Hacker News new | ask | show | jobs
by BjoernKW 1172 days ago
> If you have a reason, and tell your users, there’s nothing wrong with it.

That's still for the courts to decide. Specifically, the German federal court for example didn't define what constitutes a legitimate reason for storing IP addresses.

This is precisely the problem with GPDR: While maybe well-intentioned, that regulation has been kept intentionally vague, which has local authorities interpret the rules how they see fit (or how it suits their purpose), since there's no clearly defined ruleset to depend upon.

> "for security or other purposes"

"other purposes" is about as vague as it gets. According to GDPR, a legitimate interest has to be specific and the specific reason that constitutes such an interest has to be communicated to the user.

This is not surprising at all. The EU itself is hilariously non-compliant with GDPR. After all, why would they comply with GDPR? Public authorities are largely exempt from GDPR anyway.