Jump to content

Recommended Posts

Posted

So in terms of the right to be forgotten requirement of GDPR how does this work with filtering?

 

Some services Office 365 etc may be allowed unauthenticated. This is true when using NTLM or Kerberos.

 

If a staff member or student wishes to be forgotten how can you forget logs of visiting unauthenticated domains?

 

Does there need to be a shift to use Radius /802.1x for authentication and use an intercepting proxy?

Posted

Not sure what you mean really, if they're unauthenticated websites by definition it isn't logged as who's visiting it. As normally it'll just show as an IP in filter logs etc

 

Steve

Posted

Try not to overthink it. They can make the request but if you have a legal basis for processing still then you have grounds to retain the logs.

 

If your retention schedule is clear when logs are deleted (e.g. after 6 months) then this could be considered reasonable.

 

The authenticated bit, in this case, doesn’t become important at that point as all data (remembering IP address is considered personal data) will not be kept for long.

 

If only retaining IP then you need to think about what would be needed to make that Personal Identifiable Information... normally you would have to cross-reference with the DHCP server (MAC address) to identify the device that had the lease (unless you retain that on the filter, of course) ... and so you need to think about how long those logs are kept. If only 4 weeks ... then the IP address is effectively useless after that point ... and you might not consider it personal data, but pseudononymised data instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...