Earlier quoted context omitted.
See GDPR recital 24 ( http://www.privacy-regulation.eu/en/recital-24-GDPR.htm ): [...] In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to…
Thanks for the link. > potential subsequent use of personal data processing techniques Not a lawyer, but doesn't every access log with IPs and urls have the /potential/ to be parsed to aggregate a profile of site usage? Even if you aren't actually doing or intending to do any profiling, the potential still exists. You may well be correct about all this (and I suspect you are). I'm specifically trying to push back aga…
“Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes“
If a company starts collecting IP addresses for DDoS protection purposes, and then figures out that the data could also be used for marketing - that is most certainly in violation with this principle and therefor forbidden.
A “lawful basis” for the marketing purpose will not save you from this principle.
This is also where the public privacy policy/notice plays a role - for the company to be able to prove that the IP addresses where also originally collected for marketing purposes and fair information was given about this purpose at the point of collection.
In terms of GDPR’s territorial scope I guess at the point in time you start to use the DDoS prevention IP logs for profiling you come into GDPR scope. You would also be immediately be in violation of the purpose limitation principle if it is for marketing purposes.