The GDPR is trying to do a good thing, but it goes too far.
The GDPR is trying to do a good thing, but it goes too far.
By asking for:
* Data Classifications?
* Privacy Impact Assessments?
* Access Controls?
* Breach Escalations?
If your business is collecting and processing data on individuals, you should already have these Security 101 basics in place.
I.e. If you use any sort of machine learning model, such as a neural network, you have to be able explain every decision it makes. Given that there's currently no know method to fully explain the outcome of a neural network decision, GDPR would apparently make it illegal for any EU business to use a neural network in any user facing capacity.
GDPR advocates answer to this seems to be that, while the regulations might read as such, it hasn't actually been tested in court yet and, who knows, maybe whatever judge it eventually comes up with will decide to keep neural networks legal!
So, if you're a company using machine learning in Europe, you just have to wait a few months and keep an eye on court news to determine if you entire strategy is permitted or not. Thank God for the stability and confidence provided to businesses by the single market!
If the GDPR is forcing businesses to abandon dangerous logging practices that they don't really need, it is hardly going too far.
2 is what this regulation is intended to stop: you shouldn't be trading off "it might be useful in the future" for "it can be misused by authorized users, or exfiltrated by hackers".
3 seems reasonable, but does that require a retention policy of more than a couple of hours?
Both Apache and Nginx (and others?) log IP addresses by default. The expected result of this is that storing IP addresses in server logs is widespread, useful for troubleshooting, and entirely normal.
If you make the active decision that you specifically want the IP addresses, great, you can do that. Just have a strategy for keeping that sensitive data secure and getting rid of it at some point.
The real question is what value does storing the IP address even hold?
- You can figure out where in the world your traffic is coming from
- It can be helpful in responding to security incidents
- this can be done and then discard the address
- how so? What does knowing the address months later help? Something like fail2ban and other automated systems, sure, but long term logging?
Other information you can retrieve from IP address is geolocation information such as https://www.ip2location.com
With regards of tracking you with the help of the ISP, if you have someone with those resources, it's not you storing an IP address that's their biggest concern.
Geoinformation can also change daily. Figuring it out afterwards isn't reliable.
I am incredibly excited for the GDPR to make these products too much of a regulatory burden to be worth considering.