Earlier quoted context omitted.
> A lot of the indieweb sites don't bother collecting information about their users so they don't need to show information pop-ups nor worry about GDPR. Not true. I've spent far too much time with expensive lawyers going through the painful details of GDPR compliance and edge cases. If you keep logs at all, anywhere, then technically you could be at risk of crossing the GDPR. Don't assume that you're free and clear b…
If you keep logs forever, yes you'll be in trouble (though probably much less than plastering your website with analytics or ads). Keep logs for a reasonable amount of time (90 days) and you'll be fine. Well, given the current state of GDPR enforcement, you'll be fine whatever you do. But lawyers are going to lawyer and consent management platforms will be delighted to scare you into buying their "solution", even if…
The intent for keeping IP addresses in logs also matters. To give two examples: if you're keeping logs for legal reasons, then it is perfectly fine. If you're keeping for anti-fraud reasons, this is also fine and can be considered "legitimate interest" (as long as the amount of time for storage is reasonable, as you said). If you intend to use this data for other reasons, then you need consent before doing so.