Hacker News new | ask | show | jobs
by lokedhs 3050 days ago
The GDPR does not forbid you to do those things.

It does require you to treat the information as PII, which is going to give you some hassles, but you are not banned from recording it.

1 comments

I'm banned from recording it immutably, which is the only proper way to record a log (it should be impossible to alter a log after it's written).

If I want to record that a particular address accessed my system forever, that is my right.

Interestingly, the GDPR exempts records required for legal compliance. So it's okay to hold onto data for the law's purposes, but not my own? That's a bit one-sided.