top | item 42280267

(no title)

geewee | 1 year ago

It's unclear to me based on your post, but you do realize that public IPs very much count as personally identifiable information under the GDPR, right?

discuss

order

Avfrosta|1 year ago

Just like Plausible they're hashed with a daily rotating salt on arrival to my servers, forgot to mention that in the post.

jeffhuys|1 year ago

Yes, and choosing to ignore this while operating inside Europe will make you susceptible for hefty fines.

dcanelhas|1 year ago

Is this really the case? It's very uncommon for an IP to resolve to an actual user these days due to widespread use of Carrier-Grade Networks Address Translation (CGNAT).

Assuming you had the public IP of an actual user though, how would you link it to a person without asking the ISP?

BartjeD|1 year ago

According to case law it is personal information; Because in realistic scenario's you can use it in combination with some other data, such as from the browser headers, to identity someone with a high degree of accuracy.

Ofcourse this evolves as the landscape changes. And it isn't always the case. But the comment is accurate.