Hacker News new | ask | show | jobs
by davorak 2970 days ago
> So once the account info is deleted, that link is broken. This another piece of DP legislation that has been subject to a great deal of FUD since most of the headlines just went with ‘court confirms IP address are PII’ and omitted ‘in some cases’. TBH, this was already pretty explicitly obvious from the legislation defining Personally Identifiable Information (hint: clue’s in the name).

Makes sense.

Given the above still seems like a potential issue to not delete the ip logs.

1) Bob signs up for a service and is logged

2) Bob than asks for his account to be deleted. Account details are deleted, but the ip logs are retained.

3) Bob signs back up for a new account allowing the data processor to make the link from his new account to his ip old logs with the first account.

Weather the data processor can relink the two records with reasonable probability in step 3 depends on the particulars of the circumstance.

I assume cases like the above will be judged, at least in part, based on the data processor following best practices, and operating in good faith(not actively trying to unmask individuals and actively try to prevent unmasking).

Currently I would not let the GDPR stop me from going forward with any web services plans, however my casual reading of GDPR articles on HN and beyond have not made it obvious how cases like the above will be handled.