Because things are quite different when you start digging and trying to implement GDPR as opposed to just reading about it.
Because things are quite different when you start digging and trying to implement GDPR as opposed to just reading about it.
Number Two: If your software's a mess, then unanticipated forced changes are a worse mess.
If it is for fraud-prevention, then that is sufficient reason to keep it unanonymised...
Anonymizing it does not seem to solve anything, since the anonymized version "can be used to build a profile" so "it's PII"...
Just because something it murky, doesn't mean businesses get to ignore it. The entire point is to force companies to actually think about what their data is and decide if they need to store PII. If they do it have implications. Have a reasonable explanation for choices, and are willing to rectify issues pointed out by consumers and/or DPA.
That's exactly why GDPR is a good thing. It prevents anybody from doing statistics and keeping analytics about the users. Want to collect this information in order to profile your users and offer them a better product (ndr. better ads)? Well tough luck. You either anonymize and stop profiling and tracking your users or you close shop in Europe. I don't see how this is a bad thing in any possible way. You say it costs money? I guess then some of the money they made by targeting users and selling their personal data so far can be put to good use.
Just regular analytics and statistics of usage and environment to simply improve the product.
From the Wikipedia article about GDPR [1]
[1]: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
An IP addres, for example, isn't automatically personal data. It might be if you can link it with other information that can be used to identify someone.
Name alone is probably not as many people share names, unless you have an unusual name. Add address and phone number and it will be. IP address on its own is not.
Is "1.8m tall guy in green T-shirt who is head of team X" enough to identify them? If so it's personal data.
Most of this applied to the Data Protection Act too. GDPR adds some items like biometrics
Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
My emphasis.
1) Define "unless you have to". Am I allowed to keep business correspondence with a bad customer? With a prospective sale? With an old customer who may come back some day?
2) Define "data". Is the IP address any user sends to my site in order to simply access it "personal"? Does that mean I can't have logs? How about backups of those logs? Do I need to change the tools I am using that already generate logs? How straightforward is that?
3) Can I have analytics of my visitor base in order to optimize their experience? To understand churn and conversion rate?
5) Can I have statistics in my apps in order to understand and optimize their usage for the users?
6) Keeping data secure and allowing users to see and delete it will simply require other tools. That is not gonna be cheap or straightforward in any way.
Now I am not saying this is impossible. I am just saying that it's expensive and difficult, especially for a small business. NOT straightforward.
No. Something is only personal data if it can be used to identify a natural person.
You can be compliant by either only storing an anonymized IP address (set the last/couple of last to 0) or by not storing the IP logs at all. However, there might be resonable situations where you need the full IP address and the GDPR allows to store it in this case, but only for a specific reason and a limited time, and only if you documented it so the user is aware about the process. Reasons could be fraud protection, consent documentation (mailing list opt-in), error handling and so on ... but not "we don't really need it but store the IP address anyways without informing our users".
See here: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
"Examples of personal data: a name and surname; a home address; an email address such as name.surname@company.com; an identification card number; location data (for example the location data function on a mobile phone); an Internet Protocol (IP) address; a cookie ID; the advertising identifier of your phone; data held by a hospital or doctor, which could be a symbol that uniquely identifies a person."