Shouldn't the cloud be illegal too then? By hosting on AWS/GCP, you are leaking the IP addresses to the cloud providers after all!
Shouldn't the cloud be illegal too then? By hosting on AWS/GCP, you are leaking the IP addresses to the cloud providers after all!
For hosters where the data transmission is a technical requirement, you don't need consent at all, but you need to enter a data processing agreement ("Auftragsdatenverarbeitung" in German) with the hoster and make sure that data transmission and recording is as minimal as possible (e.g. anonymize IP addresses in logs, delete logs after 2 weeks, keep data in EU cloud regions if possible).
I'm still not convinced this is enough. The US "CLOUD Act" can force employees of a company to pull data even when hosted in foreign countries. If an ops engineer technically can give themselves access they can be forced to do so by the US federal government. That is my understanding anyway.