Do a geolookup, you have my approximate location.
Do a Google search for my IP address and you'll have my name.
Do a geolookup, you have my approximate location.
Do a Google search for my IP address and you'll have my name.
IPs specifically are quite likely to reveal some identifying info, and it's obvious how trivial it is to find that info. Even the company itself isn't looking that info up, losing that info could expose their users.
From my reading, you can interpret it that way if "the website operator has a 'legal means' of obtaining access to the information".
Refer to the "What makes a dynamic IP address personal data?" section of TFA.
(N.B.: I am not a lawyer. Ask your doctor if taking legal advice from strangers on the Internet is right for you.)
How does that happen exactly ?
Name is required on the whois record, but even if it could be anonymized, it'd still have the registrar's name. I am my registrar.
Nowhere near "personally identifiable" nor necessarily correct in any way.
> Do a Google search for my IP address and you'll have my name.
That would be highly unusual.
I'm not sure about the other RIRs but ARIN, at least, has (had?) a requirement that any assignment of a /29 or larger must be reported (see "SWIP" [0]).
In other cases, a PTR RR for a single IP address could be enough to personally identify an individual.
Commercial entities doesn't really map to one person. I thought WHOIS would have to be amended to be compatible with GDPR anyway.
I mean, you could create a website dedicated to mapping your current IP to yourself if you really wanted to, but that is hardly relevant.