The recital also mentions "accidental events that compromise availability, integrity, authenticity,..." That seems to cover debugging for me. No need to ask for consent.
To do certain analytics like page count, you don't need the IP, so that seems ok for me. To track individual customers however, that's something else.
PS: according to GDPR, a hashed IP will be "pseudonimisation", not anonymisation because you can have a key to go back to the original value. True anonymisation removes all info (the IP in this case)
People tend to set up sites and just stash web logs in the beginning. They then learn later what their business needs are and may decide to post process their logs.
You're suggesting a new site pay all of these costs up front to comply with these regulations, you can’t time shift concerns by collecting data and deciding whether you need it later.
Granted, you could argue that this is bad practice anyway, but many startups work exactly like this, maximum logging early, dropping rention later after beta.
If you are not physically hosting in the EU, how many people want to even read the GDPR? A lot of sites don’t even know where their users are coming from until they run analytics.
If you say, use a point-and-click installation of Wordpress on AWS/GCP/Azure, you're going to get IP logs being held. I'm just pointing out that the regulations impose a lot of costs and expose people to huge risks.
I mean, can I be held liable if I use an open source downstream dependency from npm or Maven, and it just so happens to have debug logs that are storing info, and I didn't know about this logging cause I didn't audit every line of code from a downstream dependency?
For large companies, this isn't going to be a problem, but the entire open source ecosystem operates on a system that for the most part, you aren't exposed to legal liability by them, except in cases like patent violations or copyright infringement, but now there's a huge cognitive burden being levied on top by a massively complicated new regulatory framework.
In addition, watch out for logs. By default all web servers log requests with the IP address, and depending on what you do with these logs, the IP are there.