Comment by openplatypus

2 years ago

> It is covered under GDPR but I think the general consensus is that server logs containing IP addresses do not require consent.

It depends on the legal basis. If you store these IPs to render service or combat fraud, you might get away from explicit consent. However, if you use and store these IP addresses for analytics, then it is a very different conversation.

GDPR is not just about what and how you collect and use data.