8 ms·
An IP by itself is not PII. You have to be sure that you or anyone else in your chain can't link an IP to a specific person without explicit consent (and thus
by scoutt 4y ago
An IP by itself is not PII.
You have to be sure that you or anyone else in your chain can't link an IP to a specific person without explicit consent (and thus compliant with the rest of the regulation).
You can have cloudflare giving you IP/location pairs as long as cloudflare doesn't know who that person is.
You can keep your own logs of IP/person. You have to keep it safe, and inform somewhere in a policy that you are doing that. If the logs are kept abroad or cloud, then you need consent (and comply with the rest of the regulation).
It's all made to avoid companies tracking using across boundaries, selling data and having all that PII unwarranted for the next "We take your data and security very seriously" blog post about a leak.
It's easier not to keep any PII around. IPs? you can have as many as you want as long it can't be used to identify a person (without consent).
PS: here is a checklist => https://gdpr.eu/checklist/ https://gdpr.eu/checklist/