Earlier quoted context omitted.
No, people were correctly answering the specific question: is an IP address on its own personal data? (No, it can't be used to identify a natural person). THe problem is that it's a stupid question. No-one has just IP addresses, they have a mix of data. If you can combine the IP address with anything else to identify a natural person it becomes personal data.
And you’re wrong Ip are personal data https://ec.europa.eu/info/law/law-topic/data-protection/refo... Without conditions. Even hashing them doesn’t make them ‘irreversibly anonimized’ because the ip space is too small for hashing to be irreversible. A rainbow table can be built with all ips and use to deanonimize the ip.
GDPR: Don't Panic
721–730 of 833 posts
Re: GDPR: Don't Panic
#722Earlier quoted context omitted.
> How do you ask user for a permission Why do you think permission is required?
Because that is personal information that is being stored and processed.
Have you even read the legal text you are complaining about?
Re: GDPR: Don't Panic
#723Where is the form on this site that claims to be GDPR compliant to get my IP removed from the server logs?
Keep reading the rest of that paragraph: > Well, this website is fully compliant with the law, so at least in this particular case it seems to work. Why? Because I don’t store any information about you. That’s a conscious choice on my part which I made long before the GDPR was even talked about in public. But if your situation is more complex then you too can be compliant, or at least - and this is key - you could tr…
Re: GDPR: Don't Panic
#724Earlier quoted context omitted.
> How do you ask user for a permission Why do you think permission is required?
Because that is personal information that is being stored and processed.
https://gdpr-info.eu/art-6-gdpr/
> Processing shall be lawful only if and to the extent that at least one of the following applies:
Consent is one:
> the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
Here are all the others (see especially the last one):
> processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
> processing is necessary for compliance with a legal obligation to which the controller is subject;
> processing is necessary in order to protect the vital interests of the data subject or of another natural person;
> processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
> processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Re: GDPR: Don't Panic
#725Earlier quoted context omitted.
> That’s not true, and for many companies this is just a simple business decision. But likely based on incorrect advice. You haven't said why you think your company isn't compliant with GDPR, and it's possible your company is compliant with GDPR, or would require only minor tweaks to privacy policies to make it compliant.
Sounds like he analyzed if very closely, so probably not base on incorrect advice. And I’m guessing he can’t share too much about why since he has said its based on architectural decisions, which might reveal business secrets. The biggest reason I don’t like complying with GDPR is the IP address situation- I’m going to continue to track them and I’m not going delete them because somebody requested.
Why do you think you need to delete them when requested to do so? Can you point me to the bit of the regulation that makes you think that's a requirement?
Here's the Right to Erasure: https://gdpr-info.eu/art-17-gdpr/
Which bit do you think applies?
Re: GDPR: Don't Panic
#726Earlier quoted context omitted.
thanks, you’ve pointed out a great signal that now exists. don’t do business with companies that choose to pull out of the eu market rather than comply with gdpr. these are companies that have made an explicit decision that user data privacy is a burden not to be cared about. my company OTOH is choosing to apply gdpr principles globally.
There is a difference between complying with GPDR and caring about privacy. I completely and utterly care about privacy, but things like not tracking IP address and allowing people to request removing them are a bridge to far. I can’t comply with that. I treat my customers important PII (names, addresses, etc) very delicately. But the cost of complying GPDR is too must.
and
> allowing people to request removing them are a bridge to far.
Are dissonant. You will have to pick the one or the other but you can't both care about privacy and not allow people to request removal of their data. That should be fairly obvious.
Re: GDPR: Don't Panic
#727Earlier quoted context omitted.
> How long is necessary? As long as is needed for the stated purpose. If you're doing IP-based rate limiting with a 1 hour window, it probably doesn't need to still be in your systems >12 hours from now. If you're doing longer term IP reputation or something, keeping it around longer can probably be justified. > What does limited mean? The same. Long enough to serve its purpose, and no longer (without justifiable exc…
That is silly. IP addresses should not be covered. I should be able to keep IPs for years. They change often anyway. IP addresses being covered is one of my big issues with GDPR.
Re: GDPR: Don't Panic
#728Earlier quoted context omitted.
Same here. EU makes up such a small amount of or customer base, and EU customers spend far less money with us. Which is generally true in most industries, US consumers spend far more than consumers anywhere else in the world. If we ever choose to enter the EU again, it will be a careful and deliberate choice, and will likely only ever happen if our growth slows in other regions.
In most industries, US consumers spend far more than consumers anywhere else in the world. Not any more. China's citizens spend twice as much on international tourism as US citizens do. The EU has 508 million people. The US has 325 million.
Re: GDPR: Don't Panic
#729Earlier quoted context omitted.
> How long is necessary? As long as is needed for the stated purpose. If you're doing IP-based rate limiting with a 1 hour window, it probably doesn't need to still be in your systems >12 hours from now. If you're doing longer term IP reputation or something, keeping it around longer can probably be justified. > What does limited mean? The same. Long enough to serve its purpose, and no longer (without justifiable exc…
That is silly. IP addresses should not be covered. I should be able to keep IPs for years. They change often anyway. IP addresses being covered is one of my big issues with GDPR.
"they change often" is arguably a good reason for not keeping them. What advantage do you get from knowing that 10 years ago $IP was sending you spam if it's been though 20 different re-allocations and tens of thousands of 'actual owners' since then?
Imagine if google or cloudflare were logging every since query to their public DNS and correlating it with other access logs or google analytics or whatever. They'd be able to relatively trivially deanonymise huge numbers of actual people's identities and browsing history (beyond what they can obtain already).
Re: GDPR: Don't Panic
#730Earlier quoted context omitted.
> If a completely foreign entity that offers a Spanish or French translation of its service could potentially be covered by GDPR, even if they're not marketing to EU markets specifically. No, the GDPR is clear that it is applicable if you are offering goods or services to Europeans. The fact you are speaking French in Quebec isn't relevant. > Or what if you fly to speak at a conference in Europe – is that "marketing"…
> the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertaine…
You really can, it says that it may make it apparent.
Does your use of English make it apparent that you are intent on selling to the UK? No. Italian, might I suppose. French wouldn't if you were based in Canada.