Make WordPress Core

Opened 8 years ago

Closed 7 years ago

Last modified 7 years ago

#44188 closed defect (bug) (invalid)

Error in the deployed update GDPR

Reported by: justnailedit's profile justnailedit Owned by:
Milestone: Priority: normal
Severity: normal Version: 4.9.6
Component: Privacy Keywords:
Focuses: Cc:

Description

Hi, I want to bring to your attention that in your last update "WordPress-4-9-6-privacy-and-maintenance-release" Is a technical error.

This is not a bug!

According to the GDPR, we must anonymize IP adresses and can not track them any longer in Google Tag Manager or Google analytics. I am not aware if a consent will eliminate this or not. However, I would either change or remove this paragraph in the rolled out update.

Keep up the good work
Juergen Kuhlmann

Change History (9)

#1 @desrosj
8 years ago

  • Component changed from General to Privacy
  • Keywords reporter-feedback removed
  • Severity changed from major to normal

#2 follow-up: @SergeyBiryukov
8 years ago

Hi @justnailedit, welcome to WordPress Trac! Thanks for the report.

Which paragraph would you change or remove? It's not quite clear from the ticket description.

#3 @swissspidy
8 years ago

  • Keywords reporter-feedback added

#4 in reply to: ↑ 2 @justnailedit
8 years ago

Replying to SergeyBiryukov:

Hi @justnailedit, welcome to WordPress Trac! Thanks for the report.

Which paragraph would you change or remove? It's not quite clear from the ticket description.

Hello,

under settings>privacy>Information We Collect>Non-Personally Identifiable Information

"This information may include (but is not limited to) the URL that you just came from (whether this URL is on our site or not), what browser you are using, and your IP address."

The IP Address is handled under the GDPR as Personally Identifiable Information and therefore should not be tracked!

Juergen

#5 @desrosj
8 years ago

  • Keywords 2nd-opinion added; reporter-feedback removed

This ticket was mentioned in Slack in #gdpr-compliance by desrosj. View the logs.


8 years ago

#7 @azaozz
8 years ago

The IP Address is handled under the GDPR as Personally Identifiable Information...

Where does it say so? Also, can you identify the person using 185.60.144.231 please? :)

As far as I've seen the notion that IP addresses are "personal information" is more or less a guess. Link to the court case this is based on: https://www.whitecase.com/publications/alert/court-confirms-ip-addresses-are-personal-data-some-cases.

Hoping that we will soon "know" one way or the other how "personal" IPs are :)

Last edited 8 years ago by azaozz (previous) (diff)

#8 @desrosj
8 years ago

  • Keywords reporter-feedback added

#9 @garrett-eclipse
7 years ago

  • Keywords 2nd-opinion reporter-feedback removed
  • Milestone Awaiting Review deleted
  • Resolution set to invalid
  • Status changed from new to closed

Hello thank you for opening the thread @justnailedit

I'm going to close this as the mentioned sections 'Information We Collect' > 'Non-Personally Identifiable Information' nor the quoted text exist in the policy guide verbiage. Were they possibly from a plugin?

Or perhaps the WP.org Privacy Policy - https://wordpress.org/about/privacy/
I did notice there's a section similar to your quote but indicates IP address as 'potentially personally-identifying information'
"WordPress.org also collects potentially personally-identifying information like Internet Protocol (IP) addresses. WordPress.org does not use IP addresses to identify its visitors, however, and does not disclose such information, other than under the same circumstances that it uses and discloses personally-identifying information, as described below."
*If it was the WP Privacy Policy then this verbiage seems to have changed and addresses the IP address concern.

If you have a code reference or link to the mentioned content feel free to reopen this issue.

All the best

Last edited 7 years ago by garrett-eclipse (previous) (diff)
Note: See TracTickets for help on using tickets.