Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To my understanding of the GDPR, as soon as you track any identifier that makes those data non-anonymous you still need consent for that. It is not about the cookies per se.


There are six legal bases for processing personal data, consent is only one of those.


Would that mean that you need consent for storing IP addresses in logs?


It depends on what you use them for, but I think you would need it documented that you do it and why.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: