|
|
|
|
|
by nrjames
3040 days ago
|
|
Standard server logs with IP addresses must be disclosed in a privacy policy but you do not have to seek consent for them because you collect them as part of a business critical need to prevent fraud. See Recital 47, which includes the language: "The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned." https://www.privacy-regulation.eu/en/r47.htm |
|
GDPR blows up a lot of assumptions we make about writing software and managing servers.
https://www.privacy-regulation.eu/en/article-17-right-to-era...