And that’s where you’re wrong. Logically? Yes. In GDPR scope? They are personal data.
Guys debating with you is a blast but if you keep downvoting all correct information because it doesn’t match your gut feelings you’ll just become even more of a circlejerk of what you already have here.
You are being downvoted because you are factually incorrect. IP addresses are only personal data if you can identify a natural person from them. You can't do so unless you've linked them to other information. Thus, by themselves IP addresses are not personal information.
> 1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Keyword indirectly. There’s plenty literature regarding ip and gdpr.
“The conclusion is that the GDPR does consider it as such. The logic behind this decision is relatively simple. The internet service provider (ISP) has a record of the temporary dynamic IP address and knows to whom it has been assigned. A website provider has a record of the web pages accessed by a dynamic IP address (but no other data that would lead to the identification of the person). If the two pieces information would be combined, the website provider could find the identity of the person behind a certain dynamic IP address.”
Why would the "website provider" ever be given access to the dynamic IP assignments of an ISP? This information will normally only be given out by court order and/or police request, at least in my native Sweden.
Doesn’t matter. This is what the eu justice court said when it was challenged in court: going from ip to identity is one simple legal request away so it is personal identifyable data. End of the story.
In particular, if the website operator cannot legally access third party information that could be used to identify an IP address owner, or if access to such third party information is “practically impossible”, then the IP address is not personal data from that operator’s perspective.
> 1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Etc. That’s what the european justice court said last time it was called to determine whether ip were personal information or not. What you gonna do now, downvote the proceedings?
> an internet service provider ("ISP") has a record of the temporary "dynamic IP address" assigned to a particular user's device (potentially identifiable data); and
Here they're not talking about "IP addresses", they're talking about "IP addresses assigned to particular users".
> In answering the BGH’s first question, the ECJ confirmed that dynamic IP addresses are considered personal data within the meaning of the Directive in circumstances where the data collector (e.g., a website operator) is likely or reasonably able to obtain information from a third party that would allow it to identify the user.
This clearly says that an IP address by itself is not personal information. It only becomes personal information when you can identify a natural person - when you link it with other data.
it clearly states 'legal means' to identify the user. a subpoena is a perfectly reasonable and legal way to disclose an identity from an ip and doesn't require access to any other personal data, merely that such a link from ip to identity exists. the link is the "third party information to identify the user". it's not that you correlate an ip with a cookie or other technical means. you have to get out of the engineering mindset.
I don't see the link between your comment and GDPR.
I think what GP is trying to do is to post their IP address in a comment, which is personal information under GDPR.
No it isn't. IP addresses are not personal data unless you link it to a natural person.
And that’s where you’re wrong. Logically? Yes. In GDPR scope? They are personal data.
Guys debating with you is a blast but if you keep downvoting all correct information because it doesn’t match your gut feelings you’ll just become even more of a circlejerk of what you already have here.
> correct information
You are being downvoted because you are factually incorrect. IP addresses are only personal data if you can identify a natural person from them. You can't do so unless you've linked them to other information. Thus, by themselves IP addresses are not personal information.
Article 4: http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
> 1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
So then all he needed to do is write his name in addition to his IP address in the comment?
> directly or indirectly
Keyword indirectly. There’s plenty literature regarding ip and gdpr.
“The conclusion is that the GDPR does consider it as such. The logic behind this decision is relatively simple. The internet service provider (ISP) has a record of the temporary dynamic IP address and knows to whom it has been assigned. A website provider has a record of the web pages accessed by a dynamic IP address (but no other data that would lead to the identification of the person). If the two pieces information would be combined, the website provider could find the identity of the person behind a certain dynamic IP address.”
https://eugdprcompliant.com/personal-data/
And many others up and including the gdpr preamble
Please stop confusing the readers on the matter.
https://www.jdsupra.com/legalnews/ecj-confirms-dynamic-ip-ad...
Why would the "website provider" ever be given access to the dynamic IP assignments of an ISP? This information will normally only be given out by court order and/or police request, at least in my native Sweden.
Doesn’t matter. This is what the eu justice court said when it was challenged in court: going from ip to identity is one simple legal request away so it is personal identifyable data. End of the story.
Your second link above ( https://www.jdsupra.com/legalnews/ecj-confirms-dynamic-ip-ad... ):
In particular, if the website operator cannot legally access third party information that could be used to identify an IP address owner, or if access to such third party information is “practically impossible”, then the IP address is not personal data from that operator’s perspective.
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
There ya go. You sucker can keep downvoting facts as you wish, reality won’t care.
that's personal data for which hacker news doesn't have a consent form. even if I don't ask a deletion, that's a huge liability for the site owner.
it's not like down voting these post changes the GDPR wording and definitions guys.
You volunteered that information (without being asked, to boot), so it was obviously not taken without your consent.
There’s nothing in gdpr about data being given up voluntarily
How do you know that is his IP address, or someone else's IP address? Under GDPR it doesn't matter who's they are.
Here is another piece of GDPR PII:
9-5 Allée des 4 Vents 69160 Tassin-la-Demi-Lune, France
Random address I pulled from google maps of someone's house.
It's not personal data until it's linked to a natural person.
Nope ip are personal data by themselves
No they aren't. They're only personal data if they can be linked to a natural person.
Who is 147.67.135.33?
Article 4:
http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
> 1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Keyword: indirect
https://privacylawblog.fieldfisher.com/2016/can-a-dynamic-ip...
https://www.jdsupra.com/legalnews/ecj-confirms-dynamic-ip-ad...
Etc. That’s what the european justice court said last time it was called to determine whether ip were personal information or not. What you gonna do now, downvote the proceedings?
From the articles that you provided:
> an internet service provider ("ISP") has a record of the temporary "dynamic IP address" assigned to a particular user's device (potentially identifiable data); and
Here they're not talking about "IP addresses", they're talking about "IP addresses assigned to particular users".
> In answering the BGH’s first question, the ECJ confirmed that dynamic IP addresses are considered personal data within the meaning of the Directive in circumstances where the data collector (e.g., a website operator) is likely or reasonably able to obtain information from a third party that would allow it to identify the user.
This clearly says that an IP address by itself is not personal information. It only becomes personal information when you can identify a natural person - when you link it with other data.
> when you link it with other data.
> reasonably able
it clearly states 'legal means' to identify the user. a subpoena is a perfectly reasonable and legal way to disclose an identity from an ip and doesn't require access to any other personal data, merely that such a link from ip to identity exists. the link is the "third party information to identify the user". it's not that you correlate an ip with a cookie or other technical means. you have to get out of the engineering mindset.