▲ | bilekas 3 days ago | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Are we sure ? I'm not disputing it, but is geo location alone as a data point covered GDPR ? I'll have to look that up, but as someone else said it's only enforced at EU member state level, however there is another central oversight to ensure it's enforced. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | d1sxeyes 3 days ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Not if you have no possible way to identify the person to whom it is related (this includes server logs etc). Theoretically, an event sent to a server with some GPS co-ordinates, with no metadata and no logs stored on the server at all could perhaps be found not to be personally identifiable. This is almost certainly a thought experiment though, the amount of engineering effort required to ensure no logs of any kind could result in deriving the IP address of the user would be high, and they’re probably not doing it (even if they are actually not sending any identifying information directly). You might also find that you have to take special care to avoid creating circumstances that allow inference of personal information. For example, sampling every night at 11pm, you’re very likely to be able to determine an address or approximate location of the subscribers home. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | Fargren 3 days ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Yes. Personal data under GDPR is "any information which are related to an identified or identifiable natural person". If it's data about a specific person, it's personal data, it's a very straightforward definition. Businesses need either informed consent or legitimate interest to store or process it. |