worth mentioning. It is a complication, but I believe it's worded so that small companies and individuals are immune from its consequences.
- deleted 5y ago[deleted]
- martin_a 5y agoYou could always hash the IP on the client side before sending it to your counter. That way you have no information which you can backtrack to a specific IP and therefore a person.
- BenjiWiebe 5y agoExcept there's so few IPs (v4) you could just bruteforce it in not too much time.
- WesolyKubeczek 5y agoThere are different kinds of hashes. You can, for example, assign numbers to your incoming IPs. The first one to come in gets 1, the second gets 2, and so on. Numbers zero out at midnight, correlation between them and real IPs are at the load balancer. Good luck bruteforcing these.
- WesolyKubeczek 5y agoAs long as you can describe the full extent to which the collected IP addresses are being used and which data they are being correlated with, and use a language comprehensible without requiring a legal degree, you can very easily be compliant. Once you involve an undisclosed number of "trusted partners" and start using weasel words to describe what you're using the data for and who you're giving them to, not so much. That said, an IP address is a shitty device to detect unique visitors. Session cookies, as long as you aren't trying to correlate them to usage patterns and such, are more reliable (you can tell that this is the same phone jumping networks, or you can tell apart users coming from behind multiple layers of NAT) and anonymous.