On the settings page under “Advanced Settings (Etc)” there’s an option to log raw IPs naned “Log raw IPs”.
Logging raw IP addresses may not meet the EU General Data Protection Regulation (GDPR) guidelines
An explanation from Gemini:
The GDPR does not explicitly prohibit logging raw IP addresses. However, it does require that personal data be processed lawfully, fairly, and transparently. This means that website owners must have a legitimate reason for processing IP addresses and must obtain appropriate consent from users.
If a website owner is processing IP addresses for a purpose that is not considered legitimate under the GDPR, this could be considered a violation. For example, if a website owner is logging raw IP addresses for marketing purposes without obtaining explicit consent, this could be a violation.
Here are some factors to consider when determining whether logging raw IP addresses is lawful under the GDPR:
- Purpose: What is the purpose of logging IP addresses? Is it necessary for the website’s operation?
- Consent: Has the website owner obtained appropriate consent from users to process their IP addresses?
- Anonymization: Can the IP addresses be anonymized to protect user privacy?
- Retention: How long are IP addresses retained? Are they deleted after a reasonable period of time?