Earlier quoted context omitted.
GDPR does not regulate “sharing,” it regulates any use of personal data. IP address is considered personal data, so you can’t avoid GDPR compliance if you are running a website at all (since you must process IP addresses in order to serve a website).
I'm using simplified language here, not writing a legal document. The first use was also supposed to be "storing/sharing", but it's processing in practice. But here you go: > GDPR does not regulate “sharing,” 13.1.e requires at least the notification of the recipients of the data. With the requirement about the purpose of use, it effectively regulates sharing. > since you must process IP addresses in order to serve a…
The irony here is that the people who think they’re standing up for GDPR are actually the ones not taking it seriously, while the people who take it seriously are the ones who know what a pain it is to comply with.