GDPR does not allow you to store dark/light mode inside local storage
github.com
github.com
Unfortunately there is no session-cookie equivalent for the `Storage` API. `sessionStorage` doesn't carry over to other tabs, and `localStorage` is persistent without the option to set an expiry date.
The OP seems to be conflating the GDPR with §25(1) of the German Telemedia act, and it does indeed have a prohibition against using local storage. But it also says that local storage is allowed if it "is absolutely necessary so that the provider of a telemedia service can provide a telemedia service expressly requested by the user." (machine translated)
So it's not the GDPR that's at issue, it's a particular German law, and that law appears to have a carve-out that specifically applies to the feature under discussion. Dark mode is a service that's (presumably) expressly requested by the user.
Contact your own lawyer if you're concerned, but this seems like unnecessary hysteria to me.
So IMHO, and IANAL, this does not require consent and should simply be explained in your privacy/cookie policy.
Lastly, depending on the implementation this piece of data may very well never leave the user's machine and thus may not even be known by the server.
However, I agree to your second point, that asking the user's browser to store the information, and then have the browser make decisions based on that without anything being shared back probably does not violate GDPR as it wouldn't count as 'processing'.
It would seem (although, without a deep dive into the codebase, I can't be 100% sure) that the tool just adds a class to the body: https://github.com/themesberg/flowbite-react/blob/765fedb3c9...
If this is the case, I think it unlikely that this would be found to be a GDPR violation as Flowbite (or the company which has deployed Flowbite) would not normally be able to detect this preference.
It would be different if for example the preference caused a different stylesheet to be downloaded, which could then be combined with server logs, but overall, it seems as though all of the processing of the data (whether you consider it personal or not) is done entirely on the user's computer, and there would be no processing of any data by the company which has deployed Flowbite, therefore it would not open up any GDPR liability.
Once again though, IANAL.
So in itself the functionality and storage of necessary flag falls outside of the GDPR.
Now, if for instance the flag is stored in the identified user's account then it becomes personal data but I think consent still isn't strictly required on the basis of legitimate interest (and frankly this is only a freaking flag for dark mode so about zero impact on privacy or anything else).
Even if it would count as legitimate interest (which I don’t think it would), you would still need to offer opt out, right to erasure, and an explanation of what you’re doing with the data.
There is no need for any of that. This is only a flag for dark mode, it is necessary for the functionality, and it has no impact on privacy. No need for "GDPR hysteria".
https://commission.europa.eu/law/law-topic/data-protection/r... clearly calls out IP addresses as the 6th bullet point underneath the heading 'Examples of Personal Data'.
Article 4 paragraph 1 says personal data can be any data which could be linked to an identifiable person. The 'indirectly' word does seem to imply that it does not necessarily have to be the processor or controller who can link that data to a person. Quote from the GDPR itself:
> 'personal data' means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier
This has been tested in courts. At least in Germany, it has been ruled that an IP address in and of itself is personal data because it can be associated with other records to determine who a user is (even though the 'online media services provider'—the server operator—does not immediately have access to this information).
https://curia.europa.eu/juris/document/document.jsf;jsession...
> The fact that the additional data necessary to identify the user of a website are held not by the online media services provider, but by that user’s internet service provider does not appear to be such as to exclude that dynamic IP addresses registered by the online media services provider constitute personal data within the meaning of Article 2(a) of Directive 95/46.
It is important to note though, that it is not unlawful to process personal data provided you have a privacy policy, etc. Maintaining server logs almost certainly is covered by legitimate interests, even though the IP addresses are personal data.
However, it is not enough just to say 'it's a minor preference, we can hand wave this away'. You must absolutely make sure that you are meeting your obligations under the GDPR, including having proper privacy impact assessments, technical and organisational controls on who can access this data, etc.
For this reason, the way it is currently implemented (end user does all 'processing' on their own computer) is best. However it's important to consider that even this may open up an organisation to some level of risk by inadvertently creating sets of circumstances which lead to the preference being detectable.
For example, if you have an image which is set to 'display:none' when dark mode is enabled, then it would be possible to infer, based on the server logs, that because the user loaded the page but their browser did not load the image, they are likely using dark mode. Obviously this isn't true for all browsers, behaviour does vary, but still.
