# GDPR 倒计时与合规

**URL:** https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190
**Category:** Community Building
**Tags:** gdpr
**Created:** [2018年五月10日 19:08 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190 "2018-05-10T19:08:03Z")
**Posts on this page:** 1
**Showing post:** 64

<div class="post-metadata">

### Author: ![C-Alexander](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/c-alexander/32/97591_2.png) [@C-Alexander](https://meta.discourse.org/u/C-Alexander)
#### Post date: [2018年五月24日 18:36 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/64 "2018-05-24T18:36:54Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/5):
>
> es, just like the EU’s cookie law prevented use of websites without a cookie notice. Total jurisdictional destruction, worldwide, immediately preventing use of every single website without a cookie notice. 🤦‍♀️
> 
> If the argument is that the IP isn’t _necessary_ , that is fine, but filing it as a bug will be met with extreme resistance.

Except the fine is 2% of your income or up to 20 million, whichever is higher, and a horde of lawyers is wringing their hands preparing for a horde of lawsuits similar to class actions.

I don’t think you grasp the gravity of the situation - the European Union is in chaos right now, I know multiple lawyers expecting their best year ever and even public institutions are severely worried. Companies _are_ pulling their website from the EU for this reason (even Microsoft shut down two services for this reason).

Please understand - for many of us, me included, this is a make or break for our companies, careers or w/e. I don’t think many people in the EU (or with serious business in the EU) will want to take the risk. I, for one, do not condone risking every job in the company because third parties think it’ll blow over…

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/7):
>
> Well, GDPR is not causing _that_ much panic, but people do want to be sure that they’re compliant. And as long as they’re not sure, they’re not even _starting_ a forum.

Depends on the industry really, and the software. A lot of older companies are not capable of being compliant due to their nature, but in general, agreed.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/8):
>
> (1) is a much much stronger and valuable argument that applies universally. GDPR is intended to protect privacy, demonstrate how privacy is potentially impacted and then make a case for the change

We are legally obliged to offer the ability to use our services while not using any personal identifiers (including IP’s) that are not strictly needed.

Is this strictly needed to use our services?

I would argue it isn’t…

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/11):
>
> If discourse has an official page, with a big fat green checkmark next to GDPR, that could be quite good for adoption.

Agreed. I think the forums not supporting the GDPR are liable to lose a _lot_ of usage. If the lawyers get their way, people will be scrambling to get rid of anything not explicitely compliant.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/16):
>
> Hashed IPs can be brute forced fairly easily (by calculating the hash of all 2^32 IPs and finding the one that matches the relevant hash in the database). Maybe there isn’t much difference between storing a real IP, and a hashed IP?

To be fair, it’d be harder using ipv6. It could also be hashed with something else.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/22):
>
> For the record, I absolutely deplore laws like this as do a poor job of protecting our rights yet they harm millions of businesses and scare the hell out of well-meaning and ethical operators.

It’s a painful law but ultimately I think it’s possible. The simple proof ot that to my opinion is that so many businesses are in panic - as they simply had _no clue_ how they were handling sensitive data. Scary if you think about it. But I digress.

I think you’re right on most of what you said, but there’s something else I’d like to note: You’re also legally obliged to offer your service with the minimal amount of personal identifier needed for basic usage. There’s a strong argument to be made that IP’s aren’t actually needed whatsoever, but serve to enrich the service. Which means it has to be optional, according to the new law.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/29):
>
> Although I do absolutely welcome these PR’s I do want to emphasize that storing the IP addresses of visitors **without** an account (for a longer time than needed for deduplication) is a much more problematic issue since those people cannot easily be asked to give their consent.

Very much true.

And to be frank, if someone wants to avoid being seen by IP, they will be able to avoid it incredibly easily using proxies. Can be asked if simply adding a cookie doesn’t suffice to offer similar protection for less trouble. Could also store a hash of the IP \* the 6 hour period perhaps, not sure if that’d help legally.

All this said and done, let’s pray to the ip god that the lawyers dont get their way.

---

_[View the full topic](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190)._
