Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The easiest way to avoid having a banner on your site is to... just not have an analytics package on your site.

What if there's back-end only analytics? Does that require a banner?



My understanding; ip adresses are considered personal information. You are allowed to store them in your log for security purposes, without consent (legitimate interest). But if you use that log for analytics, you need consent.


Are you sure about this? Parsing the logs stored for legitimate interest and then aggregating from that data for another purpose without storing PII seems to me like fair game.


You can't process personal data "for legitimate interest" per se. This is the biggest lie the adtech industry keeps telling themselves. The LI exception is that you can process personal data to do X with fewer restrictions, if you have a legitimate interest in X. For example, all companies have a legitimate interest in certain employee data e.g. legal names / tax identification. More complex, if you run an insurance company, you have some legitimate interest in a broad swath of your customer's demographic data.

The case for legitimate interest in parsing logs is extremely weak. There are situations where you could claim it but it still must be with a clear purpose. E.g. a Spanish company considering opening a branch in France might collect IPs to make a heatmap of where its French customers are. But they would not be able to use those IPs generally, to the extent e.g. they might be expected to delete the IP and only store aggregated by department.

You also said PII, not PD - note that some PII is sensitive data, which cannot be collected under LI provisions at all.

(This is not legal advice. If you think you can collect personal data with the LI exception, godspeed and I hope you have a good lawyer.)


If you're storing personal data, you need consent. A banner would be the least intrusive way to do that. (If your backend analytics don't store a cookie and don't store IPs, you may not be storing personal data to begin with.)


No.

You only need consent if there is absolutely no reason for you to have that data. Consent is the emergency hatch, only to be used in exceptional circumstances.

"But what gives?!", I hear you think. As a law professor said (roughly): it was truly amazing to see how an entire industry colluded so swiftly and completely to undermine legislation.


> You only need consent if there is absolutely no reason for you to have that data.

Also no.

There are specific acceptable reasons to have the data. LI is a weak one and does not apply in many situations (there are a lot of balancing factors applied, including a "reasonable person" standard on the data subject). As you say, consent is a very strong one, if received it can virtually always apply. The ones in-between only apply in limited situations genuinely necessary for business (company management of employee data, addresses of customers you need to ship to) or to a small set of companies (hospital management of health data, AML/KYC for banks), and rarely to general web / app analytics.

"I would like that data to serve ads better" (or "to sell to someone who wants to serve ads better") is not "absolutely no reason", but it is also rarely one of the other reasons. And conversely, even if in some case if you have a legitimate business interest i.e. would go bankrupt without it, it is not LI in the sense of GDPR if it cannot meet other factors. The modern adtech ecosystem more or less requires "consent-strength" allowances.


> If you're storing personal data, you need consent.

Could you explain this claim? I'm seeing it more often and I wonder if there's something I'm missing.

GDPR Article 6 gives five other legal bases for processing. From my reading, consent is just another basis you can use if the others don't work.


In the context of backend analytics, it is difficult-to-impossible for any of those others to apply. The point is that FE vs. BE, cookie vs. no cookie isn’t really what matters. What data you collect and why is what matters.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: