3 ms·
IANAL, but this is not entirely correct. For example, if you have server logs, that's processing personal information, most likely under GDPR Art. 6 lit 1f (leg
by janosd 3y ago
IANAL, but this is not entirely correct. For example, if you have server logs, that's processing personal information, most likely under GDPR Art. 6 lit 1f (legitimate interest). Under Art 13 the user must be informed of this. Because of the information requirement the Do-Not-Track is not enough unless you really, truly do not track any PII (which includes the IP address).
Equally, this is incorrect:
> You may not collect personal information without consent.
There are a whole host of reasons listed in Art. 6 when you do not need consent.
- happymellon 3y agoI was answering in the context of the statement that the EU made this cookie banner mess and that the do not track header died because of the GDPR. I didn't feel that logs would be relevant in this case because you would log that the Do Not Track header was present. As a distilled version of the GDPR I still feel it hits the point.
- illiarian 3y ago> that the EU made this cookie banner mess It didn't. Companies not willing to comply with GDPR did. As they didn't want to comply with Do Not Track header and used it for fingerprinting.
- happymellon 3y agoExactly this.
- janosd 3y agoDNT died the moment Microsoft decided to enable it by default in IE10. That was more than half a decade before the GDPR.