What is the right amount of information to share? Most users won't care but others will. I want to simplify rather than complicate. Finding balance is difficult.
Where do you store the salted hash?
I did build my approach around the Internet's backbone to future proof. Banning my approach would fundamentally break the Internet. I've made a note and will read into the precedent. Thank you for the research topic.
That’s simply false. The legal basis for processing an IP address in order to serve an HTTP request in the EU is Art 6 (b):
> processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
This does not give you the right to use that data for any other purpose.
The approach you’re using is called fingerprinting in the industry (relatively naive fingerprinting given it only uses IP address) and it is the ongoing subject of enforcement action in the EU. Nothing about the approach is compliant.
Frankly, if it was this easy to forgo the regulatory impact of the GDPR, every analytics service would do it (many shady ones do).
The salted hash (of the IP address) is used for one purpose: to count unique visits.
For the purposes of compliance with the GDPR, Pathview does associate individual page views with a single real IP address. From the precedent set by the CNIL ruling on Google Analytics in July, the only way for an analytics tool not to process personal data in the form of an IP address is to relay the request via a first-party proxy (and strip the referer).
Your analytics tool cannot accept HTTP requests from the users browser and be compliant with the GDPR without gaining consent. Serving an HTTP request made for the purposes of analytics is processing personal data and there's no legal basis for the processing without consent.
> The fundamental problem that prevents these measures from addressing the issue of access of data by non-European authorities is that of direct contact, via an HTTPS connection, between the individual's terminal and servers managed by Google.
> The resulting requests allow these servers to obtain the IP address of the Internet user as well as a lot of information about his terminal. This information may realistically allow the user to be re-identified and, consequently, to access his or her browsing on all sites using Google Analytics.
> Only solutions allowing to break this contact between the terminal and the server can address this issue. Beyond the case of Google Analytics, this type of solution could also make it possible to reconcile the use of other analytics tools with the GDPR rules on data transfer.
Source: https://www.cnil.fr/en/google-analytics-and-data-transfers-h...
As I've said multiple times, I will be consulting with a lawyer to ensure Pathview is in compliance with relevant privacy laws. You might be a lawyer (who knows), but I am definitely not.
Each hit is stored without personal data but including a salted hash representing the IP. Users are not tracked and are not assigned any type of individual identifier.
The way to make it compliant is to ask permission for using the data. Or doing your analysis without any user identifiers, but that doesn't get you much useful insights.
I do have an idea that might work for this scenario. If I can calculate unique visits differently, I can drop the salted hash from the database too. I'm guessing that should be sufficient to satisfy most privacy conscious users.
Edit: I implemented this approach. It's less accurate but removes the need for any representation of the IP address.
Considering I'm about 2-months in, I'm happy with the progress and general direction.