But do they store individual IP+UA hashes, or do they mush them together in a bloom filter or a HyperLogLog data structure?
In the first case, it could be argued they still store personally identifiable information (for a limited time, but still). In the second case I think it would be harder to argue the probabilistic data structure with lots of hashes mushed together still constitute personally identifiable information.
> One of the points of the article is that this is non compliant, since you need to transmit the IP+UA to do this calculation to begin with.
IP + UA gets transmitted to the first-party server already. They already have it. The question becomes – is it OK to anonymize this PII we already received for one purpose (serving the web page), to use it for another purpose also (counting unique visitors).