4 ms·
I think access logs as generated by most web servers require a GDPR notice to be compliant, as IP addresses are considered personal information.
by heftig 4y ago
I think access logs as generated by most web servers require a GDPR notice to be compliant, as IP addresses are considered personal information.
- ghusto 4y agoNot sure, but I don't think so. I think it's only if that site itself can link the IP to a name / user. For example, storing all the real world addresses in the world doesn't require a GDPR notice, but they're all related to people.
- Jon_Lowtek 4y agoIP addresses match the definition in GDPR article 4 point 1: they are "an identification number, location data, an online identifier". Well the second one has to be stretched a bit, so an address matches location data, but the other two fit quite well.
- ghusto 4y agoIf those are the only criteria, then I think it doesn't fit. When I still live in the UK 6 years ago, IP addresses were rarely fixed, and changed everytime you connected. In fact, people paid extra to get a fixed IP. I guess it's a bit of a grey area though, since sometimes it fits, sometimes it doesn't.
- Jon_Lowtek 4y agono those are not the only criteria, see gdpr.eu/article-4-definitions