A city open Wi-Fi service logs device MAC addresses for ‘security analytics’ without discussing retention limits or other protective discipline. What GDPR security insight applies?
Select an answer to reveal the explanation.
Short Explanation
Calling it security analytics does not put the logs in a legal free-fire zone. If you collect identifiers, you still need to protect them and keep the handling tight—including how long they stick around. The shield you build for security must not become a messy pile of unprotected personal data.
Full Explanation
Processing personal data for security purposes remains subject to GDPR principles, including integrity and confidentiality and storage limitation considerations. Device identifiers such as MAC addresses can constitute personal data when they relate to an identifiable individual. Labelling the purpose ‘security’ does not exempt the controller from implementing appropriate technical and organisational measures and retention discipline for the logs themselves.