Earlier quoted context omitted.
Server logs with IP addresses are acceptable to most European privacy regulators if you only use them for a technical purpose such as debugging. And not keep them longer than needed for that. So practically: logs are fine, delete them after a while. If you store the same information in a permanent database and use it for analysis you're in trouble and should have asked permission. The fact that the user uses a privat…
> The fact that the user uses a private window or other means to indicates they don't want to be tracked probably makes this a more clear case. That’s a very confusing statement. My server logs don’t filter incoming log entries based on user agent, and certainly not on whether you’re using a “private window” or not. In addition, the goal of a private/incognito session is to be indistinguishable from regular sessions,…
Especially since "Websites shouldn't be able to tell if you're in incognito mode" has been highlighted in the past as a privacy ask, yes.
People can at least agree "website shouldn't be able to tell if you're in incognito mode" and "website should not track you if you are in incognito mode" are two mutually exclusive features, right?