The vast majority of GDPR hysteria is based on people not understanding that the majority of GDPR response should not be 'WE CAN'T DO XYZ OR WE GET A HUGE FINE', and instead 'we need to do a bit of paperwork to be allowed to do xyz'. For example, a dark mode toggle privacy impact assessment could include something along the lines of 'users have to actively choose this option', 'dark mode may be preferred by users with vision conditions, but we would not be able to interpret our data to determine which users (if any) have vision conditions', etc., and would probably be less than a hundred words of actual work (more with boilerplate, etc.).
But GDPR complacency is also a problem. Companies can (and do) get fined all the time for doing things they thought weren't a big deal. You can check the fines here: https://www.enforcementtracker.com
The examples of personal data list what can be personal data. It does not mean that each item in the list is personal data in isolation.
The case law is that an IP address is personal data if it is linked to an identified or identifiable person, which is not more than what the GDPR says. The IP address was held along with other data by an entity which also had access to further data, which meant that the person was identifiable. All of these circumstances taken together meant that, in that specific case, the IP address was personal data:
"48 Thus, it appears that the online media services provider has the means which may likely reasonably be used in order to identify the data subject, with the assistance of other persons, namely the competent authority and the internet service provider, on the basis of the IP addresses stored.
"49 Having regard to all the foregoing considerations, the answer to the first question is that Article 2(a) of Directive 95/46 must be interpreted as meaning that a dynamic IP address registered by an online media services provider when a person accesses a website that the provider makes accessible to the public constitutes personal data within the meaning of that provision, in relation to that provider, where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person."
IP address is personal data for the provider because/if they have access to information to identify the person (key above is 'where the latter has the legal means' to access the necessary additional data). But an IP address isn't personal data in itself, only when additional data are available that make the person identifiable.
So your claim that "At least in Germany, it has been ruled that an IP address in and of itself is personal data" is not correct and not what this case law says.
I don't have the legal means, or any means really, to ask an ISP or whoever else for additional data on the IP addresses of random, unknown visitors to my website, therefore those IP addresses are not personal data to me as they do not related to any identifiable (by me) individuals.
Unfortunately, as you show, there is indeed a lot of confusion, misinterpretation, and misunderstanding out there.
> Although the referring court states in its order for reference that German law does not allow the internet service provider to transmit directly to the online media services provider the additional data necessary for the identification of the data subject, it seems however, subject to verifications to be made in that regard by the referring court that, in particular, in the event of cyber attacks legal channels exist so that the online media services provider is able to contact the competent authority, so that the latter can take the steps necessary to obtain that information from the internet service provider and to bring criminal proceedings.
But the wider point remains that an IP address isn't generally personal data in itself.
Certainly this is quite irrelevant to the point here, which is a simple flag for dark mode. If that has to create and endless and tedious debate then the GDPR are not fit for purpose, but I maintain that it is fine to store it without explicit consent because it is not personal data in itself and, in any case, there is a legitimate interest to do so.
Anyway, there’s no requirement for any piece of data to be independently identifying in order for it to come under the scope of personal data per GDPR.
A piece of information is personal data if it can be linked to an individual. This applies whether the linking can be done in isolation or only with other pieces of information, and whether the link is explicit or inferred, direct or indirect, and whether the controller/processor has immediate access to the other pieces of data or not.
Even if you rely on legitimate interest as a basis for processing personal data (and you might do, depending on your actual interests), you still have to do your paperwork, complete the PIAs and balancing tests.
Indeed, the case law explicitly says that an IP address is personal data IF the controller has or has a way to get additional data to make the person identifiable (which is what the GDPR already explicitly say). No-one is identifiable with an IP address only, there must be additional data, which I need to possess or have access to, even if only in specific cases (which is the key point of this German case law).
Important addendum to the title: without your consent.
That makes sense. Information in your local storage that the website can access can be used to identify and track you.
But, when some fool calls me on phone and tries to sell me something, I can ask them to remove my phone number from their list. And it actually happens, they won't call again. Pre GDPR they were like "yeah sure dude" and just kept calling every month or so.