Live data from Hacker News

Plausible Analytics Isn't GDPR Compliant

blog.paranoidpenguin.net

71–80 of 80 posts

Re: Plausible Analytics Isn't GDPR Compliant

#71
post #52

Earlier quoted context omitted.

I am curious, how are you going to unanonymise an IP to something that could have 255 combinations (and that's just if you drop that last part on an IPv4). Nevermind that an IP alone is not PII. How can you reverse something that has many possibilties?

>> IP alone is not PII It is in Europe, despite some regional rulings (Germany?). It is not considered PII in the USA.

GDPR is EU law. So the regional rulings are extremely important for deciding what you think you can and can't do.

And I think we're missing the main point. How can it be reversed if there are hundreds of possibilites.

Re: Plausible Analytics Isn't GDPR Compliant

#72
post #63
post #52

Earlier quoted context omitted.

>> IP alone is not PII It is in Europe, despite some regional rulings (Germany?). It is not considered PII in the USA.

IP addresses are also explicitly considered PII by California’s CCPA. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm... (o) (1) “Personal information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the follow…

Just to be that guy. There is a slight difference between Personal Identifying Information and Personal Information.

Re: Plausible Analytics Isn't GDPR Compliant

#73

a.) The term "GDPR Compliant" does not exist. All software can be "GDPR Compliant" and still do fingerprinting it there is consent or necessities (hard to do). What they mean is that you do not need to get consent from your users to use Plausible. b.) They don't store IP addresses. Information they gather are not stored in a way to build user profiles or do fingerprinting. It doesn't look like the articles author too…

I've was implementation lead for several GDPR implementations in Germany. Only on HN would a comment with facts that clarify a subject where a lot of misinformation exists get downvoted.

If you've downvoted that comment you have done the community a disservice.

Re: Plausible Analytics Isn't GDPR Compliant

#74

Earlier quoted context omitted.

It's also probably a legitimate interest to retain data for marketing and analytics purposes, so long as that retention meets the same sort of guidelines. Marketing is explicitly highlighted as one of the applicable uses for legitimate interest.

Have you any specific document or decision in mind ?

Recital 47 (https://gdpr-info.eu/recitals/no-47/) explicitly states:

"The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."

It's also mentioned in Article 21 describing the right to object to processing using legitimate/public interest:

"Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time… etc."

The ICO has some useful guidance on when it is an appropriate basis: https://ico.org.uk/for-organisations/guide-to-data-protectio...

Re: Plausible Analytics Isn't GDPR Compliant

#75
post #17

Plausible Analytics is GDPR compliant - with one possible exception - the IP address which if they dropped the last 3 digits would probably be enough. The blog post conflates general data points with PII. The IP address is considered PII. While other info can be used for fingerprinting, it’s ok to use in some capacity as long as you don’t. For background, I’ve done GDPR implantation a in the past, an a privacy advoca…

I was under the impression that they did not store IP addresses, though I could be incorrect. Their docs suggest as much https://docs.plausible.io/excluding/ "Most web analytics tools do this by excluding certain IP addresses from being counted. However, we do not store the visitors’ IP addresses in our database for privacy reasons"

GDPR doesn't care about storage. Even if you just acquired personal information without processing it, you still had to be GDPR compliant.

In fact, the solution suggested above (only using a truncated IP address) would still require you to acquire and process the IP address and thus be subject to GDPR.

Re: Plausible Analytics Isn't GDPR Compliant

#76
post #64
post #56

Earlier quoted context omitted.

How can an IP address without the last 3 digits possibly ever identify someone? That surface area is just way too large.

By using other information to narrow the pool of possible people.

Aren't the biggest corporations doing the same on orders of magnitude larger datasets? They get away very well with merging data from quite a few acquired companies.

If small companies are called upon compliance with such vehemence, the big ones who know so much of us should be brought up, at least 100x times more.

Re: Plausible Analytics Isn't GDPR Compliant

#77
post #63
post #52

Earlier quoted context omitted.

>> IP alone is not PII It is in Europe, despite some regional rulings (Germany?). It is not considered PII in the USA.

IP addresses are also explicitly considered PII by California’s CCPA. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm... (o) (1) “Personal information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the follow…

That was true once. Longer answer "it depends":

“[I]f a business collects the IP addresses of visitors to its websites but does not link the IP address to any particular consumer or household, and could not reasonably link the IP address with a particular consumer or household, then the IP address would not be ‘personal information.”

Source: https://iapp.org/news/a/are-ip-addresses-personal-informatio...

Re: Plausible Analytics Isn't GDPR Compliant

#78
post #76
post #64

Earlier quoted context omitted.

By using other information to narrow the pool of possible people.

Aren't the biggest corporations doing the same on orders of magnitude larger datasets? They get away very well with merging data from quite a few acquired companies. If small companies are called upon compliance with such vehemence, the big ones who know so much of us should be brought up, at least 100x times more.

> Aren't the biggest corporations doing the same on orders of magnitude larger datasets? They get away very well with merging data from quite a few acquired companies.

Yes, and it's worth noting how few data points one needs to identify an individual.

>If small companies are called upon compliance with such vehemence, the big ones who know so much of us should be brought up, at least 100x times more.

Absolutely, no argument from me here.

Re: Plausible Analytics Isn't GDPR Compliant

#79

Earlier quoted context omitted.

Have you any specific document or decision in mind ?

Recital 47 ( https://gdpr-info.eu/recitals/no-47/ ) explicitly states: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." It's also mentioned in Article 21 describing the right to object to processing using legitimate/public interest: "Where personal data are processed for direct marketing purposes, the data subject shall have the right to object…

One could argue that analytics purpose is not direct marketing purpose. My understanding is that as analytics can be considered as a usual/expected business process, it may use legitimate interests as far as it fulfill requirements (information of the process, the right to opt-out, ...). However, the problem is that analytics may be advanced analytics. Is the retrieval of Adwords parameters from a glcid allowed/expected ? Is the injection of historical behaviour or marketing segment allowed/expected ?

Re: Plausible Analytics Isn't GDPR Compliant

#80
post #77
post #63

Earlier quoted context omitted.

IP addresses are also explicitly considered PII by California’s CCPA. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm... (o) (1) “Personal information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the follow…

That was true once. Longer answer "it depends": “[I]f a business collects the IP addresses of visitors to its websites but does not link the IP address to any particular consumer or household, and could not reasonably link the IP address with a particular consumer or household, then the IP address would not be ‘personal information.” Source: https://iapp.org/news/a/are-ip-addresses-personal-informatio...

You missed the paragraph:

"However, when the attorney general revised its draft regulations for a second time March 11, the guidance was struck without explanation."

Post reply on HN