a hash of an ip address could still be 'personal data' under the eyes of gdpr.
a hash of an ip address could still be 'personal data' under the eyes of gdpr.
We did something similar for a project, which got approved by the relevant data protection officer: hash(IP + daily secret) as an identifier in the logs. This will be used to count unique visitors, the wraparound at 24:00:00 didn't matter to us. The daily secret is just a random number that our one (small setup) application server generates each day. It is never written out to disk or database, so an appserver restart also recreates that secret, it is strictly kept in RAM. That way, we could argue that, barring extreme measures like attaching a debugger to get the secret, we technically prevented deanonymisation.
But that was just a small-scale project, has never been tested in court and the usual YMMV, IANAL, ...
Edit: I think some webservers can be configured to do something similar
GDPR does aggressively define what can and cannot be done. As far as I know, I'm adhering to their definitions and guidelines. I will consult with a lawyer to confirm before I make claims about GDPR or other laws.
My goal is to make the best product possible given the constraints set. I believe there is middle ground between user privacy and analytics.