# GDPR and anonymizing personal data

**URL:** https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103
**Category:** Community Building
**Tags:** gdpr, privacy
**Created:** [October 15, 2017, 12:40pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103 "2017-10-15T12:40:56Z")
**Posts on this page:** 1
**Showing post:** 24

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [January 16, 2018, 8:29pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/24 "2018-01-16T20:29:18Z")

</div>

It’s a little bit (ok, a LOT) more nuanced than that, since the legitimate interest of the controller may not be overridden by the rights and freedoms of the subject. So to use your example, if the IP addresses in combination with the visited URLs can reveal sensitive information (for instance sexual preference or medical information), then the legitimate interest is overridden by the right of the individual to keep this data confidential.

> [@BlairMoir](#):
>
> If you collect data under legitimate interest you also don’t always have to delete it at the users request.

Not always, but most of the time you do have to comply. As a controller, you can only deny such a request if " _the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims_"

> [@BlairMoir](#):
>
> reply to the request within one month.

What is your source for that? GDPR says "the obligation to erase personal data _without undue delay"_

---

_[View the full topic](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103)._
