Hacker News new | ask | show | jobs
by Dayshine 2026 days ago
The key caveat here is:

Unless it's necessary. The legitimate interests basis of the GDPR allows you to make a balanced decision of your business requirements against user privacy expectations.

2 comments

yes, and you have to line out how the processing is necessary for providing the service, there has to be no less-intrusive method of achieving the desired result and be ready to prove it.

hint, user-level analytics rarely is. And in this specific example, repurposing logs kept for one purpose(ex, security/auditing) to user analytics is definitely not something you can just do

An example that's explicitly called out as allowed is using logs for security purposes.