3 ms·
Depends on what the logs contain. If they contain no personal information at all, EU data protection laws do not apply.
by antris 5y ago
Depends on what the logs contain. If they contain no personal information at all, EU data protection laws do not apply.
- martin_a 5y agoIP addresses are considered to be PII so you need to either truncate them before saving or have a deletion routine in place.
- quicksilver03 5y agoIP addresses are PII when they can identify a person, and that's not always the case, e.g. a company network using NAT for outgoing connections so that dozens, if not hundreds of people appear from the same IP address.
- martin_a 5y agoHow are you supposed/able to make that decision on a log level?
- quicksilver03 5y agoThere's no way you can make that decision, which is why the simplest course of action, or the less risky one, is to treat any IP address as it actually conveyed PII, even 192.168.0.1.