Earlier quoted context omitted.
Only without consent from the user. Previously it was an ethically grey area to be logging IP addresses anyway. If you are preventing malicious use, then that is allowed as long as you are not using that data outside of the bounds of the user's consent. If, however, a company is storing IP addresses to identify users without their consent and are found to be specifically targeting them without their consent, then tha…
>"Previously it was an ethically grey area to be logging IP addresses anyway." wat. Standard log formats capture IP, and have ~forever. Who claims this is an ethical quandary?
And since the recent European court decision, I suppose it is settled: yes, illegal.