Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IP address alone on an anonymous web access log need not be. Start combining it with persistent cookies or a logged in user etc and it clearly becomes personal data as it is then enough to identify someone.

The clause in the regulation is quite clearly worded:

"Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them."



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: