If small companies are called upon compliance with such vehemence, the big ones who know so much of us should be brought up, at least 100x times more.
Yes, and it's worth noting how few data points one needs to identify an individual.
>If small companies are called upon compliance with such vehemence, the big ones who know so much of us should be brought up, at least 100x times more.
Absolutely, no argument from me here.
It is in Europe, despite some regional rulings (Germany?). It is not considered PII in the USA.
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
(o) (1) “Personal information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, the following: (A) Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.
“[I]f a business collects the IP addresses of visitors to its websites but does not link the IP address to any particular consumer or household, and could not reasonably link the IP address with a particular consumer or household, then the IP address would not be ‘personal information.”
Source: https://iapp.org/news/a/are-ip-addresses-personal-informatio...
"However, when the attorney general revised its draft regulations for a second time March 11, the guidance was struck without explanation."
And I think we're missing the main point. How can it be reversed if there are hundreds of possibilites.
I can't presume what Plausible does (have not read their docs in awhile) but they have commented here to provide more specific clarification that address IP usage (TLDR: what they do is fine and compliant)